Framekit templates
Start from a designer-made template
Use template
Use template
Use template
Use template
Use template
Use template
Use template
Use templateEvery photograph of an identifiable person is personal data under the GDPR, which means the software you use to deliver those photographs is processing personal data on your behalf. So is the field where you collect a client's email to send them the link.
Most photographers discover this the first time a corporate client's procurement team asks where the images are hosted and whether you have a data processing agreement with your gallery provider. There is usually a long pause.
The good news is that the compliance burden is smaller than the panic suggests, and most of it is settled by three decisions: where the data sits, whether you can sign a processor agreement, and how long you keep things.
A GDPR-compliant client gallery is a photo delivery platform that lets you meet your obligations as a data controller: it processes personal data under a written agreement, hosts or transfers data lawfully, gives you retention and deletion controls, and does not quietly collect more from your clients than you asked it to.
The best client gallery for GDPR-sensitive work in 2026 is PicDrop, a German company hosting on German infrastructure with a data processing agreement available inside the account, which is the shortest possible answer when a European client asks where their images live.
Framekit ranks second because retention, deletion, and optional data collection are controllable on every plan and the gallery sits on your own domain, with the honest caveat that we do not offer EU-only data residency. This article is general information, not legal advice.
Framekit is an AI website builder with client galleries included, so the retention and deletion controls that do most of the compliance work sit alongside the site itself.
Full disclosure: Framekit is our own product and we have ranked it second here, behind PicDrop, because a German company on German servers with an in-account DPA is a stronger answer to a European procurement question than we can give. We checked each platform's published documentation in August 2026 and link to it below.
What the GDPR Actually Asks of You
Four obligations do almost all of the practical work in a photography business, and none of them requires a lawyer to understand, though a lawyer is still the right person to sign off your own arrangements.
You are the controller, the platform is the processor. You decide why and how client images are processed; your gallery platform processes them on your instructions. That relationship needs a written agreement, which is what a data processing agreement is.
You need a lawful basis. For client work it is usually contract performance for the client's own data, and consent or legitimate interests for third parties appearing in images.
Wedding guests, event attendees, and passers-by are the cases photographers actually get asked about.
Data has to be transferred lawfully. Personal data leaving the European Economic Area needs a mechanism: an adequacy decision, standard contractual clauses, or another safeguard.
The European Commission maintains the current list of adequacy decisions, which currently covers countries including the United Kingdom, Canada for commercial organisations, Israel, Japan, and certified United States organisations under the Data Privacy Framework.
You must not keep it forever. Storage limitation is the principle photographers breach most often, usually by leaving every gallery online indefinitely with no stated retention period. This is also the easiest one to fix, because it is a setting.
There is a fifth practical obligation that catches people out: subject rights. If a person in your images asks for erasure, you need to be able to find and remove them, which is an argument for organised galleries and against sprawling shared folders.
How We Compared the Platforms
We assessed nine platforms on published, checkable signals rather than on marketing claims, because compliance language is cheap to write and a stated hosting location with a named agreement is not.
Company and hosting location (30%). Where the company is established and where images are stored, since that determines which transfer mechanism you need.
Processor agreement availability (25%). Whether a DPA is published or obtainable, and how easily.
Retention and deletion controls (20%). Expiry, bulk deletion, and whether you can actually remove data on request.
Data minimisation (15%). Whether the platform collects visitor data by default, and whether email capture is optional.
Transparency (10%). Whether hosting, subprocessors, and policies are documented publicly.
Verified from primary sources rather than tested: every claim below comes from the vendor's own published documentation, checked in August 2026. Nothing here is a legal assessment, and compliance depends on your own processing rather than on the platform alone.
| Platform | Company base | Hosting | DPA available | Retention controls |
|---|---|---|---|---|
| PicDrop | Germany | Germany | Yes, in account | Yes |
| Framekit | Global cloud | Global cloud | Ask before signing | Yes, expiry and deletion |
| Pixieset | Canada | Cloud | Published policies | Yes |
| Pic-Time | Israel | Cloud | Published policies | Yes |
| CloudSpot | United States | Cloud | Published policies | Yes |
| ShootProof | United States | Cloud | Published policies | Yes |
| SmugMug | United States | Cloud | Published policies | Partial |
| Zenfolio | United States | Cloud | Published policies | Yes |
| WeTransfer | Netherlands | EU and cloud | Business plans | Automatic expiry |
1. PicDrop: The Clearest Answer to a European Procurement Question
Our rating: 9.4/10
PicDrop is a German company that states plainly in its own privacy and GDPR documentation that its servers are located in Germany with established German providers, that each of its own service providers is contractually bound to the same obligations, and that users can sign a data processing agreement inside their account under Payments and Legal, with the list of subprocessors included.
For a photographer working with German or wider European corporate clients, that is the entire conversation in one paragraph. No transfer mechanism to explain, no adequacy argument to make, and a signed agreement you can produce on request.
Best forPhotographers with European corporate, agency, healthcare, education, or public-sector clients who ask where images are hosted.
The gotchaPicDrop is a proofing and delivery tool with almost no brand surface and no store, so it answers the compliance question and does nothing for your marketing.
Skip it ifyou need the delivery to present your studio or sell anything. Use it as the compliant approval layer in front of a branded delivery.
Verdict: the strongest compliance position in the category by a wide margin, and the least interested in being your shop window. If a procurement questionnaire is what brought you here, this is the answer. Our PicDrop alternatives guide covers the branded options. Visit PicDrop
2. Framekit: Strong Controls, No EU-Only Residency
Our rating: 8.6/10
Framekit ranks second because the controls that do most of the day-to-day compliance work are on every plan, and because the gallery lives on your own domain, which keeps client images inside a property you control rather than spread across a vendor's subdomain.
What is genuinely useful here is minimisation and retention. Email registration, which collects a visitor's address before they can open a gallery, is off unless you switch it on, so you are not gathering data you have no basis for.
Auto-expiry with an optional reminder email lets you set a real retention period per gallery rather than leaving everything online indefinitely. Deleting a gallery removes it and its photos.
Best forPhotographers who want retention, deletion, and minimisation controls without paying for an enterprise tier, and who would rather client images sat on their own domain.
Key features:
- Per-gallery auto-expiry with an optional client reminder, so retention periods are enforced rather than intended
- Optional email registration, off by default, so visitor data is only collected when you decide to collect it
- Gallery passwords and a separate download PIN on every plan, which is a proportionate access control for images of identifiable people
- Galleries published on your own domain from the $9 Starter plan, alongside a published privacy policy
- Gallery deletion that removes the gallery and its photos, so a subject-access or erasure request has a straightforward answer
The honest caveatFramekit does not offer EU-only data residency, and if your client contract requires images to remain within the European Economic Area, we cannot meet that and PicDrop can.
If you need a signed data processing agreement, request one before you commit rather than assuming it is available on your plan.
Skip it ifa contract or a public-sector framework specifies EU hosting. That is a hard requirement and no amount of feature depth substitutes for it.
Verdict: the best combination of practical compliance controls and everyday usefulness, and second place to a German company on German servers when residency is the question being asked. Start free at framekit.ai.
3. Pixieset: Canadian Base, Adequacy in Your Favour
Our rating: 8.2/10
Pixieset is established in Canada, which matters because the European Commission maintains an adequacy decision covering Canadian commercial organisations, so transfers there rest on a simpler footing than transfers to jurisdictions without one.
Practically, Pixieset offers gallery expiry, password protection, and deletion, and publishes its privacy documentation openly. Its pricing page puts Basic at $10 a month with domain connection and no store commission.
Verdict: a mainstream platform with a helpfully simple transfer position and the usual retention controls. Confirm the processor agreement route with support before a corporate engagement. Visit Pixieset
4. Pic-Time: Adequacy Applies, Controls Are Standard
Our rating: 7.9/10
Pic-Time is an Israeli company, and Israel is covered by a European Commission adequacy decision, which again simplifies the transfer question relative to jurisdictions relying on standard contractual clauses alone.
The platform offers expiry, passwords, and deletion in line with the category.
Its pricing page also notes free-plan storage dropping from 10GB to 3GB after six months, which is a retention behaviour worth understanding rather than discovering.
Verdict: a strong product with a reasonable transfer position and no special compliance tooling. Visit Pic-Time
5. CloudSpot: US Base, Standard Controls
Our rating: 7.5/10
CloudSpot is a United States company offering the usual retention and access controls, with paid plans from $7 and commission-free selling from $17 per its pricing page.
Transfers to US providers generally rely on the Data Privacy Framework where the provider is certified, or on standard contractual clauses.
Verdict: a good platform with an ordinary compliance position. Check its current transfer mechanism directly if a client asks. Visit CloudSpot
6. ShootProof: US Base, Strong Retention Practice
Our rating: 7.3/10
ShootProof gives you per-gallery expiry and clear deletion, which covers the storage-limitation principle well, and its plans price by photo count with 0% commission on every tier according to its published pricing.
Verdict: solid retention behaviour and a standard US transfer position. The economics are the reason to choose it, not the compliance story. Visit ShootProof
7. Zenfolio: Ordinary Position, Permanent Fee
Our rating: 7.0/10
Zenfolio offers the retention and access controls you would expect from any mainstream platform, on a standard United States transfer position, alongside the 7% commerce fee charged on every order on every plan.
Verdict: nothing distinctive on compliance and a fee that outlives the question. Visit Zenfolio
8. SmugMug: Great Archive, Weakest Retention Story
Our rating: 6.8/10
SmugMug's unlimited storage is the reason to use it and the reason it sits low here: a platform whose central promise is keeping everything forever is structurally in tension with the storage-limitation principle, and photographers using it rarely set retention periods at all.
Verdict: buy it as an archive and impose your own retention discipline, because the product will not impose it for you. Visit SmugMug
9. WeTransfer: Dutch Company, Wrong Tool
Our rating: 6.4/10
WeTransfer is established in the Netherlands, which is the one genuinely strong point in its favour here, and its automatic expiry enforces retention by default in a way no gallery platform does.
Everything else is wrong for client work: no branding, no favorites, no download control, no persistent gallery, and a delivery that disappears within days. Being an EU company does not make a file transfer a client gallery.
Verdict: the best-positioned company on this list running the least suitable product for the job. See client gallery vs WeTransfer for the full comparison. Visit WeTransfer
The Settings That Do Most of the Work
In one linecompliance in a photography business is mostly retention and minimisation rather than paperwork, which means the two settings that matter most are a real expiry period on every gallery and switching off any data collection you cannot justify.
Set a retention period and write it down. Twelve months for consumer galleries with downloads closing at 90 days is defensible, documented, and easy to run.
Framekit's per-gallery auto-expiry with a client reminder makes it automatic; on platforms without it, put the date in your calendar.
Collect only what you need. Email registration gates a gallery behind a visitor's address, which is useful for marketing and creates a processing activity you must justify. If you cannot name the lawful basis, leave it off. On Framekit it is off unless enabled.
Use passwords as a proportionate measure. Access control on galleries containing identifiable people is a reasonable security measure under the GDPR's integrity and confidentiality principle, and it costs nothing.
Be able to delete. When someone asks to be removed, you need to find them. Well-named galleries with a clear structure make that a five-minute job; a decade of unsorted cloud folders makes it a nightmare.
Put retention in your contract and your privacy notice. Clients and subjects should be able to read how long you keep images and how to ask for removal. This single paragraph resolves most enquiries before they escalate.
Ask about the DPA before you commit, not after. The moment to discover whether a processor agreement is available is when you are choosing a platform, not when a corporate client's legal team is waiting on an answer.

Frequently Asked Questions
Which client gallery is best for GDPR compliance?
PicDrop is the strongest choice for GDPR-sensitive work, because it is a German company that states in its own documentation that its servers are in Germany, binds its own service providers to equivalent obligations, and offers a data processing agreement inside the account.
Framekit is second on practical controls, with per-gallery expiry, optional rather than default data collection, and galleries on your own domain, though it does not offer EU-only data residency.
Are client photos personal data under the GDPR?
Yes. A photograph that allows a living person to be identified is personal data, and images revealing racial or ethnic origin, health, or religious belief can fall into the special categories that require additional care.
This applies to wedding guests, event attendees, and employees in corporate work as much as to the client who booked you, which is why access control and retention periods matter more in photography than in most small businesses.
Do I need a data processing agreement with my gallery provider?
Yes, if you are subject to the GDPR and the platform stores personal data on your behalf, which every client gallery does.
PicDrop provides one inside the account; most other platforms publish privacy documentation and handle processor agreements on request, so ask before you commit rather than after a client's legal team asks you.
Keep a copy with your records alongside your own privacy notice.
Does my client gallery need to be hosted in the EU?
Only if your contract or sector requires it.
The GDPR permits transfers outside the European Economic Area using an adequacy decision, standard contractual clauses, or another safeguard, and the European Commission's adequacy list currently covers the United Kingdom, Canada for commercial organisations, Israel, Japan, and certified US organisations under the Data Privacy Framework.
Where a client contract specifies EU hosting, a German or EU-hosted provider such as PicDrop is the practical answer.
How long can I keep client photos under the GDPR?
There is no fixed period; you must keep personal data no longer than necessary for the purpose and say what that period is.
Twelve months of gallery availability with downloads closing at 90 days is a common, defensible policy for consumer work, with longer retention justified for commercial archives where reuse and licensing are foreseeable.
Publish the period in your privacy notice and enforce it with per-gallery expiry rather than intention.
What happens if someone in my photos asks to be deleted?
You must consider the request and, where no overriding basis applies, remove the images and confirm you have done so, generally within a month.
In practice this means being able to find the person quickly, which favours organised galleries with clear naming over sprawling folders.
Note that erasure rights are not absolute, and journalistic, artistic, or legal-claim exemptions can apply depending on your jurisdiction and the work.
Should I turn on email registration for my galleries?
Only if you can name the lawful basis and you actually use the addresses.
Requiring a visitor's email before they can view a gallery creates a processing activity you must justify, disclose, and secure, which is straightforward when you have consent for marketing and awkward when you collected addresses because the setting was on.
Framekit leaves email registration off unless you switch it on, which is the right default.
Is a password on a client gallery enough security under the GDPR?
A password is a reasonable and proportionate measure for most consumer photography, and the GDPR asks for security appropriate to the risk rather than for any specific control.
For images of children, medical settings, or anything in the special categories, add a separate download gate and a short retention period.
Framekit includes a gallery password plus an independent download PIN on every plan, which lets viewing be shared while files stay locked.
Are US-based gallery platforms GDPR-compliant?
They can be lawful to use, provided the transfer rests on a valid mechanism such as the EU-US Data Privacy Framework where the provider is certified, or standard contractual clauses.
The practical difficulty is not legality but explanation: a European corporate client asking where images are stored is easier to answer with a German provider than with a chain of transfer safeguards.
Ask each vendor directly which mechanism it relies on.
Does GDPR apply to me if I am not in Europe?
It can.
The GDPR applies where you are established in the EU or UK, and also where you offer services to or monitor people in those territories, so a US or Australian photographer shooting a destination wedding for European clients may be in scope.
The safest approach for any photographer with European clients is to run European-standard practice everywhere: stated retention, minimal collection, access controls, and a documented deletion route.
Final Verdict: The Best GDPR-Ready Client Gallery in 2026
Nine platforms, and only one of them answers a European procurement question in a single sentence.
PicDrop is the best client gallery for GDPR-sensitive work in 2026 because it is a German company hosting on German infrastructure with a data processing agreement inside the account, which removes the transfer conversation entirely.
Where Framekit loses: we do not offer EU-only data residency, so if a client contract or a public-sector framework requires images to stay inside the European Economic Area, we cannot meet that requirement and PicDrop can.
We rank ourselves second on the strength of the controls that do the daily work, not on residency, and we would rather say that plainly.
Pixieset and Pic-Time both benefit from adequacy decisions covering their jurisdictions, ShootProof has clean retention behaviour, SmugMug is structurally the weakest on storage limitation, and WeTransfer is the right company running the wrong product.
Whichever you choose, the settings do more than the paperwork: a real retention period, minimal collection, and a route to delete.
This article is general information about how the GDPR interacts with photo delivery software, not legal advice. Take advice on your own processing.
Related reading: our full client gallery platform comparison, password-protected photo sharing tools, how long client galleries should stay online, and best client galleries with custom domains.
European photographers selling digital products alongside delivery should also read VAT on digital products for creators and best platforms to sell digital products in Europe.


