Photos of identifiable people can be personal data. Whether GDPR applies depends on who processes them, the purpose, and the territorial scope of the activity. Purely personal or household sharing may be exempt; business collection and promotional reuse need a separate assessment. A private gallery helps manage access but does not establish a lawful basis by itself.
The Short Answer
Start with the intended audience and use: a family album, an employee recap, and a public advertisement are different activities. Identify who decides why and how the photos are used, check whether GDPR applies, and document the appropriate lawful basis and information for attendees. The overview below explains the decisions to discuss with your privacy adviser for a business or public event.
When event photographs fall within GDPR
An identifiable face or a combination of details can make a photograph personal data. GDPR territorial scope is not simply a question of someone being an EU resident: Article 3 covers processing connected with an EU establishment and specified offering or monitoring activities involving people in the EU.
Article 2(2)(c) excludes processing by a person in the course of a purely personal or household activity, which is why a family celebration and a company event are treated so differently. The next section covers private parties.
For a company event, identify the organization or other party deciding the purposes and means of processing. Responsibilities depend on that role and the arrangement with photographers and service providers. A guest who contributes a photo does not thereby grant every other party permission to reuse it.
Does GDPR apply to photos at a private party?
Usually not for the host and guests. Taking photos at a birthday, wedding, or family party and sharing them with the people who were there is generally a purely personal or household activity under Article 2(2)(c). A private gallery limited to invited guests fits the same pattern, and so does a slideshow or photo wall shown to the guests in the room.
The exemption has limits. Recital 18 says social networking within personal activities can be covered, but the Court of Justice held in Lindqvist (C-101/01) that publishing personal data on the internet to an indefinite number of people is not a purely personal or household activity. Posting identifiable guests on a public profile or website can therefore fall outside it. A hired photographer, venue, or caterer processing photos for its own business is not covered by the host’s exemption, and neither is a party organized by an employer.
A private host does not usually need a photo consent form for GDPR purposes. A line on the invitation saying photos will be shared with guests, and a quick word with anyone who seems uncomfortable, is proportionate. A written form makes sense when photos will be published beyond the guests, used commercially, or include other people’s children. Some countries, including Germany and France, have separate image rights that can require permission before a recognizable photo is published, whether or not GDPR applies.
Whatever the legal position, remove a photo when a guest asks, and check before posting anyone else’s picture publicly.
Before the event: record purpose, access and a lawful basis
Write down the purpose, intended audience, retention period, removal contact, and whether photos will appear on a venue screen. Give attendees clear information before collection and an accessible way to raise concerns. A sign announcing photography provides information; attendance alone is not a substitute for valid consent.
Choose an appropriate lawful basis for the specific activity. Consent has conditions, including being freely given and withdrawable; workplace power imbalances deserve particular care. Legitimate interests requires an assessment of purpose, necessity, and competing interests. Obtain advice where the context, audience, or proposed reuse makes that assessment uncertain.
Separate gallery participation, in-room display, and external publication. Before using an image in an advertisement, consider the people depicted, the photographer’s rights, the notice given, and the permission or other basis for that particular use. Include service-provider and international-transfer checks in your organization’s review.
Handle access and deletion requests accurately
Provide an obvious contact and record when a request arrives. Under Article 12, information about action taken is generally due without undue delay and within one month. A necessary extension of up to two further months has conditions, including notifying the requester within the first month.
Article 17 sets grounds for erasure and exceptions. Assess the request rather than promising every image must be deleted within a fixed 30-day period. Where erasure applies, act without undue delay and consider recipients and copies covered by your obligations.
Removing an image from the gallery cannot recall a screenshot or a file someone has already saved. Explain what action you took and address copies under your control; do not promise deletion from every recipient’s device.
What Capture controls help you manage
Capture events are unlisted and reached through a QR code or link. Access information can be forwarded. Hosts manage approval, guest participation, and photos in the iPhone app; QR-code regeneration is also available there. Review who should retain access when changing a code.
Browser guests enter a display name without completing a registration form. The service still processes data needed to run the gallery, including guest identifiers, membership and upload timestamps, and optional comments or captions. The privacy policy explains service providers, technical information, and website analytics.
Use host moderation and a clear removal contact as part of your event plan. Review Capture’s privacy policy and any provider documentation required by your organization. These features support a workflow; they are not a certification that your event or reuse plan complies with GDPR.
What This Means for You
- Family sharing: keep the intended circle clear and reassess before public or commercial reuse.
- Business events: document purpose, audience, responsibility, lawful basis, notice, retention, and a request-handling contact.
- Gallery setup: test guest access and approval; tell attendees if contributions may appear on a screen.
- Afterward: review each proposed reuse, save permitted files in a controlled archive, and carry out your retention plan.
Sources
Keep the moments close
Every guest’s perspective.
One shared collection.
Create a private gallery, share a QR code, and bring your event’s photos together.
Start 7-day free trial Explore plans