Legal

Data Protection

First Faces Models operates across multiple countries, so the way we protect personal data has to hold up against several different legal frameworks at once — not just one.

This page sets out, region by region, which rules we follow and what rights they give you, alongside the rights and protections that apply no matter where you're based.

Compliance by region

GDPR

United Kingdom & European Union

If you're in the UK or EEA, your data is processed under the General Data Protection Regulation, giving you rights to access, correct, delete and port your data, and control over how it's used.

DPDP Act 2023

India

For users in India, we follow the Digital Personal Data Protection Act 2023, which governs consent, lawful processing and your rights to access and correct your personal data — with extra safeguards where a child's data is involved.

Privacy Act 1988

Australia

We handle Australian users' data in line with the Australian Privacy Principles under the Privacy Act 1988, covering transparent collection, secure handling, and your right to access and correct your information.

PDPL

United Arab Emirates

Data belonging to users in the UAE is handled under the UAE's Personal Data Protection Law, which covers consent, access, correction and deletion rights.

CCPA / CPRA

United States (California)

California residents are covered by the CCPA and CPRA, giving rights to access and delete personal data, opt out of its sale, and protection from discrimination for exercising those rights.

PIPEDA

Canada

For Canadian users, we follow PIPEDA's requirements around consent, purpose limitation, and your right to access and challenge the accuracy of your personal information.

PIPL

China

Data belonging to users in China is handled under the Personal Information Protection Law, one of the world's strictest privacy regimes, with firm rules around consent and cross-border data transfers.

APPI

Japan

Users in Japan are protected under the Act on the Protection of Personal Information, which we follow for transparent, accurate and secure handling of your data.

Not seeing your country listed? We still apply the same core standard everywhere we operate — secure handling, clear consent, and respect for your underlying rights — even where local law doesn't specifically require it.

Your rights, wherever you are

Regardless of which regional law applies to you, we extend the following rights to every user:

  • The right to access and receive a copy of your personal data.
  • The right to request correction or deletion of your data.
  • The right to restrict or object to how your data is processed.
  • The right to request your data be transferred to another organisation.
  • The right to withdraw consent at any time.
  • The right to lodge a complaint with your local data protection authority.

Children's data & parental consent

A large part of the information we hold relates to children. We only collect or process a child's personal data where a parent or legal guardian has created and controls the account, and consented to that processing. A parent or guardian may review, correct or request deletion of their child's data at any time.

Keeping your data secure

We apply appropriate technical and organisational safeguards to protect your data against unauthorised access, loss or misuse, including secure storage, access controls limiting who within our team can view personal data, and regular review of our security practices. Information is only shared with trusted partners where necessary to deliver our services.

If something goes wrong

In the unlikely event of a data breach affecting your personal information, we will notify affected users and the relevant regulator without undue delay, in line with the notification requirements of the law that applies to you.

Questions about how we protect your data?

Email us at [email protected] and we'll be happy to help.