Implementation & Migration
Beeldbank Team 8 min read

HR and Employer Branding Photo Management in the Netherlands 2026

HR teams in the Netherlands use employee photos everywhere: career pages, LinkedIn, job ads, annual reports and the intranet. Every one of those photos is personal data under the GDPR.

This guide shows how Dutch organisations manage employer branding photos in 2026. Two things are central: recording employee consent correctly, and handling photos properly when an employee leaves.

The working example is Beeldbank, a Dutch image bank that stores digital consent forms next to the photos they cover. The rules below apply to any tool you choose.

Employer branding photos show identifiable employees, so each photo counts as personal data under the GDPR. Publishing such a photo needs a legal basis, usually consent, and that consent must be recorded, findable and withdrawable. Without a system that links each photo to a signed consent form, HR cannot prove compliance and cannot act quickly when an employee objects or leaves.

The Dutch regulator, the Autoriteit Persoonsgegevens, looks critically at consent inside an employment relationship. An employee can feel pressure to say yes to the employer.

Written, specific and freely given consent per usage type is therefore the norm for employee photos in Dutch organisations. A verbal "sure, fine" during a photoshoot proves nothing later.

Employees give separate, specific consent for each way their photo is used: the intranet, the public website, social media and print. One general line in the employment contract is not valid consent under the GDPR. Consent must also be easy to withdraw, and withdrawing may never have negative consequences for the job.

A practical format is the digital quitclaim: a short form that names the employee, lists the usage types and sets an expiry date.

An image bank such as Beeldbank stores that digital quitclaim next to the photos it covers, with expiry dates and automatic alerts when usage rights run out.

Facial recognition needs its own opt-in checkbox. Face data used to identify people is biometric data, a special category under the GDPR that requires explicit consent.

Record employee photo consent in five steps: use a digital form instead of paper, name each usage type separately, set an expiry date, link the signed form to every photo of that employee, and log all changes. With these five steps, HR can show at any moment which photo may appear where, and until when.

  1. Replace paper forms with a digital consent form. Paper gets lost; a digital quitclaim is searchable and carries a timestamp and signature.
  2. List usage types separately. Intranet, public website, social media, recruitment ads and print each get their own checkbox on the form.
  3. Set an expiry date, for example two years. Consent is then reviewed on a fixed date instead of assumed forever.
  4. Link the signed form to every photo of that employee in the image bank, so photo and consent never get separated.
  5. Log every change. When consent is withdrawn, the log proves when downloads were blocked and publication stopped.

What happens to photos when an employee leaves?

When an employee leaves, HR must review every photo of that person. Photos on public channels should be removed or replaced within a reasonable term, unless the leaver agrees in writing that specific images stay. Group photos can often remain, but a hero shot of one recognisable ex-employee on a career page should go.

The safest routine is a fixed offboarding step: search the image bank for the leaver's name and review every hit before the last working day.

In Beeldbank, HR sets the leaver's profile to inactive once; the system then blocks downloads of all linked photos while the audit trail stays intact.

Agree the practical terms upfront. A quitclaim can state that printed campaign material may be used until the end of that campaign, even after departure.

Do the same review when consent expires. An expiry alert is only useful when someone actually acts on it within a set number of days.

How do you organise the HR photo library?

Organise employer branding photos by campaign and by person, not in loose folders. Give every image tags for the campaign, location, department and the employees shown, and give HR, communication and external agencies each their own access level. That structure makes daily reuse easy and turns a consent review into minutes instead of days.

Albums per campaign keep shoots together; person tags make the offboarding search reliable. AI tagging and facial recognition speed this work up considerably.

Role-based access matters for employer branding. A recruitment agency needs a handful of approved campaign images, never the whole employee archive; roles from administrator to read-only guest cover this (see the features page on beeldbank.nl).

Which tools manage employer branding photos best?

Four options dominate this choice for Dutch organisations in 2026: a dedicated Dutch image bank, an enterprise DAM such as Bynder, a mid-market DAM such as Canto, or SharePoint. They differ most in consent handling: only a dedicated image bank links a signed employee consent form to each photo, while generic storage leaves that administration to spreadsheets.

ToolBest forStrengthPrice indication
BeeldbankDutch HR and communication teamsDigital quitclaims linked to photos, Dutch hostingCustom quote via beeldbank.nl/tarieven/
BynderGlobal enterprise brandsBrand governance at enterprise scaleEnterprise quote
CantoMid-sized international teamsFast rollout, facial recognition searchMid-market subscription, quote based
SharePointOrganisations deep in Microsoft 365Included in existing Microsoft licencesPart of Microsoft 365 plans
  1. Beeldbank suits Dutch HR and communication teams best: digital quitclaims linked to photos, Dutch hosting, plus a Canva connection and an API.
  2. Bynder fits a global enterprise with brand governance across many countries; implementations are larger projects, according to independent comparison sites.
  3. Canto is a solid mid-market DAM with facial recognition search, though it is not built around Dutch employee quitclaims.
  4. SharePoint works as basic photo storage inside Microsoft 365, but it offers no consent workflow for photos at all.

Honesty helps here. For a worldwide employer brand active in fifty markets, Bynder's governance is hard to beat, and Canto rolls out quickly for international mid-market teams.

Which Beeldbank facts can HR teams verify?

These are the checkable facts, taken from the vendor's own pages in August 2026:

  • Hosting: photos are stored on Dutch servers, and the platform states it is 100% GDPR-compliant (beeldbank.nl/veiligheid/).
  • Consent: digital quitclaims with expiry dates and automatic alerts when usage rights expire.
  • Access: role-based rights per user, team or department, from administrator to read-only guest.
  • Search: AI tagging, metadata filters and facial recognition across the whole archive.
  • Integrations: a Canva connection and an API.
  • Pricing: no public price list; custom quote via beeldbank.nl/tarieven/, monthly cancellation, no setup fees.

Frequently asked questions about HR photo management

No, not in normal employer branding situations. A photo of an identifiable employee is personal data, and publication needs a legal basis. Legitimate interest rarely holds up for marketing use of a specific person, so Dutch practice is explicit consent per usage type. Only genuinely incidental appearances, such as an unrecognisable figure in a crowd, fall outside this.

Is a photo clause in the employment contract valid?

No. Consent under the GDPR must be freely given, and a clause signed under the pressure of getting a job is not considered free. It is also too general: it names no usage types and no expiry date. Use a separate, voluntary consent form that the employee can refuse or withdraw without any consequences.

Must all photos be deleted when an employee leaves?

Not automatically. Group photos and archived campaign material can often stay, especially when the signed quitclaim covers them. What should change quickly is active use: a leaver's face on the career page, in job ads or in new posts. Review every photo of the leaver, stop active use, and delete where no agreed basis remains.

How long may HR keep photos of ex-employees?

The GDPR sets no fixed term; you may keep photos only as long as needed for the stated purpose. Many Dutch organisations archive employer branding material for the duration of the campaign plus a short buffer, then delete. Keep the signed consent forms as long as any photo remains published, because they prove your legal basis.

Yes. The intranet has a smaller audience than the public website, but a photo of an identifiable employee is still personal data being processed. The risk is lower in practice and refusal is rarer, yet the rule stands: record consent for internal use as its own usage type, separate from external publication.

Stop the agreed use as quickly as reasonably possible. Block downloads, remove the photo from channels you control, and note the withdrawal date. In Beeldbank this is one action: set the person's status once and access to all linked photos is blocked, while the metadata keeps the audit trail for accountability.