How Pickit Supports GDPR Compliance
At Pickit, privacy and trust are foundational to how we build and operate our platform. We help teams organize and find the right images fast – while ensuring personal data is handled responsibly, securely, and transparently.
What is GDPR?
The General Data Protection Regulation (GDPR) is the EU’s leading privacy law. It sets strict standards for how organizations collect, use, store, and protect personal data — giving individuals more control over their information.
Why it matters
For brands, agencies, and content teams, GDPR compliance isn’t just a legal requirement — it’s a trust requirement. When your work involves photos and people, it’s essential to ensure data is handled with care, transparency, and security.
How Pickit supports GDPR compliance
Privacy-first licensing & permissions
Pickit makes it easy to manage usage rights and permissions across your entire image library, including:
-
Licensing details
-
Model releases to document permission and consent
-
Clear visibility into how assets can be used
-
License expiration tracking: Pickit includes an expiration date feature within licensing, helping teams stay compliant by clearly tracking when usage rights expire and reducing the risk of unapproved use over time.
This helps teams stay compliant and avoid risk – especially when publishing at scale.
Fast search with Facial Recognition AI (used responsibly)
Pickit uses Facial Recognition AI to help users quickly find images of specific people—saving time and reducing manual searching.
Because this involves identifiable individuals, Pickit treats this capability with extra care, including:
-
Controlled access and secure handling of sensitive data
-
Responsible use aligned with privacy expectations and permissions
Secure cloud infrastructure on Microsoft Azure
Pickit is built on a secure enterprise data platform, and because we are part-owned by Microsoft, Pickit data is stored on Microsoft Azure cloud infrastructure.
This supports strong data protection through:
-
Industry-leading security standards
-
Encryption and access controls
-
Reliable monitoring and cloud resilience
-
EU-based hosting options: Pickit supports servers located in the EU, helping organizations meet GDPR expectations around data residency and regional requirements.
-
Enterprise access control (SAML + coming soon SCIM): Pickit supports SAML Single Sign-On (SSO) for secure, fast access and streamlined user management. SCIM provisioning is coming soon to automate onboarding/offboarding and user lifecycle management.
Designed to protect people and organizations
Pickit is built to help teams stay organized and protected — supporting privacy and security best practices such as:
-
Minimizing unnecessary data exposure
-
Ensuring only authorized users can access assets
-
Keeping governance clear across teams and workflows"