{"id":2549,"date":"2026-08-08T01:46:11","date_gmt":"2026-08-07T22:46:11","guid":{"rendered":"https:\/\/picajet.com\/articles\/glossary\/gdpr-compliance-dam\/"},"modified":"2026-08-08T03:45:54","modified_gmt":"2026-08-08T00:45:54","slug":"gdpr-compliance-dam","status":"publish","type":"glossary","link":"https:\/\/picajet.com\/articles\/glossary\/gdpr-compliance-dam\/","title":{"rendered":"GDPR compliance"},"content":{"rendered":"<p class=\"wp-block-paragraph\">GDPR applies to a DAM whenever the library holds personal data \u2014 and photo and video libraries hold it more often than teams expect. A recognizable face in an event photo, a staff headshot, a customer testimonial video, or even a photographer&#8217;s name recorded in a file&#8217;s metadata all count as personal data under the regulation, which means the DAM instance storing them is subject to the same lawful-basis, transparency, and rights obligations as an HR system or CRM.<\/p>\n<p class=\"wp-block-paragraph\">The right most likely to actually get exercised against a DAM is Article 17, the right to erasure: when a valid ground applies \u2014 the data is no longer needed, consent is withdrawn, or processing was unlawful \u2014 the controller must erase the personal data without undue delay, and where the data has been made public, take reasonable steps to inform other parties processing it as well. In a DAM this is harder than deleting one file, because a single photo can exist as an original, several resized renditions, a thumbnail, and a cached copy on a CDN; erasure means all of those, not just the primary asset record.<\/p>\n<p class=\"wp-block-paragraph\">Breach notification is the other obligation that catches DAM operators off guard. Under Article 33, if a personal data breach is likely to result in risk to individuals&#8217; rights and freedoms, the controller must notify the competent supervisory authority within 72 hours of becoming aware of it \u2014 a timeline that starts the moment the organization has reasonable certainty a breach occurred, not once an investigation wraps up. A DAM misconfigured to leave a folder of employee photos publicly accessible is exactly the kind of incident this applies to, and enforcement carries fines up to \u20ac10 million or 2% of global annual turnover under Article 83.<\/p>","protected":false},"excerpt":{"rendered":"<p>How a DAM and its customer meet EU GDPR duties for personal data captured in assets or metadata \u2014 identifiable people in photos, model releases, contributor names \u2014 including erasure rights and breach notification.<\/p>\n","protected":false},"author":0,"featured_media":0,"template":"","meta":{"footnotes":"","faq":[{"question":"What kind of DAM content actually falls under GDPR?","answer":"Any asset that makes a person identifiable qualifies: event photography and staff headshots with visible faces, and customer testimonial videos. Metadata counts too \u2014 EXIF\/IPTC fields often embed GPS coordinates showing where a photo was shot, plus photographer, model, or contributor names and timestamps. Under GDPR, anything that can identify a natural person, alone or combined with other data, is personal data \u2014 whether it lives in the image itself or its metadata."},{"question":"What does the right to erasure require of a DAM?","answer":"Under Article 17, the controller must erase personal data without undue delay when a valid ground applies, covering every copy \u2014 the original, renditions, thumbnails, and any CDN cache \u2014 not just the primary record."},{"question":"What triggers the 72-hour breach notification duty?","answer":"Under Article 33, if a personal data breach is likely to risk individuals' rights and freedoms, the controller must notify the competent supervisory authority within 72 hours of becoming aware of it."},{"question":"What's an example of a DAM-specific GDPR breach?","answer":"A concrete case: a model or employee withdraws consent for their photo, but marketing keeps publishing it across the website and social channels because no one flagged the asset for removal in the DAM \u2014 a breach of erasure rights. Another: a bulk export or integration pulls contributor and approver email addresses embedded in asset metadata into a third-party tool with no documented legal basis for that processing, breaching the lawful-basis requirement and potentially triggering Article 33 notification."},{"question":"Why do organizations wrongly assume GDPR doesn't apply to their DAM?","answer":"Most teams equate GDPR with structured customer records \u2014 CRM entries, email lists, billing databases \u2014 and treat the DAM as a purely creative or marketing tool outside that scope. They classify assets by usage (product shots, logos, brand templates) rather than by content, so nobody asks whether an event photo, staff headshot, or testimonial video contains an identifiable face. Metadata compounds the blind spot: GPS coordinates and contributor names get embedded automatically by cameras and rarely get reviewed."},{"question":"What are the potential penalties for GDPR non-compliance involving a DAM?","answer":"GDPR's Article 83 sets a two-tier maximum: up to \u20ac10 million or 2% of global annual turnover for administrative failures like missing records or late breach notification, and up to \u20ac20 million or 4% \u2014 whichever figure is higher \u2014 for the most serious violations, including unlawful processing and failure to honor data subject rights such as erasure. A DAM incident like ignoring an erasure request or exporting personal metadata without a legal basis falls squarely in that higher tier."}],"checked_date":"2026-08-11","sources":[{"statement":"Controllers must erase personal data without undue delay where a valid erasure ground applies, and take reasonable steps to inform other controllers processing publicly made data of the erasure request.","source_name":"GDPR Article 17 \u2014 Right to erasure","url":"https:\/\/gdpr-info.eu\/art-17-gdpr\/","checked":"2026-08-07"},{"statement":"Controllers must notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach likely to result in risk to individuals' rights and freedoms.","source_name":"GDPR Article 33 \u2014 Notification of a personal data breach to the supervisory authority","url":"https:\/\/www.legiscope.com\/blog\/gdpr-article-33-breach-notification-authority.html","checked":"2026-08-07"}],"kicker":"","fact_checker":0,"reading_time":0,"revisions":[],"seo_title":"GDPR compliance for DAM: personal data in assets and metadata","seo_description":"","noindex":false,"related":[2523,2548,2585,2550,2586,2491],"definition":"How a DAM and its customer meet EU GDPR duties for personal data captured in assets or metadata \u2014 identifiable people in photos, model releases, contributor names \u2014 including erasure rights and breach notification.","why":"DAM libraries routinely contain personal data that buyers don't think of as such: staff headshots, event photography with identifiable attendees, customer testimonial videos, and contributor or photographer names embedded in file metadata all fall under GDPR even though most organizations frame GDPR as an HR or CRM concern. Article 17's right to erasure means a DAM has to be able to locate and permanently remove every copy of a person's image \u2014 original, renditions, cached CDN copies \u2014 within a reasonable time, not just delete the primary record, and a personal-data breach involving DAM content (a misconfigured public share of employee ID photos, for instance) triggers the same 72-hour supervisory-authority notification duty under Article 33 as any other breach.","example_rows":[{"field":"In-scope DAM content","values":"Event photography with identifiable faces, staff headshots, customer video testimonials, photographer\/contributor names in EXIF or metadata"},{"field":"Erasure obligation","values":"Delete request must remove the person's image from originals, renditions, thumbnails, and any CDN cache, not just the main record"},{"field":"Breach obligation","values":"Notify the relevant supervisory authority within 72 hours of becoming aware, if the breach risks individuals' rights"}],"mistake":"Treating product and logo assets as the whole DAM and assuming GDPR doesn't apply, while overlooking that event photography, staff headshots, or testimonial videos stored in the very same library contain personal data and are squarely in scope for erasure and breach-notification duties.","deep_link":""},"silo":[24],"class_list":["post-2549","glossary","type-glossary","status-publish","hentry","silo-glossary"],"_links":{"self":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary\/2549","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/types\/glossary"}],"version-history":[{"count":3,"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary\/2549\/revisions"}],"predecessor-version":[{"id":3534,"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary\/2549\/revisions\/3534"}],"wp:attachment":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/media?parent=2549"}],"wp:term":[{"taxonomy":"silo","embeddable":true,"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/silo?post=2549"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}