Is Luma AI (Dream Machine) GDPR compliant?
YesLuma AI · Video
Yes. Luma AI offers a Data Processing Agreement (DPA) for Luma AI (Dream Machine), the baseline GDPR control when a vendor processes personal data on your behalf.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- Data Processing Agreement
- Confirmed
- Luma AI publishes a DPA. A DPA is necessary but does not replace your own lawful-basis, DPIA and transfer assessment.
- EU data residency
- Not offered
- No EU-residency option was confirmed in the sources reviewed for this profile.
- Default data training
- Opt-out required
- Free and standard paid consumer tiers grant Luma rights to train on your input and output; there is no in-app opt-out for consumer tiers.
- Business-tier training
- No by default
- Enterprise and API customers get an explicit no-training guarantee via the Enterprise agreement or API Terms.
Practical risk: Luma trains on your content on consumer tiers; only Enterprise and API get a contractual no-training guarantee. It is explicitly not HIPAA-ready and has no verified SOC 2 or ISO 27001, so treat it as a creative tool rather than a compliance-grade one.
How to make a decision
Check the precise account tier, written contract and intended data before approving Luma AI (Dream Machine). A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Luma AI (Dream Machine)
Is Luma AI (Dream Machine) HIPAA compliant?Is Luma AI (Dream Machine) SOC 2 compliant?Is Luma AI (Dream Machine) ISO 27001 certified?Does Luma AI (Dream Machine) train on your data?
See the full Luma AI (Dream Machine) risk profile, with every data-handling fact and its source, or browse all rated AI tools.