{"id":2549,"date":"2026-08-08T01:46:11","date_gmt":"2026-08-07T22:46:11","guid":{"rendered":"https:\/\/picajet.com\/articles\/glossary\/gdpr-compliance-dam\/"},"modified":"2026-08-08T03:45:54","modified_gmt":"2026-08-08T00:45:54","slug":"gdpr-compliance-dam","status":"publish","type":"glossary","link":"https:\/\/picajet.com\/articles\/glossary\/gdpr-compliance-dam\/","title":{"rendered":"GDPR compliance"},"content":{"rendered":"<p class=\"wp-block-paragraph\">GDPR applies to a DAM whenever the library holds personal data \u2014 and photo and video libraries hold it more often than teams expect. A recognizable face in an event photo, a staff headshot, a customer testimonial video, or even a photographer&#8217;s name recorded in a file&#8217;s metadata all count as personal data under the regulation, which means the DAM instance storing them is subject to the same lawful-basis, transparency, and rights obligations as an HR system or CRM.<\/p>\n<p class=\"wp-block-paragraph\">The right most likely to actually get exercised against a DAM is Article 17, the right to erasure: when a valid ground applies \u2014 the data is no longer needed, consent is withdrawn, or processing was unlawful \u2014 the controller must erase the personal data without undue delay, and where the data has been made public, take reasonable steps to inform other parties processing it as well. In a DAM this is harder than deleting one file, because a single photo can exist as an original, several resized renditions, a thumbnail, and a cached copy on a CDN; erasure means all of those, not just the primary asset record.<\/p>\n<p class=\"wp-block-paragraph\">Breach notification is the other obligation that catches DAM operators off guard. Under Article 33, if a personal data breach is likely to result in risk to individuals&#8217; rights and freedoms, the controller must notify the competent supervisory authority within 72 hours of becoming aware of it \u2014 a timeline that starts the moment the organization has reasonable certainty a breach occurred, not once an investigation wraps up. A DAM misconfigured to leave a folder of employee photos publicly accessible is exactly the kind of incident this applies to, and enforcement carries fines up to \u20ac10 million or 2% of global annual turnover under Article 83.<\/p>","protected":false},"excerpt":{"rendered":"<p>How a DAM and its customer meet EU GDPR duties for personal data captured in assets or metadata \u2014 identifiable people in photos, model releases, contributor names \u2014 including erasure rights and breach notification.<\/p>\n","protected":false},"author":0,"featured_media":0,"template":"","meta":{"footnotes":"","faq":[{"question":"What kind of DAM content actually falls under GDPR?","answer":"Event photography with identifiable faces, staff headshots, customer testimonial videos, and even photographer or contributor names recorded in file metadata all count as personal data."},{"question":"What does the right to erasure require of a DAM?","answer":"Under Article 17, the controller must erase personal data without undue delay when a valid ground applies, covering every copy \u2014 the original, renditions, thumbnails, and any CDN cache \u2014 not just the primary record."},{"question":"What triggers the 72-hour breach notification duty?","answer":"Under Article 33, if a personal data breach is likely to risk individuals' rights and freedoms, the controller must notify the competent supervisory authority within 72 hours of becoming aware of it."},{"question":"What's an example of a DAM-specific GDPR breach?","answer":"A DAM misconfigured to leave a folder of employee photos publicly accessible is exactly the kind of incident Article 33 notification applies to."},{"question":"Why do organizations wrongly assume GDPR doesn't apply to their DAM?","answer":"They think of product and logo assets as the whole DAM and overlook that event photography, staff headshots, or testimonial videos in the same library contain personal data."},{"question":"What are the potential penalties for GDPR non-compliance involving a DAM?","answer":"Enforcement under Article 83 carries fines up to \u20ac10 million or 2% of global annual turnover, whichever applies to the violation."}],"checked_date":"2026-08-07","sources":[{"statement":"Controllers must erase personal data without undue delay where a valid erasure ground applies, and take reasonable steps to inform other controllers processing publicly made data of the erasure request.","source_name":"GDPR Article 17 \u2014 Right to erasure","url":"https:\/\/gdpr-info.eu\/art-17-gdpr\/","checked":"2026-08-07"},{"statement":"Controllers must notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach likely to result in risk to individuals' rights and freedoms.","source_name":"GDPR Article 33 \u2014 Notification of a personal data breach to the supervisory authority","url":"https:\/\/www.legiscope.com\/blog\/gdpr-article-33-breach-notification-authority.html","checked":"2026-08-07"}],"kicker":"","fact_checker":0,"reading_time":0,"revisions":[],"seo_title":"","seo_description":"","noindex":false,"related":[2523,2548,2585,2550,2586,2491],"definition":"How a DAM and its customer meet EU GDPR duties for personal data captured in assets or metadata \u2014 identifiable people in photos, model releases, contributor names \u2014 including erasure rights and breach notification.","why":"DAM libraries routinely contain personal data that buyers don't think of as such: staff headshots, event photography with identifiable attendees, customer testimonial videos, and contributor or photographer names embedded in file metadata all fall under GDPR even though most organizations frame GDPR as an HR or CRM concern. Article 17's right to erasure means a DAM has to be able to locate and permanently remove every copy of a person's image \u2014 original, renditions, cached CDN copies \u2014 within a reasonable time, not just delete the primary record, and a personal-data breach involving DAM content (a misconfigured public share of employee ID photos, for instance) triggers the same 72-hour supervisory-authority notification duty under Article 33 as any other breach.","example_rows":[{"field":"In-scope DAM content","values":"Event photography with identifiable faces, staff headshots, customer video testimonials, photographer\/contributor names in EXIF or metadata"},{"field":"Erasure obligation","values":"Delete request must remove the person's image from originals, renditions, thumbnails, and any CDN cache, not just the main record"},{"field":"Breach obligation","values":"Notify the relevant supervisory authority within 72 hours of becoming aware, if the breach risks individuals' rights"}],"mistake":"Treating product and logo assets as the whole DAM and assuming GDPR doesn't apply, while overlooking that event photography, staff headshots, or testimonial videos stored in the very same library contain personal data and are squarely in scope for erasure and breach-notification duties.","deep_link":""},"silo":[24],"class_list":["post-2549","glossary","type-glossary","status-publish","hentry","silo-glossary"],"_links":{"self":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary\/2549","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/types\/glossary"}],"version-history":[{"count":3,"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary\/2549\/revisions"}],"predecessor-version":[{"id":3534,"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/glossary\/2549\/revisions\/3534"}],"wp:attachment":[{"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/media?parent=2549"}],"wp:term":[{"taxonomy":"silo","embeddable":true,"href":"https:\/\/picajet.com\/articles\/wp-json\/wp\/v2\/silo?post=2549"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}