Blurmyphoto

Photos and GDPR: a plain-language guide for small businesses

Published 14 July 2026 · 8 min read

This is a plain-language explanation of how data protection law treats photographs. It is not legal advice, and it cannot account for your particular circumstances. If you have a live problem — a complaint, a demand, or a regulator's letter — take proper advice.

If you run a café, a gym, a salon, a nursery, or a building firm, you almost certainly photograph your premises, your staff, your customers, or your work, and post the results. Most of the time that is fine. The rules that decide when it is not are more approachable than their reputation suggests.

Before and after: three faces in a group photo, each covered with a solid black bar
The face tool finds the faces for you and covers them with a solid bar — the one mode that replaces the pixels instead of transforming them.

The law you are actually under

In the European Union the instrument is Regulation (EU) 2016/679, the General Data Protection Regulation. In the United Kingdom, the same text was retained after EU exit as the UK GDPR and sits alongside the Data Protection Act 2018. The concepts below are common to both. The UK regulator is the Information Commissioner's Office, whose guidance is written for non-lawyers and is worth reading directly.

When is a photograph personal data?

When a living person can be identified from it, directly or indirectly. A clear shot of someone's face is the obvious case. The word doing the work is indirectly: a photograph with no face in it can still be personal data if the person can be worked out from what else is in the frame — a name badge, a uniform, a vehicle with a readable plate, a distinctive tattoo, or simply the caption naming who is in the picture.

This matters because it sets the standard for redaction. Covering a face does not automatically take an image outside the regulation. The test is whether the individual remains identifiable, taking account of all the means reasonably likely to be used.

The household exemption, and why it does not cover you

The GDPR does not apply to processing by an individual in the course of a purely personal or household activity. Photographs at a family party are outside it. The moment the same photograph is taken or published for a business — to advertise, to record work, to build a social media presence — the exemption stops applying. There is no small-business threshold beneath which the rules switch off.

Choosing a lawful basis

Processing personal data needs a lawful basis under Article 6. For business photography, two are realistic.

Consent is what most people reach for, and it is often the wrong tool. Valid consent must be freely given, specific, informed, and unambiguous, and it must be as easy to withdraw as to give. That last requirement is the trap: if a customer consents to a photograph that goes on your website and in a printed leaflet, and then withdraws consent, you must stop the processing. Consent also cannot be freely given where there is a real imbalance of power, which makes it a poor basis for photographs of your own staff.

Legitimate interests is usually the better fit for ordinary business photography. It requires you to identify the interest, show the processing is necessary for it, and balance it against the rights and expectations of the people in the photograph. Doing that assessment and writing it down — briefly, a page is plenty — is the work. A customer photographed candidly in your shop and posted without warning has a strong expectation argument; the same customer photographed at an advertised launch event, with signage at the door, has much less of one.

Special category data — the part most guides skip

Article 9 gives extra protection to data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, and to biometric data used for identification.

A photograph can reveal several of these without anyone intending it. Someone in religious dress. A visible disability, a mobility aid, or a medical device. A trade union badge at a workplace event. A political badge at a community fundraiser. Where a photograph reveals special category data, you need an Article 9 condition on top of your Article 6 basis, and the realistic one for marketing is explicit consent.

Note also that an ordinary photograph is not automatically biometric data. It becomes biometric data when it is processed through specific technical means for the purpose of uniquely identifying someone — running facial recognition over it, for instance. Simply having a photo of a face is not that.

Children

Children merit specific protection because they are less likely to understand the risks. In practice, for a nursery, a school club, or any business photographing under-18s: get consent from whoever holds parental responsibility, be specific about where the image will appear, keep the record, and honour withdrawal promptly. Photographs of children in uniform are a particular problem, because a school jumper plus a location narrows a child down very fast. There is more on that in photos of children online.

CCTV is a separate problem

Camera surveillance of a premises is its own regime, with its own expectations about signage, retention, access, and responding to requests from people captured on it. If you are pulling a still from CCTV to post — after a theft, say — you are well outside routine marketing photography and should take advice before publishing. The ICO publishes dedicated guidance on video surveillance.

What blurring actually achieves

If a person genuinely cannot be identified from an image, the image is not personal data about them, and the regulation does not apply to it. That is a real and useful outcome — but it depends on genuine anonymisation, and identification comes from context as much as from faces.

Two practical consequences. First, redact more than the face: the name badge, the vehicle plate, the letter on the counter, the appointment board. Second, the redaction has to be irreversible. A blur or a pixelation that can be partly undone has obscured the data rather than removed it — closer to pseudonymisation than anonymisation — and pseudonymised data is still personal data. A solid bar replaces the pixels outright, which is why the tools here default to it. The reasoning is set out in blur, pixelate, or black box, and there is a narrower operational walkthrough at when a business must blur people in photographs.

Someone asks to be removed

People have a right to erasure and a right to object. For a photograph, the practical response is usually the simplest one: take it down. Arguing about whether the request is well founded costs more than the photograph is worth, unless you have a specific reason to keep it.

Remember to deal with the copies. The image may sit on your website, on two or three social platforms, in a scheduling tool, in a printed leaflet, and in a shared drive. Deleting the post is not deleting the data.

A workable routine

  1. Write a short photo policy — a page — saying what you photograph, why, where it goes, and how long you keep it.
  2. Put a notice where photography happens, and tell people at the time. Most complaints come from surprise rather than harm.
  3. Use legitimate interests for ordinary business photography, with a short balancing note on file. Use explicit consent for children and for anything revealing special category data.
  4. Before publishing, look at the whole frame: bystanders, screens, paperwork, plates, name badges. Redact what does not need to be there.
  5. Keep a simple record of consents and objections, and a route for people to reach you — an email address is enough.

None of this requires a compliance department. It requires deciding once how you handle photographs, writing it down, and then actually looking at pictures before they go out.