Privacy guide
Where your client photos are allowed to live
A photograph of an identifiable person is personal data, which puts the images you deliver inside the same rules as any other customer record. That sounds heavier than it is. For most photographers it comes down to knowing where the files sit, having the right paperwork with whoever holds them, and being able to answer a client who asks. Here is the shape of it.
Three things the rules actually say
Stripped of the vocabulary, the GDPR asks a photographer for three things.
The photos are personal data
If someone can be identified from an image, it counts, and that covers most portrait, wedding and event work. Nothing about the photograph being yours, or being art, changes that.
You are the one responsible
You decide why the photos exist and where they go, which makes you the controller. The gallery platform is your processor, acting on your instructions, and you stay answerable for the choices it makes on your behalf.
The people in them can ask
People have a right to know what you hold and, in many cases, to have it deleted. That is only awkward if you cannot say where the files are, or cannot reach them to remove them.
Why everyone keeps arguing about American servers
Three rulings explain why storage location is a live question rather than a formality.
-
2015
Safe Harbour falls
The Court of Justice struck down the first arrangement for moving personal data from the EU to the United States, on the grounds that US surveillance law left it unprotected.
-
2020
Privacy Shield falls
Its replacement was struck down too, in the ruling usually called Schrems II. Transfers did not stop, but they needed extra safeguards and an assessment case by case.
-
2023 to now
The Data Privacy Framework
The current adequacy decision took effect in 2023 and remains in force. A challenge to it was dismissed by the General Court in September 2025 and appealed to the Court of Justice that October, with no hearing date announced as of August 2026.
What you need in place
None of this requires a lawyer for a one-person business, but all four are worth having before a client asks rather than after.
A straight answer on location
Know the country your gallery provider stores files in, and whether that is also true of their backups and their support tooling. If the answer takes three emails to extract, that is itself the answer.
A processor agreement
A data processing agreement with each service that holds your photos. Reputable providers publish one and let you accept it in the account settings, so you do not need to draft anything.
A reason you are allowed to hold them
Usually the contract with the person who hired you, sometimes consent, and for guests at an event often a legitimate interest you have actually thought about. Write it down once per type of job.
A way to delete on request
You should be able to remove a gallery and its files, and know how long backups keep a copy afterwards. A provider that cannot tell you the retention period cannot help you answer a deletion request.
Four questions worth asking a provider
Ask before you upload a job, not after. The answers should be quick and specific.
-
Which country are the files in?
Not the cloud, not our global infrastructure. A country, and ideally a named data centre operator. Ask about backups separately, because those often live somewhere else.
-
Who else can see them?
Sub-processors, support staff, and any analytics or machine-learning use of uploaded content. The last of those has become the question worth asking twice.
-
What happens if I leave?
How you export everything, in what format, and how long after cancellation the files are actually gone. This doubles as your check that the service is not a trap.
-
What do you publish?
A data processing agreement, a sub-processor list and a retention policy should all be readable without asking a salesperson. A provider that treats these as confidential is telling you something.
The short version, for one provider
It is easier to show than to describe, so here are Photoglacier's answers to the questions above. The company is Austrian. Photos sit on object storage in Germany and the servers run there too, so nothing crosses the Atlantic. Galleries and their files can be deleted from your account at any time, and EU hosting applies on every plan, including the free one.
- Austrian company, all photos stored in Germany
- Photos and client data never leave the EU, on every plan
- Delete a gallery and its files from your account at any time
Questions people are asking
Does client photo storage have to be in the EU?
Not strictly. The GDPR allows transfers outside the EU where an adequacy decision or another safeguard applies, and the EU-US Data Privacy Framework is currently in force. Keeping storage inside the EU simply removes the question: there is no transfer to justify and nothing to reassess if the legal position moves again.
Are wedding photos personal data under the GDPR?
Yes, wherever people are identifiable, which is most of them. That covers the couple, their families and the guests. It does not stop you photographing a wedding. It means the files you keep afterwards sit under the same rules as other personal data you hold.
What is a data processing agreement and do I need one?
It is the contract between you as controller and a service that stores data on your behalf. If a gallery platform, cloud drive or backup service holds your client photos, you need one with them. Most providers publish a standard agreement you can accept in your account settings.
Can I use a US cloud service for client photos?
Legally, yes, under the current framework and with the right paperwork in place. Practically, it adds a dependency on an adequacy decision that has been struck down twice before and is under appeal again. That is a risk assessment rather than a prohibition, and it is yours to make.
What do I tell a client who asks where their photos are stored?
Name the country and the provider. Something like stored in Germany, on infrastructure operated by Hetzner, under a data processing agreement will end the conversation. Anything vaguer tends to produce more questions rather than fewer.
How long should I keep client galleries online?
As long as the job needs and no longer than you can justify. Set an expectation with the client at delivery, then remove galleries you no longer have a reason to hold. Keeping everything forever is the option that ages worst.
GDPR-compliant photo storage in the EU
Searches for GDPR-compliant photo storage and EU-hosted client galleries come overwhelmingly from photographers who have just been asked a direct question by a client and want a direct answer to give back. The useful answer names a country and a provider. Storage location decides which law reaches the images of the people you photograph, and it is the one detail a vague reply makes worse rather than better.
Photoglacier is run by an Austrian company on infrastructure in Germany, so photos and client data never leave the EU, on every plan including the free one. Galleries are shared by link with no account required at the other end, downloads run at full resolution with per-gallery control, and video sits alongside the stills. This page describes how the rules generally work and is not legal advice.
More guides
This guide describes how data protection rules generally apply to photographers and is not legal advice. Rules change and circumstances differ, so for a decision that matters, consult a qualified adviser in your jurisdiction. Legal developments referenced here were checked in August 2026.
An answer you can give a client
Austrian company, German servers, GDPR compliant on every plan including the free one.



