PicaJet

Reference Glossary

GDPR compliance

How a DAM and its customer meet EU GDPR duties for personal data captured in assets or metadata — identifiable people in photos, model releases, contributor names — including erasure rights and breach notification.

Why it matters in a DAM

DAM libraries routinely contain personal data that buyers don't think of as such: staff headshots, event photography with identifiable attendees, customer testimonial videos, and contributor or photographer names embedded in file metadata all fall under GDPR even though most organizations frame GDPR as an HR or CRM concern. Article 17's right to erasure means a DAM has to be able to locate and permanently remove every copy of a person's image — original, renditions, cached CDN copies — within a reasonable time, not just delete the primary record, and a personal-data breach involving DAM content (a misconfigured public share of employee ID photos, for instance) triggers the same 72-hour supervisory-authority notification duty under Article 33 as any other breach.

A worked example

In-scope DAM content Event photography with identifiable faces, staff headshots, customer video testimonials, photographer/contributor names in EXIF or metadata
Erasure obligation Delete request must remove the person's image from originals, renditions, thumbnails, and any CDN cache, not just the main record
Breach obligation Notify the relevant supervisory authority within 72 hours of becoming aware, if the breach risks individuals' rights

Common mistake

Treating product and logo assets as the whole DAM and assuming GDPR doesn't apply, while overlooking that event photography, staff headshots, or testimonial videos stored in the very same library contain personal data and are squarely in scope for erasure and breach-notification duties.

GDPR applies to a DAM whenever the library holds personal data — and photo and video libraries hold it more often than teams expect. A recognizable face in an event photo, a staff headshot, a customer testimonial video, or even a photographer’s name recorded in a file’s metadata all count as personal data under the regulation, which means the DAM instance storing them is subject to the same lawful-basis, transparency, and rights obligations as an HR system or CRM.

The right most likely to actually get exercised against a DAM is Article 17, the right to erasure: when a valid ground applies — the data is no longer needed, consent is withdrawn, or processing was unlawful — the controller must erase the personal data without undue delay, and where the data has been made public, take reasonable steps to inform other parties processing it as well. In a DAM this is harder than deleting one file, because a single photo can exist as an original, several resized renditions, a thumbnail, and a cached copy on a CDN; erasure means all of those, not just the primary asset record.

Breach notification is the other obligation that catches DAM operators off guard. Under Article 33, if a personal data breach is likely to result in risk to individuals’ rights and freedoms, the controller must notify the competent supervisory authority within 72 hours of becoming aware of it — a timeline that starts the moment the organization has reasonable certainty a breach occurred, not once an investigation wraps up. A DAM misconfigured to leave a folder of employee photos publicly accessible is exactly the kind of incident this applies to, and enforcement carries fines up to €10 million or 2% of global annual turnover under Article 83.

Frequently asked

What kind of DAM content actually falls under GDPR?

Event photography with identifiable faces, staff headshots, customer testimonial videos, and even photographer or contributor names recorded in file metadata all count as personal data.

What does the right to erasure require of a DAM?

Under Article 17, the controller must erase personal data without undue delay when a valid ground applies, covering every copy — the original, renditions, thumbnails, and any CDN cache — not just the primary record.

What triggers the 72-hour breach notification duty?

Under Article 33, if a personal data breach is likely to risk individuals' rights and freedoms, the controller must notify the competent supervisory authority within 72 hours of becoming aware of it.

What's an example of a DAM-specific GDPR breach?

A DAM misconfigured to leave a folder of employee photos publicly accessible is exactly the kind of incident Article 33 notification applies to.

Why do organizations wrongly assume GDPR doesn't apply to their DAM?

They think of product and logo assets as the whole DAM and overlook that event photography, staff headshots, or testimonial videos in the same library contain personal data.

What are the potential penalties for GDPR non-compliance involving a DAM?

Enforcement under Article 83 carries fines up to €10 million or 2% of global annual turnover, whichever applies to the violation.

Sources