Infrastructure
Putting Customer Photos on Your Website: Consent, Children, and the Data Hidden in the File

Every photo on a business website carries two separate permissions, and most owners only ever think about one of them.
The first is ownership. Who took the picture, who holds the copyright, and are you licensed to publish it. That one is well covered, and if you have ever had a demand letter land over a stock image you did not license, you already know how the copyright side works.
The second permission is the one that produces the awkward email eighteen months later. Who is in the picture, and did they agree to be on your website? A photograph of an identifiable person is personal data under GDPR. That is not a technicality invented by consultants. It is the reason a happy customer can, entirely lawfully, ask you to take their face off your homepage on a Tuesday morning and expect it gone.
This is a reference piece. Work through it once, fix what needs fixing, and come back to it when you add a gallery.
Why a Photograph Counts as Personal Data
Personal data is any information relating to an identifiable living person. A face is about as identifying as information gets. Once you publish a photo of a customer, a client, a child at your summer camp, or a member of staff, you are processing their personal data, and you need a lawful basis for doing it.
Ireland's Data Protection Commission is direct about this in its own guidance on promotional photography. Consent, in the DPC's words, "of an individual to the processing of his or her personal data can provide a legal basis to process data." Legitimate interests is the other realistic route for a business, and it is a genuine option, but it requires you to have actually weighed your interest against the individual's rights and to be able to show your working if asked.
So what does that mean at street level? It means the photo of the smiling couple collecting their keys is not yours to publish just because you paid the photographer. Ownership and permission are different questions, and the person in the frame controls the second one.
The volume of people who now know this is the part that has changed. The DPC took in 16,160 new cases during 2025, up roughly 45% on the 11,091 it handled the year before, though it is worth separating those numbers properly: only 3,385 of them progressed into the formal complaint-handling process. The headline figure is contacts, not findings against businesses. The direction of travel is still unmistakable. People know they have rights over their own image, and they are increasingly willing to pick up the phone about it.
The Consent You Took at the Counter Is Not the Consent You Need Online
Most small businesses come unstuck at exactly this point. Someone says "ah go on, put it up" while you are photographing them. Nine months later they are going through a divorce, or they left the industry, or they simply changed their mind, and they want the image down.
They are entitled to that. The European Data Protection Board is explicit that under Article 7(3), a controller "must ensure that consent can be withdrawn by the data subject as easy as giving consent and at any given time." Verbal permission given across a counter is easy to give. If retracting it means three emails and a fortnight of silence from you, you are on the wrong side of that.
Consent also has to be specific. Permission to take a photo is not permission to publish it. Permission to publish it on Instagram is not permission to put it on your website, in your Google Business Profile, and on a printed banner outside the shop.
| What you are publishing | Who is in it | What you need first | Where it usually goes wrong |
|---|---|---|---|
| Before-and-after treatment shots | A paying client | Explicit, written, itemised consent | Treated as a testimonial, not as health data |
| Team and about-us photos | Your own staff | A lawful basis that is not really consent | Nobody removes the leaver's photo |
| Children at a camp, club, or crèche | A minor | Guardian consent, recorded | A verbal yes from the wrong adult |
| Event and crowd shots | Attendees | Clear notice before the camera comes out | No notice at all, then a complaint |
| Job photos at a customer's property | Often nobody visible | Permission plus a metadata check | Coordinates ride along inside the file |
Each of those five rows is its own problem. Take them in order.
Before-and-After Photos Are a Different Category Entirely
If you run a salon, an aesthetics clinic, a dental practice, a physio room, or a gym, before-and-after images are the most persuasive marketing you own. They are also the most legally loaded photo on your site.
An image that shows a person's physical condition, a treatment, or a recovery can reveal health information about them. Health data sits in the special category tier of GDPR, where the bar is not ordinary consent but explicit consent. The EDPB spells out what "explicit" adds: the individual "must give an express statement of consent," and an obvious way to satisfy that is to "expressly confirm consent in a written statement."
Written. Named. Specific to the images and the places you intend to publish them.
Without that, the failure is not abstract. A client sees her own torso on the front page of a website she never expected to be on, sends one message asking for it to come down, and the same photo is still sitting in your Google Business Profile gallery a month later because nobody wrote down where it was posted. That is how a routine marketing asset turns into a complaint.
A single consent sheet solves it. Name, date, a plain description of the images, an explicit list of where they may appear, and a line telling the client exactly how to withdraw. Keep it. The burden of proving you had consent falls on you, not on them.

Staff Photos: The Consent Problem Nobody Expects
The team page looks like the easy one. It is not.
The EDPB's position on consent in employment is blunt. "An imbalance of power also occurs in the employment context," the guidelines say, and "given the imbalance of power between an employer and its staff members, employees can only give free consent in exceptional circumstances, when it will have no adverse consequences at all whether or not they give consent." When your boss asks whether you mind having your photo on the website, saying no is not a neutral act, so the consent is shaky by definition.
For most small businesses the practical answer is to rely on legitimate interests for ordinary team photos, tell staff clearly that this is what you are doing, and honour a request to be left off without making it a discussion. That framing is more honest and more robust than a consent box nobody felt free to leave unticked.
Then there is the leaver. Somebody resigns, and their face stays on your about page for two years because taking it down was nobody's job. It is a small thing that quietly signals your site is unmaintained, and it becomes a real problem if the departure was not amicable. Add "remove from website" to whatever offboarding checklist you already run for email and logins.
Children Are the Highest Bar in the Building
If you run a crèche, a summer camp, a stage school, a swim club, or anything else that photographs minors, treat this section as the one that matters.
The DPC's guidance on photography at school events is clear that where consent is the basis for taking and publishing images, an organisation "will generally need to obtain the consent of the child's legal guardians to do so, depending on the age of the child." The DPC also offers a practical mechanism that translates directly to a business: tell parents in advance that photographs will be taken, and use something visible, such as different coloured stickers or wristbands, so the person holding the camera can tell at a glance who is in and who is out.
There is a live example in the DPC's own published case studies. A child's photograph, taken from a group's Facebook page, ended up printed in a newspaper along with the child's name and part of their address, after permission came from an adult who was not the parent. The complaint that followed turned on whether the publisher had checked who was actually entitled to give that permission.
The lesson is unglamorous and worth having: consent for a child has to come from the guardian, and you need to know it came from the guardian. A verbal yes from whichever adult happened to be at the door is not a record of anything.
Event and Crowd Shots
Open days, launch nights, charity mornings, a stand at a trade fair. You want photos, and you cannot realistically get signed permission from every person who walks past a lens.
The DPC's guidance splits by scale and it is genuinely usable. At large events, it advises "written notices in place advising attendees of the intention to take photos, the purpose of taking the photo and the intended use of the image." At smaller ones, it advises seeking consent "either in written form or by introducing a method of identifying consent from those whose photographs may be taken."
Practically, that is a sign at the door and a photographer who is willing to lower the camera when somebody shakes their head. Both cost nothing. Neither survives being remembered after the fact, which is why it goes on the sign rather than in your head.
Job Photos and the Coordinates Sitting Inside the File
This one has nothing to do with faces, and it is the failure I see most often on the sites of trades and service businesses.
A phone photograph is not just an image. When Location Services is enabled for the camera, as Apple sets out in its own personal safety guide, location metadata "gathered from cellular, Wi-Fi, GPS networks, and Bluetooth" is embedded into each photo and video, and anyone you share the file with "may be able to access the location metadata and learn where it was taken."
Consider what that means for a roofer, an alarm installer, or a landscaper. The gallery of recent work is a set of customers' homes. If the coordinates travel with the files, you have published, at scale, a map of properties along with photographs of their layout, their access points, and in the case of an alarm installer, their security arrangements. No customer agreed to that when they said the new patio looked great.
WordPress helps here, but not as completely as people assume. The core image_strip_meta filter defaults to true, and as the developer documentation notes, it "only applies when resizing using the Imagick editor since GD always strips profiles by default." So the resized versions your pages actually serve are usually clean. The original file is a different story: WordPress keeps what you uploaded, generates sub-sizes from it, and appends "-scaled" to a new copy when an image is very large. Plenty of themes, lightboxes, and gallery plugins link straight to that original.
I assumed for years that pushing a photo through the media library laundered its metadata. It strips it from the resized copies, which is what fooled me. Then I opened the full-size file a lightbox was linking to on a customer's site and the GPS coordinates were still sitting in it. Now I strip location on the phone before anything reaches the library, because the cheapest fix is always the one that happens earliest.
Turn off location for your camera app, or use the "no location" option before sending job photos to whoever updates the site. Thirty seconds, once.
Taking It Down Is Harder Than Putting It Up
Every system has an edge worth knowing before a customer finds it for you, so take this as the honest limit on all of the above.
Deleting a photo from your media library does not delete it from everywhere. Page caches and CDN nodes may serve the old version for a while. Google Images can hold a thumbnail until it recrawls. Anyone who shared the page has a preview image cached on a platform you do not control. Your own nightly backups still contain it, correctly, because a backup that quietly edited history would be useless.
None of that is a reason to skip the deletion. It is a reason to be straight with the person who asked: the image is off the site today, the cached copies clear over the following days, and you will confirm when the search results have caught up. That answer is far better received than silence. If the request arrives as a formal one, the mechanics of finding every copy are the same problem as a data deletion request that lands in your inbox, and the clock on that is not generous.
Five Checks Before a Photo Goes Live
- Identify. Look at the image and name every identifiable person in it, including the ones in the background.
- Verify the permission. Confirm you have consent that covers this image, this website, and this use, and that it came from the right person, meaning the guardian where a child is involved.
- Strip the metadata. Remove location data on the device before upload, particularly for anything photographed at a customer's property.
- Record it. Save the consent form or email beside the image name, so the proof exists without relying on anyone's memory.
- Log where it went. Note every place the image was published, so a takedown request takes ten minutes rather than an afternoon of searching.

Where the Photos Actually Live
Once you accept that images of people are personal data, the storage question stops being a technical detail.
A setup that holds up under a data protection question has a few plain characteristics. You can say which country the files are stored in. You can remove an image yourself, immediately, without raising a ticket with an agency and waiting on their hourly rate. You can restore the site if a deletion goes wrong, from a backup taken last night rather than last quarter. You can test a change to the gallery somewhere that is not production. And you can point a customer at a clear answer about where their photograph sits, rather than an unhelpful shrug about a hosting provider you have never spoken to.
That is the standard. Web60 meets it because it was built around it: managed WordPress on Irish infrastructure where your media library and backups stay in the country, full access to your own files from day one, nightly backups with one-click restore, and one-click staging for testing before anything reaches the live site, all included in the €60 a year. If your current arrangement means emailing someone to remove a photo, that is the part to fix first, and the wider security and backup guide for Irish websites covers the rest of the ground.
One honest exception. If you run a clinic where every image forms part of a patient record, a dedicated practice-management or clinical imaging system, with per-image consent flags and a proper audit trail, does a job that no website media library is designed to do. Web60 hosts your website. It is not a clinical records system. Keep the treatment archive in the right tool and let the website hold only the small set of images you have separate, explicit, written permission to publish.
A tattoo studio in Mayo photographing healed work is the clean version of this. The artist wants a portfolio, the client is proud of the piece, and both are better off when the permission is written down once, the file is stripped before upload, and the studio can pull an image the same day if the client's circumstances change.
Conclusion
The gap between a photo that helps your business and a photo that causes a problem is small and entirely manageable. It comes down to knowing who is in the frame, having their permission in a form you can produce later, checking what the file is carrying, and being able to take the thing down quickly when somebody asks.
Do that once as a habit and the rest of it takes care of itself. Your best marketing images are the ones of real customers, real work, and real people on your team, and none of that changes because you wrote a permission down.
Go through your galleries this week. Not to find fault, but because the images that need a second look are usually the oldest ones, and you already know which page they are on.
Frequently Asked Questions
Do I need written consent to put a customer's photo on my website?
Not always, but you need a lawful basis and you need to be able to prove it. For an ordinary photo of an adult, either consent or legitimate interests can work, provided the person was told what you were doing. For images that reveal health information, such as before-and-after treatment shots, you need explicit consent, and the EDPB is clear that a written statement is the obvious way to achieve that. Written consent costs you a minute and removes the argument entirely.
Can a customer make me remove a photo after they agreed to it?
Yes. Consent can be withdrawn at any time, and the EDPB guidance says withdrawal must be as easy as giving it was. If you relied on legitimate interests rather than consent, the person can still object, and in practice a business that refuses to remove a customer's photograph from its own marketing is picking a fight it will not enjoy. Take it down and confirm when it is gone.
What about photos of children at my club or crèche?
Get consent from the child's legal guardian and record that you got it. The DPC's guidance on photography at school events states that organisations will generally need the consent of the child's legal guardians to take and publish images, depending on the age of the child. A practical approach the DPC itself suggests is telling parents in advance and using coloured stickers or wristbands so whoever is holding the camera can see immediately who may be photographed.
Do I need permission for photos of my own staff?
You need a lawful basis, and consent is a weak one in an employment setting. The EDPB notes the imbalance of power between employer and employee means free consent is only possible in exceptional circumstances. For a standard team page, rely on legitimate interests, tell your staff plainly, and remove anyone who asks without turning it into a negotiation. Remember to take down photos of people who have left.
Does WordPress remove location data from my photos?
Partly. The resized versions WordPress generates for your pages usually have metadata stripped, since the image_strip_meta filter defaults to true and the GD library strips profiles regardless. The file you originally uploaded is kept as it was, though, and many themes and gallery plugins link directly to it. The safest habit is to turn off location for your camera app, or remove the location on the device before the photo ever reaches the site.
Someone asked me to delete their photo. Is deleting it from the media library enough?
It is the necessary first step, not the whole job. Cached pages, CDN copies, and Google's image index can hold the file for a while afterwards, and your backups will still contain it, which is normal and correct. Delete the original, clear your cache, check anywhere else you published the same image, and tell the person what you have done and what will take a few days to catch up.
Sources
- Data Protection Commission, guidance on promotional photographs at public events
- Data Protection Commission, official photography of children at school events
- Data Protection Commission, Annual Report 2025
- European Data Protection Board, Guidelines 05/2020 on consent under Regulation 2016/679
- WordPress Developer Resources, image_strip_meta filter
- Apple, Manage location metadata in Photos, Personal Safety User Guide
Graeme Conkie founded SmartHost in 2020 and has spent years building hosting infrastructure for Irish businesses. He created Web60 after seeing the same problem repeatedly — Irish SMEs paying too much for hosting that underdelivers. He writes about WordPress infrastructure, server security, developer workflows, managed hosting strategy, and the real cost of hosting decisions for Irish business owners.
More by Graeme Conkie →Ready to get your business online?
Describe your business. AI builds your website in 60 seconds.
Build My Website Free →More from the blog
Sale Prices and the 30-Day Rule Irish Websites Keep Breaking
Announce a sale in Ireland and you must show the prior price: the lowest price you charged in the previous 30 days. The rule, the traps, the penalties.
The Law on Website Reviews Reaches Your Own Testimonials Page
Fake testimonials, unverified five stars and cherry-picked feedback are banned under Irish law. What your website reviews page must show, and prove.
