privacyhow-to

Client Photo Privacy: A Photographer's Storage Guide

Wedding and portrait photographers hold some of the most intimate images their clients will ever appear in. Here's how to store and deliver them without exposing private files.

A photographer who delivers a wedding gallery is entrusting a couple with images of one of the most personal days of their lives. They’re also, as a matter of professional practice, responsible for storing those images somewhere between shoot and delivery — and often long after delivery, because clients come back years later asking for reprints, second copies, or original files after a hard drive fails.

The cloud storage and gallery delivery services that photographers use to manage this workflow are not all equivalent from a privacy standpoint. The terms of service covering client photo storage vary significantly. Some services explicitly claim licensing rights to hosted content. Some share data with advertising partners. Some scan hosted images for content moderation purposes. And most do not make these distinctions easy to find.

For photographers who have positioned privacy as part of their professional value proposition — or who simply want to handle client data with appropriate care — understanding what the platforms you use actually do with client photos is not optional.


Why Client Photos Are a Special Privacy Category

Client photos are not ordinary files. Wedding photos, portrait sessions, boudoir photography, newborn shoots, and family sessions contain images of real people in private moments. Unlike stock photos or marketing assets, these images were created in trust: the clients agreed to be photographed by this photographer, for their own use, under an implied or explicit expectation about how those images would be handled.

In some jurisdictions, photographs of identifiable individuals are classified as personal data under data protection law. The EU’s GDPR treats photos of identifiable people as personal data. Under GDPR, a professional photographer acting on behalf of clients has responsibilities as a data controller: you’re responsible for how personal data (client photos) is collected, stored, processed, and deleted.

This doesn’t mean you need to become a data protection lawyer. But it does mean that where you store client photos — and what the platforms you use are permitted to do with them — is a professional and potentially legal question, not just a technical one.


Several platforms are widely used for professional photo delivery: Pixieset, SmugMug, ShootProof, Pic-Time, and others. They offer polished interfaces, client-facing galleries, download management, and print sales integration. They’re convenient tools that solve real problems.

Their data practices vary, and reading the fine print matters.

Licensing clauses. Some gallery platforms include terms that grant the platform a license to use hosted content for purposes including product development, marketing, and platform promotion. Photographers should read these clauses carefully before accepting terms, and be aware that client photos stored under such terms may be covered by the license even if you didn’t intend that.

Content scanning. Most platforms that host user-uploaded photos apply some form of automated content scanning — typically for illegal content, but often using services that process image content in transit or at rest. Understand what scanning your provider performs and whether it involves third-party processing.

Third-party integrations. Gallery platforms frequently integrate with print labs, sales platforms, and analytics tools. Data flow between these integrations — including client identifiers and image metadata — is worth auditing.

Data residency. Where photos are physically stored affects which laws apply to them. EU-resident photographers delivering services to EU clients have specific obligations under GDPR. Storing client data on servers outside the EU may require additional legal basis or contractual protections.

None of this means professional gallery platforms are inappropriate — most are well-run, and the privacy risks for standard professional photography workflows are manageable. But they should not be chosen blindly, and the terms should be read specifically for client data handling.


The Working Storage Problem

Professional photographers have a workflow that involves multiple stages of storage:

  1. Shoot day: Raw files on memory cards
  2. Ingestion: Files imported to primary working storage (typically a local drive)
  3. Editing and culling: Working files in Lightroom, Capture One, or similar
  4. Client delivery: Processed files uploaded to a gallery platform
  5. Archive storage: Raw files and processed deliverables kept for client re-order or liability purposes
  6. Deletion: Eventually removing files after the contractual retention period

Each stage involves different tools and carries different privacy implications. The most common privacy mistakes in professional photography workflows happen at stages 5 and 6.

Archive storage often ends up in personal cloud accounts — Google Drive, Dropbox, iCloud — rather than in a purpose-appropriate storage solution. Personal cloud accounts have different (and often more permissive) data use terms than professional tools. Google Drive, for instance, is covered by Google’s general privacy policy, which permits use of account content for product improvement and other purposes. Storing client files in a personal cloud account is using a consumer service for professional obligations.

Deletion often doesn’t happen. Files accumulate indefinitely in working storage, archive storage, and gallery platforms because the process of tracking retention periods and executing deletion is administratively painful. From a privacy standpoint, retaining client data longer than necessary increases risk without benefit.


Raw Files and Privacy

RAW files from professional cameras contain more metadata than processed JPEGs. In addition to standard EXIF data (GPS coordinates if enabled, timestamp, device identifiers), RAW files may contain camera serial numbers and shooting metadata that connects images back to a specific camera body.

Photographers who work in jurisdictions where clients have data subject rights — the right to access, correct, or request deletion of their personal data — may receive requests for this information. Knowing where all copies of a client’s photos are stored, including RAW files, is a prerequisite for responding to these requests.

GPS metadata deserves particular attention. Most professional cameras allow GPS logging to be disabled. In sensitive professional contexts — particularly when photographing clients at their home, at medical facilities, or in any location they may want to keep private — disabling GPS logging at the camera level prevents location data from entering the file at all.


Self-hosting a client gallery is technically possible: a photographer who operates their own server can run open-source gallery software (such as Lychee, Zenphoto, or a WordPress-based solution) and deliver client galleries from their own infrastructure. This eliminates third-party data access entirely.

The trade-off is operational complexity: maintaining server software, handling uptime, managing SSL certificates, and providing client support is significant additional work for a professional photographer whose business focus is photography, not IT.

Self-hosting is worth considering for photographers who:

  • Handle particularly sensitive subject matter (boudoir, medical, legal, or activist contexts)
  • Have clients in jurisdictions with strong data protection obligations they’re navigating carefully
  • Already maintain technical infrastructure and can absorb the operational overhead

For most professional photographers, a carefully chosen third-party platform with well-reviewed data practices is the practical answer.


Choosing Cloud Storage for Your Working Archive

When selecting cloud storage for the working archive — the raw files and processed deliverables you retain after client delivery — the relevant questions are:

Who can access the files? Server-side encryption is standard. Zero-knowledge encryption would prevent the provider from accessing your files, but would also prevent server-side features like web preview. Most professional workflows don’t require zero-knowledge encryption; what they require is a provider who explicitly commits to not using client content for AI training, advertising, or third-party sharing.

What does the provider do with content at rest? Read the privacy policy for language about whether content is scanned, analyzed, used for product improvement, or shared with third parties. These distinctions are in the fine print.

What are the deletion guarantees? When you delete files, what actually happens? How long does content persist in backups or recovery systems after deletion? For managing retention periods professionally, understanding the actual deletion pathway matters.

What jurisdiction governs the data? Servers in the EU are subject to GDPR. Servers in the US are subject to US law, including government access provisions like the CLOUD Act. For EU photographers with EU clients, data residency is a compliance consideration.


Client Contracts and Data Processing

Professional photographers who store client data in the cloud should consider what their client contracts say about data processing. In the EU, a data controller (the photographer) who uses a third-party storage service (the cloud provider) for processing personal data is entering into a data processing relationship that may require a Data Processing Agreement (DPA) with the provider.

Most major cloud storage providers offer DPAs for business accounts. Google Workspace, Microsoft 365, and most professional gallery platforms provide these. A DPA is a contract that specifies what the provider can do with personal data you process through their platform.

Outside the EU, similar requirements exist in other jurisdictions with comprehensive data protection laws. The relevant requirement is not identical everywhere, but the practical question is the same: do you have a written agreement with your storage provider that specifies what they can and cannot do with client photos?


The Retention and Deletion Question

Professional photographers differ on how long to retain client files after delivery. Some retain raw files indefinitely as a backup for clients who lose their copies. Some operate on three-to-seven year retention schedules. Some delete raw files shortly after delivering processed images and retaining only the processed versions.

Whatever the policy, it should be deliberate and consistently executed. From a privacy standpoint, retaining data longer than necessary creates ongoing liability with no corresponding benefit. A client whose photos are stored for twenty years is a client whose data exists in your infrastructure for twenty years — through whatever security incidents, platform acquisitions, or policy changes happen in that time.

Deciding on a retention period and building a process to enforce it is the professional practice version of data minimization: keep what you need, for as long as you need it, and then actually delete it.


Practical Recommendations

For professional photographers reviewing their cloud storage practices:

Audit where client photos currently live. List every service that holds client photos: gallery platforms, cloud backup, personal cloud accounts, email attachments sent to clients or labs. Most photographers who do this find unexpected copies in unexpected places.

Read the terms of your gallery platform. Specifically look for content licensing clauses, content scanning practices, and data sharing with third parties. If the terms are unclear, contact the platform directly and ask.

Separate working and personal cloud storage. Don’t store client photos in personal cloud accounts with consumer-oriented terms. Use professional-grade storage for professional content.

Document your retention policy and enforce it. Decide how long you keep client files, write it down (consider including it in your client contracts), and build a recurring process to delete files that have exceeded the retention period.

Consider data residency for EU work. If you’re photographing clients who fall under GDPR, verify that your storage providers offer EU data residency and that you have appropriate agreements in place.


The Personal Photography Archive

What photographers often conflate with client work is their own personal photography archive — travel photos, personal projects, family images, behind-the-scenes documentation of their own work.

These personal images are subject to different considerations than client files. They’re your photos, taken for yourself, without the professional obligations that client work carries. But they often end up stored in the same places as client files, making the privacy practices of those places relevant to both.

For personal photo archives, the questions about who can access your files, whether photos are used for AI training, and what happens when you delete content remain relevant — they’re just personal rather than professional privacy questions.

daftei stores personal photos and files with AES-256 encryption at rest, TLS 1.3 in transit, without advertising, without selling data, and without using your content to train AI for anyone other than you. For photographers separating personal archives from professional client storage, it’s a storage environment designed around privacy as the default rather than an afterthought.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts