Character in front of a digital vault with a padlock, icons of video files and a server, representing where confidential brief data goes

If you hire a corporate video, there’s one question worth asking the producer before you sign: where does your brief data go? The document you send contains positioning, competitive advantages, budget figures and sometimes campaign strategies that haven’t launched yet. Where it is stored, who accesses it and for how long determines whether that material stays under your company’s control — or not.

What is at stake in the brief

A corporate video brief is a strategic snapshot of your company: communication messages and tone, commercial differentiators, launch dates, high-resolution brand assets and, in internal communication projects, policies and team data. That material travels from your inbox to the producer’s systems — and the path it takes, and where it rests, is the digital sovereignty question few clients ask.

Where the data goes

Many studios involve several third-party clouds in their workflow: online editing platforms, file-storage services, AI tools for scripts or images, file sharing through public links. Each service adds an operator that needs your data, with its own retention policies, subprocessors and jurisdiction. The cloud isn’t a problem by itself; it’s a problem when the client doesn’t know about the chain. “Where do the files live?” should be as routine a question as “what is the delivery deadline?”.

Checklist: 6 questions to ask your video producer

  1. Where are the project files stored during production? — your own server, local machines or third-party cloud?
  2. Which cloud tools are part of your workflow? — editing, AI, review uploads, backups?
  3. Who has access to the files? — just the producer, or also platforms, reviewers and subcontractors?
  4. How long are files retained after delivery? — and how are they erased?
  5. Do you sign an NDA? — and does the contract cover data processing?
  6. Are deliverables in open formats? — editable and portable, without depending on a specific license or platform?

A producer with a free-software pipeline and self-hosted infrastructure answers these questions naturally. I documented mine in My animation pipeline is mostly free software: briefing in a self-hosted knowledge base, local files, own backups, no telemetry. When I use external APIs, I apply protection layers — as described in The Hidden Cost of Ready-Made AI.

What the law requires

In Brazil, the LGPD (Federal Law No. 13,709/2018) requires, in articles 46 to 49, that controllers and operators adopt technical and administrative security measures capable of protecting personal data from unauthorized access and from accidental or unlawful situations.[1] When a company hires a producer, the company is the controller and the producer the operator — and the contract should reflect that relationship, with clear instructions on how data is processed. The ISO/IEC 27001 standard serves as a reference for evaluating suppliers that handle sensitive data, including video production.[2]

For anyone operating with European data, the Schrems II ruling of the Court of Justice of the European Union (case C-311/18) showed the real cost of transferring data to third-party services outside the EU: without adequate safeguards, the transfer is invalid, and the chain of processors must be documented.[3]

Hiring with digital sovereignty

Digital sovereignty in production practice means your company’s assets — script, artwork, source files — remain under the control of who you hired, not under an invisible chain of third parties. The result: fewer leakage surfaces, portable files and compliance with data protection law as a consequence, not as an effort.

An NDA helps, but it doesn’t solve it: it protects the material, not the infrastructure that processes it. The question that really separates a common producer from one with digital sovereignty is the checklist one — where the files live and who accesses them.

I’ve been producing video and animation with free software and self-hosted infrastructure for over 20 years. If your project deals with sensitive information — and almost all do — get in touch to discuss how to structure production without giving up control over your data.

Frequently asked questions

Do video producers need an NDA?

Yes, whenever the brief contains strategic information or personal data. But the NDA doesn’t replace a contract with data-processing clauses under data protection law.

Where do my video files go after delivery?

Ask about retention: many studios keep copies in third-party cloud storage indefinitely. With self-hosted infrastructure, files remain under the producer’s control and can be erased when your company asks.

What is digital sovereignty in video production?

It’s the ability to control where project data is stored, who accesses it and for how long — instead of relying on a chain of third-party services with opaque policies.

Are my data safe if the producer uses AI?

It depends on how AI is used. The risk is sending full scripts and briefs to cloud APIs without protection layers — research shows language models can reproduce training data verbatim.[4] Ask how the producer uses AI and whether they apply anonymization, redaction of sensitive data or local models.

Do data protection laws apply to a corporate video?

They apply to the personal data the project involves — testimonials, team footage, information about mentioned clients. The brief itself may contain personal data (names, emails), which triggers the security obligations of articles 46 to 49.

References

  1. Brazilian Federal Law No. 13,709/2018 (LGPD), articles 46 to 49 — security measures and good practices for personal data processing. https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm
  2. ISO/IEC 27001 — Information Security Management Systems. https://www.iso.org/standard/27001
  3. Court of Justice of the European Union (2020) Data Protection Commissioner v Facebook Ireland Ltd (Schrems II), case C-311/18. ECLI:EU:C:2020:559. https://curia.europa.eu/juris/liste.jsf?num=C-311/18
  4. Carlini, N. et al. (2021) Extracting Training Data from Large Language Models. USENIX Security 2021. DOI: https://doi.org/10.48550/arXiv.2012.07805

Ricardo A. B. Graça · ricolandia.com