A negotiator photographs a family home in Antwerp on a Tuesday afternoon. Wedding photographs on the sideboard, a school timetable on the fridge, unopened post on the kitchen table, the neighbour's car on the drive outside the window. That evening they drop three of those photos into a chatbot to clear the clutter and brighten the rooms.

Nothing has been published yet. No label is due yet. But a transfer of other people's personal data to a third-party supplier has already happened, and the agency — not the seller, not the AI vendor — is the one that has to justify it.

We wrote previously about what the EU AI Act requires of the image you publish. This is the other half of the same workflow: what leaves your office before anything is published at all. It is a quieter problem, it is older than the AI Act, and it is easier to get wrong.

Before we start

This article is general information, not legal advice, and it is written from the perspective of a Belgian B2B software operator rather than a law firm. Verify your own position with counsel or your DPO before changing how your agency handles listing media.

What is actually in the photo

Under Article 4(1) GDPR, personal data is any information relating to an identified or identifiable natural person. That last word does the work. A photograph does not have to show a face to identify someone, and an interior photograph very rarely stays anonymous once you look at it properly.

This is not a theoretical inventory. Every item below turns up routinely in ordinary listing sets.

Personal data commonly visible in listing photographs
What is visible Whose data Why it matters
Family photographs, children's drawings The seller and their household Images of identifiable people, sometimes minors.
Post, invoices, documents on a surface The seller Name and address, occasionally financial detail.
Medication, mobility aids, religious objects The seller Special category data under Article 9 — health or belief.
Licence plates through a window Neighbours and passers-by An indirect identifier that traces back to a person.
A name plate, letterbox or doorbell panel The seller and co-residents Names tied to a precise address.
Neighbouring windows, gardens, front doors Neighbours People who never agreed to anything at all.

The third row deserves particular attention. An inhaler on a bedside table or a stairlift in a hallway is data about someone's health, which Article 9 treats as a special category with a higher bar for processing. Most agents would never deliberately collect it. They collect it by photographing a bedroom.

The upload is the processing

Agencies tend to think of the compliance moment as publication. Under GDPR it is earlier than that. "Processing" in Article 4(2) includes collection, storage, alteration and disclosure by transmission. Sending a file to a third party's servers is squarely inside the definition.

So by the time an image reaches the model, the agency has already done three regulated things: collected personal data when it took the photograph, stored it, and transmitted it to a supplier. Each one needs a lawful basis under Article 6, and the transmission needs the supplier relationship to be properly papered.

The agency is the controller here — it decides why and how the data is processed. Any AI tool it uses is a processor. That distinction is not cosmetic: controllers carry the accountability obligations, and they are the ones a supervisory authority writes to.

Why the consumer chatbot is the problem

Article 28 GDPR is unambiguous. A controller may only use a processor that offers sufficient guarantees, and the relationship must be governed by a contract — the data processing agreement. No DPA, no lawful route to send personal data.

This is the specific reason a personal ChatGPT account is a different proposition from a business tool, and it is worth being precise, because the distinction gets blurred in both directions:

  • Consumer tiers — the free or personal subscription an agent signs up for on their own card — are not offered with a data processing agreement. There is no controller-to-processor contract to rely on.
  • Business and API tiers are contracted differently, are available with a DPA, and do not train on customer content by default. Used deliberately, with the paperwork done, they are a legitimate route.

The realistic failure mode in an agency is not a considered procurement decision. It is one negotiator, on a Friday afternoon, using the account they already have. That is shadow IT with a client's personal data in it, and the agency usually has no record that it happened.

Two things that make it worse

Retention. Uploaded images are stored, and on consumer tiers may be used to improve the service unless the setting is changed. You cannot honour a seller's erasure request over data you no longer control.

Records. Article 30 requires controllers to maintain a record of processing activities. An upload nobody logged is a processing activity you cannot document, which is its own breach independent of the upload itself.

The Belgian layer nobody mentioned

In July 2026 the Belgian Professional Institute of Estate Agents (BIV/IPI) had a new deontological code approved, containing AI provisions for the first time. The coverage concentrated almost entirely on transparency and labelling. Two of its requirements got far less attention and are directly relevant here.

The code requires that personal data does not end up in open AI systems, and that agents are sufficiently trained to use AI tools at all. It also keeps the agent personally responsible for what is published, even when AI produced it.

Read those together and the obligation is not simply "don't paste client data into a chatbot". It is closer to: know which tools your office uses, know how they handle data, and be able to demonstrate that the people using them were trained to. For a profession where the sanction ladder ends at removal from the register, that is a materially different kind of risk from a marketing fine.

Status check

The code was approved at the Council of Ministers in July 2026. It enters into force ten days after publication in the Belgian Official Gazette. Confirm the published text and the commencement date before relying on any specific wording, including ours.

Who actually complains

Enforcement in this area does not usually begin with a regulator sweeping the market. It begins with a person who recognised themselves.

  1. The neighbour who finds their car, their front door or their garden on a property portal and objects. This is the most common trigger by a distance, and it costs them one form to raise.
  2. The seller who did not expect photographs of their family to leave the agency, and who has an Article 15 right to ask exactly where their data went.
  3. A competitor in a market where AI use is now a live public topic and a differentiator.

The ceiling in Article 83(5) is 20 million euro or 4% of worldwide annual turnover, whichever is higher, but that number is not the useful one for a ten-person agency. The instructive case is smaller and more concrete: a Greek property company was reported to have been fined €20,000 in a matter that included failing to redact a vehicle licence plate from a published house photograph. A single unblurred plate was enough to be part of a penalty.

And a complaint is expensive well before any fine. It means correspondence with the supervisory authority, an audit of what your office actually uploaded and where, and — if the answer is "an account nobody has access to any more" — a problem you cannot close out.

A workflow that holds up

None of this argues against using AI on listing photography. It argues for doing it through a route you can describe to a regulator in one page.

  1. Minimise before you upload, not after. Blur or crop faces, licence plates, documents, name plates and neighbouring windows as a standard step in the shoot-to-listing process. Article 5(1)(c) asks for data adequate, relevant and limited to what is necessary — and none of that material was ever necessary to sell the property.
  2. Use one approved tool, with a DPA in place. One contracted supplier beats five personal accounts. Get the data processing agreement, read where processing happens, and check whether customer content trains the model.
  3. Keep processing in the EEA where you can. It removes a whole category of transfer questions under Chapter V rather than answering them.
  4. Write it into the seller mandate. Tell sellers plainly that listing images may be processed by an AI supplier for marketing visuals, and name the category of recipient. Transparency under Articles 13 and 14 is cheap at the start of a mandate and awkward to retrofit after a complaint.
  5. Log every generation. Which image, which operation, which supplier, when, by whom. That log is what turns an Article 30 record and an erasure request from an archaeology project into a query.
  6. Set a retention period and honour it. Source photographs, generated variants and the log itself should all have an end date tied to the life of the mandate.
  7. Train the people who use it. The BIV code now expects this explicitly, and it is the control that actually prevents the Friday-afternoon upload.

Look at that list and notice what it is not. It is not a prompt, and it is not a browser tab. It is a procurement decision and a process — which is precisely what a consumer chatbot cannot be, however good the images look.

Renovae is the contracted route, not the browser tab

Renovae exists so that an agency has one supplier to point at instead of a folder of personal accounts. The data side is part of the product, not an afterthought:

  • A B2B relationship with a data processing agreement, so the Article 28 question has a document behind it rather than a shrug.
  • Every generation is recorded — source image, operation, model, timestamp — so an Article 30 record and an erasure request are answerable from the system.
  • Originals and AI projections stay distinguishable at every step, with the record to prove which is which.
  • Disclosure is applied by default on published visuals, using the European Commission's own AI content label rather than an optional decoration.
  • One workspace per agency, so media stops living in whichever personal account happened to be open.
Join the free pilot See the examples first

The pilot covers one property campaign at no cost, in exchange for honest feedback. B2B only. The Renovae workspace at app.renovae.io is currently in private preview for selected agencies.

Frequently asked questions

Is a photo of an empty room still personal data?

Often yes. Personal data is any information relating to an identified or identifiable person, and a room rarely stays anonymous. Family photographs, post on a table, a name plate, a prescription, a neighbour at a window or a licence plate visible through it all make someone identifiable. The room is not the question; what is in it is.

Can I upload listing photos to ChatGPT?

Not safely on a consumer plan. Processing personal data through a supplier requires a data processing agreement under Article 28 GDPR, and consumer tiers are not offered with one. Business and API tiers are contracted differently and can be used lawfully, but the free or personal account an agent signs up for individually is the specific problem.

Do I need consent from the neighbours in a listing photo?

Usually not consent, but you do need a lawful basis and you must minimise. Marketing a property is normally handled under legitimate interests, which requires a balancing test. A neighbour's car, front door or visible window is data you did not need in order to sell the property, so the defensible answer is to blur or crop rather than to justify keeping it.

Does the new BIV code say anything about AI and personal data?

Yes. Alongside its transparency provisions, the code approved in July 2026 requires that personal data does not end up in open AI systems and that agents are sufficiently trained to use AI tools. It also keeps the agent responsible for what is published even when AI produced it. It enters into force ten days after publication in the Belgian Official Gazette.

What are the fines for a GDPR breach of this kind?

Article 83(5) sets a ceiling of 20 million euro or 4% of total worldwide annual turnover, whichever is higher. Real enforcement against small property businesses lands far lower: a Greek property company was reported fined €20,000 in a case that included failing to redact a vehicle licence plate from a published house photo. The realistic risk is a complaint and an investigation, not the ceiling.

Sources

  1. Regulation (EU) 2016/679 (GDPR), Articles 4, 5, 6, 9, 28, 30 and 83. eur-lex.europa.eu
  2. Belgian Data Protection Authority — guidance and complaint procedure. gegevensbeschermingsautoriteit.be
  3. VRT NWS, 22 July 2026 — reporting on the new BIV deontological code and its AI provisions, including personal data in open AI systems. vrt.be
  4. BIV/IPI — deontology of the estate agent and the disciplinary procedure. biv.be
  5. Regulation (EU) 2024/1689 (AI Act), Article 50 — transparency obligations, covered in our earlier article.