An employee headshot policy answers five questions: what the photos look like, who they belong to and where they may be used, when they get updated, how new hires get one, and who owns exceptions. Most companies need one page, not a handbook chapter.
New TeamShotsPro accounts currently receive 3 branded test photos for quality evaluation. Paid seats include 8 photos and use the current published pricing. After a new hire uploads one selfie, each image takes about 60 seconds to generate; directory timing depends on review and publication.
This page is for people who run photos for a company. If you only need your own portrait, start with Portreya.
For the rollout behind the policy, see the company headshots guide. For budgeting, see the cost breakdown.
What to standardize, and what to leave alone
Standardize the frame, not the person: background, crop, lighting style, and formality register. That is what makes a directory look coherent. Leave individual expression, grooming, and appearance alone beyond ordinary workplace norms; policies that reach past the frame into how people look generate friction and, in some jurisdictions, legal exposure. The practical test: two photos taken a year apart under your policy should look like they belong to the same company, not like the same person.
Consent and usage rights
An identifiable employee photo is personal data in many jurisdictions. The policy should explain where photos may appear (directory, website, proposals, social), the purpose and legal basis for each use, and what happens at offboarding. Do not treat clicking upload as automatic proof of valid consent. Unless a role-specific requirement has been confirmed with qualified advice, make participation voluntary, offer an initials or neutral-avatar alternative, and ensure that declining does not create a workplace disadvantage. Handle public-facing use separately from internal use.
Selecting or capturing an image may upload, store, and analyze it before the review or approval step is complete.
Update triggers and cadence
Calendar-based refresh cycles fail quietly: the photo day gets postponed and the directory ages. Trigger-based policies work better: update when appearance changes materially (recognition is the standard), on role changes that alter where the photo appears, and at a maximum age (two to three years) as the backstop. The policy should make updates cheap to request, because the expensive part of stale directories is usually process friction, not employee reluctance.

