Taking Photos at Events Under PDPA: Singapore Business Rules
Taking photos at events under PDPA? Learn Singapore's rules on consent, notification, and signage so your business stays PDPC-compliant at every event.

Taking Photos at Events Under PDPA: Singapore Business Rules
Taking photos at events under PDPA is one of the most common grey areas Singapore businesses face — every product launch, conference, dinner and dance, or community roadshow generates hundreds of images containing identifiable faces, which are personal data under Singapore's Personal Data Protection Act 2012. Get the consent and notification steps right, and your event photography becomes a powerful marketing asset. Get them wrong, and your organisation risks complaints to the Personal Data Protection Commission (PDPC), reputational damage, and financial penalties that can reach up to S$1 million or 10% of annual turnover for serious breaches.
This guide breaks down exactly what the PDPA requires when your business captures, stores, and publishes event photographs — in plain, actionable terms.
🔑 Key Takeaways (TL;DR)
- Photos of identifiable individuals are personal data under the PDPA 2012 — the same consent, notification, and protection rules apply.
- Consent can be deemed when attendees enter a clearly signposted photography zone, but marketing and publicity uses often need explicit consent.
- Notification is mandatory: tell attendees the purpose before or at the point of capture (Section 20).
- Withdrawal must be honoured — if someone asks you to remove their image, you must comply (Section 16).
- Children's images and sensitive contexts require extra care and usually explicit parental consent.
- Penalties for serious breaches can reach S$1 million or 10% of annual turnover, whichever is higher.
Are Event Photos Considered Personal Data Under the PDPA?
Yes. A photograph that identifies an individual — through their face, name tag, or other distinguishing features — is personal data under the PDPA 2012. This means every obligation that applies to customer databases also applies to the images sitting on your event photographer's memory card. There is no "photos are different" exemption in Singapore law.
The PDPA defines personal data as data about an individual who can be identified from that data, or from that data combined with other information the organisation has access to. A clear photo of an attendee's face easily meets this threshold. The Consent Obligation, Notification Obligation, Purpose Limitation Obligation, and Protection Obligation all apply the moment you press the shutter.
Definitive statement: If a reasonable person could look at your event photo and recognise who is in it, your business is processing personal data and must comply with the PDPA — regardless of whether the event was public or private.
There is one important carve-out: the PDPA does not apply to personal data processed by an individual for purely personal or domestic purposes. A guest snapping a selfie is exempt. But the moment your organisation captures images for business, marketing, or record-keeping purposes, the full weight of the Act applies.
What Consent Do You Need Before Taking Photos at Events Under PDPA?
Under the PDPA, your business generally needs consent before collecting, using, or disclosing an attendee's photograph — but consent can be express or "deemed" depending on how the event is set up. The right approach depends on how you intend to use the images.
The PDPC's Advisory Guidelines recognise three practical consent pathways:
1. Deemed consent (Section 15)
When an individual voluntarily provides their personal data for a purpose, or voluntarily participates in an activity where it is reasonable they would provide it, consent is deemed. If an attendee walks into a conference hall displaying clear signage stating "Photography and filming in progress for [purpose]," and continues to participate, consent to that stated purpose is generally deemed. Deemed consent works well for general event documentation and crowd shots.
2. Express consent
For uses a reasonable person would not automatically expect — such as featuring an attendee's face in a paid advertisement, a brochure cover, or an ongoing social media campaign — you should obtain express, opt-in consent. The cleanest method is a tick-box or photo-consent clause on your event registration form.
3. Deemed consent by notification (Section 15A)
Introduced in the 2020 amendments, this allows your organisation to notify individuals of a new purpose and treat silence as consent after a reasonable opt-out period — useful when purposes evolve, but it requires a documented risk assessment.
Key rule: Consent obtained by providing false or misleading information, or as an unreasonable condition of service, is not valid consent under the PDPA.
Building consent capture into your registration workflow is exactly the kind of recurring obligation that eats up SME time. This is where ComplyHQ delivers AI-powered compliance that handles your PDPA obligations in minutes, not weeks — generating consent clauses, notification templates, and record logs tailored to your event, so you are covered before the first guest arrives.
The Notification Obligation: Telling Attendees Before You Shoot
Section 20 of the PDPA requires your organisation to notify individuals of the purpose for collecting, using, or disclosing their personal data on or before collection. For event photography, this means attendees must know before or at the point of capture why you are photographing them and how the images will be used.
Effective notification in practice includes a combination of:
- Visible signage at all entrances and key areas: "This event is being photographed and filmed by [Organisation] for marketing and publicity purposes. By entering, you consent to the use of your image."
- A photography clause in event registration confirmations and tickets.
- Verbal announcements by the emcee at the start of the event.
- A named contact (your Data Protection Officer) for questions or objections.
Definitive statement: Signage alone is a reasonable notification method for general photography, but it is not a substitute for express consent when images are used for high-visibility marketing. Layer your notifications — the more identifiable and commercial the use, the stronger the consent you need.
Appointing and publicising a Data Protection Officer (DPO) is itself a mandatory PDPA requirement. Your DPO's business contact should be the point of contact for any photo-related objections raised at or after your event.
Handling Withdrawal, Objections, and Removal Requests
Under Section 16 of the PDPA, individuals have the right to withdraw consent at any time, and your business must honour reasonable requests to stop using their photograph. You cannot prohibit withdrawal, though you may inform the individual of the likely consequences.
When an attendee asks you to remove their image:
- Acknowledge the request promptly and route it to your DPO.
- Remove the photo from your website, social media, newsletters, and active marketing materials within a reasonable timeframe.
- Cease further use — you are not always required to recall already-printed collateral, but you must stop new uses.
- Document the request and your action as part of your compliance records.
You cannot charge a fee for withdrawing consent. Failure to act on a legitimate withdrawal request is a frequent trigger for PDPC complaints. For a broader walkthrough of handling incidents and complaints, see our step-by-step data breach response guide for Singapore businesses.
Special Situations: Children, Sensitive Events, and Third Parties
Photographing minors, medical or religious gatherings, or non-attendees caught in the background requires heightened care under the PDPA. The reasonableness test the PDPC applies becomes stricter as the sensitivity of the context rises.
- Children: For attendees under 13, the PDPC expects consent from a parent or legal guardian. Family-day events and school-linked activities should collect explicit parental photo consent at registration.
- Sensitive venues: Photography at health screenings, counselling sessions, or religious ceremonies demands explicit, informed consent — deemed consent via signage is rarely sufficient.
- Bystanders and vendors: People who did not register but appear in your shots (passers-by, external vendors, members of the public at a roadshow) are still protected. Blur or avoid identifiable non-consenting individuals in published images.
- Live streaming: Streaming an event is a disclosure of personal data and requires its own clear notification.
If your events involve staff being filmed as part of their duties, the rules interact with workplace privacy — our guide on employee monitoring and the PDPA explains where employer rights end and employee protections begin.
Storing and Protecting Event Photographs
The PDPA's Protection Obligation (Section 24) requires your business to make reasonable security arrangements to protect event photos from unauthorised access, loss, or misuse. Unsecured image libraries are a real breach risk — a shared drive link that leaks thousands of attendee faces is a reportable incident.
Practical safeguards include:
- Store master image files in access-controlled cloud storage, not open shared links.
- Apply the Retention Limitation Obligation (Section 25) — delete photos once the stated purpose is fulfilled. Do not keep event images indefinitely "just in case."
- Vet your external photographer or agency as a data intermediary, with a written contract specifying PDPA obligations.
- Maintain a photo-use log recording consent, purpose, and any withdrawal requests.
Under Singapore's mandatory data breach notification regime, if event photos are exposed in a breach that causes significant harm or affects 500 or more individuals, you must notify the PDPC within 3 calendar days of assessing it as notifiable.
Reviewing your end-to-end handling against the PDPA compliance checklist for Singapore SMEs is a quick way to spot gaps in your retention and storage practices.
What Are the Penalties for Getting Event Photography Wrong?
For breaches on or after 1 October 2022, the PDPC can impose financial penalties of up to S$1 million, or 10% of an organisation's annual turnover in Singapore (whichever is higher) for organisations with turnover exceeding S$10 million. The penalty framework was strengthened precisely to deter careless handling of personal data.
The PDPC has issued numerous enforcement decisions involving images and insufficient consent or protection. Beyond fines, consequences include mandatory remediation directions, public naming in enforcement decisions, and loss of customer trust. To understand how the Commission weighs intent, harm, and remediation, review these real PDPA penalty and enforcement cases.
The most reliable protection is a trained team. Everyone from your receptionist to your marketing lead should understand consent basics — our guide to PDPA staff training requirements covers how to build that culture affordably.
Your Event Photography PDPA Compliance Checklist
Before your next event, confirm your organisation has:
- Signage at all entrances notifying of photography and its purpose.
- A photo-consent clause (express tick-box for marketing uses) on registration.
- A verbal announcement by the emcee.
- A named, contactable Data Protection Officer.
- Parental consent arrangements for any attendees under 13.
- A data intermediary contract with your photographer.
- Access-controlled storage and a defined retention period.
- A documented process for withdrawal and removal requests.
Managing all of this manually across multiple events quickly becomes a burden for lean SME teams. Platforms like ComplyHQ automate the heavy lifting — and if your business needs bespoke event-tech or integration work, Adaptels builds custom digital solutions for Singapore SMEs that bake compliance in from the start.
Conclusion
Taking photos at events under PDPA is entirely manageable once you treat images as what they legally are: personal data. Notify attendees clearly, match your consent method to how commercial the use is, protect your stored files, and honour removal requests promptly. Do these consistently, and your business turns event photography from a compliance risk into a confident, PDPC-aligned marketing engine.
Industries handling richer customer data — such as F&B and restaurants or e-commerce businesses — should pair this guidance with their sector-specific obligations for full coverage.
Sources & References
- Personal Data Protection Act 2012 — Singapore Statutes Online
- PDPC — Advisory Guidelines on Key Concepts in the PDPA
- PDPC — Consent, Notification and Deemed Consent
- PDPC — Guide on Managing and Notifying Data Breaches
- PDPC — Enforcement Decisions
This article is for general guidance and does not constitute legal advice. For advice specific to your organisation, consult a qualified professional or the PDPC.
Simplify Your Compliance
ComplyHQ's AI can assess your PDPA compliance gaps in under 15 minutes and generate the policies you need.
Try Free AssessmentFrequently Asked Questions
Do I need written consent to photograph attendees at my company event?
Can I post event photos of attendees on social media without asking?
What happens if an attendee asks me to remove their photo?
Ready to get PDPA compliant?
Stop guessing about compliance. ComplyHQ uses AI to assess your gaps, generate policies, and guide you through every PDPA obligation.