GDPR and image moderation: 7 questions your lawyer will ask you
This post is informational and does not constitute legal advice.
Image moderation almost always means processing personal data — photos contain people, and sometimes much more. If you send users' uploads to an external API, sooner or later you will hear these questions from a lawyer. Better to know the answers in advance.
1. Who is the controller and who is the processor?
You (the platform operator) are the controller of your users' data. The moderation provider acts on your behalf — it is a processor. That requires a data processing agreement (DPA). Don't have a DPA with your provider? That's the first thing to fix.
2. Where do the photos go?
If the API operates outside the EU (most often: the USA), a transfer of data to a third country arises — with all the paperwork: standard contractual clauses, a transfer impact assessment, questions from the authority. A provider processing in the EU removes this topic entirely.
3. How long does the provider store images?
"We don't store them" can be elastic: some providers keep samples "for quality purposes" or use your data for training. Ask for specifics: is the image stored on disk even for a second? At modwall the answer is: no — processing exclusively in memory, only metadata is logged (time, result, size).
4. What is the legal basis for processing?
Usually legitimate interest: protecting users and the platform from prohibited content, meeting DSA obligations. It is important to enter moderation into the record of processing activities and the privacy policy — the user has the right to know that uploads are scanned.
5. Are the decisions automated?
Article 22 of the GDPR concerns decisions producing significant effects, taken solely automatically. Good practice: routing the borderline band to a human (a human-in-the-loop queue) and the possibility of appealing a decision — exactly how the review mode in modwall works.
6. How will you show what happened to a specific photo?
Accountability is a foundation of the GDPR (and the DSA). You need a trace: when the image was assessed, what the result was, what decision was taken and by whom. An immutable audit log does that for you.
7. What about minors' data?
If your platform has young users, the bar goes up: stricter thresholds, faster removal, zero retention of images. Consider the self-host variant too — the data does not leave your infrastructure at all.
Summary
Each of these questions has a good answer — provided that the moderation provider was designed with the GDPR in mind, rather than adapted to it after the fact. Take a look at the Security and compliance page — we have gathered a complete set of information for your lawyer there. And if you'd rather talk: write to us.
Plug in moderation before a problem lands on your platform
1,000 free requests per month, no card. Monitor mode shows results on your real traffic — without blocking anything.
Create a free account Pricing