How Europe's and California's landmark privacy laws treat the people who appear in your photos and video.
The Short Version
Neither law bans photography or videography. What they regulate is what happens once a photo or video contains an identifiable person and that footage is collected, used, stored, or shared — particularly by a business or organization, and particularly at scale. If you can recognize who someone is from the footage (directly from their face, or indirectly from context), both frameworks generally consider that footage to contain personal data, and obligations follow from there.
GDPR — European Union
The General Data Protection Regulation applies to any organization that processes personal data belonging to people in the EU or EEA — regardless of where the organization itself is based. A photo or video containing a recognizable face is personal data under GDPR's general definition (Article 4). If that image is specifically processed to identify someone via a unique biometric template — for example, running facial-recognition matching against it — it becomes "special category data" under Article 9, which requires a stronger legal basis, usually explicit consent.
For ordinary visual personal data, Article 6 offers several legal bases organizations can rely on: consent, legitimate interest (common for security cameras), contractual necessity (an employee ID photo), legal obligation, public task, or vital interest. One useful exception: anonymous crowd shots where no individual is identifiable generally fall outside GDPR's scope entirely. GDPR also gives people specific rights over their own image — including the right to access, correct, restrict, or erase personal data, sometimes summarized as the "right to be forgotten." In practice, that means someone can ask you to remove or blur their face from footage you've already published, and GDPR expects a response within about a month.
CCPA / CPRA — California
The California Consumer Privacy Act, as expanded by the California Privacy Rights Act, applies to for-profit businesses that meet certain revenue or data-volume thresholds and that collect personal information from California residents. Personal information under CCPA/CPRA is defined broadly enough to include visual and audio data that could reasonably be linked to a person.
CPRA carves out a stricter sub-category called "sensitive personal information," which explicitly includes biometric information — defined to cover imagery of the face, iris, retina, hand or palm, vein patterns, and voice recordings, when that data is used or intended to be used for identification purposes. California residents have the right to know what's been collected about them, request deletion, opt out of the sale or sharing of their information, and specifically limit the use of their sensitive personal information. Businesses must also provide notice at the point of collection — for example, signage where cameras are recording.
Obtain consent or a signed release wherever it's required for the context and jurisdiction
Blur or redact bystanders and anyone who hasn't consented to appear
Avoid generating biometric templates (face-matching, identity scoring) without explicit consent
Honor takedown, correction, or erasure requests promptly and document how you handled them
Keep records of the consent you did obtain, and for how long it's valid
Minimize how long you retain raw, unredacted footage once it's no longer needed
Apply extra caution around minors, medical settings, protests, and other sensitive contexts
For teams that need to show their work, BlurMe's Enterprise tier adds a GDPR audit trail, AES-256 encrypted uploads, configurable retention and deletion schedules, and an on-premise "Edge" option for closed networks — useful for healthcare and public-sector footage that can't leave a controlled environment. For everyday creators, the same underlying redaction engine handles the most common compliance step directly: removing identifiers from anyone who never agreed to appear.
For CCTV and surveillance footage subject to retention and access-request rules under either law, AI Redaction Software automates the de-identification step regulators expect before footage is shared or stored.
If your visitors still have questions, provide contact information or another resource for more help.