Photo and media consent, for organisations that work with real people.

    Almost every community organisation photographs its own events. Amateur theatre companies shoot the dress rehearsal, schools record the nativity, choirs put concert pictures in the newsletter, dance schools film the showcase. Very few of them can answer the question that actually matters: what exactly did this particular person agree to, and when, and in what words.

    This guide sets out what UK data protection law and regulator guidance say about photographing people at events, why photographing children is a different problem to photographing an audience, what happens when somebody changes their mind, and why the record of a consent is often weaker than the consent itself.

    It is general information for UK organisers, not legal advice. Photography consent sits across data protection, safeguarding, and sometimes contract, and the right answer depends on facts only you know. Nothing here tells you what is lawful in your specific case. For decisions that affect your organisation, consult a solicitor, your designated safeguarding lead, or contact the Information Commissioner's Office directly.

    Last updated 19 July 2026.

    Reviewed on 19 July 2026 against ICO guidance on consent, lawful basis and photography in schools, the current text of the UK GDPR on legislation.gov.uk (including the seventh lawful basis added by the Data (Use and Access) Act 2025, in force from 5 February 2026), the Data Protection Act 2018, and Department for Education safeguarding guidance, to the best of our knowledge at the time of writing. Guidance changes and safeguarding practice varies by setting. For decisions about your specific organisation, talk to a solicitor, your designated safeguarding lead, or the ICO directly.

    The short version.

    A photograph from which somebody can be recognised is personal data, so taking and publishing it needs a lawful basis under UK GDPR Article 6. Consent is one of seven bases, not the default, and ICO guidance for schools is explicit that offering an opt-out does not mean you are relying on consent. Many organisations use legitimate interests for general audience and atmosphere shots, having documented the assessment, and use consent where the subject is a named individual, a close-up, or a child.

    Choosing consent is a commitment, not a formality. Once you rely on it, ICO guidance requires it to be freely given, specific, informed, unambiguous, unbundled from other terms, and as easy to withdraw as it was to give. Where children are involved, permission from a person with parental responsibility is the working standard and safeguarding policy usually goes further than data protection alone would.

    The part most organisations get wrong is not the asking. It is the keeping. A signed form proves somebody ticked a box. It does not prove which wording was in front of them when they did.

    1. When a photograph becomes personal data.

    Recognisability is the test, not the subject matter

    Photographs as personal data

    ICO advice for schools puts the test simply: if someone can be recognised from a photograph, it is usually considered their personal data. That is a lower bar than most people assume. A face in focus in the third row is personal data. So is a performer in costume whose features are visible, a child identified in a caption, and often a person recognisable from context alone even when their face is partly obscured. A wide shot of a full auditorium taken from the back of the hall, where nobody can realistically be picked out, is a much weaker case for being anybody's personal data. This distinction does most of the practical work. It is why the same event can produce one set of images that needs careful handling and another set that does not, and why blanket policies covering every photograph the same way tend to be either unworkable or ignored.

    • If a person can be recognised from the image, treat it as their personal data
    • Wide, distant crowd shots where no individual is identifiable are a different case from portraits
    • A caption naming somebody turns an unidentifiable image into an identifiable one
    • Video and audio recordings raise the same questions as stills, and usually raise them more sharply
    • Context can identify a person even where the face does not, particularly in small communities
    • Ask yourself who would be able to recognise this person, not whether a stranger could

    Three different situations, routinely treated as one.

    Most photography policies fail because they cover a public audience, a named individual, and a child under one rule. These are not the same problem.

    The audience at a public performance. People who buy a ticket to a public event generally expect that the event may be photographed. That expectation is relevant to a legitimate interests balancing test, and it is why clear notice at the point of booking and at the door matters so much. It does not make the images stop being personal data.

    A named individual. A headshot of a leading performer, a photograph of a volunteer used in recruitment material, an image with a caption identifying the person. Here the subject is the point of the photograph, the use is usually promotional, and expectations are much more specific.

    A child. Everything above, plus safeguarding, plus the practical reality that the child cannot meaningfully make this decision and the person who can may not be in the room. This is covered in its own section below because it deserves one.

    2. Consent is one lawful basis, not the only one.

    UK GDPR Article 6 offers seven, and the choice has consequences

    Lawful basis for photography

    Article 6 of the UK GDPR sets out seven lawful bases: consent, contract, legal obligation, vital interests, public task, legitimate interests, and recognised legitimate interests. The last of those is new: Article 6(1)(ea) was inserted by section 70(2)(b) of the Data (Use and Access) Act 2025 and came into force on 5 February 2026. It removes the need for a balancing assessment, but only for a closed list of purposes set out in a new Annex 1, covering crime prevention and detection, safeguarding vulnerable individuals, emergencies, national security, and assisting public bodies with tasks sanctioned by law, so it is very unlikely to apply to event or production photography. You must identify which applies to each kind of processing and be able to demonstrate it under the accountability principle in Article 5(2). ICO advice for schools makes a point that surprises a lot of organisers: offering an opt-out does not mean you are relying on consent as your lawful basis, and where a school lets parents withhold permission it will normally still be processing under a separate basis. Relying on legitimate interests under Article 6(1)(f) requires a documented assessment of purpose, necessity and balance, described by the ICO as the three-part test. Relying on consent under Article 6(1)(a) imports the full set of ICO consent conditions, including the right to withdraw at any time. Neither is a shortcut. This guide cannot tell you which is right for your organisation, and any source that claims to without knowing your circumstances is overreaching.

    Article 6(1)(a): Consent

    Must be freely given, specific, informed and unambiguous, unbundled from other terms, and as easy to withdraw as it was to give. Strong on transparency, heavy on administration.

    Article 6(1)(f): Legitimate interests

    Sometimes used for general audience and atmosphere photography at public events. Requires a documented purpose, necessity and balancing assessment before you start.

    Choosing badly

    Claiming consent while behaving as though refusal is not an option is the worst of both. You take on every consent obligation and satisfy none of them.

    Why organisations quietly regret choosing consent.

    Consent looks like the safe, respectful option, and for individual portraits and children it usually is the right instinct. What organisers often do not anticipate is what comes attached to it.

    Consent has to be genuinely refusable. ICO guidance on valid consent describes freely given consent as giving people genuine ongoing choice and control, and says people must be able to refuse without detriment. So the person who says no has to be able to attend, perform, join, or take part exactly as before. Consent has to be specific, so a single agreement cannot quietly cover the newsletter, the website, the local paper, a permanent archive and next season's poster campaign. Consent has to be withdrawable at any time, and the ICO says withdrawal must be as easy as giving it was and should be a straightforward one-step process. That means somebody has to be reachable, and somebody has to act.

    None of this is a reason to avoid consent. It is a reason to decide deliberately rather than by default, and to build the withdrawal route before you need it rather than after somebody asks.

    3. Children, safeguarding, and why this is a different problem.

    Data protection is only half of what is going on

    Photographing children

    For under-18s, permission from a person with parental responsibility is the working standard at community and school events, and in most settings safeguarding policy requires it regardless of how the data protection analysis lands. ICO advice on photography in schools stresses that children's data, including photographs, needs particular care, that it must be kept safe and not given to anyone who should not have access, and that schools should keep a record of safeguarding procedures protecting particular students and train staff to avoid a breach. That last point is the one that catches volunteer-run organisations. A small number of children have specific safeguarding reasons why no image of them may be published anywhere, and those reasons are confidential. The person holding the camera will not know, and must not be told why. This is why the answer to 'can I put this on Facebook' has to come from the group leader or designated safeguarding lead, and never from the photographer's own judgement. Statutory safeguarding expectations for schools and colleges sit in the Department for Education's Keeping children safe in education guidance, which is a separate obligation from UK GDPR and is not satisfied by having a consent form.

    • Permission from a person with parental responsibility is the normal standard for under-18s
    • Some children must not appear in any published image for safeguarding reasons you will not be told
    • Decisions about publication belong to the group leader or designated safeguarding lead, not the photographer
    • Keep names away from images as a default, and never publish a full name alongside a photograph of a child
    • Avoid identifying details in captions: school year, class, home area, rehearsal times, or where a child can be found
    • Where a child is old enough to have a view, ask them as well as their parent, and respect a refusal
    • Data protection compliance and safeguarding compliance are separate. Satisfying one does not satisfy the other

    The group photo problem, and what people actually do about it.

    Here is the scenario every dance school, youth theatre and primary school runs into. Twenty-eight children in the cast. Twenty-seven parents have given permission. One has refused, for reasons that are entirely theirs and which nobody is entitled to know. The photographer wants a full company shot on the set at the end of the final rehearsal.

    There is no clever answer that makes this go away, and any guide claiming otherwise is selling something. What organisations do in practice falls into a small number of patterns, each with a cost.

    Take the photograph without that child. The most common approach and the most defensible. The cost is obvious and it is borne by the child, so it needs handling with care by an adult who knows what they are doing. Never announce why somebody is stepping out.

    Take a full-cast photograph for internal use only. The image exists, everybody is in it, nobody publishes it. This depends entirely on internal discipline being real rather than assumed, and on the file not drifting into a shared drive that later becomes a website gallery.

    Run a marker system on the night. A discreet coloured wristband, a sticker inside a costume label, a name on a list held by one named person at the side of the stage. The point is that the photographer can check without a conversation and without the child being singled out in front of the group. This is the mitigation most safeguarding leads reach for, and it works because it moves the decision away from the moment of the photograph.

    Whichever you choose, the failure mode is always the same: the permission list is on somebody's phone, or in an email thread, or in a folder in the office, and the photographer is in the wings with two minutes before the curtain. Decide in advance who holds the list and how the person with the camera checks it.

    Personal photography by families is a separate question.

    Parents filming their own child at a school play are usually outside data protection law entirely. ICO advice for schools states that people can take photographs and video recordings for personal use, such as for a family album, and that this is not something data protection law is concerned with. The ICO adds that posting to a public account viewable by an indefinite number of people is likely to go beyond personal use.

    This is why banning cameras outright tends to be both unpopular and unnecessary. The proportionate approach most schools and community groups land on is to allow personal photography and ask clearly, in advance and again on the night, that families do not post images containing other people's children to public social media. It is a request rather than an enforcement mechanism, and framing it honestly as such tends to get better compliance than pretending otherwise.

    4. Withdrawal: what it does and does not undo.

    Consent is a continuing permission, not a one-off signature

    Withdrawing consent

    Where you rely on consent, ICO guidance gives a specific right to withdraw it at any time. You must tell people about that right and offer easy ways to use it, and withdrawal must be as easy as giving consent was. Critically, ICO guidance also confirms that withdrawal does not affect the lawfulness of processing that already took place. That is the point organisers most often misunderstand in both directions: it does not mean you have retrospectively done something wrong, and it does not mean you can carry on as before. From the moment consent is withdrawn you can no longer rely on it as your basis for continuing to use that image. In practice the difficulty is never the legal position, it is the operational one. Photographs propagate. The same image ends up on a website, in a newsletter that has already gone out, in a printed programme, on a social account, in a shared drive, and in an archive that nobody has opened in three years. Withdrawal is only as good as your ability to find every copy, which is a question about how you store images rather than how you word your form.

    • Already printed: processing while consent was valid stays lawful. Most organisations stop distributing remaining stock rather than attempting a recall
    • Already on social media: take it down, and remember that reshares and screenshots are outside your control. Say so honestly rather than promising removal you cannot deliver
    • Already in the archive: decide whether the archive is a live use or a closed historical record, document the position, and apply it consistently
    • Future use: stop, immediately and completely, including in templates, slide decks and returning annual publicity
    • Record the withdrawal against the person, with the date, so nobody reinstates the image next season
    • Tell the person what you have done and what you have not been able to do. Silence is what turns a withdrawal into a complaint

    5. What a consent request actually has to say.

    A tick box reading 'I consent to photography' is not informed consent

    What a consent request contains

    ICO guidance on valid consent requires a request to be prominent, unbundled from other terms and conditions, concise and easy to understand, and user-friendly, and requires consent to be specific about the purposes and types of processing. A single unqualified line does none of that. The person ticking it does not know what will be photographed, where it will appear, how long it will be held, who else will see it, or how to change their mind, so they cannot be said to be informed. Five things carry the weight: what is being captured, where it will be used, how long it will be kept, who it may be shared with, and how to withdraw. The second of those is the one to break apart. Publication in a members newsletter, publication on a public website, publication on social media, sharing with a local newspaper and retention in a permanent archive are genuinely different propositions to most people, and bundling them into one agreement is precisely what the specificity requirement is aimed at.

    • What: stills, video, audio, and whether that includes rehearsals as well as performances
    • Where: list the destinations separately and let people agree to some and not others
    • How long: give an actual period, or say plainly that images are retained in an archive indefinitely if that is the truth
    • Who with: name the categories, including any photographer or press you routinely work with
    • How to withdraw: a named contact, an email address, and a commitment to act, in the same document
    • Written in the language of the person reading it, not in the language of the regulation

    A worked example of wording that does the job.

    Compare the version most community groups actually use with one that meets the specificity and information requirements. Both take about the same time to complete.

    What people usually write
    I consent to photography.

    What answers the question a year later
    During rehearsals and performances of our spring production, our own volunteers take photographs and short video clips. We would like your permission to use images of you. Please tick the uses you are happy with. You can tick some and not others, and you can tick none. Whatever you choose, it will not affect your place in the production or your membership of the society.

    1. Use in our printed programme and members newsletter.
    2. Use on our public website, including our production archive pages.
    3. Use on our public social media accounts.
    4. Sharing with local press if they cover the production.

    We keep images used on our website and in our archive indefinitely, because the archive is a record of the society's productions. We keep images not used for any of the purposes above for twelve months and then delete them. We never publish a full name alongside a photograph without asking separately.

    You can change your mind at any time by emailing our secretary at the address on our contact page. We will remove the image from our website and social accounts and stop using it in anything new. We cannot recall printed copies already distributed, and we cannot remove copies other people have already shared or saved.

    The second version is longer, and it is longer for a reason. It names the purposes separately, states the retention honestly rather than aspirationally, gives a route to withdraw with a named person behind it, and is straightforward about the limits of what withdrawal can achieve. That last paragraph is the one most organisations omit, and it is the one that prevents an angry conversation later.

    6. Separability: photography cannot be the price of taking part.

    Bundled consent is the failure mode ICO guidance names directly

    Separating consent from participation

    ICO guidance on valid consent says consent must be freely given, meaning genuine ongoing choice and control, that people must be able to refuse without detriment, and that consent requests should be unbundled from other terms and conditions. Applied to photography, that means the decision to join, audition, enrol, volunteer or buy a ticket has to be genuinely separable from the decision to be photographed. A membership form where the photography paragraph sits inside the block of text you must accept to join is bundled. A booking flow where the only way past the photography question is to agree is bundled. An audition application that will not submit until the photography box is ticked is bundled. The remedy is structural rather than editorial: two decisions, two places to record them, and a real path through the process for somebody who says no to the second. If your activity genuinely cannot proceed without photography, that is a signal that consent is the wrong basis for it rather than a reason to bundle harder.

    • Joining, enrolling or buying a ticket is one decision. Being photographed is another
    • A person who declines photography must be able to complete the process unchanged
    • Do not put photography inside the block of terms somebody has to accept to proceed
    • Do not make the photography question mandatory in a form that will not otherwise submit
    • Granular options beat a single yes or no, because most people are not absolutists about this
    • If refusal genuinely breaks the activity, take advice on whether consent is the right basis at all

    7. Record keeping: the version is the part everyone loses.

    A signed form proves a tick, not a wording

    Record keeping and versioning

    ICO guidance on obtaining, recording and managing consent expects you to be able to show who consented, when, how, and what they were told. The accountability principle in UK GDPR Article 5(2) means the burden of demonstrating that sits with you. Most community organisations can produce the first three from a paper form or a spreadsheet. Almost none can produce the fourth. Here is the mechanism by which it fails, and it is entirely ordinary. In 2024 your consent form covers the programme and the newsletter. In 2025 the committee agrees to start using photographs on Instagram, and somebody sensibly updates the wording. In 2026 a parent asks what their child agreed to. Your file contains a form signed in 2024 and a document that now mentions Instagram, and there is nothing connecting the signature to the wording that was actually on the page at the time. Every record predating the change has quietly become unprovable, not because anybody did anything wrong, but because the form and the wording were never attached to each other. Paper is particularly bad at this, but a shared document that anybody can edit is worse, because it fails silently and looks fine.

    What you can usually prove

    That a named person ticked a box on a particular date. This is the easy part and almost every organisation has it.

    What you usually cannot

    Which version of the wording was in front of them. Once the wording changes, older records stop describing what those people actually agreed to.

    What fixes it

    Freeze the wording shown at the moment of sign-off and attach the record to that specific version, rather than to a living document that keeps moving.

    Why versioning is not a technicality.

    The question you eventually get asked is never "do you have a consent form". It is "what exactly did this person agree to, in March, before you changed the wording". That is the question a parent asks, it is the question a trustee asks after a complaint, and it is the question a regulator would ask.

    If your consent lives in a document you have since edited, you cannot answer it. You can show that somebody agreed to something, and you can show what the document says today, and you cannot connect the two. In practical terms that means the safest assumption is that the older consents only ever covered the narrower original wording, which is usually not what your archive has been relying on.

    Handled on paper, this needs a discipline most volunteer organisations never sustain: date every version of the wording, keep every superseded version, and record against each signature which version number it relates to. It is entirely doable and it is almost never done. Some systems avoid the discipline problem by freezing the exact wording displayed at the moment of sign-off and giving it a reference, so the record and the wording stay attached to each other whether or not anybody remembers to file anything.

    8. Codes of conduct and everything else people have to read.

    The same version problem, in a setting where it matters more

    Codes of conduct and read-and-agree documents

    Photo consent is the most common read-and-agree document in community organisations, but it is far from the only one. Safeguarding codes of conduct, chaperone agreements, membership terms, health and safety briefings before a get-in, social media policies for cast members, and behaviour agreements for youth groups all work the same way: somebody reads a document and records that they have read, acknowledged, or agreed to it. All of them raise exactly the same problem, and in the safeguarding cases the stakes are higher. A code of conduct signed in 2023 does not tell you anything useful if the code was rewritten in 2025 after an incident, because the person who signed it never saw the clause you now care about. It is also worth distinguishing between three different acts that organisations tend to record identically: having read something, acknowledging that you have understood it, and agreeing to be bound by it. They are not interchangeable, and the difference is the first thing anybody will ask about.

    • Distinguish read, acknowledged and agreed. Record which one you actually asked for
    • Date every version and keep superseded versions rather than overwriting them
    • When a safeguarding document is rewritten, treat existing sign-offs as covering the old version only
    • Re-issue a document for fresh sign-off when a material clause changes, not just at the annual renewal
    • Give people a copy of what they signed, at the time they sign it
    • Store the sign-off record where the next committee will find it, not in the outgoing secretary's inbox

    9. Where this gets broken.

    The recurring failures, in roughly the order they happen

    Common photo consent mistakes

    None of the mistakes below come from carelessness. They come from photography consent being handled by whoever had time, in whatever tool was to hand, under time pressure, in an organisation where the committee changes every couple of years. Reviewing your own setup against this list will catch most of them before they matter.

    • A single tick box reading "I consent to photography", with no purposes, no retention period and no withdrawal route
    • Bundling photo consent into membership terms or the checkout, so refusal is not a real option
    • Editing the consent wording and leaving every previous signature attached to nothing in particular
    • Assuming a sign at the door constitutes consent. Notice tells people what is happening; it is not the same as consent, and the ICO treats an opt-out arrangement as relying on a different basis entirely
    • Publishing a child's full name alongside their photograph, or including identifying detail in the caption
    • Letting the photographer decide what can be published, rather than the group leader or designated safeguarding lead
    • Holding the permission list somewhere the person with the camera cannot check it thirty seconds before curtain up
    • Treating a withdrawal as a request to consider rather than an instruction to act on
    • Promising to remove images from social media in terms that ignore reshares and screenshots you cannot reach
    • Keeping an image archive live indefinitely while keeping the consent records for only a year, so the images outlive the permission for them
    • Reusing last season's photographs in this season's publicity without rechecking whether anybody has withdrawn
    • Losing the whole record set when the secretary steps down, because it lived in a personal email account

    A practical checklist for a community organisation.

    1. Write down, in one paragraph, what photography your organisation actually does: who takes the images, at which events, and where they end up. Most organisations have never done this and are surprised by the answer.

    2. Decide and record your lawful basis for each kind of photography, treating general audience shots and images of identified individuals separately. If you rely on legitimate interests anywhere, do the three-part assessment and keep it.

    3. Rewrite your consent request so it names the purposes separately, states a real retention period, identifies who images may be shared with, and gives a named person and address for withdrawal.

    4. Separate photo consent from joining, enrolling and buying a ticket, and check that somebody who declines can still get all the way through the process.

    5. For under-18s, obtain permission from a person with parental responsibility, and agree with your safeguarding lead who holds the list of children whose images must not be published.

    6. Put a marker system in place for event nights so the photographer can check without singling anybody out, and brief whoever is holding the camera before the event rather than during it.

    7. Version your wording. Date it, keep superseded versions, and make sure every record points at the version that person was actually shown.

    8. Agree a withdrawal process: who receives the request, what gets removed, how quickly, and what you tell the person about the limits of what you can reach.

    9. Set a retention rule for images and make sure the consent records outlive the images rather than the other way round.

    10. Review annually, and make the handover of these records an explicit item when officers change.

    When to take proper advice.

    This guide describes what published UK guidance says. It does not, and cannot, tell you what is lawful in your specific circumstances, and you should be wary of anything that claims to. The situations below are the ones where organisations most often get it wrong on their own.

    You are photographing or filming children regularly, particularly where any child has a safeguarding plan or a restriction on their image being published. Speak to your designated safeguarding lead first, every time.

    You want to rely on legitimate interests rather than consent and have not carried out a documented assessment.

    You have received a withdrawal request covering material you have already published widely, or a complaint about an image that is already in circulation.

    You are engaging a professional photographer or a press outlet, where the question of who is the controller, what they may do with the images afterwards, and what your contract actually says all become live.

    You are streaming or recording performances for later sale or distribution, which raises performers' rights and contractual questions alongside data protection.

    You have discovered that your existing consent records cannot be matched to the wording people were shown, and you need to decide what you can still rely on. For any of these, consult a solicitor, your safeguarding lead, or the Information Commissioner's Office, which publishes detailed guidance and runs a helpline for small organisations.

    If your organisation matches one of these patterns.

    The principles are the same everywhere, but the pressure points differ a lot by setting.

    If you are a school running a nativity or a summer production where hundreds of families are photographing their own children and the school is also publishing its own images, the two questions are genuinely separate and worth answering separately. See notes for schools.

    If you are a dance school where showcase photography is part of how families remember the year, and where under-13s make up most of the cast, granular consent options matter more than a single yes or no. See notes for dance schools.

    If you are an amateur dramatic society with a production archive going back decades, the retention and withdrawal questions bite hardest on the archive rather than on this season. See notes for amateur theatre groups.

    If you are a choir or orchestra with a stable adult membership and a concert programme that reuses images year after year, the risk is quietly reusing a photograph of somebody who left. See notes for choirs and orchestras.

    If you are a church or parish photographing services, baptisms and youth activities, the mix of congregants, visitors and children in one room is the hard part. See notes for churches.

    If you are a heritage attraction or visitor site photographing the public on site, notice at the point of entry and the legitimate interests assessment do most of the work. See notes for charity attractions.

    If you are a village hall hosting other people's events, be clear about which organisation is the controller for photography at any given booking. See notes for village halls.

    If you are a producing or receiving theatre working with professional photographers and press, the contractual layer sits on top of everything above. See notes for theatres.

    Where tooling makes a difference.

    Most of what this guide describes can be done on paper, and plenty of well-run organisations do exactly that. The part that reliably degrades is the record: not whether somebody agreed, but which wording they saw when they did, and whether that connection survives three committee handovers and two rewrites of the form.

    That is a version-control problem wearing a compliance costume, and it is worth checking how any system you use handles it. The question to ask is simple: if the wording changes tomorrow, does last year's sign-off still point at last year's wording, or does it silently start pointing at the new one? Some platforms freeze the exact document shown at the moment of sign-off and give it a reference so the two stay attached. Seaty's surveys and forms work that way, and let you distinguish between asking somebody to read a document, acknowledge it, or agree to it. Whichever route you take, that is the bar to hold a system to.

    Related guides and policies

    Plain-English explanations of the parts of running UK events that catch organisers out.
    GDPR for UK event organisersSelling tickets for UK charity eventsHow UK ticketing fees actually workSurveys, forms and consent sign-offCustom questions on the order form Anonymity and data protection in surveysPrivacy policyBuilding a form or surveyReading and exporting responses

    Get the record right while it is still easy.

    Consent is easy to collect and hard to evidence a year later. Whatever you run your events on, the thing worth checking is whether a sign-off from last season still points at the wording that was on the page at the time.

    Sources & further reading

    This guide draws on ICO guidance, UK legislation, and Department for Education safeguarding guidance. For decisions specific to your organisation, consult these primary sources directly or speak to a solicitor or your designated safeguarding lead.

    ICO guidance
    Taking photographs: data protection advice for schools (ICO)
    Taking photos in schools (ICO, guidance for the public)
    Consent as a lawful basis (ICO)
    What is valid consent? (ICO)
    How should we obtain, record and manage consent? (ICO)
    A guide to lawful basis (ICO)
    What is the legitimate interests basis? (ICO)
    Children's information (ICO)

    UK legislation
    UK GDPR (Regulation (EU) 2016/679) (legislation.gov.uk)
    UK GDPR Article 6: lawfulness of processing, as amended (legislation.gov.uk)
    Data (Use and Access) Act 2025: data protection and privacy changes (gov.uk)
    Data Protection Act 2018 (legislation.gov.uk)

    Safeguarding
    Keeping children safe in education (Department for Education, gov.uk)
    Working together to safeguard children (gov.uk)
    Seaty made with love in BritainSeaty made with love in Britain

    Seaty

    Find out moreFees & pricingHow Seaty comparesFrequently asked questionsIndustry guidesTerms of servicePrivacy policy

    Events

    Create an eventFor your organisationSelling ticketsRunning eventsManaging organisationsSecurity & data
    Address11 Brindley PlaceBirminghamB1 2LPCompany no08960314Support@Seaty.co.uk
    Seaty.co.ukSeaty.co.uk
    © 2026 All rights reserved.
    Seaty is a registered trademark in the United Kingdom. Privacy & Cookies
    Connecting to Apple…