Most articles comparing proofing galleries rank them on price, storage and how the client gallery looks. Those matter. But if you shoot in Europe, there is a question none of those comparisons answer: where do your clients' photos physically sit, and what does that oblige you to do?
This is not a compliance lecture. It is the short list of things a European photographer should be able to answer about their gallery platform, and what changes when the files stay in Europe.
First, the word: proofing
In the United States, "proofing" is the standard term for the gallery you send a client to review, select and approve images before final delivery. In Europe the same step is usually just called delivering the gallery, which is why European photographers searching in English often miss half the market.
Worth knowing, because it is the word every US platform organises its product around. If you are comparing tools in English, search for proofing galleries, not delivery galleries.
Your clients' photos are personal data, and you are the controller
A photograph in which a person can be identified is personal data. That is the starting point, and it applies to a corporate headshot session as much as to a wedding.
Two roles follow from it. You decide whose photos are taken, why, and how long they stay online, which makes you the controller. The platform hosting the gallery acts on your instructions, which makes it a processor.
That relationship is not informal. Article 28 requires a written contract between the two of you, a data processing agreement, covering what the processor may do, its security measures, who its own sub-processors are, and what happens to the data at the end.
The practical test: can you download that agreement from the platform's site today, without contacting sales? On serious platforms you can. Where you cannot, you are the one holding the obligation without the paperwork.
Hosting in the United States is not illegal. It is paperwork
This is where most of the confusion sits, and it cuts both ways.
Transferring personal data outside the European Economic Area is lawful when a legal mechanism covers it. Since July 2023 the EU-US Data Privacy Framework provides exactly that: a US company that has self-certified under it can receive personal data from the EU without further formalities, the same way a transfer inside the EU would work.
So a US proofing platform is not automatically a problem. What matters is one factual question: is this specific company certified?
The register is public. Search the company's legal name at dataprivacyframework.gov, and check that the certification is active. Note that a marketing page saying "GDPR compliant" is not an answer, and neither is a support reply saying the data is "secure". Certification is a status on a public list, or it is not.
If the provider is not on that list, the transfer needs standard contractual clauses and a transfer impact assessment, an analysis of whether the destination country's laws undermine those clauses in practice. That assessment is the controller's job. Yours, in other words.
The six things to check before you sign
Run these against any platform, European or not. Most take five minutes.
The data processing agreement. Downloadable without asking, and signed by the entity you are actually paying.
The storage region. Not the company's headquarters, the region where image files and database records sit. Some platforms let you choose it, most do not.
The transfer mechanism. Data Privacy Framework certification, or standard contractual clauses plus your own assessment.
The sub-processor list. A gallery platform is never alone: object storage, a content delivery network, transactional email, analytics. Ask for the list and how you are notified when it changes. Silent additions are the usual failure.
Retention and deletion. What happens to the files when a gallery expires or you close your account. A platform that cannot state a deletion timeline cannot help you answer a client's deletion request.
Face matching, if you use it. Photographs are not biometric data by default. Recital 51 is explicit on that point. They become biometric only when processed through technical means allowing unique identification, which is precisely what face matching does, and that moves you into Article 9 and explicit consent. The framing is covered in detail in facial recognition and GDPR for photographers.
What the European option actually changes
Nothing magic. It removes one chapter of the regulation from your file.
With storage in the European Union, Chapter V on international transfers stops applying to that part of your stack. No certification to verify, no standard contractual clauses to attach, no transfer impact assessment to write and keep up to date. The other obligations remain exactly as they were.
Where this stops being abstract is B2B. Corporate clients increasingly send a supplier questionnaire before a shoot, and one of its lines asks where sub-processors store the data. Answering "in the European Union, here is the agreement" closes that thread in one email. Answering "in the United States, under a framework, let me find the certificate" opens a conversation with a legal department that has no reason to hurry.
The second thing it changes is jurisdiction. A European processor contracts under European law with a European supervisory authority. When something goes wrong, that is one less layer between you and a remedy.
Pixieset, ShootProof and the European question
To be fair to them: these are good products, built by serious teams, and the reason photographers use them is that they work. Nothing here says otherwise, and our own comparison of Pixieset alternatives recommends several of them by profile.
What they are not built around is the European question. Their storage, their support and their contracts are organised for a US market where this paperwork does not exist. That is not a flaw, it is a different market.
So do not ask whether they are compliant, which is not a yes-or-no property of a product. Ask the three factual questions above: what does the agreement say, where is the storage, and is the company on the public register. Then decide with the answers in front of you.
Where Evokly sits, and where it does not
Evokly hosts in the European Union, publishes a data processing agreement, and frames face matching on recorded explicit consent with deletion when the event expires. Galleries are white-labelled under your own brand from the one-off Event Pro plan, without a subscription.
It is built for events with many different subjects: weddings, galas, conferences, corporate days. Guests scan a QR code, and each person finds the photos they appear in by taking a selfie, which is what removes the "can you find the ones with me in them" thread the week after.
Where it does not fit: Evokly is not a print sales platform and does not manage contracts or invoicing. If your business model rests on paper prints, or if you want delivery and studio admin in one dashboard, the tools above do that and Evokly does not.
When a US platform is still the right answer
Three cases, honestly.
Your clients are American. The transfer question runs the other way, and the local platform is the one their expectations are built around.
Print sales are your margin. The lab integrations that make that work are mature on US platforms and absent from most European ones.
You are already set up and it works. Migration costs real hours, and a platform you know beats a marginally better file on paper. Switch when there is a reason, not because of an article.
In short
Hosting location is not compliance, and European hosting is not a certificate. What it does is delete one chapter of your obligations, the one on international transfers, and give you a one-email answer when a corporate client asks where the photos live.
Before you sign anything, get the agreement, the storage region and the transfer mechanism in writing. If a platform cannot produce all three in an afternoon, that is your answer about the rest.
For how long you should keep the files once delivered, see event photo retention under GDPR.
Try a white-labelled gallery for free, on a real session, before you decide anything.
Frequently asked questions
Is it illegal to host client photos in the United States under GDPR?
No. Transfers outside the European Economic Area are lawful when a legal mechanism covers them. Since July 2023 the EU-US Data Privacy Framework provides one: a US company that has self-certified under it can receive personal data from the EU without standard contractual clauses. If your provider is not certified, the transfer needs standard contractual clauses plus a transfer impact assessment, and that work falls on you as the controller, not on them.
How do I check whether a proofing platform is certified under the Data Privacy Framework?
The list is public and searchable at dataprivacyframework.gov. Search the company's legal name rather than its product name, and check that the certification is active and that it covers the right data categories. A vendor claiming to be "GDPR compliant" on a marketing page is not the same as an active certification on that register.
Am I the data controller for my client galleries?
In the normal case, yes. You decide whose photos are taken, why, and how long they stay online, which makes you the controller. The proofing platform acts on your instructions, which makes it a processor. That relationship requires a written data processing agreement under Article 28, and it is the document you should be able to download without contacting sales.
Are photographs biometric data under GDPR?
Not by default. Recital 51 is explicit that photographs are not systematically special-category data. They become biometric data only when processed through specific technical means that allow a person to be uniquely identified, which is exactly what facial recognition does. A plain gallery of faces is ordinary personal data; add face matching and you move into Article 9, which requires explicit consent.
Does hosting in Europe make me compliant on its own?
No, and any vendor telling you otherwise is selling. European hosting removes one chapter of the regulation from your file, the one on international transfers. You still need a lawful basis for the photos, a data processing agreement, a retention period you actually apply, and a way to answer a deletion request. Hosting location is one line of the checklist, not the checklist.