What you say is fair but if an individual's data doesn't matter, what happens when they ask to have their data deleted under GDPR. is there a way to demux their data from existing models?
While your example isn't exactly coherent (I don't think GDPR would cover photos/videos taken by the user, unless maybe the user was in the photo/video?), presumably they could just train the model again without that user's data. I doubt the end result would be that much different
GDPR isn't a magic spell. It's only relevant for personally-identifiable data: https://gdpr.eu/eu-gdpr-personal-data/