GDPR and client photo galleries: a practical guide for UK photographers
The LensQuay Team · 24 Aug 2026
If you photograph people in the UK, you handle personal data — recognisable faces, and usually names and email addresses too. That means UK GDPR applies to you. It sounds daunting, but for most photographers it comes down to a few sensible habits. This is a plain-English overview, not legal advice — if in doubt, check the ICO website or speak to a professional.
Why GDPR applies to photographers
Under UK GDPR, a photo of an identifiable person is personal data, and you are the "data controller" for the images and contact details you hold. You do not need to register anything complicated for most small studios, but you do need to handle that data responsibly.
Have a lawful basis, and be clear about it
You need a lawful basis to process someone's photos. For paid client work this is usually contract (you are delivering the photos they hired you to take) or legitimate interests; for marketing use of their images — putting them on your website or social — you generally need consent.
- Tell clients, in plain words, what you will do with their photos.
- Keep marketing use separate and opt-in — do not assume a paying client is happy to be your advertising.
- Record that consent so you can show it later if asked.
Store and share securely
- Keep full-resolution originals somewhere access-controlled, not on a public link.
- Deliver client photos through a private gallery — ideally link-only, and PIN-protected where it matters — rather than a public folder anyone can find.
- Use reputable, secure platforms and avoid emailing large batches of identifiable images around unprotected.
Respect clients' rights
People whose photos you hold have rights: to see what you hold, to have errors corrected, and in many cases to ask you to delete their images. Have a simple way to handle a request like "please remove my photos", and be able to actually do it.
Do not keep photos forever "just in case"
GDPR expects you to keep personal data only as long as you reasonably need it. Decide on a retention period (for example, how long after delivery you keep a client's gallery live and their originals archived), tell clients what it is, and stick to it.
A quick checklist
- A clear line in your contract or booking form about how you use client photos.
- Separate, opt-in consent for any marketing or social use.
- Private, access-controlled delivery — not public links or unprotected email.
- A simple process for access and deletion requests.
- A sensible retention period, communicated to the client.
How LensQuay helps
LensQuay is built with this in mind: client galleries are private and link-based with optional PIN protection, full-resolution originals sit behind access controls rather than public URLs, and separate social-sharing consent is built into the client gallery so marketing permission is opt-in and recorded — not assumed. It handles the secure-delivery side so you can focus on the photography. (This is general guidance, not legal advice.)
Run your whole studio on LensQuay
Portfolio, client galleries, bookings and payments — all in one place.
Get started free