Is HeyGen GDPR compliant?
YesHeyGen · Video
Yes. HeyGen offers a Data Processing Agreement (DPA) for HeyGen, the baseline GDPR control when a vendor processes personal data on your behalf.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- Data Processing Agreement
- Confirmed
- HeyGen publishes a DPA. A DPA is necessary but does not replace your own lawful-basis, DPIA and transfer assessment.
- EU data residency
- Not offered
- No EU-residency option was confirmed in the sources reviewed for this profile.
- Default data training
- Opt-out required
- Non-enterprise inputs and outputs may be used to train and improve HeyGen's avatar models; consumer users can request opt-out by emailing [email protected].
- Business-tier training
- No by default
- Enterprise customer data is excluded from training by default under the Master SaaS Agreement.
Practical risk: HeyGen holds SOC 2 Type II and stays US only. On consumer plans HeyGen may use your inputs to improve its models unless you email to opt out, and there is no BAA, so keep PHI out of it.
How to make a decision
Check the precise account tier, written contract and intended data before approving HeyGen. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on HeyGen
Is HeyGen HIPAA compliant?Is HeyGen SOC 2 compliant?Is HeyGen ISO 27001 certified?Does HeyGen train on your data?
See the full HeyGen risk profile, with every data-handling fact and its source, or browse all rated AI tools.