A comprehensive handbook on consent, compliance and best practice for Danish organisations
Welcome to this comprehensive guide to GDPR and images. This guide is for professionals working in communications, marketing or content production in Danish municipalities, educational institutions, businesses and associations.
Whether you lead communications in a medium-sized municipality or create content at an educational institution, this guide aims to help you work correctly, efficiently and with documented processes for photos and video.
📑 Contents
- 1. When are photos and video personal data?
- 2. Ordinary vs. sensitive personal data
- 3. Legal basis: Consent or legitimate interests?
- 4. The big pitfall: Opt-out consent
- 5. Methods of collecting consent
- 6. Special considerations: Children, young people and employees
- 7. Consent vs. model agreements
- 8. Best practice: Five steps to a secure workflow
- 9. Frequently asked questions (FAQ)
1. When are photos and video personal data?
Under GDPR, photos and video are personal data as soon as a person can be identified, directly or indirectly. This applies to everything from traditional portraits to situational images and video recordings.
A person is identifiable if:
- Their face can be recognised: The most obvious criterion.
- Recognition through context: The person can be identified through the surroundings (such as a particular school or workplace), clothing or unique characteristics.
- Combination with text: The image is accompanied by text revealing their identity, such as a name in a caption.
💡 Key insight: It is identifiability, not the photographer’s intention, that matters. An atmosphere shot from a municipal event may still require consent if participants can be recognised.
2. Ordinary vs. sensitive personal data
Not all data is alike. Some images contain what GDPR defines as special categories of personal data (sensitive data).
If an image reveals information about:
- Health (for example, a person in a wheelchair or with visible signs of illness)
- Political or religious beliefs (such as religious symbols or attendance at political meetings)
- Sexual orientation or trade union membership
Additional requirements apply in these cases. As a starting point, you should always obtain explicit, written consent, and consider use of the material particularly carefully to protect the data subject.
3. Legal basis: Consent or legitimate interests?
To process photos lawfully, you need a legal basis. The appropriate basis depends on the organisation, the purpose and the specific processing.
Legitimate interests (balancing of interests)
This can be used if:
- The organisation has a valid and legitimate purpose.
- The processing is necessary to achieve that purpose.
- The organisation’s interests outweigh the individual’s right to privacy.
Public and private organisations may rely on different legal bases. A public authority cannot rely on legitimate interests when processing personal data in the performance of its public tasks. A task carried out in the public interest may, for example, be relevant where the legal framework supports the processing.
If photos are to be used for a new purpose, such as external recruitment, you must assess whether the new use is lawful and which legal basis can apply.
Consent
Consent can be a relevant legal basis for using photos and video, but it is not automatically the best choice. The person must have a genuine free choice and be able to withdraw consent. Assess the legal basis before collecting consent.
Valid consent must meet the following requirements:
| Requirement | Description |
|---|---|
| Freely given | The person must be able to say no without negative consequences. |
| Informed | The person must know who will use the image, for what purpose and for how long. |
| Active | An active action is required: a yes, signature or click. Silence is not consent. |
| Documented | The organisation must be able to prove that consent was given. |
| Withdrawable | Withdrawing consent must be as easy as giving it. |
| Specific | Consent must cover clearly defined purposes. Where relevant, the person must be able to choose separately between different purposes. |
4. The big pitfall: Opt-out consent
Many organisations still use “opt-out consent”, for example a sign saying: “We are taking photos – let us know if you do not want to be included”).
⚠️ WARNING: This is NOT valid consent under GDPR. Silence or passive behaviour can never be equated with an active yes. Without an active action from the data subject, consent is invalid and you risk complaints to the Danish Data Protection Agency.
5. Methods of collecting consent
Your choice of method affects your ability to demonstrate compliance:
- Verbal consent: Verbal consent can be valid, but you must be able to document who gave it, when and what it covered. A written or digital solution can make the documentation easier to store and retrieve.
- Video-recorded consent: Clear acceptance, but administratively demanding to archive and retrieve.
- Written consent (paper): Traditional, but vulnerable to illegible handwriting, loss and manual handling that can lead to data breaches.
- Digital consent (such as PhotoConsent): Digital consent can make it easier to collect, archive and retrieve documentation. Security depends on the design of the solution, access controls and the organisation’s working practices.
6. Special considerations: Children, young people and employees
- Children under 15: As a starting point, you should obtain consent from the holder of parental responsibility. Whether the child can independently consent to the use of photos and video depends on an individual assessment of their maturity and understanding of what they are agreeing to.
- Employees: Be cautious because of the power imbalance between employer and employee. Consent in an employment contract is rarely valid because it is not considered entirely voluntary. Instead, collect specific consent for individual productions.
7. Consent vs. model agreements
A model agreement can define the terms of participation and use of photos and video, such as the purpose, duration and payment. It does not automatically replace the need for a valid legal basis under the GDPR.
The ability to terminate the agreement or end use of the material depends on the agreement and applicable rules. If processing is based on consent, the right to withdraw consent still applies.
8. Best practice: Five steps to a secure workflow
To avoid consent-related complications and legal mistakes, your organisation should implement these five steps:
- Shared workflow: Establish one consistent process from recording to deletion. Plan for consent from the start.
- Clear responsibilities: Who takes the photo? Who collects consent? Who archives it?
- Digital documentation: Move away from spreadsheets and paper. Use a central, searchable system linking images and consent.
- A defined deletion policy: There is no single general GDPR retention period for photos and video. Set retention periods based on the purpose, necessity and any specific applicable rules. Regularly assess whether the material may and needs to be used. Storing the photos themselves and retaining evidence of consent may serve different purposes and require different retention periods.
- A withdrawal process: Have a clear plan for promptly removing an image if a citizen withdraws consent.
Frequently asked questions (FAQ)
What are the GDPR rules for images in Denmark?
Denmark follows the European GDPR rules, supplemented by the Danish Data Protection Act. The main principle is that an identifiable person requires a lawful basis for processing, most often consent or a balancing of interests.
Do situational images require consent?
This depends on an individual assessment of the photo, its purpose and the consequences for the people shown. The labels “portrait” and “situational photo” do not in themselves determine whether consent is required. You must always have a lawful basis and assess whether consent is necessary.
How long may a municipality keep photos of citizens?
There is no single general GDPR retention period for photos and video. Set retention periods based on the purpose, necessity and any specific applicable rules. Regularly assess whether the material may and needs to be used.
Storing the photos themselves and retaining evidence of consent may serve different purposes and require different retention periods.
Is a verbal yes enough to use an image on social media?
Verbal consent can be valid, but you must be able to document who gave it, when and what it covered. A written or digital solution can make the documentation easier to store and retrieve.
How should consent from children under 15 be handled?
As a starting point, you should obtain consent from the holder of parental responsibility. Whether the child can independently consent to the use of photos and video depends on an individual assessment of their maturity and understanding of what they are agreeing to.
A natural next step
Many organisations already have elements of these practices in place. In practice, however, they are often scattered, dependent on individuals or inconsistent.
If you work with many photos and videos, it can make sense to review how your current practices actually work day to day. Not to find fault, but to create clarity and confidence.
Want to understand where you stand today?
Your next step could be:
- A no-obligation review of your current consent process – We help you identify what works well and where improvements may be possible.
- Or a practical checklist to assess whether your image use complies with GDPR – A practical tool you can use immediately.
Both aim to make the rules easier to work with, not more burdensome.
Trusted by Danish organisations
PhotoConsent helps Danish municipalities, organisations, educational institutions and businesses manage consent securely and efficiently.
Summary
Working with photos and video under GDPR is about creating structure rather than isolated fixes. By digitising processes and maintaining a clear audit trail, you protect both citizens’ data and your organisation’s reputation.
Need help digitising consent management? PhotoConsent helps Danish municipalities and schools make compliance simple and efficient.
📚 Sources & references
This guide is based on Danish and European legislation and guidance from Danish and European authorities:
- Datatilsynet.dk – Denmark’s independent data protection supervisory authority
- GDPR-Info.eu – GDPR text and article-by-article guidance
- Danish Data Protection Agency guidance on images online
- European Data Protection Board (EDPB) – European guidance on interpreting GDPR
- Danish Data Protection Act (Act No. 502 of 27 April 2018) – Danish legislation supplementing GDPR
Last updated:
Disclaimer: This guide is informational and based on current legislation. It does not replace legal advice. For specific legal questions, we recommend contacting a lawyer specialising in data protection.
