Skip to content
Legal Analysis

Criminal Liability for Deepfakes of Public Figures in Spain

17 May 2026Updated: 

Key Takeaways

  • 95% of deepfakes are non-consented pornographic
  • Art. 197.7 CP does not reach synthetic images
  • DSA + AI Act: mandatory labelling and takedown
  • Combined criminal + civil + DSA strategy

The Spanish Criminal Code does not yet contain a specific deepfake offence, so prosecution rests on the existing offences: insult and slander (Arts. 205 et seq. CP), the offence against moral integrity (Art. 173 CP), fraud in fake commercial endorsements (Art. 248 CP), usurpation of civil status through voice deepfakes (Art. 401 CP) and, in sextortion, threats (Art. 169 CP) or extortion (Art. 243 CP). Art. 197.7 CP (non-consented sharing of intimate images) only fits real images obtained with consent, so it does not reach a purely synthetic deepfake. The right strategy combines the criminal route with the civil one (Organic Law 1/1982) and the platforms' takedown obligations (DSA and AI Act).

Need help with your case? Talk to a criminal defence lawyer at Alonso Sala.

Singers, actresses, presenters, footballers and politicians today make up the group most exposed to the mass fabrication of deepfakes. Studies indicate that over 95% of the deepfake content in circulation is pornographic and that 99% of the people depicted are women, mostly public figures. As criminal lawyers specialising in digital offences, we summarise the applicable offences, platform liability and the appropriate procedural strategy.

Casuistry: Types of Deepfake Against Public Figures

  1. Non-consented pornographic deepfake: the generation of synthetic sexual content with the victim's face superimposed on a real body. The most frequent pattern.
  2. Political or propaganda deepfake: a fake video or audio of a politician saying what they never said, for electoral manipulation or discredit.
  3. Fraudulent commercial endorsement deepfake: advertisements with the synthetic image and voice of celebrities promoting cryptocurrency or pyramid scams. We cover this type of fraud, alongside other generative AI scams, in a dedicated guide.
  4. Sextortion through deepfake: the threat of sharing a pornographic deepfake in exchange for money.

Applicable Criminal Offences

  • Art. 197.7 CP — Non-consented sharing of intimate images: it punishes sharing, without authorisation, images or recordings that the offender obtained with the victim's consent in a home or any other place out of sight of third parties, where disclosure seriously harms their privacy. The provision was designed for real images and does not expressly mention AI-generated ones, so it does not reach a purely synthetic deepfake, which is channelled into insult and offences against moral integrity. Prison of 3 months to 1 year or a fine of 6 to 12 months.
  • Arts. 205-206 CP — Slander: the false imputation of an offence through a deepfake. With publicity, prison of 6 months to 2 years.
  • Arts. 208-210 CP — Insult: harm to dignity and reputation.
  • Art. 401 CP — Usurpation of civil status: may apply to voice deepfakes through which another person's identity is fully assumed, not to a one-off use of their voice.
  • Art. 248 CP — Fraud: a fraudulent endorsement with the celebrity's synthetic image.
  • Art. 510 CP — Hate speech: a deepfake with racist or discriminatory content: 1 to 4 years and a fine if it incites hatred (Art. 510.1), or 6 months to 2 years and a fine if it harms dignity (Art. 510.2), in the upper half if spread online (Art. 510.3).

Sextortion Through Deepfake

The typical scheme consists of sending the victim a pornographic deepfake fabricated from public social-media photos and demanding a cryptocurrency payment. Here the following concur: insult and unlawful interference with honour (Arts. 205 et seq. CP and Organic Law 1/1982) for the fabricated sexual content — Art. 197.7 CP would only come into play if a real intimate image obtained with the victim's consent had been shared; Art. 169 CP (conditional threats) or Art. 243 CP (extortion) when money is demanded; and Art. 197 bis CP if there was prior computer intrusion to obtain material.

Platform Liability (DSA and AI Act)

The European framework changed radically in 2024-2026. Regulation (EU) 2022/2065, the Digital Services Act (DSA), imposes on online platforms accessible notice-and-action mechanisms, an internal complaints system, cooperation with trusted flaggers and fines of up to 6% of worldwide turnover for serious non-compliance. Regulation (EU) 2024/1689, the AI Act, provides for the mandatory labelling of content generated or manipulated by AI representing real people or events (Art. 50).

Procedural Strategy: Civil and Criminal Combined

  1. Urgent phase (first 48 hours): a notarial record of the published content, a takedown notice to the platform via the DSA.
  2. Criminal complaint: filed with the competent Investigation Section of the Court of Instance (Sección de Instrucción; formerly the Investigating Court), classifying the concurrence of offences and seeking interim measures (removal of content, prohibition of dissemination).
  3. Civil claim for the protection of honour, privacy and image (Organic Law 1/1982): with a request for compensation.
  4. Actions against the platform: an administrative claim for breach of the DSA and, where appropriate, a civil liability action if the platform kept the content after a proper notification.

State of the Regulation (June 2026)

Section updated on 12 June 2026. As of today, the Spanish Criminal Code (CP) contains no specific deepfake offence. On 26 May 2026 the Council of Ministers approved the draft Artificial Intelligence Act and sent it to Parliament: according to the official Council of Ministers statement, the bill designates the supervisory authorities for the EU AI Regulation and sets their administrative penalty regime, with fines of up to 35 million euros or 7% of turnover. Until the parliamentary procedure is completed, it is not law in force, and any reference to its content must be made in the conditional.

Prosecution today rests on the existing offences: Art. 197.7 CP — which does not reach purely synthetic images, since it requires images obtained with the victim's consent in a home or other private setting —, the offence against moral integrity (Art. 173 CP), insult and slander and, in fake commercial endorsements, fraud. In parallel, the EU AI Act, whose obligations for high-risk systems will not apply until 2 December 2027 (Regulation (EU) 2026/1744), provides in its Art. 50 for the labelling of content generated or manipulated by AI, supervised in Spain by AESIA. That labelling will make it easier to prove before a court that a video is synthetic and will strengthen takedown actions.

Are you the victim of a deepfake?

Time is critical: every hour the content remains online multiplies its dissemination. We activate the interim takedown, criminal complaint and civil action in a coordinated way.

📞 Call us: +34 91 078 65 74

Official text: article 205 of the Spanish Criminal Code (BOE)

Frequently asked questions

Is there a specific deepfake offence in Spain?

No. As of today, the Criminal Code contains no specific deepfake offence. The organic bill on artificial intelligence approved by the Council of Ministers on 26 May 2026 focuses on supervision and the administrative penalty regime of the EU AI Regulation, and until the parliamentary procedure is completed it is not law in force.

What criminal offences apply today to a deepfake?

Insult and slander (Arts. 205 et seq. CP), the offence against moral integrity (Art. 173 CP), fraud in fake commercial endorsements (Art. 248 CP), usurpation of civil status in voice deepfakes that impersonate identity (Art. 401 CP), and hate speech (Art. 510 CP). In sextortion, threats (Art. 169 CP) or extortion (Art. 243 CP) also come into play.

Does Art. 197.7 CP apply to a pornographic deepfake?

Not to a purely synthetic deepfake. Art. 197.7 CP punishes sharing real intimate images obtained with the victim's consent in a home or private place; where the content is generated entirely by AI that requirement is missing, and the conduct is channelled into insult and the offence against moral integrity (Art. 173 CP).

What liability do platforms have?

The Digital Services Act (DSA) imposes on platforms notice-and-action mechanisms, a complaints system and cooperation with trusted flaggers, with fines of up to 6% of worldwide turnover. The AI Act provides for the mandatory labelling of content generated or manipulated by AI representing real people or events (Art. 50).

How should a deepfake victim act?

By combining the criminal and civil routes. In the first 48 hours it is advisable to obtain a notarial record of the content, notify the platform of the takedown via the DSA and, where appropriate, use the Spanish Data Protection Agency's priority channel. Afterwards, file a criminal complaint requesting interim measures and a civil claim for the protection of honour, privacy and image (Organic Law 1/1982).

Do you need criminal defence in this area?

We are criminal defence lawyers specialising in cybercrime and technological criminal law. We act urgently to protect your rights.

View expertise

This page is for information purposes only and does not constitute legal advice: every case requires individual assessment. How this content is produced and verified: editorial policy.

Related Articles

View all

Before you act, speak to a criminal defence lawyer.

What you read here is just the beginning. Transform information into active defence by contacting our team of experts.