It is just past midnight, the Christmas party is winding down, and someone says the sentence every organising team knows: "Just drop your photos in the group." By the next morning there are five groups. Management is in two of them and not in the other three. A picture of your colleague from accounting, one she would never have approved, now sits on forty phones. And at some point someone from HR asks whether all of this is actually fine.
The short answer: not really. The long answer is this article.
Why your company party is legally different from a private one
At your brother's wedding, the hosts are generally covered by the GDPR's household exemption (Art. 2(2)(c) GDPR). Purely private celebrations fall outside the regulation, as long as the photos stay within a private circle.
A company party is a different matter. As soon as a business hosts an event, lets photos of its staff be taken there, and then displays them on a screen, stores them or uses them later, that is processing of personal data. You as the employer are the controller, not the colleague who pressed the shutter. The household exemption will not help you here.
That is no reason to do without photos. It is a reason to set the process up properly once. After that it is routine, and you can reuse it for every event that follows.
Two bodies of law you should keep apart
In German-speaking Europe, photos of people touch two separate sets of rules. Anyone who thinks of only one reliably overlooks the other.
GDPR: taking and storing
A photo in which a person is identifiable is personal data. Every act of processing needs a legal basis, information for the people concerned under Art. 13 GDPR, a defined purpose, and an answer to the question of when the data disappears again.
The right to one's own image: showing and distributing
Alongside that, the right to one's own image protects publication. In Germany through sections 22 and 23 KUG, in Austria through section 78 UrhG. Put simply, a person's likeness may generally only be displayed publicly with that person's consent, and the legitimate interests of the person depicted must not be harmed.
Satisfy both sets of requirements and the question is settled for you.1
The legal basis: why consent is delicate in an employment relationship
The obvious route is consent. In an employment relationship, though, it has a weak spot that supervisory authorities and courts examine very closely: the imbalance of power between employer and employee.
Consent is only valid if it is freely given. And it is only freely given if saying no carries no consequences. Someone asked in front of the assembled workforce whether they want to be on the screen rarely says no honestly. In Germany, section 26(2) BDSG additionally requires employee consent to be in writing as a rule, along with information about the right to withdraw.
In practice that means three things:
- Ask beforehand, not afterwards. A paragraph in the invitation email is worth considerably more than a notice next to the bar.
- Saying no has to be easy. Anyone who does not want to appear on the wall says so once, informally, to one named person, and never has to justify it.
- Withdrawal at any time. Consent is not a one-way street. If someone gets in touch three weeks later, the picture has to be able to disappear, everywhere.
Information is not consent
This is where the most common mistake happens, and it usually happens in good faith. A note in the invitation informs your staff, but it does not obtain their agreement. And silence is not agreement: someone who does not object has not consented. If your documentation ends up saying "legal basis: consent" while nobody ever actively agreed, you are processing the photos without the basis you believe you have.
Consent therefore requires an active step from every person concerned. For employees in Germany, section 26(2) BDSG generally requires written or electronic form. In practice very little is needed: a tick box when registering for the party, a short reply to the invitation email, or a column on the attendance list that people mark.
If that effort feels excessive, that is a legitimate decision. But then you have to rely honestly on a different basis and document it as such. For purely internal, documentary photos, legitimate interest under Art. 6(1)(f) GDPR can carry the processing in individual cases, together with a balancing test that you record. In that case objection is the right instrument, not consent.
What does not work is the mixture of the two: informing people, collecting no agreement, and calling the result consent anyway.
Once the pictures move into marketing, onto LinkedIn or onto the careers page, there is no way around genuine, demonstrable consent in any event.
Where the WhatsApp group fails
The group is convenient, which is why it is so widespread. It satisfies none of the points above.
- No control before distribution. A photo has been sent before anyone has looked at it. Pulling it back is impossible.
- No way to delete. You can remove a message from the group. You cannot remove it from the devices of the forty people who received it.
- No defined set of recipients. Groups get forwarded, screenshots travel, former colleagues stay members.
- No evidence. If someone asks who approved what and when, you have nothing to show.
- No separation of private and work. Whoever is not in the group gets nothing. Whoever is in it hands their private mobile number to everyone else.
On top of that comes the practical annoyance: the pictures are compressed, spread across several chats, and simply impossible to find a few months later.
How a moderated photo wall defuses the problem
A photo wall does not answer your legal questions. What it does is give you the tools to act on the answers at all. With EventWall it looks like this:
Access only through your link. People reach the wall if they received the link or the QR code from you. It is not publicly listed. That gives you a genuinely defined set of recipients for the first time.
Approval before display. With moderation switched on, no photo appears on the screen before someone on your team has approved it. That is the decisive difference from the group: a deliberate decision sits between uploading and becoming visible.
Permanent deletion. You remove individual pictures permanently, both from the screen and from the gallery. A withdrawal can actually be carried out, not just promised.
Little data from guests. No app download, no registration, no social media account. All your guests enter themselves is the photo, plus an optional caption and an optional name, and anyone who prefers to take part without a name can.2
Stored in the EU. Photos and the associated database backups sit with our infrastructure partner in a data centre in Frankfurt am Main. Which other service providers are involved is set out in full in our privacy policy, so that you can reflect it in your record of processing activities.
Data processing agreement under Art. 28 GDPR. Because you are the controller as a business and we process on your behalf, you need a DPA. We conclude one with commercial organisers; a short message is enough.
The part almost everyone forgets: the time after the event
The evening is over, the screen is off, and that is not where your responsibility ends. Three points that most often go wrong in practice:
Purpose limitation. Photos collected for the internal party are not automatically marketing material. If a picture from the summer party turns up in a job ad six months later, that is a new purpose and needs its own consent from the identifiable people in it.
A deletion plan. Decide in advance how long the pictures should stay available, four weeks for the team to download them for instance, and who deletes the wall afterwards. With EventWall the photos stay stored until you delete them, either individually, as an entire wall, or along with the account. That is deliberately your decision, which is exactly why it needs a date and a named person.
People who have left. Someone leaving the company rarely thinks about the photo wall from the last kick-off. A deletion date handles that case automatically.
A ready-made paragraph for the invitation
Most of the work is a paragraph you write once and reuse for every event. You can take this one as a starting point and adapt it to your situation:
At our party on 12 December we will be setting up a digital photo wall. Anyone who wants to can upload photos from the evening via a QR code, and they will then appear on the screen in the hall. Every picture is approved by [name of the responsible person] before it is displayed. The photos are intended solely for the people attending this event and will be available until 15 January. After that we will delete the wall completely. They will not be used for advertising or social media. If you would rather not be photographed, or want a picture removed, a short message to [email address] is enough, including after the party.
Four details make this paragraph usable: who decides, how long the pictures stay, what they will not be used for, and who to contact. Leave one of them out and you create exactly the uncertainty that leads to awkward conversations later.
What this paragraph does not do
It is an announcement. It is neither the consent nor the complete privacy notice, and it should not be sold as either.
For consent it lacks the active agreement described above. For the information required by Art. 13 GDPR it lacks several mandatory items: who the controller is and how to reach them, the data protection officer where applicable, the specific legal basis, the retention period, the recipients, employees' rights of access, rectification, erasure, objection and withdrawal, and the right to lodge a complaint with the competent supervisory authority.
None of that belongs in an invitation email in full. The usual route is one closing sentence pointing to your complete privacy information, along the lines of: "Full details of the processing are available at [link]; [data protection contact] will answer any questions."
If your company has a works council, bring them in early. Depending on how they are set up, photo activities in the workplace are often subject to co-determination, and the process takes considerably less time when it happens before the invitation rather than after it.
Checklist for your next company party
- Define the purpose: entertainment on the night only, internal documentation, or external communication as well?
- Determine and document the legal basis. With consent, step 3 follows; with legitimate interest, record the balancing test instead.
- Actively obtain consent if that is your basis: one response per person, in writing or electronic form as a rule for employees in Germany. A notice without a reply does not count.
- Inform people in advance, ideally in writing in the invitation: what happens to the pictures, for how long, who gets to see them, how to withdraw.
- Link from that information to your complete privacy notice, covering the controller, legal basis, retention, data subject rights and the right to complain to the supervisory authority.
- Involve the works council if there is one. Photo activities in the workplace are frequently subject to co-determination.
- Name a route for objection and withdrawal: one person, one email address, no form-filling marathon.
- Switch on moderation so that no picture reaches the screen unchecked.
- Signpost the photo wall visibly on site, for example at the entrance and by the buffet.
- Conclude the DPA with the provider before the first photo is uploaded.
- Set a deletion date and enter a responsible person.
- Obtain separate consent from the people depicted before any reuse in marketing.
Steps one to seven will cost you perhaps an hour the first time. For the second event you copy the paragraph out of the old invitation.
For event agencies and caterers
If you run events for clients, the roles shift. The controller under the GDPR is usually your client as the host, and you sit in between. So settle early in the quote who informs the guests, who moderates, and who deletes after the event. That is not paperwork for its own sake, it is an argument in the sales conversation: you are not just supplying a screen, you are supplying a clean process.
One account covers any number of client events, each with its own wall and its own access code. The details are on our page for corporate events.
Frequently asked questions
Is a sign at the entrance enough as consent?
No. A clearly visible sign is an important building block of transparency, but it is neither consent nor the complete information required by Art. 13 GDPR. Consent presupposes active agreement, and the mandatory details belong in a privacy notice that you point to.
What about group photos where someone did not want to take part?
Then that person does not belong in the picture. Blurring them afterwards is possible but unsatisfying. It is easier to know the preference in advance and take it into account while photographing.
May we use the photos on social media afterwards?
Only with separate consent from the identifiable people for exactly that purpose. Agreeing to the wall on the night does not cover it.
What happens if someone uploads an inappropriate picture?
With moderation it never appears in the first place. Without moderation it is visible immediately, but it can be deleted at any time and then disappears from the screen right away.
Do our guests need an app?
No. Scan the QR code, pick a photo, done. The browser on their phone is enough.
This article gives a practical overview and is not legal advice. For how to set this up in your own company, please involve your data protection officer or a lawyer.
Want to try it straight away? event-wall.com/en/corporate has everything on corporate events, or you can create an account directly and set up your first wall free of charge.
