Compliance
Photography, video and GDPR at European corporate events: a practical primer
General educational notes on how European corporate events typically handle photo and video consent under GDPR. Not legal advice.
Amplify editorial team · 17 March 2026 · 8 min read

This article is a general educational primer, not legal advice. Every organisation should confirm its approach with its own data protection officer or lawyer.
GDPR has made corporate event organisers cautious about photography and video. Some of that caution is warranted; much of it is based on a misunderstanding of what the regulation actually requires. This piece summarises how the events we cover typically handle photo and video consent.
The basic idea
GDPR generally treats a photograph or video of an identifiable person as personal data. Capturing, storing and publishing that data requires a lawful basis. For corporate events, the two lawful bases that typically apply are consent and legitimate interests. Both are workable; neither is a blocker.
Consent at ticketing
The cleanest model for closed corporate events is consent embedded in the ticket terms: by attending, the attendee acknowledges that photography and video will be produced for the organiser's own promotional use.
Even when consent is embedded in ticket terms, best practice is still to display a visible sign at the entrance and to offer an opt-out marker on the day — a coloured wristband or lanyard clip that the crew is briefed to respect.
Legitimate interests for open events
For events without a ticket-based flow, the more workable model is typically legitimate interests: a documented assessment plus clear on-site notification that the event is being photographed for the organiser's promotional and communications use.
This is the pattern most major European trade shows and conferences already operate under.
Speakers and public figures
Speakers on stage, executives on stage and identified public representatives are typically treated differently from general attendees: their appearance is intentional and on-record. Best practice is still to include a photography clause in the speaker agreement.
Storage and retention
Working files should be stored on encrypted drives with access controls, retained only as long as necessary, and not silently repurposed. A reasonable production partner can provide a short document describing how they handle event material.
The takeaway
GDPR is not a reason to stop photographing European corporate events. It is a reason to plan the consent flow, notify attendees clearly, provide an opt-out and handle files responsibly. All of that is compatible with high-quality corporate imagery. Confirm your specific approach with your legal counsel.
Have an event or corporate content project? Let's talk.
Request a quote →


