GDPR compliance for galleries: protecting your collectors' data
The General Data Protection Regulation, which came into force on 25 May 2018 across the European Union, has transformed the obligations of every business that processes personal data. Art galleries are no exception. A dealer manages sensitive information daily: collector names and contact details, purchase history, artistic preferences, estimated financial capacity, delivery addresses for primary and secondary residences. This data, which constitutes the gallery's relational capital, is protected by the GDPR and its processing engages the dealer's legal liability. The Commission nationale de l'informatique et des libertes (CNIL) in France, and its equivalents in each EU member state, enforce these obligations with sanctioning powers reaching four per cent of annual turnover.
By Artedusa
••9 min read01What the GDPR changes for galleries
The GDPR rests on several fundamental principles that the dealer must integrate into daily practice. The first is consent: every collection of personal data must have a legal basis, which for a gallery will most often be the consent of the data subject or the legitimate interest arising from the commercial relationship. A collector who provides an email address to receive gallery invitations implicitly consents to this use, but that consent does not automatically extend to purposes the collector did not anticipate, such as sharing contact details with a commercial partner.
The second principle is purpose limitation: data must only be collected for specified objectives and must not be used for other purposes. A gallery that collects collector addresses to send invitations cannot use that database to prospect on behalf of a third party or sell the list to a service provider. This principle obliges the dealer to think in advance about how collected data will be used.
The third principle is data minimisation: the gallery must collect only data necessary for the stated purpose. Requesting date of birth, family status and income from a collector during a simple newsletter registration constitutes excessive collection that contravenes this principle. The subscription form should be limited to genuinely useful information: name, email address, and possibly artistic preferences if the gallery segments its mailings.
02Collector files: a treasure to protect
The collector database constitutes one of a gallery's most valuable assets. It contains information that, in the wrong hands, could harm the collectors themselves: the address of a collector who owns works of significant value represents sensitive information from a security perspective. Purchase preferences, amounts spent, works owned: this information pertains to private life and deserves rigorous protection.
Securing this database starts with technical measures. Storage in an unprotected Excel spreadsheet on a shared computer constitutes a risky practice that the GDPR implicitly condemns. The file should be password-protected, ideally encrypted, accessible only to authorised gallery personnel. A professional customer relationship management (CRM) system offers a higher level of security than a desktop file, with access logs, automatic backups and granular permission controls.
Database backup must be performed regularly and backup copies must benefit from the same level of protection as the primary file. A gallery that loses its collector database following a computer failure loses years of commercial relationships. A gallery whose database is compromised by a cyberattack faces regulatory sanctions and irreparable loss of trust among its clientele. David Zwirner, which manages data for some of the world's most important collectors, necessarily invests in information security systems commensurate with this responsibility.
03Collector rights over their data
The GDPR grants data subjects a set of rights that the dealer must be able to respect. The right of access allows any collector to ask the gallery what data is held about them. The gallery must be able to provide this information within one month. The right to rectification allows the collector to have inaccurate information corrected. The right to erasure, known as the "right to be forgotten", allows the collector to request deletion of their data when its retention is no longer justified.
The right to data portability allows the collector to retrieve their data in a readable format for transmission to a third party. In practice, this right is rarely exercised in the gallery context, but the dealer must be prepared for it. The right to object allows the collector to refuse certain processing, particularly commercial prospecting. A collector who requests no further communications must be removed from mailing lists without delay.
Managing these rights requires the gallery to have a clear procedure and an identified contact. In a small gallery, the dealer themselves can assume this role. In a larger gallery, designating a data protection officer, even part-time, is recommended. Hauser & Wirth, which manages thousands of international contacts, necessarily has formalised procedures to respond to rights exercise requests. Gagosian, present in multiple jurisdictions, must articulate these procedures with the local legislation of each country in which it operates.
04Daily practices to adapt
GDPR compliance is not reducible to a legal document filed in a drawer. It requires changes in the gallery's daily practices. Newsletter mailings must include a visible and functional unsubscription link. Contact forms on the website must include an information notice about data processing. Guest books at openings, where visitors write their name and email, constitute data collection that must be accompanied by information about how those details will be used.
Data transmission to third parties requires particular attention. When a gallery communicates a collector's details to a shipper for artwork delivery, it performs a data transfer that must be governed by a GDPR-compliant subprocessing contract. When it shares its guest list with a fair or event partner, it must ensure that the third party also complies with data protection rules.
Gagosian, which operates in multiple jurisdictions with different data protection legislation (GDPR in Europe, CCPA in California, PIPL in China), has had to develop a data policy that simultaneously respects these different regulatory frameworks. For a gallery operating solely in France, the situation is simpler, but compliance remains a legal obligation that the CNIL can audit at any time.
Sales teams must be trained in best practices. A team member who notes a collector's contact details on a sticky note attached to their screen or who transfers the collector database to an unencrypted USB drive for home working creates security gaps that the GDPR penalises. Galerie Perrotin, with teams distributed across several continents, must ensure consistent training of all personnel in data protection principles.
05The processing register
The GDPR requires businesses to maintain a register of personal data processing activities. For a gallery, this register lists the different processing operations performed: collector database management, newsletter distribution, sales management, accounting, artwork loan tracking, insurance management. For each process, the register specifies the categories of data processed, the data subjects, the purpose of processing, the retention period and the security measures in place.
This register, which can take the form of a simple document, constitutes the centrepiece of compliance. It forces the gallery to map its data flows and identify risk points. The CNIL provides register templates that galleries can adapt to their activity.
Data retention periods are a point often neglected. The GDPR requires that data not be retained beyond the period necessary for the purpose for which it was collected. An active collector's details may be retained for the duration of the commercial relationship. The contact details of a visitor who signed the guest book five years ago and never followed up should be deleted if no relationship has been established. This obligation to periodically clean the database is constraining but healthy: it ensures the file reflects the reality of active clientele and does not retain obsolete data.
06Data breach notification
In the event of a data breach, whether through hacking, loss of a computer containing data, or accidental dispatch of a file to the wrong recipient, the GDPR requires the data controller to notify the CNIL within 72 hours if the breach is likely to present a risk to the rights and freedoms of the affected individuals. If the risk is high, the affected individuals must also be informed directly.
This notification obligation pushes galleries to establish incident management procedures. Who should be alerted internally? How should the severity of the breach be assessed? Who contacts the CNIL? These questions must have prepared answers before an incident occurs. White Cube, Galerie Thaddaeus Ropac and other galleries that process data for some of the world's most important collectors cannot afford any laxity in this area.
Prevention remains the best strategy. Training staff in good digital practices, including strong passwords, phishing vigilance, computer locking and encryption of removable media, considerably reduces the risk of a breach. A team member who opens a malicious attachment can compromise the entire collector database in seconds.
07Getting expert guidance
GDPR compliance can seem daunting for a dealer whose core business is art, not digital law. Specialist data law firms offer guidance packages adapted to SMEs that structure the process: initial audit, drafting of mandatory documents, team training and procedure implementation. The cost of this guidance, typically a few thousand euros, is negligible compared to the penalties for non-compliance and the reputational damage a data breach can cause.
Professional trade bodies in the art world, such as the Comite professionnel des galeries d'art (CPGA) in France, offer resources and training on GDPR compliance adapted to the specific gallery context. These sector-specific resources are more relevant than generalist guides because they address issues particular to the art market: collector databases, information sharing with fairs, relationships with shippers and insurers.
For galleries on Artedusa, GDPR compliance is all the more important given that the online platform multiplies data collection points. Artedusa ensures the protection of data collected on the platform, but the dealer remains responsible for data collected and processed in the course of their own activity. This complementarity between the platform and the gallery guarantees collectors coherent end-to-end protection.
Every artwork finds its collector
Showcase your artists, discover new talent and reach perfect collectors. Strengthen your cultural influence through Artedusa.
Apply