🎉 15% off your first plan, code
← All articles
vodnik·9 min read

GDPR and Wedding Photo Sharing in the EU: A Practical 2026 Guide

A practical guide to collecting and sharing wedding guest photos in the EU: lawful basis, transparency, data minimisation, retention, privacy settings and marketing consent.

By CamLove Team

This guide is general information, not legal advice. GDPR application depends on the event, organiser, country, people involved and intended use of the photos. For high-risk, commercial or sensitive events, check with your data-protection adviser or national supervisory authority.

Wedding and event photos can contain personal data whenever a living person is identifiable. That does not mean the answer is always 'collect consent from everyone'. GDPR provides several possible lawful bases for processing, and the correct one depends on the purpose and context. The important part is to decide why you are processing the photos before you collect them, explain that clearly and avoid using the same data later for unrelated purposes without a proper basis.

Who is the controller when wedding guests upload photos?

Under GDPR, the controller is the person or organisation that decides the purpose and essential means of processing personal data. A processor handles data on the controller's behalf. At a private wedding the situation can differ from a commercial conference, venue activation or brand event, so do not assume the same legal setup for every event. If a business organises the event and decides why participant data is collected, it should document its role and responsibilities.

No single lawful basis applies to every event. GDPR recognises several legal grounds, including consent, contractual necessity, legal obligations, public-interest tasks, vital interests and legitimate interests where the required balancing test is satisfied. Consent, when used, must be freely given, specific, informed, unambiguous and withdrawable. Do not use consent as a decorative checkbox if another legal basis is actually being relied on, and do not bundle unrelated purposes into one vague acceptance.

What should guests be told before they upload?

Transparency is one of the core GDPR principles. Where GDPR applies, people should be given clear information about who is processing the data, why it is being processed, the legal basis, relevant recipients, retention, rights and any international transfers that need to be disclosed. For an event gallery, the notice should be understandable on a phone and available before or at the point of upload rather than hidden after submission.

QuestionGood event-gallery practiceWhy it matters
Why are photos collected?State the event-gallery purpose clearlyPurpose limitation
What data is required?Ask only for fields genuinely neededData minimisation
Who can see the gallery?Use private access appropriate to the eventConfidentiality and expectations
How long is content kept?Set and communicate a retention periodStorage limitation
Can email be used for marketing?Use a separate, optional marketing choice where requiredDifferent purpose and consent requirements

Privacy settings should match the event rather than default to maximum exposure. A wedding gallery normally does not need to be indexed by search engines. If access should be limited to invited guests, use a private link and, where appropriate, password protection. If the event is sensitive or the organiser wants control over what appears on a live screen, enable moderation before publication. Remember that anyone who receives a shareable link may forward it, so a secret URL alone is not the same as identity-based access control.

  • Keep public search indexing off for private event galleries.
  • Use password protection when the guest list or content calls for stronger access control.
  • Do not collect guest names or email addresses unless the feature genuinely needs them.
  • Use moderation when photos will immediately appear on a public venue screen.
  • Give organisers a clear way to remove content when a legitimate request is received.
  • Download and archive what is needed, then delete online content according to the stated retention plan.

Can you collect guest email addresses for a prize draw or newsletter?

A prize draw, event-gallery upload and future marketing are different purposes. Do not automatically treat an email entered for one purpose as permission for another. If you want to add participants to a marketing list, design a separate, clear and genuinely optional choice that meets the rules applicable to electronic marketing in the relevant country. Keep evidence of the choice and make withdrawal easy.

What about children in event photos?

Images of children deserve additional care. GDPR and national laws can apply differently depending on the processing and legal basis, and rules around children's consent for online services vary across EU countries. For weddings, schools, sports events and family events, avoid assuming that a general adult event notice solves every situation involving minors. Use appropriate access controls, moderation and local guidance where needed.

What GDPR principles matter most for an event photo platform?

  • Lawfulness, fairness and transparency: know the legal basis and explain the processing clearly.
  • Purpose limitation: collect photos for a defined purpose and do not silently repurpose the data.
  • Data minimisation: collect only the data needed for the event feature.
  • Storage limitation: do not keep personal data indefinitely just because storage is cheap.
  • Integrity and confidentiality: use appropriate security and access controls.
  • Accountability: be able to explain the choices and safeguards you made.

How CamLove can support a privacy-conscious event workflow

CamLove is a tool, not a substitute for the organiser's legal assessment. The platform can support a privacy-conscious workflow by keeping event galleries out of search indexing, allowing private gallery access, supporting password protection and moderation, separating the TV Photo Wall from organiser access, and letting guests upload through the browser without forcing a guest account. The organiser still needs to choose appropriate settings, information notices, retention and any marketing-consent flow for the specific event.

Create a private event photo gallery with CamLove

Create a private event photo gallery with CamLove

FAQ

FAQ

Are wedding photos personal data under GDPR?+

They can be. If a living person is identified or identifiable from a photo or associated information, the processing can involve personal data. The exact GDPR obligations depend on the context.

Does every person in a wedding photo have to sign a consent form?+

Not as a universal GDPR rule. Consent is one possible lawful basis, but other legal grounds may apply depending on who processes the photos, why, and in what context.

Is a private link enough to make a gallery GDPR-compliant?+

No. Access control is only one part of data protection. You also need an appropriate legal basis, transparency, purpose limitation, minimisation, retention and other safeguards relevant to the processing.

Can I use upload emails for future marketing?+

Do not assume so. Marketing is a separate purpose and may require a separate valid consent or another applicable legal basis under privacy and electronic-marketing rules.

Should a private wedding gallery appear in Google search?+

Normally there is no need for a private event gallery to be search-indexed. Keeping private galleries out of search results better matches guest expectations, although this alone does not determine GDPR compliance.

CamLove

Create your free CamLove gallery

No app and no guest sign-up. Just a QR code and every memory in one place.

Start free →

Related articles

Read in another language