Last updated 19 July 2026.
Reviewed on 19 July 2026 against ICO guidance on consent, lawful basis and photography in schools, the current text of the UK GDPR on legislation.gov.uk (including the seventh lawful basis added by the Data (Use and Access) Act 2025, in force from 5 February 2026), the Data Protection Act 2018, and Department for Education safeguarding guidance, to the best of our knowledge at the time of writing. Guidance changes and safeguarding practice varies by setting. For decisions about your specific organisation, talk to a solicitor, your designated safeguarding lead, or the ICO directly.
Recognisability is the test, not the subject matter
ICO advice for schools puts the test simply: if someone can be recognised from a photograph, it is usually considered their personal data. That is a lower bar than most people assume. A face in focus in the third row is personal data. So is a performer in costume whose features are visible, a child identified in a caption, and often a person recognisable from context alone even when their face is partly obscured. A wide shot of a full auditorium taken from the back of the hall, where nobody can realistically be picked out, is a much weaker case for being anybody's personal data. This distinction does most of the practical work. It is why the same event can produce one set of images that needs careful handling and another set that does not, and why blanket policies covering every photograph the same way tend to be either unworkable or ignored.
UK GDPR Article 6 offers seven, and the choice has consequences
Article 6 of the UK GDPR sets out seven lawful bases: consent, contract, legal obligation, vital interests, public task, legitimate interests, and recognised legitimate interests. The last of those is new: Article 6(1)(ea) was inserted by section 70(2)(b) of the Data (Use and Access) Act 2025 and came into force on 5 February 2026. It removes the need for a balancing assessment, but only for a closed list of purposes set out in a new Annex 1, covering crime prevention and detection, safeguarding vulnerable individuals, emergencies, national security, and assisting public bodies with tasks sanctioned by law, so it is very unlikely to apply to event or production photography. You must identify which applies to each kind of processing and be able to demonstrate it under the accountability principle in Article 5(2). ICO advice for schools makes a point that surprises a lot of organisers: offering an opt-out does not mean you are relying on consent as your lawful basis, and where a school lets parents withhold permission it will normally still be processing under a separate basis. Relying on legitimate interests under Article 6(1)(f) requires a documented assessment of purpose, necessity and balance, described by the ICO as the three-part test. Relying on consent under Article 6(1)(a) imports the full set of ICO consent conditions, including the right to withdraw at any time. Neither is a shortcut. This guide cannot tell you which is right for your organisation, and any source that claims to without knowing your circumstances is overreaching.
Must be freely given, specific, informed and unambiguous, unbundled from other terms, and as easy to withdraw as it was to give. Strong on transparency, heavy on administration.
Sometimes used for general audience and atmosphere photography at public events. Requires a documented purpose, necessity and balancing assessment before you start.
Claiming consent while behaving as though refusal is not an option is the worst of both. You take on every consent obligation and satisfy none of them.
Data protection is only half of what is going on
For under-18s, permission from a person with parental responsibility is the working standard at community and school events, and in most settings safeguarding policy requires it regardless of how the data protection analysis lands. ICO advice on photography in schools stresses that children's data, including photographs, needs particular care, that it must be kept safe and not given to anyone who should not have access, and that schools should keep a record of safeguarding procedures protecting particular students and train staff to avoid a breach. That last point is the one that catches volunteer-run organisations. A small number of children have specific safeguarding reasons why no image of them may be published anywhere, and those reasons are confidential. The person holding the camera will not know, and must not be told why. This is why the answer to 'can I put this on Facebook' has to come from the group leader or designated safeguarding lead, and never from the photographer's own judgement. Statutory safeguarding expectations for schools and colleges sit in the Department for Education's Keeping children safe in education guidance, which is a separate obligation from UK GDPR and is not satisfied by having a consent form.
Consent is a continuing permission, not a one-off signature
Where you rely on consent, ICO guidance gives a specific right to withdraw it at any time. You must tell people about that right and offer easy ways to use it, and withdrawal must be as easy as giving consent was. Critically, ICO guidance also confirms that withdrawal does not affect the lawfulness of processing that already took place. That is the point organisers most often misunderstand in both directions: it does not mean you have retrospectively done something wrong, and it does not mean you can carry on as before. From the moment consent is withdrawn you can no longer rely on it as your basis for continuing to use that image. In practice the difficulty is never the legal position, it is the operational one. Photographs propagate. The same image ends up on a website, in a newsletter that has already gone out, in a printed programme, on a social account, in a shared drive, and in an archive that nobody has opened in three years. Withdrawal is only as good as your ability to find every copy, which is a question about how you store images rather than how you word your form.
A tick box reading 'I consent to photography' is not informed consent
ICO guidance on valid consent requires a request to be prominent, unbundled from other terms and conditions, concise and easy to understand, and user-friendly, and requires consent to be specific about the purposes and types of processing. A single unqualified line does none of that. The person ticking it does not know what will be photographed, where it will appear, how long it will be held, who else will see it, or how to change their mind, so they cannot be said to be informed. Five things carry the weight: what is being captured, where it will be used, how long it will be kept, who it may be shared with, and how to withdraw. The second of those is the one to break apart. Publication in a members newsletter, publication on a public website, publication on social media, sharing with a local newspaper and retention in a permanent archive are genuinely different propositions to most people, and bundling them into one agreement is precisely what the specificity requirement is aimed at.
Bundled consent is the failure mode ICO guidance names directly
ICO guidance on valid consent says consent must be freely given, meaning genuine ongoing choice and control, that people must be able to refuse without detriment, and that consent requests should be unbundled from other terms and conditions. Applied to photography, that means the decision to join, audition, enrol, volunteer or buy a ticket has to be genuinely separable from the decision to be photographed. A membership form where the photography paragraph sits inside the block of text you must accept to join is bundled. A booking flow where the only way past the photography question is to agree is bundled. An audition application that will not submit until the photography box is ticked is bundled. The remedy is structural rather than editorial: two decisions, two places to record them, and a real path through the process for somebody who says no to the second. If your activity genuinely cannot proceed without photography, that is a signal that consent is the wrong basis for it rather than a reason to bundle harder.
A signed form proves a tick, not a wording
ICO guidance on obtaining, recording and managing consent expects you to be able to show who consented, when, how, and what they were told. The accountability principle in UK GDPR Article 5(2) means the burden of demonstrating that sits with you. Most community organisations can produce the first three from a paper form or a spreadsheet. Almost none can produce the fourth. Here is the mechanism by which it fails, and it is entirely ordinary. In 2024 your consent form covers the programme and the newsletter. In 2025 the committee agrees to start using photographs on Instagram, and somebody sensibly updates the wording. In 2026 a parent asks what their child agreed to. Your file contains a form signed in 2024 and a document that now mentions Instagram, and there is nothing connecting the signature to the wording that was actually on the page at the time. Every record predating the change has quietly become unprovable, not because anybody did anything wrong, but because the form and the wording were never attached to each other. Paper is particularly bad at this, but a shared document that anybody can edit is worse, because it fails silently and looks fine.
That a named person ticked a box on a particular date. This is the easy part and almost every organisation has it.
Which version of the wording was in front of them. Once the wording changes, older records stop describing what those people actually agreed to.
Freeze the wording shown at the moment of sign-off and attach the record to that specific version, rather than to a living document that keeps moving.
The same version problem, in a setting where it matters more
Photo consent is the most common read-and-agree document in community organisations, but it is far from the only one. Safeguarding codes of conduct, chaperone agreements, membership terms, health and safety briefings before a get-in, social media policies for cast members, and behaviour agreements for youth groups all work the same way: somebody reads a document and records that they have read, acknowledged, or agreed to it. All of them raise exactly the same problem, and in the safeguarding cases the stakes are higher. A code of conduct signed in 2023 does not tell you anything useful if the code was rewritten in 2025 after an incident, because the person who signed it never saw the clause you now care about. It is also worth distinguishing between three different acts that organisations tend to record identically: having read something, acknowledging that you have understood it, and agreeing to be bound by it. They are not interchangeable, and the difference is the first thing anybody will ask about.
The recurring failures, in roughly the order they happen
None of the mistakes below come from carelessness. They come from photography consent being handled by whoever had time, in whatever tool was to hand, under time pressure, in an organisation where the committee changes every couple of years. Reviewing your own setup against this list will catch most of them before they matter.