GDPR and event photography: a practical guide for organizers
Willem Himpe
Founder & CEO, Relivo
2 June 2026 · 7 min read
Consent, facial recognition and data retention explained in plain language, so you can deliver personal galleries without legal headaches.
Consent is a feature, not a hurdle
Most organizers treat GDPR as a compliance box to tick after the fact. The stronger approach is to design consent into the experience itself: when a guest uploads a selfie to find their photos, they are actively opting in, and that action is logged with a timestamp.
Explicit, purpose-bound consent also builds trust. Attendees are far more comfortable with facial matching when they triggered it themselves than when a system scanned them silently in the background.
The questions to ask any photo platform
Where is the data hosted, and does it leave the EU? How long are selfies and facial embeddings retained, and can a guest delete them? Is facial recognition run by a third-party API or by the platform itself? Who is the data processor, and is there a DPA you can actually read?
Relivo's answers, for the record: EU hosting, guest-controlled deletion, proprietary on-platform matching, and a standard DPA. Whatever platform you choose, insist on written answers to all four questions before the event, not after.
Retention: decide the end date on day one
Photos and selfies should have a lifecycle you chose deliberately. A common pattern: galleries stay live for 90 days, selfie data is deleted immediately after matching, and the full archive returns to the organizer. Put those dates in your privacy notice and honor them automatically.
The payoff is not only legal safety. A clear retention story is increasingly a procurement requirement for corporate clients, and having it documented turns a security questionnaire from a week of back-and-forth into an attachment.