GDPR and company event photos: what HR actually needs to know
By Andrew Tjong · Published 15 August 2026
Photos of identifiable employees at a company event are personal data under the GDPR, so you need a lawful basis to collect and share them, usually consent (Article 6(1)(a)) or legitimate interest (Article 6(1)(f)). The bigger practical risk is losing control of copies: scattered WhatsApp exports and personal phones make erasure requests impossible to honour.
That is the short version. The rest of this guide unpacks what those words actually mean in practice, what the European Data Protection Board (EDPB) says about employee consent, and what to do when someone asks you to delete a photo. It is practical guidance for HR and office managers, not legal advice. For anything contested, talk to your data protection officer or a lawyer.
First, the basics: are event photos really personal data?
Yes, when people are identifiable in them. The GDPR's definition of personal data (Article 4(1)) covers any information relating to an identified or identifiable natural person, and a clear photo of a colleague's face qualifies.
One common misconception worth clearing up: photos are not automatically "special category" biometric data. Recital 51 says the processing of photographs should not systematically be considered special category processing, because photos only count as biometric data when processed through specific technical means allowing unique identification, such as facial recognition. A normal event album does not do that. So you are in ordinary personal data territory, which is more forgiving, but still regulated.
The "household exemption" (Article 2(2)(c)) does not rescue you either. It covers purely personal or household activity. A company organising, collecting, or publishing photos of its own event is acting as an organisation, not a private individual, so the company is a controller and the GDPR applies.
Lawful basis: consent or legitimate interest?
You have two realistic options for event photos, and each has a catch.
Option 1: Consent (Article 6(1)(a))
Consent must be freely given, specific, informed, and unambiguous (Article 4(11)). Under Article 7 you must also be able to demonstrate that consent was given (Article 7(1)), and withdrawing consent must be as easy as giving it (Article 7(3)).
The catch in an employment setting is the power imbalance, covered in detail below. The practical catch is Article 7(3): if someone withdraws consent, you must be able to act on it. If the photos have already spread across a WhatsApp group and a dozen camera rolls, you cannot.
Option 2: Legitimate interest (Article 6(1)(f))
Legitimate interest lets you process personal data where it is necessary for your legitimate interests, except where those interests are overridden by the interests or fundamental rights and freedoms of the data subject. That "except where" clause is a balancing test, and you are expected to actually run it, usually as a short written legitimate interest assessment (LIA).
Recital 47 tells you what the balance turns on: the reasonable expectations of data subjects based on their relationship with the controller, at the time and in the context of collection. Concretely:
- Internal album of a summer party, clearly announced in advance, shared only within the company: most employees would reasonably expect this. Legitimate interest is defensible.
- Publishing those same photos on the company's public LinkedIn or website: a much bigger intrusion, weaker expectations, and many DPAs and DPOs will steer you towards consent for external use.
Legitimate interest also comes with the right to object (Article 21(1)). If an employee objects, you can only continue if you demonstrate compelling legitimate grounds that override their interests, rights and freedoms. For a party photo, you almost never will. In practice an objection means you take the photo down.
A workable rule of thumb many EU organisations follow: legitimate interest for low-key internal sharing with clear advance notice and an easy opt-out, explicit consent for anything public-facing or promotional. Whichever basis you choose, Article 13 still requires you to tell people what you are doing: who the controller is, the purpose, the basis, who will see the photos, and how long you keep them. A short notice on the event invite and a sign at the venue covers most of this.
Employee consent and the power imbalance problem
This is the part HR teams most often get wrong, so it deserves its own section.
Recital 43 says consent should not provide a valid legal ground where there is a clear imbalance between the data subject and the controller. The EDPB's Guidelines 05/2020 on consent apply this squarely to employment: given the dependency in the employer/employee relationship, it is unlikely an employee can refuse consent without fearing detrimental effects (paragraph 21). The EDPB concludes that for the majority of data processing at work, the lawful basis "cannot and should not" be employee consent (paragraph 23).
That sounds like consent is dead at work. It is not, quite. The EDPB accepts employee consent in exceptional cases where refusing carries no adverse consequences at all. Their own worked example (Example 5 in the same guidelines) is close to our topic: a film crew records in an office, employees who decline are simply given equivalent desks elsewhere for the duration, and nobody is penalised. That consent can be valid.
Translated to your event:
- Consent to appear in event photos can be valid if saying no is genuinely cost-free: no manager pressure, no awkward singling out, no career subtext, and a real way to participate in the event without being photographed.
- Consent is not valid if it is bundled into attendance ("by attending you agree to be photographed"), collected by someone's direct manager face to face, or if refusing means missing the event.
Practical implication: make opting out quiet and easy. A checkbox on the RSVP, a coloured lanyard or sticker system, or a named list held by the photographer all work better than asking people to raise their hand in front of colleagues.
The real compliance problem: scattered copies
Here is the uncomfortable truth about most company events. The legal analysis above assumes the company controls the photos. Usually it does not. Photos live on thirty personal phones, get dumped into a WhatsApp group, auto-save to thirty personal cloud accounts, and get reshared into side chats. At that point:
- You cannot demonstrate anything. Article 5(2) makes you accountable for compliance and able to demonstrate it. You cannot demonstrate control over copies you do not know exist.
- You cannot honour withdrawal.Article 7(3) says withdrawing consent must be as easy as giving it. There is no mechanism to withdraw a photo from a WhatsApp group's thirty camera rolls.
- You cannot honour erasure. Article 17 requires deletion without undue delay. Deleting the original while copies persist everywhere is not erasure, it is theatre.
- You cannot enforce retention limits. Article 5(1)(e) (storage limitation) expects you to keep personal data no longer than necessary. Personal camera rolls have no retention policy.
WhatsApp groups also blur the controller question. Was that photo shared as a private act between colleagues, or as part of the company's event? The employee who took it may believe they are in household-exemption territory. The company that encouraged "share your pics in the group!" probably is not. Ambiguity like this is exactly what a DPA will pick apart after a complaint.
The fix is structural, not legal: collect photos into one place the organisation actually controls, from the start, and make that the norm for the event.
The right to erasure in practice
When an employee (or an ex-employee) asks you to delete photos of them, here is how Article 17 plays out:
- Check the ground. Erasure applies where the data is no longer necessary (17(1)(a)), where consent is withdrawn and no other basis applies (17(1)(b)), or where they object under Article 21 and you have no overriding grounds (17(1)(c)). For event photos, one of these almost always applies. Plan to delete, not to argue.
- Act without undue delay.That is the statutory wording. In practice, treat it as days, not weeks, and note the GDPR's general one-month outer limit for responding to data subject requests (Article 12(3)).
- Chase the copies. If you made the photos public, Article 17(2) requires reasonable steps, taking account of available technology and cost, to inform other controllers processing the data that erasure was requested. If the photos went to a public social account, that means taking the post down and contacting anyone you passed them to.
- Keep a short record. Who asked, when, what you deleted, when you confirmed. That is your Article 5(2) accountability trail.
The lesson to take upstream: the effort of an erasure request is proportional to how far the photos spread. One controlled album, one delete action, one confirmation email. Thirty camera rolls, no realistic path to compliance.
How a controlled single album maps to these duties
This is where we should be upfront: we make Kept, a guest photo camera for events, so we have a product interest here. No tool makes you GDPR compliant, and anyone claiming otherwise is overclaiming. What a controlled album does is make the duties above mechanically possible:
- One place, known copies. Guests scan a QR code and shoot in the browser. Photos land in a single album the host controls, instead of thirty camera rolls. Your Article 5(2) accountability story becomes describable in one sentence.
- Join by name. Contributors identify themselves when they join, so you know who took what, which helps when tracing a photo someone wants removed.
- Host can delete anything. An erasure request under Article 17 becomes an actual deletion you can perform and confirm, not a plea into a group chat.
- No public spray by default. Nothing is posted publicly unless you choose to publish it, which keeps you out of Article 17(2) notify-other-controllers territory.
- A clear announcement moment."Scan this code, photos go into the company album, here is the notice" is also your Article 13 transparency notice happening naturally.
What it does not do: choose your lawful basis, write your LIA, or stop someone photographing the event on their own phone anyway. Those remain your job, and the checklist below covers them. If you run company events, the practical setup is described on our corporate events page and in the offsite photo playbook.
Practical checklist for your next event
Before the event:
- Decide your lawful basis. Internal-only album: legitimate interest with a short written LIA is usually defensible. Public or promotional use: collect specific consent for that use.
- Write a two-paragraph photo notice: what is collected, why, who sees it, how long you keep it, how to opt out or request deletion, who to contact. Put it on the invite and at the venue (Article 13).
- Set up the opt-out so it is quiet: RSVP checkbox, lanyard or sticker, or a list for the photographer. No hand-raising in front of the team.
- Pick one collection point for photos and tell everyone that is the place. Explicitly ask people not to start a parallel WhatsApp thread.
- Set a retention date now (Article 5(1)(e)). "Album deleted after 12 months" is a policy. "We'll see" is not.
During the event:
- Brief whoever is photographing (staff or hired) on the opt-out signals.
- Point casual snappers to the single album, not the group chat.
After the event:
- Review the album before wider sharing and remove anything unflattering, sensitive, or featuring opted-out colleagues.
- Get specific consent from the individuals pictured before anything goes on public channels.
- Log and action any deletion requests without undue delay (Article 17), and record what you did.
- Delete the album on the retention date you set.
Common questions
Do we need written consent from every employee before taking photos at a company party?
Not necessarily. For an internal album with clear advance notice and an easy opt-out, legitimate interest (Article 6(1)(f)) is often the more honest basis, because the EDPB doubts employee consent is freely given (Guidelines 05/2020, paragraphs 21 to 23). Reserve explicit consent for public or promotional use of identifiable photos.
Is a photo of an employee biometric data?
No, not in normal use. Recital 51 states photos are only biometric data when processed through specific technical means for unique identification, such as facial recognition. An ordinary event album is regular personal data, still protected, but not special category.
An ex-employee wants all photos of them deleted. Do we have to comply?
Almost always, yes. Article 17 grounds will usually apply: the photos are no longer necessary, consent (if used) is withdrawn, or they object and you have no compelling overriding grounds (Article 21(1)). Delete without undue delay, and if the photos were made public, take reasonable steps to inform anyone you shared them with (Article 17(2)).
Employees shared party photos in a private WhatsApp group. Is that the company's problem?
It can be. Purely personal sharing between colleagues may fall under the household exemption (Article 2(2)(c)), but if the company created or encouraged the group as the event's photo channel, the company is likely a controller for it, with duties it cannot practically fulfil there. Safer approach: give people one company-controlled place for event photos and keep official sharing out of private chats.
Can we put event photos on our public LinkedIn or website?
Only with care. Public posting is a significant step beyond internal sharing, and reasonable expectations (Recital 47) are much weaker. Best practice, and the direction most DPA guidance points: get specific consent from identifiable individuals for public use, and honour any later withdrawal by taking the image down.
How long can we keep event photos?
The GDPR sets no fixed number, but Article 5(1)(e) requires you to keep personal data no longer than necessary for the purpose. Pick a defensible period when you plan the event, state it in your notice, and actually delete on that date.
This article is general information for HR and office managers, not legal advice. Rules are applied by national data protection authorities, and details vary by country. When in doubt, ask your DPO or a data protection lawyer.
Sources
- GDPR Article 4 (definitions, including consent at 4(11))
- GDPR Article 5 (principles, storage limitation, accountability)
- GDPR Article 6 (lawful bases)
- GDPR Article 7 (conditions for consent)
- GDPR Article 13 (information to be provided)
- GDPR Article 17 (right to erasure)
- GDPR Article 21 (right to object)
- GDPR Recital 43 (freely given consent, clear imbalance)
- GDPR Recital 47 (legitimate interest, reasonable expectations)
- GDPR Recital 51 (photographs and biometric data)
- EDPB Guidelines 05/2020 on consent, v1.1 (paragraphs 21 to 23, Example 5)
Kept is in App Review and arrives on the App Store soon
Want it for your wedding? Join the waitlist with your date and we'll email you on opening day. If your wedding is too soon to wait, say so: we'll get you set up early. No spam, ever.
Join the waitlistButton not opening your mail app? Email hello@kept.pictures with your wedding date.