How long are you allowed to keep photos from a wedding, a company offsite or a conference? The question comes up at every event, and the answer is neither "forever" nor "as briefly as possible". GDPR sets a clear principle (the period must be proportionate to the purpose) but leaves each controller to set it. This guide gives concrete reference points, by event type, without unnecessary legal jargon.
The GDPR storage limitation principle
GDPR article 5(1)(e) sets out the "storage limitation" rule: personal data may only be kept for as long as necessary for the purpose it was collected for. A photo is personal data as soon as an identifiable person appears in it: a recognisable face, a number plate, a readable name badge.
In practice this means two things. First, the purpose has to be defined explicitly before collection: "personal memento for the couple", "internal company communications", "promoting next year's conference". Second, a period consistent with that purpose has to be set and stuck to. Keeping data indefinitely "just in case" is a breach.
Regulators distinguish three phases in a data lifecycle: the active use period (the data serves the purpose day to day), the intermediate archiving period (the data is kept to meet a legal or contractual obligation but is no longer freely consulted), and permanent deletion. For event photos, intermediate archiving is rarely justified; you are generally either in active use or in deletion.
The right reflex: ask yourself "why am I keeping these photos for another six months?" every six months, and be willing to delete as soon as there is no documented reason left.
Recommended periods by use case
There is no single statutory period for event photos. But practice, cross-referenced with regulator guidance, produces reasonable ranges by context.
Wedding photos (long term, legal basis suited to the couple)
For a wedding the purpose is eminently personal: preserving the memory of a unique moment. The most solid legal basis is generally the contract (between the couple and the photographer) or the couple's legitimate interest when they run the gallery themselves.
In practice the following periods are defensible:
- Gallery shared with guests: 6 to 18 months after the wedding, long enough for everyone to retrieve their photos. Beyond that the sharing purpose has lapsed.
- The couple's personal archive: no explicit limit, for as long as they wish. It is their own data and their own purpose.
- Backup held by the professional photographer: generally 1 to 5 years depending on the contract, to allow reprints or additional albums.
The point to watch concerns the guests who appear in the photos. If they ask for an image of themselves to be removed (right to erasure, see below), whoever runs the gallery must act within a reasonable time, even if the couple disagrees. The individual right takes precedence over the collective memento here.
Offsite and team building photos (short to medium, 1 to 3 years)
In an internal professional context the purpose is generally internal communications or HR value: newsletters, intranet, onboarding booklets, client presentations. Regulators consider a period of 1 to 3 years consistent with this kind of use.
Beyond 3 years the photos lose operational relevance: faces have changed, so have the premises, and the message no longer lands. Continuing to keep them creates risk with no upside. For an annual offsite, a simple rule: keep the photos until edition N+2, then delete those from edition N.
Centralising offsite photos in one place, with a traced collection date and a bulk deletion mechanism, makes applying this rule vastly simpler. Sharing by WhatsApp or USB sticks makes compliance almost impossible: every attendee holds their own copy, outside any control. The article Centralising offsite photos without an IT team covers the options for organising that centralisation simply.
One special case: employees who leave the company keep their right to erasure over photos in which they appear. A deletion procedure must remain reachable even after they have gone.
Public conference photos (variable, depending on releases)
For a conference open to the public the situation gets more complicated. Several categories coexist: speakers (often with a signed image release), identifiable attendees (generally on the basis of the organiser's legitimate interest or consent), and VIPs or sensitive guests (case by case).
For speakers who signed an explicit release, the period can be long: 5 to 10 years is common for video replays and archive galleries. The contract governs.
For attendees captured in wide shots, the usual range is 2 to 5 years, long enough to promote subsequent editions. Beyond that, legitimate interest becomes thin and deletion is required.
For sensitive guests (minors, political figures, people who explicitly asked not to be photographed), you need to be able to identify and remove their images quickly. This is one of the cases where facial recognition, used to manage the right to erasure, can paradoxically make compliance easier, by locating every photo of the same person in seconds.
Professional photographers' client galleries (1 to 5 years after delivery)
For a professional photographer, the client gallery is a contractual deliverable. The retention period is generally set by the contract itself, and the classic range is 1 to 5 years after final delivery, to allow reprints, additional albums or occasional licensing.
Beyond that period, the photographer must either request explicit renewal of consent or delete the originals. Keeping every former client's RAW files forever has not been defensible since GDPR came into force in 2018.
The article Facial recognition and photographers: GDPR compliance covers the obligations specific to professionals, particularly when they use a face-sorting tool to deliver galleries.
A good client contract explicitly states: the retention period, the deletion procedure at the end of that period, and the client's ability to request an archive copy before deletion.
The right to erasure in practice
GDPR article 17 gives anyone identifiable in a photo the right to request its deletion, without having to give a reason in most cases. It is the most operational obligation in the regulation, and the one that causes the most difficulty in practice.
The request can take several forms: an email, a letter, a message on social media, even a verbal request during the event. The controller has one month to respond (GDPR article 12(3)), extendable by two months where the request is complex.
Three operational questions arise immediately.
Who receives the requests? A dedicated email address (for example gdpr@yourdomain.com) must be published on the gallery, the invitation or the event page. Without an identifiable point of contact, requests get lost and the one-month deadline blows out.
Who technically deletes? The event organiser, the photographer, the gallery host? The role has to be assigned before the event, not on the day a request arrives. If the sharing tool allows deletion per photo or per person (through facial recognition), handling becomes far quicker.
How do you verify deletion is complete? Photos may have been downloaded, shared on other channels, embedded in printed material. The controller is not required to chase copies outside their sphere of control, but must be able to prove they deleted every copy within it. Keeping a deletion log (date, requester, photos concerned) is good practice.
For organisations running many events, putting a documented compliance workflow in place, including the right to erasure, saves considerable time. The Evokly compliance page details the built-in features that automate part of these obligations.
Documentation to produce
GDPR is not just about durations: it also requires documenting your practices. Three documents at minimum should be produced and kept current.
The processing register (GDPR article 30). Mandatory for organisations over 250 employees and strongly recommended below that, it lists every processing operation with its purpose, legal basis, categories of data subject and retention period. For an event, one line is enough: "2026 offsite photos, purpose: internal communications, period: 24 months, basis: legitimate interest, owner: HR director".
Notices at the point of consent or collection. When attendees scan a QR code to reach the shared gallery, a short notice must tell them who is collecting the photos, for what purpose, how long they will be kept, and how to exercise their rights. A two-line sentence at the bottom of the gallery page is enough in most cases.
An explicit period in the client contract (for photographers and agencies). The contract must state the retention period for source files, how long the delivery gallery stays available, and the deletion procedure at expiry. This also protects the supplier: without an explicit clause, it is on them to prove GDPR compliance.
These documents do not need to be long. They need to be current and consistent with what actually happens. A policy announcing "12 months of retention" whose photos are still online three years later is more dangerous than no policy at all.
Penalties for non-compliance
GDPR fines regularly make headlines, but the operational reality is more nuanced. Regulators overwhelmingly favour formal notices and guidance before financial penalties, especially for organisations acting in good faith.
The theoretical ceiling is high: up to 20 million euros or 4% of annual worldwide turnover, whichever is higher (GDPR article 83). In practice, penalties actually imposed over event photos and retention are more modest, but they are public, which creates reputational damage often more painful than the fine.
In a public decision in 2023, a regulator penalised a recruitment company for keeping candidate photos for more than 5 years with no up-to-date legal basis and no operational deletion procedure. The amount (several tens of thousands of euros) was proportionate, but the associated coverage had a lasting HR impact.
In 2024, a similar decision targeted an events platform that failed to answer erasure requests within the legal deadline. The failure was procedural as much as about retention: no dedicated contact address, no request log, no proof of action. The regulator's message is consistent: it is not the durations themselves that cause problems, it is the absence of a documented process around them.
For the vast majority of organisers, the real risk is not a massive fine but a complaint from an unhappy attendee, handled publicly by the regulator. That is enough to justify investing in a clear policy.
FAQ
How long can you keep photos from a professional event?
The usual period is 1 to 3 years for an offsite or internal event, and 2 to 5 years for a public conference. Beyond that the communications purpose lapses and retention becomes hard to justify. The legal test is not a fixed duration but proportionality to the documented purpose.
Do you need written consent from every person photographed?
Not always. Consent is one possible legal basis, but the organiser's legitimate interest can also suffice for atmosphere shots at a professional event. A visible information notice (a sign at the entrance, a mention on the invitation) is mandatory, however, along with a procedure for exercising the right to object or to erasure.
What do you do if someone asks for their photo to be deleted?
You have one month to handle the request (GDPR article 12), extendable to three months where it is complex. Identify the photos concerned, delete them from every medium under your control, and confirm in writing to the requester that this has been done. Keep a log of the deletion so you can prove it if audited.
Are image rights and GDPR the same thing?
No, they are two distinct legal regimes that apply in parallel. Image rights fall under national civil law and protect the use of an identifiable person's likeness. GDPR is a European regulation on personal data. A photo can comply with image rights (a signed release) while breaching GDPR (an undocumented retention period), and vice versa.
Do you have to declare photo collection to the regulator?
No, prior declaration disappeared when GDPR came into force in 2018. You must, however, keep an internal processing register, available on request in the event of an audit. For high-risk processing (large-scale facial recognition, for instance) a data protection impact assessment (DPIA) may be required.
Does GDPR apply to photos taken at a private event?
For strictly personal and household use (the domestic exception in GDPR article 2(2)(c)), no. A parent photographing a birthday party and keeping the photos to themselves is not subject to GDPR. As soon as there is organised sharing with third parties (an online gallery, posting on social media, handing files to a supplier), GDPR applies in full.
GDPR compliance on event photos is neither mystical nor impossible. It rests on three concrete actions: set a period consistent with the purpose, document that period in a simple register, and organise the right to erasure around an identifiable point of contact. Most modern event tools now build these obligations in by default.
See pricing for the Evokly plans that include the shared gallery, per-photo deletion and the right-to-erasure workflow.