GDPR for School Photos: What Photographers Need to Consider
The topic of data protection and GDPR causes uncertainty for many school and kindergarten photographers. Schools and daycares rightly demand watertight concepts when it comes to photos of children. How do you ensure that your workflow is GDPR-compliant?
The legal basics in school photography
Since the GDPR came into force in 2018, the following applies: Photos of people may only be processed with valid consent or on another legal basis. Since students are minors, the legal guardians usually have to agree to school photos and daycare pictures.
The parents' declaration of consent
Before you even pick up the camera, you should have written or digital consent from the parents. Many daycares and schools obtain this at the beginning of the school year. However, it is important that the consent covers the specific purpose (e.g. “Creation of portraits and class photos for purchase in a protected online gallery”).
The Data Processing Agreement (DPA)
As a photographer, you process personal data (e.g. names, classes, and photos) on behalf of the school or daycare. Online shop software systems in turn process this on your behalf.
Therefore you must:
- Conclude a DPA with the school or daycare in order to meet the legal requirements.
- Conclude a DPA with your online gallery platform. With Pixalo, you can easily generate and conclude this contract digitally directly in the dashboard.
How to protect photo galleries from unauthorized access
It is an absolute no-go to make photos of children available in public galleries where anyone can browse. Every child needs an individual, password-protected access:
- Individual PIN codes: Parents receive a password card (PIN). Upon login, they only see photos of their own child.
- Class & Group pictures: These should be stored in separate folders that can only be viewed by logged-in parents of the same class.
Deletion periods and data minimization
The GDPR stipulates that data must be deleted when the purpose of processing no longer applies. Set fixed deletion periods (e.g. 6 months after the photo day). The system should automatically and completely delete student lists, e-mail addresses and uploaded photos from the servers after this period has expired.
Conclusion: On the safe side with the right tool
Data protection does not have to be an obstacle. By relying on GDPR-compliant software whose photo and customer data are hosted on German servers (Frankfurt am Main), you minimize your liability risk and convince school management with a clear security concept.
Test school photography shop system with 0% commission
Pixalo is the commission-free alternative for school and daycare photographers in the DACH region. Own domain, app sorting and Stripe/PayPal direct connection.