Deepfakes & Data Privacy: How can users protect their data?

- Artificial intelligence creates deepfakes that manipulate images, videos, and audio.
- Deepfakes threaten data privacy through the unauthorized use of personal information.
- Deepfakes are often used for fraud, extortion, and misinformation.
- Protective measures: adjust privacy settings, avoid suspicious apps, and strengthen media literacy.
- Employee training and security protocols help prevent deepfake fraud in a business context.
Manipulating photos is becoming easier all the time. We all remember the hype surrounding an app that could make people in a photo look younger or older, or even change their gender. We are talking about FaceApp, an app that does questionable things with the data provided to it. Now, it is also becoming increasingly simple to manipulate videos. And just like that, Barack Obama appears in a video clip mocking Trump – a classic deepfake, in other words, an artificially generated video, created from an official video of the former US president. How does it work? And what do deepfakes mean for personal data?
What is a deepfake?
The term deepfake is a portmanteau of the English words "deep learning" and "fake" and describes photos, but especially videos or audio recordings, that have been created or manipulated using artificial intelligence and machine learning . For such a manipulated video, a single photo of a person is often enough to produce fake media content. While some see it as fun to use in their spare time via deepfake apps, it is highly controversial, particularly in political, economic, and social contexts. The danger of spreading fake messages or videos of, for example, heads of government spouting fabricated content is highly volatile. Consequently, there are efforts to
- make it easier to identify deepfake conten
- restrict its use, or
- criminalize unauthorized creation.
How this is to be implemented, however, remains questionable. The creation of deepfakes is still open source and theoretically accessible to everyone: according to GitHub, approx. 95% of all deepfakes are produced using the open-source software DeepFaceLab .
Deepfakes & Data Privacy – What risks and data protection breaches do deepfakes pose?
In art, education, and science, deepfakes can be and are already being used for positive purposes. However, if this technology is misused, it can have far-reaching consequences: victims are either deceived by a deepfake, or their voice, image, or video material is used to create one. The latter, in particular, poses a major problem, as the unauthorized use of a person's voice, image, or video recordings violates their right to their own image and audio/video recordings, but also constitutes an unauthorized use of sensitive personal data (e.g., biometric data).
There is currently no established legal frameworkin Germany regarding deepfakes used with malicious intent. In any case, legal clarification is needed on how to handle data protection breaches in this area.
Real-world deepfake examples
Deepfakes can literally take on many forms and, outside of the arts, are unfortunately often used for misinformation, fraud, and extortion . Some of the most well-known examples include
- Manipulated videos. In particular, the video of Barack Obama mentioned at the beginning, or a video of the supposedly intoxicated Nancy Pelosi, Speaker of the US House of Representatives, garnered millions of clicks on the internet (though the latter, to be precise, was more of a "cheap fake"). It was not immediately apparent at first glance that these were manipulated videos, and they sparked heated political debates, especially the latter.
- Manipulated audio recordings. Voices can also be affected by deepfakes and artificially generated. For example, a voice deepfake helped scammers net nearly a quarter of a million euros: at a British energy company, the voice of a parent company executive was faked to instruct one of his CEOs to make an emergency transfer of $243,000. The transfer was executed, and the money was gone.
- Manipulated images. Manipulated images are nothing new, but deepfake technology is constantly refining them, making it increasingly difficult to identify them as fakes. Particularly insidious are deepfake pornographic images or videos, which are usually created via face swapping and primarily used against female journalists or politicians. A well-known example is that of Indian author and journalist Rana Ayyub, who fights against the abuse of power in India and was targeted by a fake video intended to discredit her. Unfortunately, this is not an isolated case: according to a study by Vox Media, 96% of all deepfakes created to date are pornographic in nature.
How can users protect their data from deepfake attacks?
Protecting yourself from deepfakes is unfortunately not easy, especially if you are very liberal with your personal data and leave an active digital footprint on the internet. This means you are busy posting pictures, videos, or similar content of yourself online, for example on social platforms. In addition to actively reducing the number of images, videos, and audio recordings you post online that are easily accessible to strangers, you can:
- Adjust your privacy settings . Use social networks and all social media accounts only with the highest privacy settings so that strangers cannot access your images, videos, and audio recordings, or at least find it much harder to do so.
- Avoid dubious apps . As mentioned at the beginning, apps that can edit images or videos in a deepfake style—such as FaceApp, Fao, or wombo.ai—are very popular. However, in addition to your images (and thus biometric data), you often grant these apps unrestricted usage rights to your photos. Stay away from such apps, especially if the terms of use are very difficult to understand.
- Your media literacy Expand: You are not only at risk of becoming a victim of a deepfake attack yourself, but you can also fall for misinformation and fake news circulated via deepfake videos. To prevent this, only get your news from high-quality sources and cross-check information with other outlets.
- Your Educate your circle: Less experienced or younger internet users are often unaware of the dangers of deepfakes. Educate those around you and point out the risks involved.
Deepfake attacks are not just a private issue, but also a business environment problem, as shown in the examples above. That is why it is important to take action in a professional setting as well:
- Employee training: Most employees receive training on IT security. Make sure to include the topic of deepfake attacks in these sessions.
- Protocols: Even if a transfer seems incredibly urgent, establish security protocols that must be strictly followed. When multiple people review an instruction and processes have to pass through various security hurdles, the risk of falling for a scam decreases significantly.
- Technical and organizational measures (TOM): TOM helps secure systems and access points through backups, secure passwords, and more, or reconstructs destroyed data. This often prevents even greater damage, even if scammers have managed to bypass an initial security hurdle.
- Specialized programs: Specialized programs designed to expose deepfakes by detecting inconsistencies in image artifacts are increasingly entering the market and can provide a solution for sensitive business areas.
The issue of deepfakes is still in its infancy. Whether it will become a major problem remains a matter of speculation. Some countries are already reacting and have enacted laws against deepfakes, such as California (laws AB-602, which prohibits the synthesis of human faces to create pornographic material, and AB-730, which prohibits the manipulation of images of politicians or political candidates within 60 days of an election). Other countries still need to follow suit. Until then, our advice is: do not trust everything you see. This applies even more so to the internet.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













