Photos at company parties: what the GDPR actually requires
Photos from the Christmas party are personal data. That doesn't make them forbidden — it just means you should be able to say what you're relying on. Below: which legal basis holds in which case, when a data processing agreement is required, and the questions a works council usually asks.
This is not legal advice. The legal position is cited with sources and the statements about our system have been verified — but only your data protection officer or a lawyer can assess your specific case.
The four questions people actually ask
Where is the data stored?
The most common first question — and where US services usually fail. With us: database in Frankfurt (Google Cloud, europe-west3), photo storage on Cloudflare R2 with an EU location constraint. No bucket is publicly reachable; images are served only through access that is checked per event.
Is a data processing agreement required?
Yes. When a company has photos of its employees processed by a service, that is processing on behalf under Art. 28 GDPR — a contract is mandatory, not optional. We provide one on request; without it no company should deploy such a service, ours or anyone else's.
Consent or legitimate interest?
In an employment relationship consent is delicate, because it must be freely given (§ 26(2) BDSG) — and 'freely' towards your employer needs explaining. Usually more workable: participation voluntary, withdrawal at any time, no disadvantage for not taking part. That is exactly how the product is built — nobody has to install anything or create an account.
What does the works council want to know?
Whether monitoring of conduct or performance is possible (§ 87(1) no. 6 BetrVG) — that is where codetermination kicks in. The helpful answer: no facial recognition, no mapping of images to personnel numbers, no analysis of who was where when. A gallery is not a monitoring tool.
What to do, concretely
Five steps that set up a company party gallery cleanly. Half an hour of work, not a project.
Sign the DPA before creating the event
Not afterwards. Processing starts with the first photo, and a retroactive contract doesn't fix that.
Keep participation visibly voluntary
The QR code is there, nobody is prompted. Taking no photo must have no consequence — that is the core of 'freely given'.
Inform beforehand, not at the party
A short note in the invitation is enough: there will be a shared gallery, participation is voluntary, images are deleted after X weeks, here is the privacy notice.
Set a retention period and stick to it
Art. 5(1)(e) GDPR requires a storage period appropriate to the purpose. For a party, weeks to months is defensible — indefinite is not. Every event here has an expiry date.
Make objection easy
Anyone who doesn't want their picture in the gallery must be able to have it removed without giving a reason. The organiser can delete any individual photo.
What our system actually does
- Where are the photos stored?
- Cloudflare R2 with an EU location constraint. The bucket is not public; delivery runs through access checked per event.
- Where is the database?
- Google Cloud Firestore in europe-west3 — Frankfurt am Main.
- Do guests need an account?
- No. Scanning the QR code is enough. No accounts, no email addresses and no phone numbers are collected from participants.
- Is there facial recognition?
- No. No biometric processing takes place — neither for sorting nor for search. That is the distinction that matters in an employment context.
- What happens after the event?
- Every event has an expiry date fixed when it is created. After that the images are deleted; the organiser can remove individual photos or the whole gallery at any time before that.
Frequently Asked Questions
A gallery for your company party
Create one for free and look at it before you decide. The data processing agreement is available on request.
Create event