Law
Wedding photos and privacy: what you should know
Collecting photos of guests means processing personal data. Less dramatic than it sounds. But it has consequences.
Тези статии засега са само на английски.
The moment you collect and store photographs of people, you are processing personal data. That is as true of a group chat as of any gallery. It is not a reason to panic, but it is worth knowing a few things beforehand rather than sorting them out afterwards.
This is practical orientation, not legal advice. When in doubt, ask somebody who carries liability for the answer.
As a private individual you are usually outside the rules
The GDPR explicitly exempts processing "in the course of a purely personal or household activity". A private wedding normally falls under that. It is the reason nobody has to keep a record of processing activities for their family party.
The exemption stops carrying, though, as soon as things become commercial: a company party, a club event announced publicly, anything a business organises. Then the ordinary rules apply, including a data processing agreement with your provider.
Image rights apply either way
The point almost everyone misses: even where the GDPR does not reach you, personality and image rights do. Distributing pictures of identifiable people needs their agreement, and "distributing" starts earlier than most people assume.
Inside a closed gallery that only the party's guests see, this is unproblematic. It becomes a problem when pictures travel from there to Instagram. The sentence that solves it is short and belongs on the card next to the QR code:
These pictures stay between us. Please do not post them anywhere else.
That is not legal protection, but it sets the expectation, and in practice people respect it when you say it.
Children are the sensitive case
Do not put photographs of other people's children into a collection other guests can see without asking the parents. That is less a legal question than one somebody will ask you the next day.
Practically: if your gallery has moderation, switch it on for this. New pictures then wait with you before they become visible.
Three technical questions worth asking your provider
- Where does the data sit? Servers inside the EU save you the entire discussion about international transfers. Ask about the location of the servers, not the address of the company.
- What happens at the end? Every gallery has a runtime. What matters is what follows: do you get the pictures out, and are they then actually deleted?
- Who can reach a picture without the link? The honest answer at nearly every provider is: images are delivered through a content network, and whoever knows an image address can open it. An access code protects the page, not the individual file. Providers who claim otherwise deserve a closer look.
What is inside the pictures
A photo from a phone carries more than the subject: capture time, device model and, depending on the settings, GPS coordinates. At a wedding the location is no secret. In pictures taken inside a guest's home it might be.
We deliberately keep originals untouched, because that is the file you have printed later. What we generate for display is a new file without that extra data. If you want certainty before passing individual originals on, check what is in them.
The short version
- Private party: relaxed, but tell your guests the pictures stay among you.
- Commercial: you need a processing agreement and a legal basis.
- Children: moderate when in doubt.
- Provider: EU servers, clear deletion, an honest answer about image addresses.
Our privacy notice describes how we do it in detail.