GDPR checklist for school photographers
Tick off, project by project.
Before photo day
- Data processing agreement signed with the school or its operator (Art. 28 GDPR)
- Processing agreements with the gallery platform and the photo lab in place
- Consent forms with separate purposes handed to the school
- Consent forms collected and documented
- List of children without consent received and shared with the team
- Record of processing activities updated for this project (Art. 30 GDPR)
- Privacy policy on your own website up to date
On photo day
- Children without consent are not photographed
- No child's name next to a photo on posters or in messages
- Memory cards and laptop encrypted or secured
- No photos on helpers' private devices
- No transfer over insecure channels such as messengers or unencrypted email
After photo day
- Photos transferred only over an encrypted connection
- Online gallery reachable only with a personal access code
- Order deadline and deletion date communicated to parents
- Photos deleted after the season (deletion period: [Number of weeks] weeks)
- Deletion documented, backups included
Technical measures
- SSL encryption for gallery and shop
- Payments through certified providers, no card data on your own systems
- Regular backups with access protection
- Team access rights limited to what is needed
- Two-factor login for every account with photo access
In an emergency: data breach
- Report to the supervisory authority within 72 hours (Art. 33 GDPR)
- Inform those affected if there is a high risk (Art. 34 GDPR)
- Document the incident, its cause and the measures taken
Country notes
Authority: the data protection authority of your country.
Schools are often public bodies. Ask for the school's data protection officer and local education rules.
Image rights may apply alongside data protection law. Check your national rules.
Template, not legal advice. Review the list with your privacy adviser.