Ask a random business owner whether they have GDPR under control, and they'll point to the cookie banner and the data processing agreement with their accounting system. That's fine too. The problem is just that that's almost never where the risk lies. It lies in that photo of a smiling customer you just posted on LinkedIn, in the staff portrait still on the website two years after the person resigned, and in the AI tool that culls your event photos by uploading them to a server you've never checked the location of.
A photo of a recognisable person is personal data
That's the simple point most people overlook: a photograph in which a person can be recognised is personal data in exactly the same way as a social security number or an e-mail address. When you post a photo of a customer, tag an employee or share a group photo from an event, you're processing personal data — and then you need a lawful basis for it. In the vast majority of cases that means real consent, not a quick “that's okay, right?” across the table at the reception.
It sounds pedantic until you remember that the person who complained is rarely the customer in the photo. It's the guest in the background, the former employee who no longer wants to be found online, or the competitor who's found a cheap way to annoy you. And the authority doesn't ask whether you meant well.
Where it typically goes wrong
- →Event photos where recognisable guests in the background never agreed to being shared.
- →Customer testimonials with name and photo, where consent was verbal and never written down.
- →Staff portraits that stay on the website and social media long after the person has left.
- →Screenshots of DMs, reviews or e-mails with names, shared as “social proof”.
- →AI tools that upload your customer photos to third-party servers — sometimes entirely outside the EU.
The GDPR fine rarely comes from the website's cookie banner. It comes from the photo you thought was completely innocent.
AI makes it worse — and far more invisible
This is where it gets uncomfortable for today's most popular workflows. When you run 3,000 event photos through an AI tool for selection, or let a service generate captions from the photos' content, you're in practice passing personal data on to a data processor — often an American one. That requires both a lawful basis and control over where the data ends up. Very few check it. The convenience of a tool that “just works” gets the vast majority to click accept without reading where the photos travel.
This isn't an argument against AI — we use it ourselves every day. It's an argument for knowing which tools process customer data, and where they do it. The difference between a tool that runs locally and one that uploads everything to an unknown server is the whole difference between responsible and irresponsible.
It's not about fear — it's about routine
The point isn't that you should stop posting, or that content now requires a lawyer listening in. The point is that responsible content has a routine built in: a short, written consent at events, a clear agreement about staff photos and what happens when someone leaves, and a quick check of where your tools send data. It's cheap insurance against an expensive and embarrassing case.
- →Obtain consent in writing — even when it's just a tick box in a form when signing up for the event.
- →Have a fixed process for removing photos of people who have left or withdraw their yes.
- →Know your tools: what processes customer data, and does it happen within the EU?
- →Write it down in one place, so it doesn't depend on one person remembering the agreement.
That's also why we've started advising our clients on compliance and data processing as a fixed part of the content work — not as a legal package on the side, but because in 2026 it's simply part of doing content properly. The companies that get the routine in place now aren't the ones slowing down. They're the ones who can post freely, because they don't have to be nervous about what's hiding in the background of the photo.
Written by MediaMate
Book a chat with us