AI image generation and data protection under GDPR and the EU AI Act
Reading Time: 4 minutes
Authors: 
Valeria Quadranti | Data Protection Advisor
Date: 29 July 2025
In recent months, social media platforms have seen an increase in AI-generated images that transform personal photos (including facial images) into a variety of artistic styles, often inspired by famous visual aesthetics. Among these, generators that produce images in the style of Studio Ghibli are widely used by OpenAI users. Studio Ghibli, co-founded by Hayao Miyazaki and Isao Takahata in 1985, is a Japanese animation studio known for its hand-drawn artistry, and imaginative storytelling. Ghibli’s films like My Neighbour Totoro and Princess Mononoke have largely impacted global animation and inspired many filmmakers.
While users generally value the creative possibilities offered by these technologies, critics have highlighted risks associated with sharing personal data (specifically biometric and facial information) that could inadvertently be provided to OpenAI for the purpose of improving AI models. These issues have sparked meaningful dialogue regarding data protection.
As technological advancement enables new forms of creative expression, it also requires increased vigilance and transparency to ensure individuals retain authority over their personal data.
This article explores data protection implications associated with AI tools like the one generating Studio Ghibli-style images using ChatGPT, as well as the requirements for compliance with the General Data Protection Regulation (GDPR) and EU AI Act during the implementation of similar technologies.
ChatGPT and the generation of Studio Ghibli-Style images using GPT-4.0
ChatGPT (OpenAI) is a large language model (LLM) that employs machine learning techniques to generate coherent, though not always entirely accurate, responses across a broad spectrum of subjects. LLMs contain hundreds of billions to trillions of parameters, each designed to perform specific functions. Further examples of LLMs include Google’s Gemini and Microsoft’s Copilot.
The ability to generate Studio Ghibli-style images emerged with the launch of GPT-4.0 by OpenAI on the 25th March 2025. Users can now upload photos and input textual prompts to create visuals inspired by Ghibli’s artistic approach. The underlying model utilizes an autoregressive algorithm that tokenizes image input and predicts visual features based on patterns characteristic of Studio Ghibli’s style.
Data Protection implications associated with Studio Ghibli-Style image generation
According to OpenAI’s privacy policy, the company collects both account information and user content such as file uploads. According to the said policy, Open AI may use Content provided by the user to improve their Services, for example to train the models that power ChatGPT. Users can opt out of training through ChatGPT’s privacy portal by clicking on “do not train on my content”. Once the user opts out, ChatGPT will not use new conversations to train their models. Therefore, unless users expressly opt out of training data collection or request deletion via account settings, this content may be retained and used to enhance future AI models.
Privacy and AI experts caution that uploading facial images for AI art generation exposes users to risks including potential misuse, unauthorized access, or exploitation of personal data, beyond the user's awareness or consent. Since facial images constitute biometric data, their collection and storage introduce heightened legal and ethical considerations under the GDPR and the EU AI Act. For example, the collection and processing of biometric data, classified as special category personal data under the GDPR, require a specific lawful basis, typically explicit consent. Collecting this data may involve ethical considerations, particularly regarding user awareness of how their facial data is used, including potential reuse for training or commercial purposes.
How do we ensure compliance with GDPR and the EU AI Act?
This example can be used to describe the requirements for compliance with both the GDPR and the EU AI Act when implementing and using these AI tools. These regulations are complementary, and implementation of both may be necessary in certain situations. To support compliance with both the GDPR and the EU AI Act when uploading images containing people to an AI system, the organization developing or deploying the AI system should apply several key requirements. An overview is provided below:
GDPR compliance requirements
1. Lawful Basis for processing:
- Ensure you have a valid legal basis under Article 6 GDPR. Generally, explicit consent is often the safest legal basis, especially for identifiable images.
- If the image contains special category data such as biometric data (e.g., facial features), it requires additional safeguards under Article 9 GDPR.
2. Transparency and information:
- Inform individuals that their image is being processed by an AI system.
- Clarify the purpose, data retention, and rights (Articles 13–14 GDPR).
3. Data Subject Rights:
- Enable rights, such as access, rectification, erasure, objection, and data portability.
- If automated decision-making is involved, ensure compliance with Article 22 GDPR, including the right to human intervention.
4. Data Minimisation and Purpose Limitation:
- Only collect and process data necessary for the stated purpose.
- Avoid repurposing data unless compatible with the original scope.
5. Security measures:
- Implement appropriate technical and organizational measures (Article 32 GDPR), including encryption, pseudonymization, and access controls.
6. Data Protection Impact Assessment (DPIA):
- Carry out a DPIA, required if the processing is likely to result in high risk to individuals (Article 35 GDPR), especially relevant for facial recognition or profiling.
EU AI Act compliance requirements
1. Risk classification:
- Determine if the AI system qualifies as high-risk (e.g., in case of biometric identification, decision-making affecting individuals).
2. Transparency obligations:
- Inform users that they are interacting with an AI system.
- Mark AI-generated content (e.g., stylized images) as synthetic.
3. Human oversight:
- Ensure human oversight mechanisms are in place to monitor and intervene if necessary.
4. Data governance and quality:
- Ensure training and input data are relevant and free from bias.
- Respect the original purpose of data collection and apply safeguards when using sensitive data.
5. Documentation and logging:
- Maintain logs of system use.
- Keep technical documentation demonstrating compliance (especially for high-risk systems).
6. Fundamental Rights Impact Assessment (FRIA):
- Assess whether a FRIA is needed, as it is required for certain high-risk systems, especially those used by public bodies.
The proliferation of generative AI capable of producing innovative text, images, and multimedia has intensified data protection concerns, especially as individuals increasingly upload personal content for AI-driven art creation. OpenAI's evolving strategy exemplifies the complex legal and ethical landscape characterizing this domain. Although OpenAI asserts that user content is excluded from model training unless users opt in, uncertainties remain regarding the security and ultimate handling of uploaded images, particularly those containing sensitive or personally identifiable information.
Given these concerns, users are encouraged to be cautious when sharing images containing personal data with AI platforms. Measures such as anonymizing or blurring identifiable attributes and avoiding the upload of sensitive materials are recommended best practices. Both organizations and individuals should remain informed, carefully assess potential risks, and proactively pursue responsible AI usage to uphold privacy, accountability, and trust within this rapidly advancing field.
Trilateral’s Responsible AI Services Team have extensive experience supporting organisations to comply with their AI and data protection obligations, and assess any risk relating to these. They will assist you to get ready to develop and deploy compliant and responsible AI solutions. Please feel free to contact our advisors, who would be more than happy to help.


