GDPR for photographers — handling client photos legally
Under the GDPR, the photos you take of people are personal data — so as a photographer you’re expected to have a lawful basis for processing them, keep them no longer than you need to, be able to honour a client’s data rights, and use tools (like your gallery platform) that are themselves compliant. None of that requires a law degree; it requires a few sensible defaults. This is general guidance, not legal advice.
Why client photos count as personal data
A photograph that identifies a person is personal data. A wedding or event set is a large amount of it, often including guests who never signed anything. That’s why the platform you deliver on, and where it stores the files, matters as much as your own paperwork.
The five things to get right
- Lawful basis. For commissioned work this is usually your contract with the client. For guests and third parties, legitimate interest is the common basis — documented, and balanced against their rights.
- Data minimisation & retention. Keep what you need for as long as you need it. Deliver galleries permanently for the client, but don’t hoard personal data with no purpose. Decide a retention approach and be consistent.
- Security. Store and transmit photos securely. Verified uploads and encrypted storage are part of this; so is not emailing hi-res sets around.
- Data-subject rights. People can ask to access or erase their data. You need a route to honour that — including asking your platform to remove specific content when required.
- Processors. Any service that stores or processes the photos on your behalf is a processor. You’re expected to have a data processing agreement (DPA) with them. More on DPAs →
Where your platform does the heavy lifting
Most of the security and processor obligations are carried by the tool you deliver on. A platform with EU data residency, a DPA on request, and GDPR-native design does a lot of this for you. A US consumer tool with opaque storage does the opposite — which is exactly why agencies, schools and public-sector clients often can’t use one.
A sensible baseline
Use a written contract, a short privacy notice, a GDPR-native delivery platform with a DPA, and a consistent retention approach. That covers the common cases for most photographers. For high-stakes or public-sector work, get a professional to review your specifics.
CuratePics is GDPR-native: EU data residency, processor paperwork on request, and a delivered-gallery permanence guarantee. See the detail →