ModelCharter

Is Luma AI (Dream Machine) GDPR compliant?

Yes

Luma AI · Video

Yes. Luma AI offers a Data Processing Agreement (DPA) for Luma AI (Dream Machine), the baseline GDPR control when a vendor processes personal data on your behalf.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

Data Processing Agreement
Confirmed
Luma AI publishes a DPA. A DPA is necessary but does not replace your own lawful-basis, DPIA and transfer assessment.
EU data residency
Not offered
No EU-residency option was confirmed in the sources reviewed for this profile.
Default data training
Opt-out required
Free and standard paid consumer tiers grant Luma rights to train on your input and output; there is no in-app opt-out for consumer tiers.
Business-tier training
No by default
Enterprise and API customers get an explicit no-training guarantee via the Enterprise agreement or API Terms.
Practical risk: Luma trains on your content on consumer tiers; only Enterprise and API get a contractual no-training guarantee. It is explicitly not HIPAA-ready and has no verified SOC 2 or ISO 27001, so treat it as a creative tool rather than a compliance-grade one.

How to make a decision

Check the precise account tier, written contract and intended data before approving Luma AI (Dream Machine). A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Luma AI (Dream Machine)

See the full Luma AI (Dream Machine) risk profile, with every data-handling fact and its source, or browse all rated AI tools.