Field notes / Compliance

Consent for AI training data: what to ask your vendor

Masana15 July 20265 min read

When you buy training data that shows or records real people, the consent behind it becomes your problem as much as the vendor's. A model trained on footage nobody agreed to is a liability that does not go away after the invoice is paid. This guide covers what good consent looks like under the main privacy laws you are likely to meet, and the specific questions to put to any data vendor before you sign. This is not legal advice: use it to structure the conversation, then have your own counsel review the contracts.

Why consent is a buyer's issue

Most privacy laws put obligations on whoever decides why and how personal data is used. Once you take delivery of video, audio or images of identifiable people and train on them, you are very likely making those decisions yourself. If the original collection was weak, you inherit the weakness: you may have to delete data, retrain models, or explain to a regulator or a customer where your data came from.

There is also a practical cost. Enterprise customers and procurement teams increasingly ask for data provenance during due diligence. A vendor who can hand you signed releases, a clear purpose statement and a manifest that ties each file to a contributor makes that conversation short. A vendor who cannot makes it expensive.

What the main laws say about consent

Consent is not the only legal basis for processing personal data, but for custom collection of people's faces, voices and activities it is usually the cleanest one. Three regimes come up most often.

GDPR (European Union)

The GDPR's conditions for consent require that the controller can demonstrate consent was given, that the request is clearly distinguishable from other matters and written in clear and plain language, and that the person can withdraw consent at any time. Withdrawal must be as easy as giving consent, and the person must be told about that right before they agree. Withdrawal does not make earlier processing unlawful, but it does stop future processing.

If data is used to uniquely identify someone through biometrics, such as face or voice recognition, it falls into the special categories in Article 9, where the relevant exception is explicit consent for one or more specified purposes.

CCPA as amended by the CPRA (California)

California's statute defines consent as a freely given, specific, informed and unambiguous indication of the consumer's wishes for a narrowly defined purpose. It states that accepting general terms of use does not count, and neither does agreement obtained through dark patterns (see the definitions in Civil Code section 1798.140). The CPRA also created a category of sensitive personal information that includes processing biometric information to uniquely identify a consumer.

Indonesia's UU PDP (Law No. 27 of 2022)

Indonesia's Personal Data Protection Law was enacted in October 2022 with a two-year transition period that ended in October 2024. Consent must be explicit and given for specific purposes, and it must be written or recorded, electronically or manually. Before asking for consent, the controller must explain the purpose, the type of data, the retention period and the person's rights. The law treats biometric data and children's data as specific personal data, requires parental or guardian approval for processing children's data, gives people the right to withdraw consent, and reaches processing outside Indonesia that has legal effect in Indonesia. Practitioners also recommend that consent be presented in Bahasa Indonesia.

The common thread is clear: consent must be specific, informed, documented and revocable. A buried checkbox or a vague "data may be used to improve our services" line will not hold up well under any of them.

Questions to ask your vendor

These are the questions that separate a well-run collection program from a risky one. Ask for documents, not reassurances.

  1. Can I see a blank release form? It should name the purpose (training machine learning models), the types of data captured, who may receive it, how long it is kept and how to withdraw. Check that "AI training" or equivalent is stated plainly.
  2. What language was the release in? Contributors should sign in a language they read fluently. A release in English signed by someone who does not read English is weak evidence of informed consent.
  3. Does the release cover my use? If you plan to share data with a partner, use it for commercial models, or keep it indefinitely, the release needs to allow that. Ask whether the scope covers resale, sublicensing or derivative datasets.
  4. How is consent linked to files? Each file in the manifest should map to a contributor ID and a signed release. Without that link, you cannot act on a withdrawal request.
  5. What happens when someone withdraws? Ask how withdrawals reach you, how fast, and what the contract requires you to do. Plan for it now rather than after a request arrives.
  6. How are minors excluded? Ask how age is checked. Excluding minors entirely is simpler than managing guardian consent across jurisdictions.
  7. What about bystanders? In field and street video, passers-by have not signed anything. Ask whether faces are blurred, how the blurring is checked, and whether raw unblurred footage is retained anywhere.
  8. Were contributors paid fairly and told the truth? Consent obtained under pressure, or with misleading descriptions of the work, is not freely given. Ask how contributors are recruited and paid.
  9. Where is the data stored and transferred? Cross-border transfers carry their own rules under GDPR and UU PDP. Know where the data sits at each stage.

Red flags

  • The vendor cannot produce a sample release, or says consent is "covered in our terms".
  • Releases are in one language for contributors in several countries.
  • No per-file contributor mapping in the manifest.
  • Vague answers on bystanders, minors or withdrawal.
  • Data described as "public" or "scraped" being sold as consented.
  • Pressure to skip a pilot and go straight to a large order.

Build consent into the spec

The easiest way to get consent right is to write it into your data specification from the start. State the jurisdictions involved, require a signed release per contributor in their own language, require bystander face blurring for field footage, exclude minors, exclude brand logos if they matter to you, and require a manifest field linking every file to its release. Then check those points during a pilot before you scale. Our guide to writing a data collection spec includes a template you can adapt.

At Masana, every contributor signs a release in their own language, bystander faces in field footage are blurred, and minors are not recorded. That is the baseline we think buyers should expect from any vendor, not a premium feature.

Want to see how we handle releases, blurring and withdrawals in practice? Read our ethics and consent approach.

Read our ethics policy