Most product photography is not personal data, so most retouching is not a restricted transfer at all. The moment a person is identifiable in the frame it is — and then three documents decide whether the work can legally happen. Bangladesh has no EU adequacy decision, so ours is the Standard Contractual Clauses.
Usually not, and this is the step most vendor pages skip. Article 4(1) of the GDPR defines personal data as information relating to an identified or identifiable natural person. A shoe on a white background is not a person. Neither is a bottle, a watch or a sofa.
Two things change that answer, and both are easy to miss:
Metadata. A photographer’s name, a device identifier, a location tag. These travel inside the file and can be personal data even when the picture is not. They are also the first thing most production teams forget to look at.
Incidental identifiability. A hand holding the product. A reflection in a bottle. A tattoo, a name tag, a face in the background of a lifestyle frame. The regulator’s test is whether someone can be recognised, and it turns on image quality and context rather than intent.
One honest note. We could find no published guidance from the EDPB or the ICO addressing product-only photography directly. The position above is the statutory definition applied to the facts, not a regulator’s ruling. A data protection officer may reasonably take a stricter line, and that is a sensible place to be strict.
The ICO’s own formulation is that if someone can be recognised from a photograph, it is usually their personal data. An on-model fashion image is personal data of that model. So is a hand model’s hand, if the hand is identifiable in context.
From that point the retouching is processing of personal data, it happens outside the EEA, and the paperwork below is not optional.
On the EDPB’s controller-and-processor framework, a studio that retouches to the client’s brief, on the client’s instructions, without deciding anything for itself, is a processor. Article 28 applies and the client remains the controller.
That stops being true the moment the studio decides something on its own account: keeping files for a portfolio, reusing them in marketing, or feeding them to a model. That is the studio determining its own purpose, and Article 28(10) then treats it as a controller for that processing, with its own liability attached.
This is the practical reason we do not publish client work and do not train on client files. It is a confidentiality promise, but it is also what keeps us on the right side of that line — and what keeps the liability where the contract says it sits.
| Document | What it does | Where it comes from |
|---|---|---|
| Processor contract (DPA) | Binds the studio to process only on your documented instructions, to confidentiality, to security measures, to sub-processor controls, to assistance with data subject rights, and to deletion at the end | GDPR Article 28(3) |
| Transfer mechanism | Makes the transfer lawful where the destination has no adequacy decision | Article 46 — Standard Contractual Clauses, Module Two for controller to processor |
| Written transfer assessment | Records why the clauses actually work in the destination country, including local access powers | EDPB Recommendations 01/2020; in the UK, the statutory data protection test |
The clauses in force are those in Commission Implementing Decision (EU) 2021/914. They have not been replaced. If a vendor offers you the 2010 clauses, they stopped being valid in September 2021.
The European Commission has recognised a short list of countries and territories as offering adequate protection: Andorra, Argentina, Brazil, Canada for commercial organisations, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States for organisations in the Data Privacy Framework, Uruguay, and the European Patent Organisation.
Bangladesh is not among them. Our production sits in Dhaka, we state that openly on every page, and it means a transfer to us is a restricted transfer that needs Article 46 safeguards.
Bangladesh enacted its own Personal Data Protection Act in 2026. That is a domestic statute; it does not create an EU adequacy decision and we do not present it as one. The mechanism for your files remains the Standard Contractual Clauses plus your assessment.
We would rather you read that here than discover it in a due diligence questionnaire.
A UK controller needs either the ICO’s International Data Transfer Agreement, or the UK Addendum bolted onto the EU clauses. Both remain current. The ICO has said it intends to reissue them during 2026, so a contract that elects the automatic update mechanism will age better than one that does not.
Alongside it sits the transfer risk assessment. Under the Data (Use and Access) Act the statutory question is whether the standard of protection after transfer is not materially lower than in the UK. That is not quite the EU’s essential equivalence test, and the two should not be treated as interchangeable.
When volume exceeds our own floor, work can go to contracted partner studios. Article 28 does not forbid that. It requires three things: your prior authorisation, the same obligations flowed down in writing, and the original processor remaining fully liable for the sub-processor’s failures.
So our partner studios are named rather than hidden, they work under equivalent written terms, and every image still passes our own QC before it is delivered. If you would rather your account never leaves our own floor, say so at onboarding and it will not.
Article 28(3)(g) requires a processor to delete or return everything at the end of the service. Ours is thirty days of working retention, a further thirty days of backup, then permanent deletion. Deletion on request inside five business days, and written confirmation whenever you ask for it. There is no indefinite storage.
These are the questions we would ask if we were buying. Ask them of us too.
1. Will you sign our DPA, or only your own paper?
2. Which SCC module have you executed, and can you send the signed version?
3. For UK work, do you use the IDTA or the Addendum?
4. Who are your sub-processors, by name and country?
5. Will you help complete our transfer assessment, including questions about government access powers where you operate?
6. What is your deletion window, and will you confirm deletion in writing?
7. Are our files ever used to train a model?
8. Does any generative tool run inside the edit itself?
A studio that cannot answer question 4 in one sentence is a studio that has not thought about question 3.
1. Yours. 2. Module Two, controller to processor, and yes. 3. Either; tell us which your counsel prefers. 4. Named at onboarding, in writing, or none at all if you prefer. 5. Yes, in writing. 6. Thirty days plus thirty, confirmation on request. 7. Never. 8. Never — every image is retouched by hand.
A German-language version of this guide, written for buyers searching in German, is at Bildbearbeitung outsourcen. The security and confidentiality page covers how files move and who can open them. The AI labelling post covers the separate question of whether a retouched product image needs a disclosure under the EU AI Act.
Usually not. Article 4(1) defines personal data as information relating to an identified or identifiable natural person, and a shoe on a white background is not a person. Two things change that: metadata carried in the file, such as a photographer name or device identifier, and incidental identifiability, such as a hand, a reflection or a name tag.
If any image contains an identifiable person, yes. Article 28(3) requires a written contract before a processor touches the data. We sign the client’s DPA rather than insisting on our own.
No. Bangladesh is not on the European Commission’s adequacy list, so transfers rely on the Standard Contractual Clauses under Article 46, using Module Two for a controller sending to a processor.
The EU Standard Contractual Clauses alone are not valid for a UK restricted transfer. The mechanism is either the ICO’s International Data Transfer Agreement or the UK Addendum to the EU clauses, together with a transfer risk assessment.
Only on overflow, only under written terms flowing down the same obligations, and they are named as sub-processors rather than hidden. Every image still passes our own QC before it is delivered.
Sources: the European Commission’s adequacy decisions page, Commission Implementing Decision (EU) 2021/914, GDPR Articles 4, 28 and 46, EDPB Recommendations 01/2020, and the ICO’s guidance on the IDTA, the Addendum and transfer risk assessments. Retouch Atelier is a retouching studio, not a law firm. Anything here that carries consequence should be checked with your own counsel.
Test our quality risk-free — NDA first if you prefer. No commitment, no card.