Event photo sharing
that fits your
privacy notice
Employee event photos are personal data. Knipsmig is built to make GDPR compliance straightforward: media stored in the EU, automatic deletion after 1 month, no guest accounts, and full host control over every photo.
No guest sign-up • Host moderation available • DPA on request
The facts your DPO will ask about
Straight answers, no compliance theater
Stored in the EU
Photos and videos live on AWS eu-west-1 (Ireland) and Hetzner (Germany). Media storage stays on EU infrastructure.
Deleted after 1 month
Free events auto-delete after 1 month. Data minimization isn't a setting you have to remember — it's the default.
No guest accounts
Employees upload via QR code in the browser — no account, no email, no profile. Minimal personal data collected in the first place.
Pre-moderation available
Enable host approval and every upload waits for review before anyone else sees it — useful when not everyone wants to be on the party wall.
Delete anything, any time
The host can remove any single photo instantly, or delete the entire event and all its media at any moment.
DPA on request
Your company is the data controller; Knipsmig processes photos on your behalf. Need a written DPA for procurement? Contact us and we'll sort it out.
What GDPR actually requires for employee event photos
Photos of identifiable employees are personal data. Here is what that means in practice, and how each requirement maps to a Knipsmig control.
A lawful basis
You need a legal ground for processing — for internal event photos this is usually legitimate interest, or consent where photos will be used more widely (e.g. marketing). That assessment is yours as the employer; no tool can make it for you.
How Knipsmig helps: because guests upload without accounts, the processing stays limited to the photos themselves — a narrower, easier-to-justify footprint than platforms that also profile the people uploading.
Informing employees
Employees must know photos are being taken, where they're stored, and for how long — typically a short privacy notice on the invitation or at the venue.
How Knipsmig helps: the notice writes itself: "Photos are shared in a private album hosted in the EU and deleted after 30 days unless the host chooses to keep them." Both halves of that sentence are simply how the product works.
Storage limitation
Data may only be kept as long as needed. Indefinite retention of party photos "just in case" is exactly what regulators dislike.
How Knipsmig helps: automatic deletion after 1 month is the default for free events. Retention beyond that is a deliberate host decision, not something that happens by forgetting.
Right to erasure
An employee who doesn't want a photo of themselves online can ask for it to be removed, and you need a way to actually do that.
How Knipsmig helps: the host deletes the specific photo from the dashboard in seconds. And the auto-deletion backstop means even unhandled cases resolve themselves within a month.
A processor agreement (Article 28)
When your company organizes the event, you are the data controller and Knipsmig is a processor handling photos on your behalf. Article 28 GDPR requires that relationship to be governed by a written data processing agreement.
How Knipsmig helps: we sign DPAs on request. Need one for procurement? Contact us and we'll sort it out.
This page explains how Knipsmig's controls map to common GDPR requirements. It isn't legal advice — your DPO or counsel decides what your organization needs.
How a privacy-conscious event runs
Create the event and set your controls
Thirty seconds of setup. Enable host approval if you want to review photos before colleagues see them, and add a co-host from HR or comms if helpful.
Add a line to your privacy notice
"Photos are shared in a private album hosted in the EU and deleted after 30 days unless kept." Put it on the invite and the QR signage.
Employees upload without accounts
Scan the QR code, upload from the browser. No sign-ups means no extra personal data to inventory later.
Retention handles itself
Download what you need, delete anything on request, and the free event auto-deletes after 1 month either way.
GDPR and event photos FAQs
Where is the data stored?
Photos and videos are stored in the EU — on AWS in eu-west-1 (Ireland) and on Hetzner in Germany. Media does not leave EU infrastructure for storage.
How long are photos kept?
Free events are automatically deleted after 1 month. That's a built-in retention limit you can state in your privacy notice: photos are deleted after 30 days unless the host chooses to keep the event. Hosts can also delete individual photos or the entire event at any time before that.
Do guests need to create accounts?
No. Guests upload via a QR code in their browser — no account, no email address, no profile. That keeps the personal data collected from employees to a minimum.
Can employees have their photo removed?
Yes. The host can delete any individual photo instantly from the dashboard, which supports erasure requests. And if no action is taken, the photo disappears anyway when the free event auto-deletes after 1 month.
Do you sign DPAs?
Yes, on request. If your procurement or legal team needs a written data processing agreement under Article 28, contact us and we'll sort it out.
Photo sharing for your company events
The same privacy defaults apply to every event you run
Photo sharing your legal team can live with
EU hosting, deletion by default, no guest accounts. Create an event and see for yourself.
No guest sign-up • Deleted after 1 month by default • DPA on request