Mabooth
The BoothPricingFAQContact
/
Book Now
Corporate6 min read

GDPR and a photo booth at the company party

A photo booth at the staff party is a crowd-pleaser — but sooner or later someone in HR or events asks how this squares with GDPR. Short answer: a photo booth is entirely fine, you just need to think a few things through in advance. Here is a practical walk-through in plain language.

Why it matters

A photo of an identifiable person is personal data. That applies to booth photos just as much as the group shot in the annual report. If you also collect email addresses to send out the digital gallery, those are personal data too. So GDPR applies — but that does not make it complicated.

The point of getting this right is not to tick off a rule; it is that your staff feel comfortable. Nobody should have to wonder where their photo ends up. Once you have thought it through beforehand, the booth is simply the fun addition it is meant to be.

Legal basis: usually legitimate interest

For internal event photos, most employers rely on legitimate interest as their legal basis. The company has a reasonable interest in documenting and enjoying its own staff party, and guests choose to step into the booth themselves. That makes legitimate interest a natural basis for this particular situation.

Consent sounds simple but is actually a weaker basis here — it has to be entirely free, and in an employer–employee relationship it is hard to show that consent truly is. Whatever the basis, the key is transparency: tell people the booth is there and how the photos will be used.

A practical checklist before the party

Most of this is common sense put in writing. Run through the list before the event and you are set.

  • Inform people in advance — mention in the invitation or on the night that a photo booth is there and how the photos are used
  • Put up a small sign by the booth: that photos are taken, who is responsible and where the gallery goes
  • Keep participation voluntary — a photo booth is opt-in by nature; nobody is photographed who does not step in themselves
  • Share the gallery link internally, for example via the intranet or an email to those who attended
  • Do not post identifiable employees externally (LinkedIn, website) without asking them first
  • Set a retention period — how long the gallery stays up — and delete the photos afterwards
  • Stay in control: decide yourselves whether a digital gallery is created at all and how long a gallery link stays live

Less data to keep track of

A core GDPR principle is not to collect more than you need, and not to keep it longer than necessary. You as the company decide why and how the photos are processed — you are the one in control. The fewer photos that are stored, and the shorter they stay, the less there is to keep track of.

So a good question to ask yourselves is: do you actually need a digital gallery, or are the prints on the spot enough? If you do want a gallery, decide in advance how long the link should stay live. It is always easiest to protect data that was either never collected or has already been deleted.

How Mabooth keeps it simple

You decide whether a digital gallery is created at all — if you only want the prints on the spot, no photos need to be stored digitally. If you do choose a gallery, it is delivered via a private link that is not published anywhere, available only to whoever you share it with.

And the link does not live forever: a gallery link is automatically destroyed after 14 days. That keeps your data footprint small on its own, without anyone having to remember to ask for deletion.

An important caveat

This is general guidance, not legal advice. The rules and their interpretation can change, and every organisation is different. Check with your own data protection officer or legal counsel before you settle your routines — especially if you have a large staff or feel unsure about the legal basis.

FAQ

Usually not. For internal event photos most employers rely on legitimate interest rather than consent — partly because consent in an employment relationship is hard to show as truly free. What matters is that you clearly inform people that the booth is there and how the photos are used.

Decide in advance whether you even need to store the photos digitally. With us, you choose whether a gallery is created at all, and if it is, the gallery link is automatically destroyed after 14 days. If you only want the prints on the spot, no gallery is stored.

Sharing the gallery internally is one thing; publishing identifiable employees externally is another. Always ask the people shown in a photo before you post it on LinkedIn or your website — it is both courteous and safest from a data protection point of view.

You as the company decide why and how the photos are processed, so the main responsibility sits with you. We keep our own role as small as possible: we only handle a gallery if you ask us to, and if we do, the link is automatically destroyed after 14 days. If you have your own data protection policy or questions about agreements, check with your data protection officer.

A photo booth your company party can trust

Want a photo booth that respects your guests and your data protection policy? Tell us about your event and we will show you how we keep you in control — and get back to you within 24 hours.