GDPR Photography

Last updated:
14.10.2024
Biometric data is a special category of personal data, which is why the General Data Protection Regulation (GDPR) also applies to photographers. Depending on the context in which it is practiced, photography constitutes the processing of personal data. We will clarify what you need to keep in mind regarding data protection and photography.
GDPR Photography
Key Takeaways
  • Event photography: Informing attendees via signage in accordance with GDPR.
  • Consent required for individual and children's photos.
  • Media privilege: Limited GDPR application for journalistic purposes.
  • Wedding photography: GDPR-compliant through contract fulfillment.
  • Proliance provides consulting and software for GDPR-compliant data protection.

Data protection in photography – what are the legal regulations under the GDPR?

First things first: the General Data Protection Regulation (GDPR) does not apply to family photos that are not published or to photos that do not show people in a clearly identifiable way. Furthermore, the "processing" of image files as defined in Art. 4 No. 2 GDPR applies not only to digital photography but also to analog photography. Professional photographers and media representatives should keep the following in mind:

What needs to be considered regarding data protection when taking photos?

Professional portrait photographers are particularly affected by the GDPR. To ensure compliance with data protection when taking photos, they must primarily refer to Art. 6 (1) (b) GDPR. This states that both the taking and the subsequent use of the photo are permitted if both are necessary for the performance of a contract with the person(s) depicted. In other words: if you are working on a photography assignment with a manageable number of people, such as a wedding, you do not need to worry.

Things become more difficult, however, when photographing a public event for a reportage. Theoretically, Art. 6 (1) (f) GDPR applies here. In terms of balancing interests, this states that a photographer may lawfully process a digital photo if the processing is necessary for the purposes of the legitimate interests pursued by the controller (i.e., the photographer) or by a third party, provided that the interests or fundamental rights and freedoms of the data subject (i.e., the people being photographed) are not overridden. This means that if the photographer is acting on an assignment or for their own artistic or documentary purposes, they can theoretically justify this in most cases using the aforementioned article. However, due to the complexity of this issue, an individual assessment is always required for safety, and it cannot be answered with a blanket statement.

When is a declaration of consent required?

This principle cannot be applied as a blanket rule. Individual shots that are made public or photos of children, in particular, should be clarified in advance, as the personal interest of the individual(s) outweighs other interests. However, if you are photographing at an event, for example, those present must be informed, for instance, through appropriate signage.

If you are working as a professional photographer on assignment at a party or corporate event, it is the client's duty to inform the guests via appropriate signage. Furthermore, obtaining a declaration of consent that can be signed by those present is also the responsibility of the client, not yours as the photographer. If you wish to reuse the images afterward, e.g., as a reference on your website, you will also need a declaration of consent from the people depicted.

Read here to find out about the special regulations for (internal) employee photos regarding data protection and when consent is or is not required.

Special case: Photographing people for media and press representatives

Art. 85 GDPR contains a so-called opening clause that specifically concerns the media, the press, and journalism in general: if you create photos for journalistic purposes, you are operating under the so-called "media privilege," meaning the GDPR applies only to a limited extent. This also applies to images that are demonstrably created for artistic, scientific, or literary purposes.

Common data protection mistakes in photography – how to avoid GDPR violations?

To avoid common data protection mistakes in professional photography, we recommend the following:

  • If you are photographing at an event, clarify with the organizer in advance whether all participants have been informed that photography is taking place, for example, through appropriate signage. It is also important to know whether there is a declaration of consent from everyone. If people present do not agree to being photographed, they can make themselves recognizable to you as the photographer, for example, by wearing a colored sticker on their lapel.
  • If you want to reuse images that you created on the basis of a contract, for example for your portfolio, you need a separate written declaration of consent from the respective person(s).
  • If you are demonstrably photographing for journalistic purposes, this falls under the so-called "media privilege," and you are therefore exempt from the GDPR.
  • You may only photograph children, even if it is a photography assignment, with the prior consent of their parents.
  • The interests of the people depicted generally outweigh yours if you take pictures secretly, covertly, unobserved by the subject, or in an intimate situation. In these situations, you can assume that you are violating the personal rights of the individual and are likely not permitted to take the photo.

How can Proliance support photographers with data protection?

At Proliance, we know what matters when it comes to the GDPR for photographers. We understand your everyday challenges and are your competent partner: we support you in implementing data protection requirements in your photography business. With the help of our innovative Proliance 360 data protection software you can easily integrate data protection into your daily business operations. Contact us; we would be happy to advise you.

We answer your questions about GDPR and photography

Photographing people for evidence – permissible or not?

This question is always decided on a case-by-case basis following a specific assessment. In principle, however, the following can be said: Photographing someone for evidence purposes does not necessarily constitute a violation of privacy, provided these images are neither distributed nor publicly displayed. A prerequisite for this, however, is at least that the images are not taken secretly, covertly, without the subject's knowledge, or in an intimate situation.

Is it allowed: photographing people without consent?

If you are working in a journalistic capacity, you may photograph people without their explicit consent. The same applies to demonstrably artistic, literary, or scientific purposes. However, these images must not be used for any commercial purpose. In general: if the photography cannot be justified through a balancing of interests, the consent of the data subject (i.e., the people being photographed) must be obtained.

Does the GDPR apply to private photography?

If you only take photos within your family circle and do not publish them, the GDPR does not apply. Even if you practice photography as a hobby, the GDPR generally does not apply.

Does the GDPR affect wedding photography?

If you are taking photos to fulfill a contractual relationship, as is the case at weddings where you have been hired as a photographer, you generally do not need to worry about the GDPR: both the taking and the subsequent use of the photos are permissible under the GDPR if both are necessary for the performance of a contract with the person(s) depicted – i.e., the bride and groom and their guests. Ensuring that guests at the wedding are informed about your photography activities is the responsibility of the bride and groom.

Our services at a glance

With our Proliance 360 data protection software, we help you implement your company's data protection systematically, step by step. This is how you can ensure your photography business is compliant with data protection regulations!

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in