Photos are part of site documentation. As soon as people are identifiable, the GDPR, the German Federal Data Protection Act and the German Art Copyright Act apply. Which legal basis supports documentation, what applies to your own staff, and which practical rules businesses should follow.
One photo of the burst pipe, one of the finished bathroom, one of the crack in the screed: hardly any site documentation works without pictures. As long as only building components are in the frame, there is no data protection issue. As soon as a colleague, the electrician from the other trade or the client is recognisably in the picture, the business is processing personal data. That is no reason to stop taking photos. It is a reason to know a few rules.
When a photo is personal data
The GDPR applies as soon as a person in the picture is identifiable. A face is enough, but so can be a distinctive company jacket with a name on it or the number plate of the van in the background. From then on, taking, storing and passing on the image each need a legal basis under Article 6(1) GDPR.
The legal basis: legitimate interest
For a business's own site documentation, Article 6(1)(f) GDPR is usually the relevant basis. Processing is lawful where it "is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data". The interest in proving construction progress, the condition of preceding work and defects is a recognised interest. The word "necessary" is the yardstick: if the component can be documented just as well without the person, the person is not necessary.
Whoever relies on legitimate interest also has an information duty under Article 13(1)(d) GDPR: the business tells the data subject "the legitimate interests pursued by the controller or by a third party". In practice that means a note in the order or the terms of business that photos are taken for documentation and may show people.
Photograph the component, not the colleague. Then the data protection question mostly does not arise at all.
Your own staff: employee data protection
For photos of your own fitters, § 26 (1) sentence 1 of the German Federal Data Protection Act (BDSG) additionally applies: personal data of employees may be processed for the purposes of the employment relationship where necessary for its performance (unofficial translation). A photo that documents the state of the work and happens to show the fitter can be covered by that. A photo that is meant to show the fitter, for the website for example, needs their consent. Under § 26 (2) BDSG, the voluntariness of that consent has to be assessed, and consent must be given in writing or electronically unless a different form is appropriate due to special circumstances (unofficial translation).
Publishing is different from documenting
As long as the photo stays in the project file, data protection is the issue. As soon as it goes outside, the German Art Copyright Act (KunstUrhG) applies as well. § 22 sentence 1 KunstUrhG: images of a person may only be distributed or publicly displayed with the consent of the person depicted (unofficial translation). Exceptions are listed in § 23 (1) KunstUrhG, including pictures in which people appear only as an incidental feature next to a landscape or other location. The reference photo of the finished roof with the roofer in the foreground is not an incidental feature.
Five practical rules
First: photograph the object, not the person, and where a person is needed, from behind or at a distance. Second: file photos for their purpose, in the project, not in the smartphone's private gallery. Third: limit access to those working on the project. Fourth: set deletion periods, usually tied to the project's warranty period, not "forever". Fifth: inform the client and, when working on other companies' premises, the principal about the photo documentation.
The same applies to voice notes in which names are mentioned: they are personal data too. Scrypa processes and stores within the EU and deletes the audio file after transcription; what remains is the reviewed entry that you assign to your project and can delete once the retention period has expired.
This article gives a general account of the legal position under the GDPR, the German Federal Data Protection Act and the German Art Copyright Act and is not data protection advice for individual cases.
The figures in this article are illustrative and based on industry studies of voice-based documentation. They do not replace an assessment for your own organisation.
