Someone takes photos at every work party. On very few of them has anyone settled beforehand what may be done with the pictures. That usually surfaces when a colleague wants to put a group shot on LinkedIn and stops to wonder whether that's actually alright.
This guide is written from the point of view of whoever is organising the event: what you settle beforehand, what matters on the night, and what happens to the images afterwards.
First, the caveat: this is practical orientation, not legal advice. For anything with real reach, for campaigns, or whenever you're unsure, the case belongs with your data protection officer or a qualified lawyer. National rules on top of the GDPR vary between countries.
The short answer
Photos in which staff are identifiable are personal data. You need a lawful basis to process them. For purely internal use β intranet, a look back at a team meeting β organisations generally rely on legitimate interests. Once the images go outward, onto your website, social media or recruitment material, you normally need consent from the people shown. And in both cases you have to tell people in advance that photography is happening.
Legitimate interests or consent?
Both are lawful bases under Article 6 of the GDPR, and the choice has practical consequences.
| Legitimate interests Art. 6(1)(f) | Consent Art. 6(1)(a) | |
|---|---|---|
| Typical for | Internal use: intranet, internal newsletter, year in review | External publication: website, social media, advertising |
| Effort | Low β informing people is enough, nothing to collect | High β per person, documented |
| Withdrawal | Individuals have a right to object | Withdrawable at any time, no reason required |
| The catch | Requires a balancing test you may have to justify | In an employment relationship, freely-given consent needs particular care |
The second catch is the one organisers underestimate. There is an imbalance of power between employer and employee, which is exactly why regulators scrutinise consent at work β and why some countries impose extra conditions on top of the GDPR. In practice it means nobody may be disadvantaged for saying no, and saying no must be possible without explaining yourself. A form passed around at the door while everyone watches does not really clear that bar.
The distinction that decides everything: internal or external
The question isn't "may I take photos", it's "where does this image end up". People at an internal Christmas party expect pictures to circulate inside the company. They generally do not expect to appear on the company's Instagram account.
That expectation is the yardstick. The further an image travels from what the person could reasonably have anticipated, the more you need explicit consent β and the more carefully you should be able to show you have it.
What you settle beforehand
- A notice in the invitation. One sentence is enough, but it has to exist before the event: that photos will be taken, who is taking them, what they'll be used for, and who to speak to if you'd rather not be in them.
- A sign at the venue. Clearly visible at the entrance, in the same language as the invitation. Anyone who only finds out on the night at least still has a choice.
- Define the purpose β narrowly. "For internal communications" is a purpose. "For marketing purposes" is a blank cheque, and vulnerable for exactly that reason.
- Make opting out visible. Coloured wristbands, a sticker on the name badge, a designated table outside the photo area β anything the photographer can read at a glance, so nobody has to explain themselves in front of the group.
- Brief the photographer. Ask before portraits and small group shots. It costs five seconds and prevents most of the arguments that come later.
Wording for the invitation
"[Name / agency] will be photographing our Christmas party for our internal communications. The images will appear on the intranet and in our year in review; we will only publish them outside the company with your explicit agreement. If you'd rather not be photographed, just let [contact] know, or pick up a [wristband/sticker] at reception on the night β that's enough, and you don't need to give a reason."
Adapt it to what's actually true for you. If you do intend to use the images externally, say so and collect consent separately β don't reinterpret it after the fact.
What matters on the night
Two things prevent most problems in practice:
- No pictures of people who are drunk. Legally this is a personality-rights question; practically it's simple. You don't publish images that embarrass someone, whatever consent you hold. Best to delete them straight away.
- Children only with a parent's agreement. Family days and summer parties with children attached are held to a stricter standard, and consent comes from whoever holds parental responsibility.
What happens to the images afterwards
The part that gets forgotten most often β and the first thing an audit picks up on.
- Where they live. Not a personal cloud folder, not a WhatsApp group. A system your IT controls and for which you have a processing agreement in place.
- Who can see them. For an internal party, staff is almost always the right audience β not the open internet.
- A retention period. Set one. "We keep them as long as they're relevant" is not a period. A year after the event is a common and defensible figure.
- Withdrawal you can actually action. If someone later wants an image gone, you have to be able to find it. That only works with an organised library.
Checklist
- Photo notice is in the invitation, at least four weeks ahead
- Sign at the entrance, clearly visible
- Purpose is narrowly worded and written down
- Opting out is possible without explanation and legible to the photographer
- Consent for external publication is documented
- Storage location settled, access limited
- Retention period set
- If in doubt: your DPO has looked at it beforehand
πΈ Photos where the consent is built into how it works
With FotoBingo we don't photograph your people β your guests do, voluntarily, because taking the photo is the game. Anyone who doesn't want to join simply doesn't; anyone who uploads an image is actively choosing to in that moment. The pictures land in one place instead of on a hundred phones, and you get them back organised.
Plan a corporate event βCommon questions
Is a notice in the invitation the same as consent?
No. A notice satisfies your transparency obligation; it does not replace consent. For internal use resting on legitimate interests it's usually sufficient, but for external publication you need real, documented agreement.
Can employees take their own photos at the party?
Purely for personal use, that falls under the GDPR's household exemption. The moment those images land in a company chat, on a company account or in a shared gallery it stops being personal use β and then the same rules apply to them as to you as organiser.
What if someone withdraws afterwards?
Consent can be withdrawn at any time. You then remove the image from every channel it was published in. Withdrawal takes effect going forward; it doesn't make the earlier use retrospectively unlawful.
Does this apply to a team of ten?
Yes. The GDPR has no headcount threshold. With ten people the effort is simply far smaller β you can genuinely ask everyone individually.
In short
Inform people before the event, word the purpose narrowly, make opting out possible without explanation, keep internal and external clearly separate, and hold to a retention period afterwards. That covers most of what goes wrong in practice. For anything beyond it β and for any publication with real reach β ask your data protection officer.
What an event looks like where the photos happen voluntarily and as a side effect is on our page for corporate events. How to plan the rest of the evening is in our guide to planning a Christmas party.