Kept

GDPR and company event photos: what HR actually needs to know

By Andrew Tjong · Published 15 August 2026

Photos of identifiable employees at a company event are personal data under the GDPR, so you need a lawful basis to collect and share them, usually consent (Article 6(1)(a)) or legitimate interest (Article 6(1)(f)). The bigger practical risk is losing control of copies: scattered WhatsApp exports and personal phones make erasure requests impossible to honour.

That is the short version. The rest of this guide unpacks what those words actually mean in practice, what the European Data Protection Board (EDPB) says about employee consent, and what to do when someone asks you to delete a photo. It is practical guidance for HR and office managers, not legal advice. For anything contested, talk to your data protection officer or a lawyer.

First, the basics: are event photos really personal data?

Yes, when people are identifiable in them. The GDPR's definition of personal data (Article 4(1)) covers any information relating to an identified or identifiable natural person, and a clear photo of a colleague's face qualifies.

One common misconception worth clearing up: photos are not automatically "special category" biometric data. Recital 51 says the processing of photographs should not systematically be considered special category processing, because photos only count as biometric data when processed through specific technical means allowing unique identification, such as facial recognition. A normal event album does not do that. So you are in ordinary personal data territory, which is more forgiving, but still regulated.

The "household exemption" (Article 2(2)(c)) does not rescue you either. It covers purely personal or household activity. A company organising, collecting, or publishing photos of its own event is acting as an organisation, not a private individual, so the company is a controller and the GDPR applies.

Lawful basis: consent or legitimate interest?

You have two realistic options for event photos, and each has a catch.

Option 1: Consent (Article 6(1)(a))

Consent must be freely given, specific, informed, and unambiguous (Article 4(11)). Under Article 7 you must also be able to demonstrate that consent was given (Article 7(1)), and withdrawing consent must be as easy as giving it (Article 7(3)).

The catch in an employment setting is the power imbalance, covered in detail below. The practical catch is Article 7(3): if someone withdraws consent, you must be able to act on it. If the photos have already spread across a WhatsApp group and a dozen camera rolls, you cannot.

Option 2: Legitimate interest (Article 6(1)(f))

Legitimate interest lets you process personal data where it is necessary for your legitimate interests, except where those interests are overridden by the interests or fundamental rights and freedoms of the data subject. That "except where" clause is a balancing test, and you are expected to actually run it, usually as a short written legitimate interest assessment (LIA).

Recital 47 tells you what the balance turns on: the reasonable expectations of data subjects based on their relationship with the controller, at the time and in the context of collection. Concretely:

Legitimate interest also comes with the right to object (Article 21(1)). If an employee objects, you can only continue if you demonstrate compelling legitimate grounds that override their interests, rights and freedoms. For a party photo, you almost never will. In practice an objection means you take the photo down.

A workable rule of thumb many EU organisations follow: legitimate interest for low-key internal sharing with clear advance notice and an easy opt-out, explicit consent for anything public-facing or promotional. Whichever basis you choose, Article 13 still requires you to tell people what you are doing: who the controller is, the purpose, the basis, who will see the photos, and how long you keep them. A short notice on the event invite and a sign at the venue covers most of this.

Employee consent and the power imbalance problem

This is the part HR teams most often get wrong, so it deserves its own section.

Recital 43 says consent should not provide a valid legal ground where there is a clear imbalance between the data subject and the controller. The EDPB's Guidelines 05/2020 on consent apply this squarely to employment: given the dependency in the employer/employee relationship, it is unlikely an employee can refuse consent without fearing detrimental effects (paragraph 21). The EDPB concludes that for the majority of data processing at work, the lawful basis "cannot and should not" be employee consent (paragraph 23).

That sounds like consent is dead at work. It is not, quite. The EDPB accepts employee consent in exceptional cases where refusing carries no adverse consequences at all. Their own worked example (Example 5 in the same guidelines) is close to our topic: a film crew records in an office, employees who decline are simply given equivalent desks elsewhere for the duration, and nobody is penalised. That consent can be valid.

Translated to your event:

Practical implication: make opting out quiet and easy. A checkbox on the RSVP, a coloured lanyard or sticker system, or a named list held by the photographer all work better than asking people to raise their hand in front of colleagues.

The real compliance problem: scattered copies

Here is the uncomfortable truth about most company events. The legal analysis above assumes the company controls the photos. Usually it does not. Photos live on thirty personal phones, get dumped into a WhatsApp group, auto-save to thirty personal cloud accounts, and get reshared into side chats. At that point:

WhatsApp groups also blur the controller question. Was that photo shared as a private act between colleagues, or as part of the company's event? The employee who took it may believe they are in household-exemption territory. The company that encouraged "share your pics in the group!" probably is not. Ambiguity like this is exactly what a DPA will pick apart after a complaint.

The fix is structural, not legal: collect photos into one place the organisation actually controls, from the start, and make that the norm for the event.

The right to erasure in practice

When an employee (or an ex-employee) asks you to delete photos of them, here is how Article 17 plays out:

  1. Check the ground. Erasure applies where the data is no longer necessary (17(1)(a)), where consent is withdrawn and no other basis applies (17(1)(b)), or where they object under Article 21 and you have no overriding grounds (17(1)(c)). For event photos, one of these almost always applies. Plan to delete, not to argue.
  2. Act without undue delay.That is the statutory wording. In practice, treat it as days, not weeks, and note the GDPR's general one-month outer limit for responding to data subject requests (Article 12(3)).
  3. Chase the copies. If you made the photos public, Article 17(2) requires reasonable steps, taking account of available technology and cost, to inform other controllers processing the data that erasure was requested. If the photos went to a public social account, that means taking the post down and contacting anyone you passed them to.
  4. Keep a short record. Who asked, when, what you deleted, when you confirmed. That is your Article 5(2) accountability trail.

The lesson to take upstream: the effort of an erasure request is proportional to how far the photos spread. One controlled album, one delete action, one confirmation email. Thirty camera rolls, no realistic path to compliance.

How a controlled single album maps to these duties

This is where we should be upfront: we make Kept, a guest photo camera for events, so we have a product interest here. No tool makes you GDPR compliant, and anyone claiming otherwise is overclaiming. What a controlled album does is make the duties above mechanically possible:

What it does not do: choose your lawful basis, write your LIA, or stop someone photographing the event on their own phone anyway. Those remain your job, and the checklist below covers them. If you run company events, the practical setup is described on our corporate events page and in the offsite photo playbook.

Practical checklist for your next event

Before the event:

During the event:

After the event:

Common questions

Do we need written consent from every employee before taking photos at a company party?

Not necessarily. For an internal album with clear advance notice and an easy opt-out, legitimate interest (Article 6(1)(f)) is often the more honest basis, because the EDPB doubts employee consent is freely given (Guidelines 05/2020, paragraphs 21 to 23). Reserve explicit consent for public or promotional use of identifiable photos.

Is a photo of an employee biometric data?

No, not in normal use. Recital 51 states photos are only biometric data when processed through specific technical means for unique identification, such as facial recognition. An ordinary event album is regular personal data, still protected, but not special category.

An ex-employee wants all photos of them deleted. Do we have to comply?

Almost always, yes. Article 17 grounds will usually apply: the photos are no longer necessary, consent (if used) is withdrawn, or they object and you have no compelling overriding grounds (Article 21(1)). Delete without undue delay, and if the photos were made public, take reasonable steps to inform anyone you shared them with (Article 17(2)).

Employees shared party photos in a private WhatsApp group. Is that the company's problem?

It can be. Purely personal sharing between colleagues may fall under the household exemption (Article 2(2)(c)), but if the company created or encouraged the group as the event's photo channel, the company is likely a controller for it, with duties it cannot practically fulfil there. Safer approach: give people one company-controlled place for event photos and keep official sharing out of private chats.

Can we put event photos on our public LinkedIn or website?

Only with care. Public posting is a significant step beyond internal sharing, and reasonable expectations (Recital 47) are much weaker. Best practice, and the direction most DPA guidance points: get specific consent from identifiable individuals for public use, and honour any later withdrawal by taking the image down.

How long can we keep event photos?

The GDPR sets no fixed number, but Article 5(1)(e) requires you to keep personal data no longer than necessary for the purpose. Pick a defensible period when you plan the event, state it in your notice, and actually delete on that date.

This article is general information for HR and office managers, not legal advice. Rules are applied by national data protection authorities, and details vary by country. When in doubt, ask your DPO or a data protection lawyer.

Sources

Kept is in App Review and arrives on the App Store soon

Want it for your wedding? Join the waitlist with your date and we'll email you on opening day. If your wedding is too soon to wait, say so: we'll get you set up early. No spam, ever.

Join the waitlist

Button not opening your mail app? Email hello@kept.pictures with your wedding date.