Generative AI (GenAI) is a powerful tool capable of creating text, images, music and other forms of content, but its use raises serious questions about privacy and data protection. Models trained on large amounts of data often include private or sensitive information, leading to risks of data leakage and inadvertent reproduction of confidential data. The main challenges include the collection of data from different sources, the storage of personal information in the models and the possibility of generating content that reveals sensitive information. Regulatory and other data protection laws play an important role in limiting these risks, imposing requirements for transparency, consent and the right to erasure of personal data. The aim of the paper is to additionally explore the key privacy risks in GenAI, analyze the applicable regulatory requirements, and propose strategies for managing personal data that comply with modern laws and ethical standards.