Privacy guide
GDPR compliant online gallery for photographers: what to check before you upload
Every client gallery holds personal data: faces, names, email addresses, sometimes a child's birthday party. That makes the gallery provider your processor, and the GDPR has a short list of things it expects from that relationship. This guide sets out what the law asks, gives you a checklist to hold a provider against, and shows you how to answer a client who asks.
What the GDPR actually asks of a gallery
The regulation never mentions photographers or galleries. It talks about controllers, processors and personal data, and a photo of a recognisable person is personal data. Three articles do most of the work.
A lawful basis, and telling people (Art. 6 and 13)
You need a reason to process the photos, usually the contract with the client or your legitimate interest, and the people in them need to know what happens to the pictures. For a wedding that means the couple's contract and a line for guests about where the photos go. This part is yours to sort out; no provider can do it for you.
A contract with whoever stores them (Art. 28)
The company hosting your galleries processes personal data on your behalf, so the GDPR requires a written contract between you: a data processing agreement, or Auftragsverarbeitungsvertrag (AVV) in German. It fixes what the provider may do with the data, who its sub-processors are, and what happens when you leave. Without it, the hosting itself is the breach.
Security and retention (Art. 32)
Appropriate technical measures: encryption in transit, access control, backups, a data centre with a recognised certification. And a limit on how long things stay: the storage limitation principle says photos remain online as long as there is a purpose for them, and then they go. A gallery that lets you set who gets in and take the whole thing down in one click is doing its half of this.
The checklist
Six things to hold a gallery provider against before you upload a single client photo. A provider that passes all six makes your side of the GDPR mostly a matter of paperwork you already have.
EU hosting, and a published sub-processor list
Where the files physically sit decides whether you have to explain an international transfer. Storage inside the EU removes the question. The sub-processor list tells you who else touches the data: the email service, the error monitoring, the payment provider. If a provider will not say who they are, that is your answer.
A signed AVV or DPA
Not a paragraph in the terms of service that says one exists, but a document with your name and the provider's on it. It should name the sub-processors, the security measures, the breach notification deadline, and what happens to your data when you cancel. Keep the signed copy with your client contracts.
Access control you can set per gallery
A wedding gallery and a corporate headshot session need different doors. A password keeps strangers out, an email gate tells you who came in, a download PIN separates looking from taking. Check that each is a per-gallery setting rather than an account-wide one.
Retention and deletion you control
You decide how long a gallery stays up, not the provider's pricing plan. Deletion should be immediate on your side and finite on theirs: a stated number of days for the live copy and for backups. A provider that keeps deleted data indefinitely leaves you unable to honour an erasure request.
Breach notification with a deadline
You have 72 hours from becoming aware of a breach to tell the supervisory authority. Your provider therefore needs to tell you well inside that window, and the DPA should say how quickly. Without undue delay is a common phrase and a weak one; a number of hours is better.
Help with access and export requests
Clients can ask what data you hold about them and ask for a copy. For a gallery that means the photos, the guest list, the reactions and the download log. A provider that can export a gallery and its activity in one go turns a legal obligation into an afternoon's admin.
Where the common providers stand
Four gallery platforms photographers in Europe actually use, on the five checklist points a provider can answer for itself. Checked September 2026; a provider's setup can change, so confirm against its current DPA before you sign.
| What matters | Pixieset Vancouver, Canada | Pic-Time Headquartered in Israel | picdrop Berlin, Germany | Photoglacier Austria, servers in Germany |
|---|---|---|---|---|
| Company seat | Canada | Israel | Germany | Austria (nord3 digital e.U.) |
| Where photos are stored | May be stored outside the EU | Azure, AWS and MongoDB in the EU, the US and Australia | Germany | Hetzner Object Storage in Germany, ISO/IEC 27001 data centres |
| Processor agreement | DPA forms part of the terms | Not listed on the pages we checked; ask for the DPA before you sign | AVV available | DPA in English and AVV in German, signed electronically |
| Transfers outside the EU | Yes, covered by Standard Contractual Clauses | Yes, with servers in the US and Australia | Hosting is in Germany, so none for the photos | None: every sub-processor is EU-hosted, payments go through Stripe Ireland |
| Sub-processor list published | Check the DPA before you sign | Check the DPA before you sign | Ask for it with the AVV | Yes, in the DPA: Hetzner, Mailgun or Mailjet, Sentry, PostHog, Let's Encrypt |
When a client asks where their photos are
It happens more often than it used to, and usually from the client you least expect: a lawyer at a wedding, a school, a company whose privacy officer has a list. The answer takes four sentences if the setup is right.
-
Name the country and the company
Germany, on servers run by Hetzner, through an Austrian company: that is an answer. The cloud is not. If you cannot fill in that sentence for your own provider, it is the first thing to fix, and the sub-processor list is where to find it.
-
Send the paperwork
Attach the signed DPA or AVV. A client who asked the question is usually satisfied by a document with two signatures on it, and a corporate client may need it for their own records. It also shows you knew the question was coming.
-
Explain who can open the gallery
Say whether it is password protected, whether guests come in through an email gate, and whether downloads need a PIN. If the couple has shared the link with family, say so; the guest list in the gallery tells you who has opened it.
-
Give a date, and a way to end it earlier
Tell them how long the gallery stays online and what happens then. Offer to take it down sooner if they ask, and say what deletion means at the provider: how long until the live copy is gone, and how long until backups are overwritten.
What the Photoglacier DPA actually commits to
Photoglacier is a client gallery platform run by nord3 digital e.U. in Austria, with every photo on Hetzner Object Storage in Germany. The DPA is the same on every plan, including the free one. It does not watermark, it has no print store or CRM, and the free plan shows Photoglacier branding. What it does is keep the data inside the EU and put the numbers in writing.
- Breach notification to you within 48 hours
- On termination, your data is deleted or returned within 30 days, and backups are overwritten within 90 days
- Gallery guest-list entries are anonymised after 14 days, and IP logs are kept for at most 14 days
- Photos are stored, displayed and transmitted, nothing more: never analysed, never used for training
- Sub-processors named in the DPA, all EU-hosted: Hetzner, Mailgun or Mailjet, Sentry, PostHog, Let's Encrypt
Questions people are asking
Is an online gallery for client photos subject to the GDPR?
Yes, if you are in the EU or the people in the photos are. A photo of an identifiable person is personal data, and so are the names and email addresses attached to a gallery. That makes you the controller and the gallery provider your processor, which is why the provider's location and contract matter.
Do I need a data processing agreement with my gallery provider?
Yes. Article 28 of the GDPR requires a written contract between a controller and anyone who processes personal data on their behalf, and a company hosting client photos for you is doing exactly that. Some providers put the agreement inside their terms of service; a separately signed document is easier to show a client or an authority. Keep it with your client contracts.
Does the GDPR require photos to be stored in the EU?
No. It requires that any transfer outside the EU rests on a recognised mechanism, such as an adequacy decision or Standard Contractual Clauses, and that you can explain which one applies. Storing the photos in the EU removes the question altogether, which is why many photographers treat EU hosting as the simplest route rather than a legal necessity.
Is Pixieset GDPR compliant?
Pixieset is a Canadian company, its data may be stored outside the EU, and its DPA forms part of its terms, with Standard Contractual Clauses covering EU transfers. That is a workable setup under the GDPR, but it means you as the controller are relying on a transfer mechanism and should be able to say so if asked. Whether that is acceptable for your clients is your decision, not the provider's.
Is picdrop GDPR compliant?
picdrop is a Berlin company that hosts in Germany, offers an AVV, and states that it runs no AI on user data. On the points a provider can answer for itself, that is a strong position: no international transfer for the photos and a signed processor contract. As with any provider, compliance still depends on how you use it, from access settings to how long galleries stay up.
How long may I keep client photos online?
The GDPR sets no number of days; it says personal data should be kept no longer than the purpose needs. For a delivery gallery the purpose is the client collecting their photos, so write a period into your contract, tell the client, and act on it. Twelve months is common for weddings. Photoglacier galleries never expire on any plan, so the date is yours to set rather than the pricing plan's.
What do I do if a client asks me to delete their photos?
Take the gallery down, delete it at the provider, and confirm to the client in writing with the date. Check what the provider's DPA says about backups, because a copy in a backup cycle is still a copy; Photoglacier's DPA puts numbers on this at account level, with data deleted or returned within 30 days and backups overwritten within 90. Your own archive is a separate question, since you may have contractual or copyright reasons to keep the files, and that is one to settle with a qualified adviser.
Does Photoglacier provide an AVV or DPA?
Yes, on request. There is a German Vereinbarung zur Auftragsverarbeitung (AVV) and an English Data Processing Agreement (DPA), the same agreement in two languages. Ask through the contact form under the topic “DPA request” and say which language you need. You fill in your details and sign it first, then send it back; we countersign and return the completed copy. The agreement applies on every plan, including the free one.
A GDPR client gallery is mostly a matter of where, and with whom
Searches for a GDPR compliant online gallery for photographers usually come from someone who has just been asked the question by a client and realised they cannot answer it. The answer is rarely complicated. It comes down to where the files are stored, whether a data processing agreement exists between the photographer and the provider, who else touches the data, and whether the photographer can take a gallery down when the purpose has ended. A provider inside the EU with a signed contract and a published sub-processor list answers most of it before the client has finished asking.
Photoglacier is built for that answer. The company is Austrian, the photos sit on Hetzner Object Storage in Germany, and the data processing agreement a photographer signs is the same document on every plan, with the breach deadline, the deletion periods and the sub-processors written in. A GDPR client gallery still needs the photographer's side done properly: a lawful basis, a line in the contract about where the photos go, and a date on which they come down. The platform's part is to make that side the only part left.
More guides
This guide describes how the GDPR generally applies to photographers and their gallery providers and is not legal advice. Rules change and circumstances differ, so for a decision that matters, consult a qualified adviser in your jurisdiction. Pixieset, Pic-Time and picdrop are trademarks of their respective owners; Photoglacier is not affiliated with any of them. Provider details were checked in September 2026 and may change.
An answer you can put in writing
Austrian company, German servers, and a DPA that applies on every plan, including the free one.



