· Marc Hendricks

GDPR Property Photos: Checklist for EU Agents

GDPR Property Photos: Checklist for EU Agents

GDPR applies to a property photo when the image or its context contains information relating to an identified or identifiable person. A generic photograph of an empty room is not automatically personal data. An occupied home needs a closer look. Family portraits, names on post, number plates or the listing's address may identify a resident even when nobody appears in the frame.

Before taking or uploading a photo, remove personal details that the listing does not need. Record the lawful basis for what remains and explain how the agency will use the images. If another provider handles the files, check its contract, subprocessors, processing locations and deletion terms. "Hosted in the EU" does not describe the whole data path, and "GDPR compliant" does not answer whether the provider uses photos for model training.

There is no single EU retention period for listing photos, and consent is only one possible lawful basis. What fits depends on the property, its occupants, the purpose and national law. This is a working checklist for EU agencies, not legal advice for every sale or letting.

Are property photos personal data under GDPR?

Property photos are personal data when they relate to an identified or identifiable living person. Article 4(1) of the GDPR uses a broad definition, but it does not make every photograph of a building personal data.

The Irish Data Protection Commission illustrated the distinction in a 2023 case study. It said an image of a property alone may not be personal data, while a photograph combined with an address and house number may be. The agency therefore needs to assess the photo together with its address and listing.

Treat a listing photo as potentially personal data if it shows or reveals:

  • a face, reflection or recognisable body;
  • family portraits, children's artwork or certificates;
  • names on letters, labels, calendars or screens;
  • a vehicle number plate or other unique identifier;
  • medical, religious, political or financial information;
  • distinctive possessions that connect an occupant with the address; or
  • an occupied interior that people familiar with the resident could recognise.

What does the German occupied-home case mean?

A German appellate judgment shows why occupied interiors deserve more care. On 9 December 2025, the Higher Regional Court of Zweibrücken considered photos of rented rooms taken for a property sale. No people appeared in them, but the court treated information relating to the tenants and the handling of the interior photos as falling within the tenants' data-access rights. The tenants had been present during the agreed photo appointment, and the court found implied consent in that specific setting. It did not award damages.

The official court report (in German), published on 16 December 2025, concerns one German judgment, not an EU-wide rule that every room photograph is personal data. The case did not concern an AI photo-editing workflow, although the court report notes that access information can include whether and how personal data was processed using AI. Its narrower lesson is still useful outside Germany: an occupied interior can reveal more about a resident than an empty room. Agencies should separately document how they collect, store, share, edit and delete those photos.

What should agents remove before taking or uploading photos?

Remove personal information while you are still at the property. Then it never reaches the photographer, cloud drive or editing provider. This is the simplest way to apply the GDPR principle of data minimisation.

Run a two-minute privacy sweep before the camera comes out:

  1. Put away post, prescriptions, certificates, school material and calendars.
  2. Remove or turn over family photographs and named artwork.
  3. Switch off televisions, monitors and smart displays.
  4. Move vehicles where possible or frame out readable number plates.
  5. Check mirrors, shower screens, ovens and windows for reflections.
  6. Look at desks, bedside tables and kitchen noticeboards at full camera resolution.
  7. Take a final test frame and zoom in before shooting the room.

If a detail cannot be moved, change the angle, crop before upload or blur it. Restrict access to any unblurred original to staff who need it. The broader real estate photography checklist for EU agents covers the rest of the shoot.

Estate agents do not always need consent, but they always need a lawful basis when a photo is personal data. Article 6 GDPR lists six bases. Possible bases for listing work include consent, contractual necessity or legitimate interests. None applies automatically.

Consent must be freely given, specific, informed and unambiguous, and the person must be able to withdraw it. The seller cannot automatically consent for a tenant, neighbour or other adult occupant. Where a child is involved, confirm who has parental authority and whether consent is the appropriate lawful basis. For a tenanted property, record who agreed, which rooms may be photographed, where the images will appear and how long they will remain available.

Contractual necessity applies only when the agency needs the processing to perform a contract with that person. Legitimate interests require the agency to identify its interest, show necessity and balance it against the person's rights and expectations.

Record separately why you take the photo, send it for editing and publish it. Each step exposes the image to different people. National property, tenancy and image-rights rules may add requirements beyond GDPR.

Who is the controller when an AI tool edits the photo?

The estate agency is usually the controller for its listing-photo workflow because it decides why the photos are taken and how they are used. A photographer or editing service may act as a processor when it handles the images only on the agency's documented instructions. Roles depend on facts, not labels in a supplier's terms.

A supplier that reuses photos for its own model training or another independent purpose may become a controller for that separate use. A "processor" label in its terms is not enough.

Where a provider processes personal data on the agency's behalf, Article 28 requires a binding contract with specific terms. The European Commission's controller and processor guidance summarises the required content.

What should an AI photo editor's DPA cover?

The data processing agreement should match what the provider actually does with each photo. Keep a copy of the agreement and the current subprocessor list.

Check What the answer should include Warning sign
Roles and purpose Who is controller and processor, and exactly why each photo is processed Broad rights to use content for unspecified business purposes
Data and people Listing photos, account data, prompts, logs and likely data subjects Terms that discuss account data but ignore uploaded images
Subprocessors Current names, functions, locations and a notice process for changes "Trusted partners" with no usable list
Security Access controls, encryption, incident handling and staff confidentiality Security described only as "industry standard"
Rights requests How the vendor helps with access, erasure, restriction and objections No route for locating a photo or associated log
Retention and deletion Periods for originals, results, temporary files, logs and backups "Deleted promptly" with no period or scope
International transfers Every relevant destination and the safeguard used EU storage presented as proof that no transfer occurs
Model training Whether customer photos, edits or prompts are used to train or improve models Opt-out wording that leaves default reuse unclear
End of service Return or deletion process and any legal exceptions An indefinite licence surviving account closure

Check that the subprocessor list covers image processing, not just hosting, email and analytics. Ask how the supplier gives notice before a new subprocessor receives photos.

Must listing photos remain inside the EU?

GDPR does not impose a blanket rule that listing photos must remain inside the EU or EEA. A non-EEA transfer may rely on an adequacy decision. Otherwise, the agency may need safeguards such as standard contractual clauses and an assessment of the transfer.

Map where photos are stored, edited, cached, backed up and accessed for support. A file stored in Frankfurt can still be transferred if a provider elsewhere processes or remotely accesses it.

Ask for the countries and transfer mechanism. The Commission maintains the current adequacy decisions and transfer guidance, while the EDPB provides recommendations on supplementary transfer measures.

How long should agents keep listing photos?

There is no universal GDPR retention period for listing photos. Storage should last no longer than necessary for the stated purpose, subject to any justified legal or evidential need. The European Commission's retention guidance recommends setting time limits to erase or review stored data.

Tie the schedule to events such as publication, withdrawal, sale or letting. Adjust these examples for national law and how long the agency genuinely needs each file. They are not EU deadlines.

Record Practical trigger Example agency rule
Rejected shoot frames Selection of the final gallery Delete after quality and privacy review unless needed for a documented reason
Published originals and edits Listing withdrawn, sold or let Move out of active systems, then review against complaints, contract and limitation needs
Portal and social copies Marketing purpose ends Remove where the agency controls the copy and record any platform limitation
Editing prompts and job logs Edit accepted and support window closes Keep only the minimum needed for support, security and audit
Supplier temporary files Processing completes Apply the contracted deletion period and check whether it covers derived files
Backups File deleted from the live system Let the stated backup cycle expire, with access restricted in the meantime
Consent and balancing records Related photo is deleted Retain only as long as needed to demonstrate compliance or address a claim

Deletion should cover originals, crops, edits, download folders, shared drives, controllable portal copies and supplier-held files. Backups may expire on a separate cycle, but deleted data should not return to normal use.

Can a vendor use listing photos for model training?

Model training is a separate question from storage location and should be answered explicitly in the contract. Do not infer "no training" from a GDPR claim. Ask exactly what the provider reuses: originals, results, prompts, ratings or human reviews. Check whether reuse is enabled by default and which subprocessors receive the data.

The EDPB's Opinion 28/2024, adopted on 18 December 2024, says lawfulness depends on the circumstances. It is not a blanket approval for training. Prefer a precise contractual commitment to a privacy slogan.

A seven-step GDPR workflow for listing photos

  1. Define the purpose and lawful basis. Record why the images are needed, who the data subjects may be and the basis for each relevant activity.

  2. Inform the occupants. Explain who takes the photos, where they will be published, who edits them, how long they are kept and how to exercise rights.

  3. Minimise before capture. Run the privacy sweep, frame out unnecessary details and restrict photographs to rooms and features needed for the listing.

  4. Approve providers before upload. Use approved photographers and editors, put processor terms in place and document subprocessors and international transfers before upload.

  5. Review before publication. Inspect every file at full size for names, faces, reflections, number plates and details introduced or exposed during editing. For AI alteration and disclosure questions, use the separate guide to AI real estate photo editing in the EU.

  6. Record only what the agency needs. Link the approved original and edit to the property, lawful-basis record, publication channels and deletion trigger without collecting extra personal data.

  7. Follow the retention schedule. When the purpose ends, delete or archive according to the schedule, remove controllable portal copies and confirm that supplier deletion and backup cycles follow the contract.

Name the person responsible for checking that deletion is complete after a sale or letting.

Frequently asked questions

Are empty-room photos personal data?

An empty-room photo is not automatically personal data. It becomes more likely to fall within GDPR when its content or context relates to an identifiable occupant, for example through an address, distinctive possessions, family photographs or other identifying details. Assess the complete listing and audience, not just one isolated image.

Written consent is not mandatory in every case, and consent is not the only lawful basis. If an agency relies on consent, it must be able to demonstrate that the person gave a freely chosen, specific, informed and unambiguous agreement. Recording it in writing is usually clearer than relying on conduct, especially in an occupied or tenanted home.

Should faces and number plates be blurred?

As a practical default, remove, frame out or blur faces and number plates that the listing does not need. Removing the detail before capture is better because the unredacted data never enters the editing chain. If a person or plate must remain visible, document why and assess the applicable lawful basis and publication risk.

Can an AI editor process photos outside the EU?

An AI editor may process photos outside the EU or EEA, but the agency still needs a lawful basis, suitable processor terms and a valid transfer mechanism where one is required. The agency should know the destination, recipient, purpose and safeguard. EU-based storage does not answer where image processing or support access occurs.

How long should listing photos be retained?

Keep listing photos only as long as necessary for the documented purpose and any justified legal or evidential need. Set review or deletion triggers for originals, edits, portal copies, logs and backups. GDPR does not provide one fixed retention period for every estate agency or transaction.

Make GDPR part of your property photo workflow

The best privacy check happens before upload. Remove personal details at the property, then record who handles the images and when each copy should be deleted.

Immopix lets agents upload a property photo, request a defined enhancement and review the result before publication. Users can delete individual photos or complete property folders from the dashboard. The service uses external providers for image analysis, editing and quality checks, and its privacy policy explains the current processing information and how to make a data-protection request. Use the free real estate photo enhancement tool to test the workflow, then compare the result with the original before publication.

3 photos free, no credit card

Upload a property photo and Immopix fixes skies, rooms and distracting details within a minute.

Try for free