top of page
Google-Shell-Extend-NoordzeeWind-Offshore-Wind-Farm-1024x683.png

Shell Global
GDPR Compliance

Bringing Control and Strategy to Complex Consent Data

Summary

The Challenge

Shell’s global photography team had already initiated work on GDPR compliance for their photo and video content — but the project lacked ownership, clear governance, and cross-department coordination.

The scope was complex: from filming in public petrol stations and documenting sustainability initiatives in Indigenous communities, to managing thousands of heritage assets featuring past staff, suppliers, and sites. Legal risks were real — and rising.

 

Shell required full confidence that all visual content complied with evolving GDPR standards around personal data, consent, and retention.

The Solution

 

I was brought in to lead delivery across departments and bring structure to a highly complex compliance effort.

A central framework was established to align legal, creative, and tech teams around clear milestones. Legal expectations were rigorous, but through close collaboration, we developed a tiered approach that balanced risk, regulation, and heritage value.

We also scoped key platform updates to support GDPR compliance — embedding consent tagging, expiry tracking, and data management at scale.

ChatGPT Image Sep 25, 2025, 11_19_45 AM_edited_edited.jpg

The Approach

Building the Framework

I established a structured delivery system that brought together Shell’s legal, photography, film, and digital asset management departments — aligning workflows and setting clear decision points.

We mapped risk levels across content types and time periods, then phased delivery into manageable sprints — from legal policy interpretation through to platform tagging rules.

Legal Negotiation & Risk Stratification

Working closely with Shell Legal, I helped shape a pragmatic, risk-aware strategy for consent and archival policy. This involved tiered categorisation across decades of content — from recent shoots without formal consent, to 1950s legacy assets from Shell’s historical archive.

We created a model that upheld GDPR principles while maintaining brand continuity and historical integrity.

Tech Integration & System Updates

The project extended into platform capability — advising the team responsible for Shell’s global image and video library.

 

This included functional specs for GDPR tagging, audit trails, automatic expiry, and data removal processes to meet regulatory standards across markets.

The Results

6

Departments Aligned

Legal, brand, asset management, tech, and comms brought into one structured delivery programme.

1

Global Framework

Centralised compliance structure created to govern consent, retention, and risk across Shell’s visual assets.

1000s

Assets Secured

Heritage and new content tagged, tracked, and controlled to ensure GDPR compliance at scale.

Perfect For

Large organisations navigating sensitive legal or compliance-driven delivery

Creative, content, or media teams managing personal data at scale

Brand, archive, or DAM system owners seeking GDPR-aligned operations

Complex initiatives requiring legal negotiation, stakeholder alignment, and structured rollout

Need Support Like This?

Whether you're planning or mid-build, I can design the framework that drives meaningful outcomes, without the waste.

bottom of page