GDPR and Event Photos: A Practical Guide for 2026
- Photos of identifiable people are personal data under GDPR - for event photos, the two relevant legal grounds are consent and legitimate interest.
- Internal use (closed group, intranet) usually works with a notice plus opt-out; publishing on social media or a website requires explicit consent from identifiable people.
- Children need written parental consent - always, even at private events.
- Delete photos 30-90 days after the event, respond to erasure requests within 30 days (ideally 48 hours), and use EU-based servers with upload moderation.
Contents
- Why GDPR at Events? The Basics
- When Do You Need Consent - and When Not?
- Practical Solutions for Different Event Types
- Employee Photos: Consent and GDPR in the Workplace
- Event Photo Wall & GDPR: How to Get It Right
- Social Media & GDPR: What's Allowed?
- Common Mistakes - and How to Avoid Them
- Ready-to-Use Templates (Free)
- A Realistic Risk Assessment (No Scaremongering)
- 10 Practical Tips for GDPR-Compliant Events
- Event Photowall & GDPR: Why It Works
- FAQ: GDPR at Events
- Conclusion: GDPR Is Manageable - No Panic Needed
Many event organizers are unsure how to handle event photos in a GDPR-compliant way. The good news: it's less complicated than most people think - once you know the ground rules.
This article is not a law seminar. It gives you concrete, practical answers to the most important questions: When do you need consent? What are the rules for social media? Which mistakes should you avoid? And how do you implement all of this in practice - without making your guests wade through legal fine print for every photo?
Important: This article is general information, not legal advice. GDPR applies across the EU, but rules differ by country - national laws add their own provisions on top. Where we mention country-specific rules (for example from Germany), we say so explicitly. When in doubt, check your local regulations or consult a data protection lawyer.
Why GDPR at Events? The Basics
Since May 2018, the General Data Protection Regulation (GDPR) has applied across the entire EU. It governs how personal data may be collected, processed, and stored. Photos of identifiable people count as personal data - which is why you, as an organizer, need to follow certain rules.
The core question: May I take photos of people and use them - or do I need their permission first?
The short answer: It depends. On the type of event, on how the photos will be used, and on whether people are the focus of the image or merely incidental.
What exactly does GDPR regulate for photos?
GDPR essentially gives you six possible legal grounds for photos:
- Consent (Art. 6(1)(a) GDPR) - the person explicitly says: "Yes, you may take photos"
- Legitimate interest (Art. 6(1)(f) GDPR) - you have a legitimate interest (e.g. documenting the event) that outweighs the person's interest in protecting their data
- Contractual necessity - rarely relevant for event photos, more for product shoots
- Public interest - for public authorities or official events
- Vital interests - not relevant for events
- Legal obligation - also not relevant here
For event photos, only the first two really matter: consent or legitimate interest.
The key distinction: private vs. public events
This is the most important point to understand:
Private events (wedding, birthday, private company party):
- Closed circle, invited guests only
- Legitimate interest can be sufficient - but consent is safer
- Guests expect that photos will be taken
Public events (trade fair, concert, street festival, public conference):
- Anyone can attend, large crowds
- If people are merely incidental to the shot (audience in the background), no consent is needed
- If individuals are the focus, you need consent
Wedding example: You invite 80 guests. The guests know photos will be taken - it's part of the event. The legal argument: you have a legitimate interest in documenting your wedding, and by attending, guests have implicitly consented. But as soon as you want to publish those photos on social media, you need the explicit consent of the identifiable people (see the section "Social Media & GDPR").
Trade fair example: You photograph the exhibition hall with visitors in it. The visitors are incidental - they illustrate the atmosphere, but they're not the focus. That is generally permitted. If, on the other hand, you take a portrait shot of an individual visitor at a booth, that requires consent.
The right to your own image (a note on national laws)
On top of GDPR, many countries have additional national rules on image rights. In Germany, for example, the Art Copyright Act (Kunsturhebergesetz, KUG) applies: under § 22 KUG, images of a person may generally only be distributed or publicly displayed with their consent. The important exceptions for events are in § 23 KUG: people appearing as incidental elements next to a landscape or location, and images of gatherings and processions in which the people depicted took part. Other countries have their own image-rights or privacy laws with similar - but not identical - logic. The practical takeaway is broadly the same everywhere: close-ups of individuals need consent, while wide atmosphere shots of a public event are usually acceptable without it. If your event is outside Germany, check your country's specific rules.
When Do You Need Consent - and When Not?
Now for the practical part. Here's an overview.
✅ No consent needed (as a rule)
1. People are incidental to the shot
- Audience at a concert or talk
- Crowds at a trade fair
- Background figures in event atmosphere shots
What "incidental" means is defined above in the section "The key distinction": the people are interchangeable and not the focus of the photo.
2. Event documentation for internal purposes
- Photos of your company holiday party for the internal intranet (only employees see them)
- Wedding photos you keep private (not published)
- Team event photos in a closed employee portal
Rule of thumb: as long as the photos aren't shown publicly and are only accessible to a defined, closed group of people, the risk is low.
3. Group photos with voluntary participation
- Everyone lines up for a group photo
- People are deliberately posing
- The situation makes it obvious: "A photo is being taken here"
Anyone who deliberately joins a group photo and looks into the camera has implicitly consented. That's not written consent, but it's clear behavior that says: "I'm okay with this."
⚠️ Consent recommended or required
1. Individuals as the focus
- Portrait photos of guests
- Interviews or on-camera statements
- Photos where a person is clearly the center of attention
2. Publication on social media or a website
- Instagram posts with identifiable people
- Facebook event galleries
- Photos on your company website ("Highlights from our event")
As soon as photos are publicly accessible (internet, social media), you need consent from identifiable people.
3. Commercial use
- Photos for advertising (flyers, posters, ads)
- Marketing material (brochures, presentations)
- Photos you sell or pass on to third parties
4. Children and minors
- For children, you need the consent of their parents or legal guardians - always, even at private events. The exact age threshold varies by country, but as a rule of thumb: get parental consent for anyone under 16 (details in the section "Children's birthday or kids' event")
Practical Solutions for Different Event Types
How do you put this into practice? Here are solutions for the most common event types.
🎊 Private wedding (60-120 guests)
Situation: You're getting married, you have a photographer, and you want to collect guest photos (e.g. via a photo wall or disposable cameras).
Recommended approach:
-
Note in the invitation: Write on the invitation: "We're looking forward to lots of beautiful photos of our big day! Please note: there will be photography and filming. If you'd prefer not to appear in photos, please let us know."
-
Sign at the entrance: Put up a clearly visible sign at the venue entrance (A3 size works well): "Photos are being taken today! By joining our celebration, you agree that photos of you may be taken. The photos are just for us and our guests - not for the public. Questions? Come talk to us."
-
Offer an opt-out: Give guests a way to opt out. It can be as simple as: "Let us know if you'd rather not be photographed."
-
Social media: extra permission If you want to post wedding photos on Instagram, ask the identifiable people first (see the section "Social Media & GDPR").
Legal basis: Legitimate interest + implied consent through attendance. For social media: obtain explicit consent.
Risk: Very low, as long as you don't use the photos commercially or publish them against someone's will.
🏢 Company event (50-300 employees)
Situation: Summer party, holiday celebration, or product launch. You want photos for internal communication (intranet, newsletter) and possibly for social media (employer branding).
Recommended approach:
-
Pre-event info by email: Send an email to all attendees a week before the event: "Photos and videos will be taken at the event, which we'll use for internal communication and possibly on social media. If you'd prefer not to be photographed, contact [name/email]. Alternatively, you can wear a 'No photos please' sticker at the event (available at check-in)."
-
Opt-out stickers at check-in: Offer small red stickers at the entrance: "No photos please". Anyone wearing one is skipped by the photographer and kept off the photo wall (enable moderation).
-
Photo wall with moderation: Use a photo wall with a moderation feature. You can note in advance which employees don't want to appear in photos - and review their uploads before approval.
4. Social media: separate consent Set up a "social media release" table. Employees who agree to have their photos posted on LinkedIn, Instagram, etc. sign there briefly - this can also be done digitally on a tablet. More background on employee photos and GDPR consent in its own section below.
Legal basis: Legitimate interest (internal communication) + explicit consent (social media).
Important for companies: Document your data protection measures. Your data protection officer (if you have one) should know and sign off on the process. For larger companies, a structured consent-management process makes sense.
Risk: Medium - employees tend to be more sensitive about photos. With transparency (advance notice, opt-out), you reduce it significantly.
🎤 Public conference/trade fair (500+ attendees)
Situation: Large, publicly accessible event. You want atmosphere shots to use later on your website and social media.
Recommended approach:
-
Notice in the terms/ticket conditions: Include in the terms of participation: "Photos and video recordings will be made during the event and may be used for marketing purposes. By purchasing a ticket, you agree to this. Attendees who do not wish to be photographed can notify us during registration or at check-in."
-
Signage at the entrance: Put up large, clearly visible signs (e.g. at the entrance, in the lobby): "Please note: photography and filming are taking place at this event. The recordings may be published on our website and social media. By attending, you agree to this."
-
Photo-free zones: Set up areas where no photography takes place (e.g. a quiet room or a networking lounge with "No Photo Zone" signs).
-
Identify professional photographers: If professional photographers are roaming the event, make them identifiable (e.g. a yellow vest or a name badge saying "Photographer").
-
Moderation for audience photos: If you're running an event photo wall (audience uploads their own photos), enable the moderation feature. That way you ensure no problematic photos get published.
Legal basis: Legitimate interest (event documentation) + notice in terms + signage. For individuals in focus: obtain consent afterwards.
Risk: Medium to high - at large events, the likelihood of a complaint rises. Respond quickly to deletion requests (see below).
🎈 Children's birthday or kids' event
Situation: Event with children. Extra caution required!
For children, written consent from parents or legal guardians is essential. Here's how to handle it in practice:
-
Obtain parental consent (in writing!): Send a short form with the invitation: "May [child's name] be photographed? Yes/No. May photos be shared internally (closed group)? Yes/No. May photos be shared publicly (social media)? Yes/No."
-
Keep a list: Note which children may be photographed and which may not. Pass this information on to the photographer or the supervisors.
-
With a photo wall: no kids' uploads without permission: If children can upload photos themselves (via a photo wall), definitely enable moderation. Review every photo before it goes live.
Legal basis: Consent of the parents/legal guardians (essential!).
Risk: High. Don't compromise here - always get written consent.
Employee Photos: Consent and GDPR in the Workplace
Company events come with a special consideration: legitimate interest only covers purely internal documentation (intranet, internal photo album). As soon as you use employee photos publicly - on your website, in job ads, or on social media - you need explicit consent.
What to pay attention to:
- Voluntariness: An employment relationship involves a power imbalance. Consent must be demonstrably voluntary - no one should fear a disadvantage for saying no.
- Written form recommended: Documented consent (form, email, digital tablet) can be proven later.
- Withdrawal: Employees can withdraw their consent at any time with future effect. In that case, remove the photos in question from publication.
- State the purpose: Say clearly what the photos will be used for (e.g. "LinkedIn careers page"). A blanket consent "for everything" is risky.
That way, handling employee photos under GDPR stays transparent and provable.
Event Photo Wall & GDPR: How to Get It Right
Digital photo walls (like ours) are popular because guests can upload photos spontaneously. Data protection matters especially here, because: guests upload photos of other people, the photos are shown live on a screen (public display), and they're stored on servers.
The 5 most important GDPR features for photo walls
1. Enable moderation
Most professional photo wall tools (including Event Photowall) have a moderation feature. Uploads only go live after you've reviewed them. Especially useful for company events (control over content), public events (avoiding problematic photos), and events with children (protecting minors).
How it works: guests upload photos → you get a notification → you approve or reject the photos → only then do they appear on the screen.
2. Servers in the EU
Make sure the photo wall runs on servers in the EU. Many US providers store data in the USA - which has been more complicated since the Privacy Shield framework was struck down (keyword: the Schrems II ruling).
Event Photowall runs on Hetzner servers in Germany (EU) - data center in Falkenstein. No data sharing with third parties.
3. No sharing with third parties
Check the photo wall provider's privacy policy: are photos or data shared with third parties (e.g. tracking tools, ad networks, analytics services)? With Event Photowall, there's no sharing - the photos belong to you, we only store them temporarily.
4. Automatic deletion after the event
Don't store photos forever if you no longer need them. Many photo wall tools offer auto-deletion after X days. Rule of thumb: 30-90 days after the event is usually enough; if you need them longer for internal purposes or marketing, get consent first.
5. Notice for guests at upload
Show guests a short notice when they upload: "By uploading photos, you confirm that you hold the rights to the images and that the people shown agree to their publication."
This shifts some responsibility to the uploaders - but as the organizer, you remain responsible (see next section).
Social Media & GDPR: What's Allowed?
The most common question: "May I post event photos on Instagram?"
The answer: Only with the explicit consent of the identifiable people.
What "identifiable" means
Identifiable = the face is clearly visible
- Portraits: always identifiable
- Group photos with 5-10 people: usually identifiable
- Photos from behind/the side: it depends (if friends would recognize the person → identifiable)
- Pixelated/obscured: no longer identifiable (but often looks odd)
Not identifiable:
- A large crowd where no one stands out
- Detail shots (e.g. hands clinking glasses - no faces)
- Photos from behind where no one can be clearly identified
Practical tips for social media
Option 1: Get consent in advance
The easiest way: collect consent before the event. Example (company event):
Email to all employees: "We'll be taking photos at the event and posting the best shots on LinkedIn and Instagram. Are you okay with photos of you being published? Please reply yes or no by [date]."
Document the answers (e.g. in a spreadsheet).
Option 2: Ask afterwards (for individual photos)
You have a great photo and want to post it. Message the identifiable people (WhatsApp, email): "Hey [name], we have a great photo of you from the event - may we post it on Instagram? Here's the picture: [link/attachment]. If not, no problem!"
Option 3: Use "incidental" photos
Only post photos where people aren't the focus (the "incidental" principle from the section "The key distinction"). Examples:
- Wide shot of the venue with lots of people (atmosphere)
- Detail photos: decor, food, drinks, the DJ booth
- Shots from behind: a dancing crowd, but no faces
What does NOT work:
"But everyone joined in - that's implied consent!"
No. Attending the event does not automatically mean you may post photos publicly. Private/internal use? Yes. Public publication on social media? Requires explicit consent.
Common Mistakes - and How to Avoid Them
Mistake #1: "We don't collect consent because everyone knows anyway"
Problem: Implied agreement isn't enough for public publication. As soon as photos end up on the internet, you need explicit consent.
Solution: Make it easy for yourself - send an email, put up a sign, ask informally via WhatsApp. What matters is that you have a documented "yes".
Mistake #2: Social media without permission
Problem: You post a photo from your event on Instagram - without asking the people in it. Someone complains, demands deletion, or threatens legal action.
Solution: Either ask beforehand or only post "incidental" photos (see above).
Risk: Formal legal action over an event photo is rare, but possible. In Germany, a formal cease-and-desist letter (Abmahnung) typically costs somewhere between several hundred and a couple of thousand euros plus legal fees; costs in other countries vary.
Mistake #3: Photographing children without parental permission
Problem: At a kids' event, photos are cheerfully taken and posted in the WhatsApp group chat. Some parents react with outrage - rightly so.
Solution: Always - really always - ask the parents first. In writing.
Mistake #4: Storing photos for years without reason
Problem: You keep event photos on your server for years even though you no longer need them. GDPR says: store data only as long as necessary (the principle of storage limitation).
Solution: Delete according to the rule of thumb above (30-90 days), or set up automatic deletion.
Mistake #5: Ignoring deletion requests
Problem: Someone writes to you: "Please delete the photo of me in your Instagram post." You ignore the message.
Legal situation: The person has a right to erasure (Art. 17 GDPR). You must respond - and quickly (within 30 days, ideally sooner).
Solution: Take deletion requests seriously. Reply within 48 hours, delete the photo, and confirm the deletion.
Ready-to-Use Templates (Free)
Here are practical templates you can use right away.
Template 1: Note in the wedding invitation
We're looking forward to lots of beautiful memories of our big day!
Please note: photos and videos will be taken during the celebration. They are just for us and for you - not for the public. If you'd prefer not to be photographed, please let us know in advance.
We've also set up a digital photo wall. Scan the QR code at the entrance and upload your favorite moments!
Template 2: Privacy notice for company events (email)
Subject: [Event name] - Info on photo/video recordings
Dear colleagues,
We're looking forward to our [event name] on [date]!
**Note on photos and videos:**
Photos and video recordings will be taken during the event. We'll use them for our internal communication (intranet, newsletter) and possibly on our social media channels (LinkedIn, Instagram).
If you'd prefer not to be photographed, please contact [name/email] or wear a "No photos" sticker, available at check-in.
For social media posts, we'll ask for your consent separately - either in advance or before publication.
Questions? Get in touch anytime!
Best regards,
[Name/signature]
Template 3: Sign at the entrance (A3 poster)
📸 NOTICE: PHOTOGRAPHY IN PROGRESS
Photos and video recordings are being taken at this event.
The recordings will be used for [internal documentation / marketing / social media].
By attending, you agree to this.
Prefer not to be photographed? Let us know at check-in!
Template 4: Consent form (kids' event)
CONSENT FORM - PHOTOGRAPHY
I hereby consent to my child [child's name] being photographed/filmed at the event [event name] on [date].
☐ Yes, my child may be photographed (for internal purposes, e.g. photo album)
☐ Yes, photos may be shared in a closed group (e.g. WhatsApp group)
☐ Yes, photos may be shared publicly (website, social media)
☐ No, my child may not be photographed
Place, date: _________________
Signature (parent/legal guardian): _________________
Template 5: Privacy text for the photo wall (at upload)
By uploading photos, you confirm:
- You hold the rights to the images
- The people shown agree to their publication
- The photos do not violate applicable law
The photos are stored on our servers in Germany (EU) and [automatically deleted 30 days after the event / used for internal purposes only].
A Realistic Risk Assessment (No Scaremongering)
How high is the real risk of getting into trouble?
Very low risk:
- Private wedding, internal use: Practically zero. Your guests are not going to sue you.
- Small company events (under 50 people), no social media posts: Very unlikely that anyone takes legal action.
Medium risk:
- Company events with social media posts: Someone might complain or demand deletion. Costs you time and nerves, but rarely gets truly expensive.
- Public events without clear notices: If someone complains and you had no signs or terms in place, you're in a weaker position.
Higher risk:
- Kids' events without parental permission: Here, real legal consequences are possible. Parents have strong arguments and take this seriously.
- Commercial use without consent: If you use event photos for advertising (posters, ads) without permission, you risk formal legal claims.
What happens in the worst case?
Scenario 1: Deletion request Someone writes: "Delete the photo of me." You delete it. Done. No costs.
Scenario 2: Formal legal claim Someone has a lawyer send you a formal demand. In Germany, a cease-and-desist letter (Abmahnung) plus damages typically runs to several hundred up to a couple of thousand euros; elsewhere, costs depend on your country's legal system. Unpleasant, but not the end of the world.
Scenario 3: Regulatory fine (GDPR violation) In theory, data protection authorities can impose fines (up to €20 million or 4% of annual turnover). In practice, this almost never happens over event photos - fines are typically reserved for large data breaches or systematic violations.
Reality: Most problems can be solved by reacting quickly and deleting. Lawsuits over event photos are extremely rare - except in serious cases (e.g. publishing children's photos without permission).
10 Practical Tips for GDPR-Compliant Events
To wrap up: a quick checklist you can run through for every event.
1. Communicate transparently
Tell attendees in advance that photos will be taken. Email, invitation, terms - use whatever channels you have.
2. Offer an opt-out
Give people the chance to say no. Stickers, a list, an email - however you do it, make sure there's an option.
3. Distinguish: internal vs. public
Internal use (intranet, closed group) requires less strict consent than public posts (Instagram, website).
4. Enable moderation on photo walls
If guests can upload photos themselves, review the uploads before approval.
5. Children = always ask the parents
No exceptions. Always in writing.
6. Servers in the EU
Make sure your photo wall or cloud runs on EU servers.
7. Delete photos after the event
Don't store photos forever. 30-90 days is usually enough.
8. React quickly to deletion requests
If someone says "delete that photo", do it immediately. No arguments.
9. Document your processes
Note how you obtained consent (email, sign, form). If questions come up, you can prove you did things right.
10. When in doubt: ask one more time
If you're unsure whether a photo is okay - ask the person. Takes 30 seconds and prevents trouble.
Event Photowall & GDPR: Why It Works
Our tool, Event Photowall, is built GDPR-compliant from the ground up. What that means in practice:
Servers in Germany (EU)
All photos are stored on servers in Germany (see the photo wall section above). No US servers, no data sharing with third parties.
No tracking tools or ad networks
Event Photowall uses no Google Analytics, no Facebook pixel, no tracking cookies. Your guests are not tracked.
Moderation & control
You decide which photos go live. With the moderation feature (in the Triathlon package), you review every upload before approval.
Automatic deletion
You can configure all photos to be automatically deleted X days after the event. Or download them beforehand and delete them manually.
Transparency for guests
Guests see a privacy notice at upload. They know what happens to their photos.
No vendor lock-in
You can download all photos as a ZIP file at any time. The photos belong to you - not to us.
Price: Triathlon package with moderation, custom branding, and GDPR features: €169 (up to 4,000 photos, no subscription).
FAQ: GDPR at Events
Do I need consent for a private wedding?
For the wedding itself (internal use of the photos): generally no - a note in the invitation plus a sign at the entrance is enough. For social media posts: yes, get consent.
What if someone says: "Delete that photo"?
Delete it and briefly confirm - the details are above under "Mistake #5: Ignoring deletion requests".
Do I have to collect consent in writing?
No, not necessarily. An email or WhatsApp message is enough. What matters is that you can prove the consent (screenshot, saved email, etc.).
Is a sign at the entrance enough as consent?
For internal use (no public publication): yes, that can count as implied consent. For social media: better to ask explicitly.
What does a legal claim over event photos cost?
It varies by country. In Germany, a formal cease-and-desist letter (Abmahnung) plus possible damages typically amounts to several hundred up to a couple of thousand euros. It rarely comes to that, though - usually deleting the photo settles the matter.
How long may I store event photos?
As long as you need them. Rule of thumb: 30-90 days after the event is enough. Then delete - unless you have a legitimate reason (e.g. marketing with consent).
Does GDPR also apply to private events?
Yes, but less strictly. GDPR generally applies to private individuals too - but there's an exception for "purely personal or household activities" (Art. 2(2)(c) GDPR). As long as you keep your wedding photos private, you're on the safe side. As soon as you post them publicly, GDPR applies again.
Do I need a data protection officer?
Under GDPR, a data protection officer is mandatory only in specific cases - for example, if your core activities involve large-scale processing of personal data or sensitive data (e.g. health data). Some countries add their own thresholds: in Germany, for instance, companies generally need one once at least 20 people regularly process personal data. For a private wedding: no.
What about livestreams of events?
Livestreams (e.g. hybrid events) are sensitive from a data protection perspective because they're broadcast live to the internet. Solution: notify people in advance (email, signage), only stream the stage/speakers (not the audience), or inform the audience beforehand and offer an opt-out.
Conclusion: GDPR Is Manageable - No Panic Needed
GDPR at events is entirely manageable. Yes, there are a few things to keep in mind. But with common sense, transparency, and a few simple measures, you're on the safe side.
The three most important rules:
- Communicate transparently: Tell people in advance that photos will be taken.
- Respect boundaries: If someone doesn't want to be photographed, accept it.
- Delete proactively: Don't store photos forever if you no longer need them.
Don't drive yourself crazy. The vast majority of events run smoothly - as long as you handle your guests' data honestly and respectfully.
A GDPR-compliant photo wall for your next event?
Event Photowall runs on servers in Germany (EU), offers moderation and automatic deletion. Triathlon package: €169 (no subscription, up to 4,000 photos).
More helpful pages:
- Social Wall for Corporate Events: More Engagement
- Digital Wedding Guest Book: All Options Compared
- Collecting Wedding Photos from Guests: The Best Methods
Sources & further reading:
- Official GDPR text: eur-lex.europa.eu
- European Data Protection Board (guidelines): edpb.europa.eu
- In Germany - Art Copyright Act (KUG): gesetze-im-internet.de
- In Germany - Federal Commissioner for Data Protection: bfdi.bund.de
Disclaimer: This article does not replace legal advice. Rules differ by country - for complex cases or legal uncertainties, please consult a data protection lawyer in your jurisdiction.
Published January 28, 2025 | Reading time: approx. 11 minutes | Category: Tech