Privacy and GDPR when sharing photos from an event

Photos of people are personal data. That sounds heavy, but in practice it comes down to three things: people know what is happening, the photos sit somewhere safe, and they can be deleted again. Here is how to get it right.

When do party photos fall under GDPR?

Sharing photos in a purely private setting – a family birthday in a closed album – is generally covered by the household exemption. For a company event, an association or any event where the photos are used further, the ordinary rules apply and you need a lawful basis. For company parties that is typically consent or a clear legitimate interest assessment.

Tell your guests what happens

The simplest and best protection is openness. Write on the QR card or in the invitation that there is a shared album, who has access, how long photos are kept, and who to contact to have a photo removed. Two lines are enough, and they prevent most discussions afterwards.

GPS and EXIF data are stripped automatically

An ordinary phone photo often contains location, timestamp and device model. ShareEvent strips GPS and EXIF metadata on upload, so a guest's home address does not travel with a photo taken in the garden. It happens automatically – there is no setting to remember.

Where are the photos stored?

Photos and videos are stored on servers in the EU. Albums are not public and can only be opened with the album code. We do not sell data, show ads or train AI models on your photos. AI is used solely to organise the album – for example face grouping – and to moderate inappropriate content.

The right to be deleted

A guest can always ask to have their photo removed, and the host can delete individual photos or the entire album. Deleting an album removes the files and the QR code stops working. If you want that to happen automatically after the event, set a deletion date in advance.

Extra care at company events

For company parties, agree up front whether photos may be used on the intranet, LinkedIn or in recruitment material – that is different from the internal album and needs its own consent. Always let employees opt out without explaining why, and appoint one person responsible for the album.

Frequently asked questions

Do I need consent from every guest?

For private parties, clear information is normally enough. For company events and associations you should have a clear basis – usually consent – especially if photos will be used beyond the album itself.

Are the photos stored in the EU?

Yes. Photos and videos are stored on servers in the EU, and ShareEvent is operated from Denmark.

Are my photos used to train AI?

No. AI is used to group faces inside your own album and to moderate inappropriate content. Photos are not used for model training and are never sold.

Is location data removed from photos?

Yes. GPS and EXIF metadata are stripped automatically on upload.

Guides for your event

Read next

See all guides · Create a free album