Back to BlogSetup & Tips

Photo Booth Privacy: A GDPR Checklist for Event Hosts

September 3, 20269 min readBy Steffen Knödler
Guest holding up a smartphone to photograph a group of people

A photo booth produces hundreds of pictures of identifiable people in a few hours. Under the EU GDPR and the UK GDPR, each of those pictures is personal data. For a private birthday in your living room the rules barely apply; once a company, a club, or a paid provider is involved, or photos are uploaded somewhere, they do. This guide explains what matters and ends with a checklist you can print and tape to the back of the booth.

Disclaimer: this is general information from experienced event hosts, not legal advice. For corporate or public events, or anything involving minors at scale, ask a data protection officer or a lawyer.

Why photos count as personal data

A face is enough to identify a person, so a booth photo falls under Art. 4(1) GDPR. Biometric processing (face recognition, automatic tagging) would move the photo into the "special category" of Art. 9 with stricter handling. A booth that takes a picture and applies an instant-photo frame does not do this; some cloud booths with face-matching galleries do.

When the GDPR applies to your party at all

The GDPR has a "household exemption" (Art. 2(2)(c)) for purely personal or household activities. A family wedding where the booth photos stay with the guests is generally covered. The exemption stops applying when:

  • a company or association organizes the event (staff party, club anniversary);
  • a rental provider processes the photos as part of their service;
  • photos are published on a public gallery, a company page, or social media;
  • photos are uploaded to a cloud service under the host's account for later use.

Most rental booths and cloud booth apps fall into the second and fourth cases.

Legal basis: consent or legitimate interest

Every processing needs a legal basis under Art. 6 GDPR. For event photos, two are realistic:

Consent (Art. 6(1)(a))

Guests agree to being photographed and to what happens with the picture. Consent must be informed, specific, freely given, and revocable. Stepping in front of the camera after reading a clear sign is usually treated as consent for the capture itself. It does not cover publication or marketing use; that needs a separate, explicit agreement, ideally in writing.

Legitimate interest (Art. 6(1)(f))

The organizer's interest in documenting the event is balanced against the guests' rights. This works for capturing and internal sharing at a company event, provided guests are informed and can opt out by not using the booth. It is a weak basis for publishing close-ups of employees or handing photos to a third party.

Practical rule: capture at the booth → legitimate interest plus a clear sign. Publishing or marketing → explicit consent from the people in the picture.

Informing guests: the sign at the booth

Art. 13 GDPR requires you to tell people, at the time of collection, who processes their data and why. For a booth this is a printed sign at eye level, A4 or larger, next to the screen:

  • who is responsible (host or company, contact email);
  • what happens with the photos (guest download only / gallery / print);
  • where they are stored and for how long;
  • whether a third party (rental company, cloud provider) receives them;
  • how to have a photo deleted;
  • that using the booth is voluntary.

If the booth processes photos only on the device, the sign becomes short: "Photos are created in the browser of this tablet, downloaded by you, and not stored or transmitted by the organizer." That sentence answers four of the six points. For company events, add a QR code to the full privacy notice.

Children

Children enjoy heightened protection throughout the GDPR, and consent for minors under the digital age of consent (13–16 depending on the member state, 16 in Germany, 13 in the UK) requires a parent. At a family party, ask the parents before a child's collage goes into a shared album. For school fairs and youth events, collect written parental consent in advance and instruct the booth helper not to upload children's pictures without it. Our wedding photo booth guide covers briefing a helper.

Where the files end up

SetupWhere photos liveGDPR implications
Browser booth, local processingOnly in the guest's downloadNo storage by host, no third party, no transfer. A sign covers it.
Booth app with cloud gallery (EU host)Provider's servers in the EUData processing agreement (Art. 28) needed; retention and deletion must be defined.
Booth app with cloud gallery (US or other non-EU host)Servers outside the EUAdditionally needs a transfer mechanism (EU–US Data Privacy Framework or Standard Contractual Clauses). Check the provider's privacy policy explicitly.
Rental company with post-event galleryProvider's cloud, often also their marketing archiveDPA needed, plus a clause forbidding marketing use of guests' faces.

Local processing simplifies everything: if nothing is stored by you and nothing is sent to a server, there is no processor to contract, no retention to enforce, no transfer to justify, and no deletion request you cannot fulfil. Photobooth Free, the free online photo booth, works this way: it runs in the browser, takes four countdown photos, builds the collage locally, and the photos stay on that device: as the JPEG the guests download and, if the host leaves it switched on, in the on-device gallery the host can clear at any time. A separate QR-based gallery such as Guest Pictures is a distinct service; treat it as the "cloud gallery" row above.

Retention and deletion

Art. 5(1)(e) requires that data is kept no longer than necessary. Define the retention period before the event, put it on the sign, and set a reminder:

  • Private event with shared album: 4–12 weeks, then delete or hand the archive to the couple or birthday host.
  • Company event: delete the raw set once the internal newsletter is out; keep only pictures with publication consent.
  • Rental gallery: ask for the default retention (often 30–90 days) and get written deletion confirmation.

Deletion requests (Art. 17) must be honoured without undue delay. With a local booth the answer is "we hold no copy"; with a cloud gallery you need an admin login during the event.

Questions to ask a rental company

Send these before signing:

  1. Where are photos stored, in which country, and for how long?
  2. Is there a data processing agreement under Art. 28, and can we see it?
  3. Do you or your software vendor use guests' photos for marketing, portfolios, or AI training?
  4. Does the software use face recognition or automatic tagging?
  5. How do guests request deletion, and how fast is it done?
  6. Can the online gallery be switched off so photos are only printed and handed over?

A reputable provider answers all six in one email. Hesitation on 3 or 4 is a reason to look elsewhere.

Printable checklist

Before the event

  • Decided: local processing, cloud gallery, or rental with gallery
  • Legal basis chosen (legitimate interest for capture, consent for publication)
  • Data processing agreement signed with rental or cloud provider, if any
  • Non-EU transfer checked, if the provider is outside the EU
  • Sign printed (responsible party, purpose, storage, retention, contact, voluntary use)
  • Parental consent collected for youth or school events
  • Helper briefed: no uploads or posts without consent

During the event

  • Sign visible at eye level next to the booth
  • Face recognition and auto-tagging disabled in any app
  • Guests asked before their photo goes into any shared album
  • Session reset after each group

After the event

  • Deletion executed on the noted date and, for rental galleries, confirmed in writing
  • Publication only of photos with explicit consent

For the physical setup, see our photo booth tips and the DIY photo booth guide.

FAQ

Do I need a privacy sign at a private birthday party?

A purely private party usually falls under the household exemption. A short sign is still good practice: it tells guests what happens to their pictures and avoids the awkward "please delete that" conversation.

Can I post booth photos from a company party on LinkedIn?

Only with explicit consent from the identifiable people. Legitimate interest covers capture and internal sharing, not public marketing use.

Is a US-based photo booth app allowed under the GDPR?

Yes, if the provider is certified under the EU–US Data Privacy Framework or uses Standard Contractual Clauses, and you sign a data processing agreement. Check before the event.

How does a local browser photo booth help with the GDPR?

If photos are processed on the device and never uploaded, the host stores nothing and shares nothing. There is no processor to contract, no retention to manage, and no data to delete; the guests' downloads are the only copies.

Steffen Knödler

Our editorial team checks every guide against the current workflow and feature set of the free browser photo booth.

About the product and editorial process

Try These Tips Yourself!

Ready to create amazing photos with all the effects mentioned in this article? Try our free photo booth now!