Reference Glossary
GDPR compliance
How a DAM and its customer meet EU GDPR duties for personal data captured in assets or metadata — identifiable people in photos, model releases, contributor names — including erasure rights and breach notification.
Why it matters in a DAM
DAM libraries routinely contain personal data that buyers don't think of as such: staff headshots, event photography with identifiable attendees, customer testimonial videos, and contributor or photographer names embedded in file metadata all fall under GDPR even though most organizations frame GDPR as an HR or CRM concern. Article 17's right to erasure means a DAM has to be able to locate and permanently remove every copy of a person's image — original, renditions, cached CDN copies — within a reasonable time, not just delete the primary record, and a personal-data breach involving DAM content (a misconfigured public share of employee ID photos, for instance) triggers the same 72-hour supervisory-authority notification duty under Article 33 as any other breach.
A worked example
Common mistake
Treating product and logo assets as the whole DAM and assuming GDPR doesn't apply, while overlooking that event photography, staff headshots, or testimonial videos stored in the very same library contain personal data and are squarely in scope for erasure and breach-notification duties.
GDPR applies to a DAM whenever the library holds personal data — and photo and video libraries hold it more often than teams expect. A recognizable face in an event photo, a staff headshot, a customer testimonial video, or even a photographer’s name recorded in a file’s metadata all count as personal data under the regulation, which means the DAM instance storing them is subject to the same lawful-basis, transparency, and rights obligations as an HR system or CRM.
The right most likely to actually get exercised against a DAM is Article 17, the right to erasure: when a valid ground applies — the data is no longer needed, consent is withdrawn, or processing was unlawful — the controller must erase the personal data without undue delay, and where the data has been made public, take reasonable steps to inform other parties processing it as well. In a DAM this is harder than deleting one file, because a single photo can exist as an original, several resized renditions, a thumbnail, and a cached copy on a CDN; erasure means all of those, not just the primary asset record.
Breach notification is the other obligation that catches DAM operators off guard. Under Article 33, if a personal data breach is likely to result in risk to individuals’ rights and freedoms, the controller must notify the competent supervisory authority within 72 hours of becoming aware of it — a timeline that starts the moment the organization has reasonable certainty a breach occurred, not once an investigation wraps up. A DAM misconfigured to leave a folder of employee photos publicly accessible is exactly the kind of incident this applies to, and enforcement carries fines up to €10 million or 2% of global annual turnover under Article 83.
Frequently asked
What kind of DAM content actually falls under GDPR?
Any asset that makes a person identifiable qualifies: event photography and staff headshots with visible faces, and customer testimonial videos. Metadata counts too — EXIF/IPTC fields often embed GPS coordinates showing where a photo was shot, plus photographer, model, or contributor names and timestamps. Under GDPR, anything that can identify a natural person, alone or combined with other data, is personal data — whether it lives in the image itself or its metadata.
What does the right to erasure require of a DAM?
Under Article 17, the controller must erase personal data without undue delay when a valid ground applies, covering every copy — the original, renditions, thumbnails, and any CDN cache — not just the primary record.
What triggers the 72-hour breach notification duty?
Under Article 33, if a personal data breach is likely to risk individuals' rights and freedoms, the controller must notify the competent supervisory authority within 72 hours of becoming aware of it.
What's an example of a DAM-specific GDPR breach?
A concrete case: a model or employee withdraws consent for their photo, but marketing keeps publishing it across the website and social channels because no one flagged the asset for removal in the DAM — a breach of erasure rights. Another: a bulk export or integration pulls contributor and approver email addresses embedded in asset metadata into a third-party tool with no documented legal basis for that processing, breaching the lawful-basis requirement and potentially triggering Article 33 notification.
Why do organizations wrongly assume GDPR doesn't apply to their DAM?
Most teams equate GDPR with structured customer records — CRM entries, email lists, billing databases — and treat the DAM as a purely creative or marketing tool outside that scope. They classify assets by usage (product shots, logos, brand templates) rather than by content, so nobody asks whether an event photo, staff headshot, or testimonial video contains an identifiable face. Metadata compounds the blind spot: GPS coordinates and contributor names get embedded automatically by cameras and rarely get reviewed.
What are the potential penalties for GDPR non-compliance involving a DAM?
GDPR's Article 83 sets a two-tier maximum: up to €10 million or 2% of global annual turnover for administrative failures like missing records or late breach notification, and up to €20 million or 4% — whichever figure is higher — for the most serious violations, including unlawful processing and failure to honor data subject rights such as erasure. A DAM incident like ignoring an erasure request or exporting personal metadata without a legal basis falls squarely in that higher tier.
Sources
- Controllers must erase personal data without undue delay where a valid erasure ground applies, and take reasonable steps to inform other controllers processing publicly made data of the erasure request. checked 2026-08-07 — GDPR Article 17 — Right to erasure
- Controllers must notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach likely to result in risk to individuals' rights and freedoms. checked 2026-08-07 — GDPR Article 33 — Notification of a personal data breach to the supervisory authority