Photography Articles

Data Retention Policies for Photographers

Build a photography data retention policy with a practical worksheet. Separate gallery expiry, file deletion and backups, and document your studio’s decisions.

Published August 20, 2026 Updated September 21, 2026 8 min read

Data retention policies tell a photography studio which files to keep, why it needs them, and when to review or delete them. Start with separate decisions for client access, working files, business records and backups. A gallery closing date is not a deletion policy, and there is no single retention period that fits every studio.

This guide is an operational worksheet, not legal advice or a ready-made privacy policy. Use it to document your decisions, then check the obligations that apply to your location, clients and contracts before setting deletion dates.

What your policy needs to cover

Inventory a real completed project. Follow its files from the camera card to your editing computer, external drives, gallery service and backup system. Include copies shared with an editor or second photographer. Record who controls each copy rather than assuming that deleting the delivery gallery removes the originals.

  • Camera originals and editing catalogs: what you need to finish the job or deliver an agreed revision.
  • Delivered photographs and videos: what the client receives and whether you offer a separate archive service.
  • Proofs and rejected selections: material that may no longer be needed after selection or delivery.
  • Contracts, invoices and release forms: records with purposes different from storing every image.
  • Client messages and contact information: project communication, support and any separately managed marketing list.
  • Backups and exports: recovery copies, temporary downloads and files held by collaborators.

Give each category an owner and an action

For each category, write down its purpose, storage location, retention trigger, review date, responsible person and final action. A trigger could be final delivery or the end of an agreed revision window. A review date tells someone to make a decision; it does not silently authorize permanent deletion.

Separate access expiry, deletion and backups

  1. Close client access when the agreed delivery window ends. Check the shared link while signed out. This confirms access behavior, not removal of stored files.
  2. Review the studio copy. Confirm delivery, resolve any applicable exception and decide which files still have a documented purpose.
  3. Delete approved files in the systems you control. Check the outcome rather than treating a queued operation as complete.
  4. Account for remaining copies. Record backup handling and ask collaborators or service providers about copies outside your direct control.

An expired link can leave files stored in the account. Removing a file from a live folder can leave a recovery copy elsewhere. Likewise, a client may already have downloaded a copy that your gallery controls cannot recall. Avoid telling clients that every copy disappears when their link expires.

Choose retention periods for the actual purpose

Do not copy a blanket three-year, seven-year or 90-day rule from another studio. Instead, complete a separate record for each file category. The prompts below are a worksheet: they deliberately do not prescribe legal deadlines.

A compact retention worksheet

  • Purpose: why is this category still needed after delivery?
  • Trigger: which event starts its retention or review period?
  • Duration and reason: what period have you selected, and what supports it?
  • Location and owner: where are the copies, and who will act?
  • Client promise: what availability or deletion information have you actually agreed?
  • Exceptions: who checks an active dispute, applicable recordkeeping requirement or other reason to retain specific material?
  • Action and evidence: what will be removed, what remains, and how will you confirm the outcome?

Use the worksheet differently for different records. For RAW files, consider the agreed editing and revision work. For gallery exports, document the delivery window and any separately agreed archive service. For invoices, obtain the applicable accounting requirement rather than borrowing an image-storage deadline. For proofs, ask whether selection is complete and whether keeping the rejected images still serves a purpose.

A worked delivery example, not a legal default

Suppose a studio agrees to keep a portrait gallery available for 60 days after delivery. That is an illustrative service choice, not a recommended retention period. Its project record would name the delivery date, access-end date and person responsible for checking the gallery. The studio would separately record when to review RAW files, editing catalogs and business records.

If the client requests an agreed extension, update the access date and confirmation message. Do not automatically extend every file category. If a dispute affects selected records, document the specific exception and review date instead of keeping the entire archive forever.

Check privacy and recordkeeping requirements

For UK GDPR, the ICO’s storage-limitation guidance does not prescribe one duration for every data type. It calls for justified retention linked to purpose and periodic review. The ICO also distinguishes taking data offline from deleting it. Its guidance is currently under review following UK legislative changes; check the current version when setting your policy.

The California Privacy Protection Agency’s CCPA FAQ explains which businesses are covered and describes purpose-based limits on retention. It does not establish a universal 12-month maximum for photography files. Deletion rights can have exceptions. Do not promise that every request requires erasing every business record immediately.

Clients in different jurisdictions

A client’s location alone is not enough to choose a retention schedule. Identify the laws that apply to your business and the particular information, along with contractual requirements. Where duties appear to conflict, seek qualified advice for those records; choosing the shortest period is not a reliable way to resolve the conflict.

Make the procedure safe to operate

Protecting access and limiting retention are complementary tasks. Limit account access to the people who need it, keep account recovery information current, and avoid scattering unnecessary downloads across personal devices. None of these measures replaces a documented review and deletion process.

Check recovery copies separately

Before promising a deletion timeline, find out how your backup system and each provider handle deleted files. Ask how long recovery copies remain, who can access them, and what happens if a backup is restored. Record unanswered questions instead of describing an unverified system as automatically compliant.

Keep a small operational log: project reference, category, action date, operator, systems checked and any outstanding copy. The log should demonstrate what happened without becoming another unnecessary collection of photographs or sensitive client messages.

Use SendPhoto controls for their specific jobs

SendPhoto has separate share-expiration and self-delete settings. Share expiration makes a gallery private after its expiration date. The self-delete schedule is a separate deletion control; it is not implied by ending access. Treat these as different decisions in your project record.

  1. Agree the delivery window and tell the client when access will end.
  2. Set share expiration for that window, then verify the shared-link behavior.
  3. Only set a self-delete date after checking the files and any applicable retention exception. Do not use a client’s gallery as your only copy of work you still need.
  4. If you enable a deletion reminder, check the account owner’s email details. This reminder is for the account owner; it is not a substitute for telling the client about delivery access.
  5. After the scheduled date, check the gallery’s state. Deletion uses background processing, so do not promise an exact instant when all copies disappear.

These controls do not delete originals on your computer, a collaborator’s exports or a client’s downloaded files. Keep those locations in your own worksheet. Explore SendPhoto’s gallery delivery features and download controls when planning the client handoff.

Put the policy into practice

Start with one finished project

  1. List its file categories and storage locations using the worksheet.
  2. Check applicable obligations and the promises already made to the client.
  3. Set the review dates and assign an owner. Test gallery settings with non-sensitive sample files before using a destructive schedule on client work.
  4. Send clear delivery instructions, including the access deadline and how to request an extension.
  5. Review the project at the scheduled time, record the actual action and follow up on any outstanding copies.

What to include in client-facing wording

Write the final wording from decisions you have actually made. Explain how long the delivery link remains available, whether an archive service is included, what the client should download, and whom to contact with questions. Explain retention of studio files separately from delivery access. Have relevant privacy and contractual language checked for your circumstances.

For example, a delivery message can state the actual gallery closing date and ask the client to download their delivered files before it closes. It should not say that closing the gallery destroys all originals, backups and downloaded copies. Avoid advertising permanent storage unless that is a service you can genuinely provide.

Common questions

Does a password-protected gallery count as deleted?

No. A password limits access; it does not remove the stored photographs. Expiring the shared link and deleting a gallery are also separate actions.

Should I keep every RAW file forever?

Make that decision from the purpose, your commitments and applicable requirements. An archive without an owner, review date or documented reason is not a useful retention policy. If you offer long-term storage, define its scope and limits clearly.

Can a retention schedule guarantee compliance?

No. A schedule is one operational tool. The relevant law, your actual handling of information and the accuracy of your client promises still matter.

Ready to organize client delivery? Create a SendPhoto account and test the gallery controls with sample files before applying your studio’s schedule to client work.

A better way to deliver client photos.

SendPhoto helps photographers turn finished work into private, branded galleries with passwords, watermarks, and download controls.

No credit card. Clients open the gallery without an account.