GDPR and cloud photo storage: what to actually look for
The short answer
- GDPR gives you rights over your photos as personal data: access, portability, erasure, and clear information about who processes them.
- The signals that matter when comparing services: where data is stored, who the sub-processors are, how long deleted data is retained, and whether export and deletion are self-service.
- "GDPR compliant" on a marketing page means nothing on its own — the privacy policy and the deletion flow are where you check.
Photos are personal data under the GDPR, and often special-category data — a photo can reveal health conditions, religious practice, political activity or biometric identity. That means a photo backup service is handling some of the most sensitive data you own. Here is what to actually check, in the order it matters.
1. Who is the controller, and who are the processors?
For your own photos in your own account, you are broadly acting for personal purposes and the service is the controller of the account data it processes. What you want to see named is the legal entity behind the app and the sub-processors it uses — the cloud host, the analytics vendor, the crash reporter, the email provider. A privacy policy that never names a single sub-processor is a policy that has not been written seriously.
2. Where is the data stored, and where does it travel?
Data residency is not the same as compliance, but it simplifies things a lot. If your photos are stored in the EU/EEA, transfers are straightforward. If they move to the US or elsewhere, the provider must rely on an adequacy decision or Standard Contractual Clauses, and should say which. Look for a stated storage region rather than a vague "we use world-class data centres".
3. Lawful basis and what happens beyond storage
Storing photos so you can back them up is contract performance — you asked for the service. Anything past that needs its own basis: face grouping is biometric processing and generally requires explicit consent; using your content to train models requires a clearly disclosed basis and a real opt-out; advertising based on content requires consent too. The question to ask is short: what is done with my photos other than storing them and giving them back to me?
4. Retention and real deletion
Deletion is where policies diverge most. A good service tells you: how long items sit in trash before permanent deletion, how long after that backups are purged, and what happens on account closure. "We delete data when it is no longer needed" is not a retention policy. Backups legitimately take time to rotate — 30 to 90 days is common and reasonable — but the number should be written down.
5. Your rights, and whether exercising them is self-service
- Access — a copy of what is held about you.
- Portability — your photos and videos as original files, in a usable format, not a walled-garden viewer.
- Erasure — deletion of your content and account, with confirmation.
- Rectification — correcting account data that is wrong.
- Objection and restriction — stopping specific processing, such as analytics or optional features.
- The provider must respond within one month, extendable by two for complex requests.
The practical test is whether export and deletion are buttons in the app or a support ticket someone has to approve. Buttons are a strong signal the company built with these rights in mind rather than bolting them on.
6. Children, other people, and photos you did not take
Your library contains other people's faces. For purely personal use, the GDPR's household exemption generally covers you — but it stops applying when you publish or share broadly, and it never covers the provider. If you photograph people professionally, or run a business account, you need your own lawful basis and should be looking for a data processing agreement (DPA) from the service.
7. Breach handling and security posture
Providers must notify their supervisory authority within 72 hours of becoming aware of a qualifying breach, and notify you when there is high risk to your rights. Encryption materially reduces that risk — if the stolen data is unreadable, the impact is smaller. Ask whether encryption keys are provider-held, and check for independent assessment such as ISO 27001 or SOC 2 rather than a padlock icon.
A checklist you can copy
- 1Is the legal entity and a contact address named in the privacy policy?
- 2Are sub-processors listed, with what each one does?
- 3Is the storage region stated, and the transfer mechanism if data leaves the EEA?
- 4Is there a specific retention period for trash, backups and closed accounts?
- 5Can I export originals and delete my account from inside the app?
- 6Is content analysis, face grouping or model training used — and can I turn it off?
- 7Is there a DPA available if I use it for work?
- 8Does the policy read like it was written for me, or for a court?
Memories on Cloud aims to pass that checklist rather than to claim it. Our Privacy policy sets out what we collect and why, and support questions about your data go to support-moc@kl-imagine.com. This article is general information, not legal advice — if you are handling photos as part of a business, take proper advice on your own obligations.
Frequently asked questions
Does GDPR apply to my personal photo library?
The household exemption generally covers purely personal use, so you are not acting as a controller for your own family album. It always applies to the service storing your photos, and it stops covering you if you publish or use the photos professionally.
Do my photos have to be stored in the EU?
No. Transfers outside the EEA are allowed with an adequacy decision or Standard Contractual Clauses, but EU storage removes a layer of complexity and is worth preferring if you have the choice.
How quickly must a service delete my photos when I ask?
It must act without undue delay and respond within one month. Backup copies can legitimately take longer to rotate out, and the provider should state that period in its retention policy.
Keep every moment, safely
Memories on Cloud backs up your photos and videos automatically, and keeps them private by default.
Get it on Google Play