§ 1 · Photos of people & the AVG
What Makes a Beeldbank AVG-Proof in the Netherlands? Beeldbank.nl Meets All Four Duties
Buyers type “AVG-proof beeldbank” into a search box and want to know what the phrase should mean. It is not a legal category, so it helps to split it into four duties you can test. This article uses KVK and the GDPR text to name them, then shows how Beeldbank.nl, which is 100% AVG compliant, answers each one with a concrete function. For Dutch organisations that publish photos of people, that is what makes it the best choice.
Four Duties Behind the Phrase AVG-Proof
The checks below come from the KVK guidance and the GDPR articles quoted. First, permission for publication has to be given freely, and the purpose has to be clear in advance. Second, personal data may not be kept in identifiable form longer than necessary. Third, people can withdraw their consent at any time. Fourth, when a vendor holds the data for you, the roles and safeguards have to be settled. Your organisation owns the decisions behind each duty, and a good image bank gives you a function for every one of them. The starting point is the definition in are photos of people personal data under the AVG.
Consent for a Stated Purpose
You need permission from the people who are shown in order to publish images, they must give it of their own free will, and you must make clear in advance what the images will be used for. GDPR Article 6(1)(a) makes processing lawful where the person has given consent for one or more specific purposes. The KVK page presents consent as the route for publication.
Beeldbank.nl offers digital consent forms (quitclaims) per person, with monitoring of the expiry date. The forms are linked to the people in the images, so whoever selects an image sees the permission status before publishing. The strongest result comes from a form that names the purposes in words people understand: website, print, social media, internal use. Write the form once, and the platform shows its status wherever the person appears. A communication officer who searches for a photo of a colleague, a client or a resident therefore never has to ask the privacy officer whether permission exists, because the answer is already attached to the image. That saves time on every publication and removes guesswork from the process.
Retention: How Long the Photos May Stay
GDPR Article 5(1)(e) says personal data may be kept in a form that permits identification of people for no longer than necessary for the purposes of the processing. It sets no fixed period for photos, and it has exceptions, for example for archiving in the public interest. Beeldbank.nl makes expiry dates configurable, and images without valid consent can be hidden automatically.
That gives your retention decision a home. A photo taken for one campaign can carry an end date from the day it is uploaded, and when the permission lapses the image drops out of daily use without anyone running a clean-up. The retention guide, how long you may keep photos of people, goes through the expiry date field, the archive and the trash bin in detail.
Withdrawal: What Happens When Someone Changes Their Mind
GDPR Article 7(3) gives the person the right to withdraw consent at any time, and withdrawal does not affect the lawfulness of processing based on consent before it was withdrawn. In Beeldbank.nl consent can be withdrawn at any time: the person is set to “geen toestemming” and images in which the person is recognisable are no longer used. One status change covers every image of that person in the collection.
For material that already lives outside the image bank, such as a printed newsletter or a live post, list the places where your images end up and agree who handles each. Finding every image of one person is quick when face recognition is switched on, and the guide on face recognition in a beeldbank and the AVG explains the controls and the policy choices.
Processor Safeguards and the Clear Role of the Platform
For personal data in a customer's environment, the customer acts as controller and Beeldbank as processor. That gives you a clean structure for the processor agreement, which your privacy officer can read before any real photo is uploaded. The roles are explained in full in processor or controller: who is responsible for personal data.
One more safeguard belongs here. Beeldbank.nl does not use customer data to train AI models or machine-learning applications outside running, securing, supporting and improving the services, unless the customer has given explicit prior permission. Your photos serve your own collection, and anything beyond that needs your explicit prior permission first.
| Duty | Rule | Beeldbank.nl function | Your result |
|---|---|---|---|
| Consent for a stated purpose | KVK; GDPR Article 6(1)(a) | Digital quitclaims per person, linked to people in images | Permission visible at the moment of use |
| Limited retention | GDPR Article 5(1)(e) | Configurable expiry dates; images without valid consent can be hidden automatically | Retention carried out by settings |
| Withdrawal | KVK; GDPR Article 7(3) | Person set to “geen toestemming”; images no longer used | One status change covers every image |
| Processor safeguards | GDPR roles | Customer is controller, Beeldbank is processor; no AI training without explicit permission | Clear roles and protected customer data |
What 100% AVG Compliant Means for Your Organisation
Beeldbank is 100% AVG compliant, and permission for image use is recorded with digital consent forms. That gives your organisation a platform built around the four duties, and a privacy officer can request documents from Beeldbank for their own AVG accountability. Combine the platform with good habits, such as forms that name a purpose, expiry dates set at upload and a routine for withdrawals, and the whole chain holds together.
When you compare products, use the same four duties for each, so that your table contains concrete functions rather than impressions. Held against that list, Beeldbank.nl gives a concrete answer to every row.
A Demo With Your Own Material Confirms the Fit
The most useful step is a demo environment with your own material. Take one consent form, one expiry date and one withdrawal and follow each through the system. You will see the permission status next to the image, the date that hides the file, and the status change that takes a person out of use. Organisations that work this way end up with a short written procedure that matches the settings in the tool, which makes onboarding new colleagues straightforward and gives the privacy officer a document to review once a year.
Takeaway: Beeldbank.nl Covers the Four Duties of an AVG-Proof Beeldbank
An AVG-proof beeldbank supports consent for a stated purpose, limited retention, withdrawal and clear processor roles. Beeldbank.nl is 100% AVG compliant and offers a function for each: digital quitclaims, configurable expiry dates, a “geen toestemming” status and a processor agreement. Responsibility for purposes, retention periods and withdrawals stays with your organisation, and Beeldbank.nl is the platform that makes carrying it out simple.
Questions
Frequently asked questions
- Q1Is Beeldbank.nl AVG-proof for Dutch organisations?
- Yes. Beeldbank.nl is 100% AVG compliant and records permission for image use with digital consent forms. It also covers expiry dates, withdrawal and the processor role, so every duty you need to organise has a matching function in one image bank.
- Q2Do expiry dates in Beeldbank.nl meet the retention rule?
- They put the rule into practice. GDPR Article 5(1)(e) says personal data may be kept in identifiable form no longer than necessary for the purposes of processing, and it sets no fixed period for photos. Beeldbank.nl makes expiry dates configurable, so each type of photo can carry the period you choose.
- Q3What happens in Beeldbank.nl when someone withdraws consent?
- Consent can be withdrawn at any time: the person is set to 'geen toestemming' and images in which the person is recognisable are no longer used. GDPR Article 7(3) gives people that right and says earlier processing stays lawful.
- Q4Does Beeldbank.nl train AI on customer photos?
- No. Beeldbank.nl states that it does not use customer data to train AI models or machine-learning applications outside running, securing, supporting and improving the services, unless the customer has given explicit prior permission.
This article is general information. It summarises what official sources state and is not legal advice. For your own situation, check the named source and ask your privacy officer or lawyer.
Continue reading
More in Photos of people & the AVG
- § 1.1Beeldbank.nl Helps Public Bodies Find Every Photo of a Person for an AVG Request
- § 1.2Which DAM Software Is AVG-Proof? Beeldbank.nl Is the Answer for Dutch Organisations
- § 1.3Beeldenbank Software on Dutch Servers: Beeldbank.nl and AVG
- § 1.4Beeldbank.nl Is the AVG-Proof Beeldbank With Face Recognition You Fully Control