← Blog
Blog · Event photo album and GDPR: privacy
Guide

Event photo album and GDPR: where are your memories and who can access them

Event photos are personal data, often intimate. Before entrusting the memories of your wedding or family to a service, it's worth knowing where they are stored and who can see them. Here's the essentials.

Event photo album and GDPR
Illustration: generated scene, not contractual.

The real issue: where do your photos go

When you upload photos to an online service, they are stored on servers. The question is where these servers are located, how the data is protected, and what the service is allowed to do with it.

Many free tools earn revenue indirectly: selling data, targeted advertising, or using content to train models. For family memories, this deserves attention.

Hosting in the European Union or elsewhere

Hosting in the European Union places your data under the General Data Protection Regulation, one of the most protective frameworks in the world.

A service hosted outside the European Union may be subject to other, sometimes less protective, legislation that allows broader access to content. The location of the servers is therefore not a minor detail.

GDPR and your rights

GDPR grants you concrete rights: to be informed about data usage, access your data, correct it, and request its erasure.

A compliant service must also apply data minimization: collect only what is necessary and delete data when it is no longer needed. Automatic deletion after the event is a good sign.

The right to your guests' images

Gathering photos from an event involves handling the images of dozens of people. This topic is rarely addressed, yet it deserves two minutes of attention.

A private setting, but not a lawless zone

Within a private circle, among people invited to the same gathering, sharing photos generally poses no difficulty. What changes the nature of things is distribution: publishing an image on a social network, using it for marketing, or making it accessible to people outside the event. It is publication, not collection, that engages responsibility.

The simple rule that avoids trouble

An album accessible only by a code, non-public and non-indexed, remains within the private framework of the event. If you later plan to use a photo differently, for example for professional use or open publication, ask for permission from recognizable individuals. A request made afterward is almost always well received; an unsolicited publication is much less so.

Plan for removal

Someone may wish for an image of themselves to disappear. Make sure you can delete a specific photo from the album easily and quickly. A service that doesn't allow this puts you in a difficult position when the request arises.

Children, minors, and absent guests

Two cases require particular vigilance, and they come up in almost every family event.

Children

The image of a minor is the responsibility of their parents or guardians. At a christening, communion, or child's birthday, not all photographed children are yours. The best practice boils down to one sentence: a closed album for the event circle, and no open publication without the parents' consent. This is also the most convincing argument for choosing a private album over a discussion group or social network.

People who prefer not to appear

There are some at every event, and they rarely mention it. Simply mentioning in a word, on the notice or during thanks, that a photo can be removed upon request is enough to ease any discomfort. It costs one line and avoids unpleasant situations.

How long to keep the photos

GDPR does not set a specific duration: it requires that data not be kept longer than necessary for its purpose. For an event album, the purpose is clear: allow participants to retrieve memories.

In practice, this justifies keeping the album for a few months, long enough for everyone to download their photos, followed by deletion. An announced duration, with effective deletion at the end, is a better sign than unlimited storage: it proves the provider has thought about what happens to your files.

Check three points: the exact duration, the ability to delete the album yourself before the deadline, and what happens to backups. Deletion that leaves copies indefinitely in backups is not truly deletion.

How to choose a respectful service

Check for hosting in the European Union and media encryption.

Look for a clear commitment: no resale, no advertising, no third-party artificial intelligence training on your content.

Ensure access remains private, via link and code, and media is automatically deleted after the event. This is the approach Fotelya takes.

Frequently asked questions

Can my photos be resold?
It depends on the service. Read the privacy policy. A respectful service explicitly commits not to resell your data or use it for advertising purposes.
Are my photos used to train artificial intelligence?
Check this carefully. Some services do it, others explicitly exclude it. Prefer those that commit not to train third-party artificial intelligence on your content.
What happens to the photos after the event?
With a service that follows the principle of data minimization, media is downloadable and then automatically deleted after a defined period. You remain the owner of your content.

See also