A school asks parents for permission to use photographs. A box is ticked. For the next six years, that single answer is treated as permission for assemblies, newsletters, social posts, fundraising campaigns, cloud storage and future publicity nobody described at the beginning.
The form exists. The child’s privacy may still not.
Children are photographed and recorded by schools, nurseries, sports clubs, charities, clinics, faith communities and youth programmes. Much of this serves a legitimate purpose: celebrating achievement, keeping families informed, documenting work or raising support.
But a good purpose does not remove the need for limits.
A child’s privacy should not begin at eighteen. It should be protected while the child is still learning how to protect it.
Children are not publicity assets
Institutions often speak about children while making decisions around them. The child becomes a face for the annual report, proof of impact, a recruitment image or an emotional centre for a fundraising appeal.
The resulting material may be beautiful and accurate. The moral question remains: was the child treated as a participant with interests—or as evidence that the institution is doing good?
Power matters. A family may depend on the school place, treatment, food support, scholarship or community service. Consent obtained inside that dependency can feel compulsory even when the form says optional. A parent may fear that refusal will make the child appear difficult or ungrateful.
Institutions must therefore make refusal real. A child should be able to attend, learn, receive care and celebrate without being required to become public content.
One consent box cannot govern every future use
Consent should be specific enough to be understood. An internal learning record is not the same as an open social-media post. A photograph sent to enrolled families is not the same as a billboard. A current newsletter is not the same as a permanent archive reused five years later.
| Purpose | Audience | Risk and control |
|---|---|---|
| Internal educational record | Relevant staff and family | Restricted access, defined retention and secure storage |
| Closed parent communication | Current families | No reposting expectation, access removed when families leave |
| Website or public social media | Unlimited and copyable | Separate permission, minimal identifiers, review before publication |
| Fundraising or advertising | Donors, customers and public campaigns | Heightened scrutiny, no exploitation of distress or dependency |
| Third-party media | Publisher’s audience and archives | Explain loss of institutional control and obtain specific agreement |
Bundled permission hides meaningful choices. Good governance separates them.
Permission from an adult is not the whole answer
Parents and guardians carry legal and practical authority, particularly for younger children. Children also possess views, dignity and developing autonomy. An institution should seek age-appropriate assent in addition to the required adult permission.
That can be simple: “We would like to use this photograph on the school website, where anyone may see it. Are you comfortable with that?”
A child who turns away, covers their face or says no should not be persuaded for convenience. A teenager’s objection deserves serious weight even if a form was signed years earlier. Consent should be renewable, withdrawable and attached to the use—not treated as institutional property.
Privacy is more than hiding a face
An image can identify a child without naming them. Uniforms, badges, captions, event dates, locations, team lists and distinctive settings can combine into a clear identity. A blurred face may still leave a full name on a certificate.
Data minimisation means asking what the purpose actually requires. If the purpose is to show a science activity, the institution may not need a child’s full name. If the purpose is to inform parents, the material may not need to be public. If the purpose is to demonstrate impact, an anonymised story or adult testimony may work without exposing a child’s hardship.
Collect less. Publish less. Retain for less time. Give access to fewer people.
Never use vulnerability as proof of impact
Children facing poverty, disability, illness, displacement, family crisis or institutional care are often the most powerful subjects for fundraising. They may also be least able to refuse.
The organisation should not make a child’s pain perform for adult generosity. Avoid images of distress, degrading conditions, treatment, private living spaces and narratives that reduce the child to a problem the donor can solve.
Tell the truth about need without stripping the person of dignity. Use representative, non-identifying visuals where possible. Centre capacity and agency. Explain to families where the story will appear and that digital material may travel beyond the original campaign.
A worthy cause does not make every method of showing the cause worthy.
The institution must control the entire image journey
Privacy failures do not occur only at publication. Risk begins when the photograph is taken.
Who uses the camera? Is a personal phone permitted? Where are files uploaded? Can volunteers download them? Does a third-party platform train systems on them? How long are they retained? Who deletes rejected images? What happens when a staff member leaves? Can the child or family request removal?
An effective process maps the full lifecycle:
- Plan: define the purpose, audience, lawful basis and least intrusive method.
- Explain: give parents and children clear, accessible information before recording.
- Capture: use approved equipment and avoid private or humiliating situations.
- Store: restrict access, protect transfers and prohibit informal personal archives.
- Select: check backgrounds, identifiers, other children and the dignity of the moment.
- Publish: use the smallest audience and least identifying caption that meet the purpose.
- Review: remove outdated material and renew permission when purpose changes.
- Delete: follow a defined retention schedule and record third-party removal requests.
Children need a no-camera path
Institutions sometimes protect privacy by excluding the child: the child without photo permission stands aside while classmates celebrate, misses the front of the performance or is cropped from the team.
That turns privacy into a social penalty.
Plan participation and publicity separately. Use designated photography zones, group angles that respect choices, coloured lanyards only if they do not stigmatise, staff briefings and alternative activities that do not isolate. The child should be included in the experience even when excluded from public distribution.
Staff and parents need clear rules
An institution can control its official photographer but lose control through twenty audience phones. Events need proportionate, visible guidance: whether personal photography is allowed, whether images may be shared publicly, how children with protective needs are safeguarded and whom to ask before posting another family’s child.
Rules should avoid both false guarantees and blanket panic. They must reflect the event, law and safeguarding context. Where recording is restricted, explain why and enforce the rule consistently.
Staff should never use personal accounts to publish children. Volunteers and contractors need the same standards as employees. Marketing targets must never override safeguarding decisions.
AI increases the duty of restraint
Institutions are beginning to use automated editing, tagging, recognition and content-generation tools. A convenient upload may transfer a child’s face or voice into a system whose retention, training or reuse terms are not understood.
Do not place children’s identifiable images, voices, health information or case histories into public generative-AI tools without a properly assessed, authorised basis. Procurement teams should examine data location, retention, model training, subcontractors, deletion and breach response. “The tool was free” is not a privacy assessment.
The best-interests standard should govern the technology, not the novelty of the feature.
Withdrawal must be practical
Families should know how to change a decision. The institution should be able to locate where an image appears, stop future use and remove controlled copies promptly.
It must also be honest: a public post may have been copied, cached or archived by others. Withdrawal may not erase the entire internet. That limitation is an argument for restraint before publication, not a reason to ignore withdrawal afterward.
Children who become old enough to understand should have a direct route to ask questions or request removal without needing to challenge an adult publicly.
When an image escapes, respond as a safeguarding incident
A photograph may be posted to the wrong account, shared beyond the authorised audience, retained on a staff member’s phone or used by a third party outside the agreed purpose. The response should not begin with public-relations language.
Contain further distribution, preserve the facts, notify the responsible safeguarding and privacy leads, assess risk to the child, contact the family honestly, request removal from controlled and third-party locations, and meet any applicable breach-reporting duty. Offer the child practical support if peers or strangers have seen the material.
Then correct the system: access, training, approvals, vendor terms or event controls. Calling the incident “an unfortunate mistake” does not explain why the organisation made it easy to happen.
Leadership must see the archive
Boards and senior leaders should receive assurance on more than whether consent forms exist. They should know how many public images are held, how old they are, which vendors process them, how withdrawal requests are handled, whether refusals affect participation, and what incidents or complaints have occurred.
A periodic sample of real pages, newsletters, shared drives and campaign assets will reveal more than a policy review alone. Governance begins when leadership can see the child’s actual journey through the system.
A minimum institutional standard
Ten controls every child-serving organisation should adopt
- Separate operational recording, closed family communication and public publicity.
- Explain each purpose, audience, retention period and withdrawal route plainly.
- Seek adult permission where required and age-appropriate child assent.
- Make refusal free from lost services, stigma or exclusion.
- Prohibit public use of distress, nudity, punishment, medical care and humiliation.
- Minimise names, locations, uniforms, routines and sensitive personal information.
- Use approved equipment, access controls and retention schedules.
- Assess vendors and AI tools before transferring children’s data.
- Review public archives and remove material whose purpose has expired.
- Give children and families a visible, responsive removal and complaint route.
The test of a child-safe institution
A child-safe institution is not one that never takes a photograph. It is one that understands the difference between recording a moment and acquiring a person.
It asks why the image is needed, who benefits, who may be exposed and whether the same purpose can be achieved with less data. It remembers that a parent’s signature is the beginning of responsibility, not the end of thought.
The child in today’s campaign will become the adult who must live with the archive. By then, the staff may have changed, the project may have ended and the password may have been lost. The institution’s good intention will not travel beside every copy.
Protect the child now—not only from obvious danger, but from becoming permanently public before they understand what public means.
Do not wait until a child becomes an adult to recognise that their private life always belonged to a person.
Evidence and further reading
The recommendations are a public-interest synthesis and should be adapted to applicable law and safeguarding duties. These official sources support the rights and design principles used above.
- UN Committee on the Rights of the Child: General comment No. 25 on children’s rights in relation to the digital environment
- UK Information Commissioner’s Office: Age appropriate design code
- ICO: Children’s code design guidance
- UNICEF and ITU: Guidelines for Industry on Child Online Protection

