A nursery’s guide to children’s photos, consent and privacy
A plain-English guide to getting consent, privacy and photography right — and keeping children’s images safe in a world where they’re easier to misuse.
Photographs are part of everyday life in a nursery. Observations, learning journeys, a proud moment caught on a tablet and sent home — it’s how you show families what their child’s day looked like, and done well it builds real trust. But every one of those images is personal data. How you take, store and share it is something parents, Ofsted and UK GDPR all care about.
This is our practical advice on getting it right: how to photograph children, how to get consent that actually holds up, what your privacy policy needs to say, and how to protect images once they’ve been shared. It’s written for busy people, and it applies whether you’re a single-site PVI nursery, a preschool, a school setting or a multi-site group.
It matters more now than it did a few years ago. Criminals are taking publicly available photos of children — from websites, open social media, school pages — and using AI to create illegal imagery, and under-fives are already being affected. That’s not a reason to stop sharing a child’s learning with their own parents. It’s a reason to make the policy around it as strong as it can be.
We work with hundreds of nurseries and early years settings across the UK, including LEYF — one of the organisations featured in the recent coverage. Much of the public debate has focused on websites and open social media. We want to add the part that gets less attention: what happens to images inside your management software, and where your responsibility as a setting begins and ends.
Start with this. A closed app is the most controlled way to share children’s images — far safer than any public platform. Nothing here is a reason to stop using one. It’s about making your policy as strong as the software behind it.
Private doesn't mean permanent
Photographs of children are personal data. If a child can be identified from an image — and at nursery, they almost always can — then UK GDPR applies. That means you need a lawful reason to use the image, and you need to handle it carefully.
Most nursery management platforms — including ours — let practitioners capture observations, document learning, and share images with parents through a closed app. This is a good thing. It keeps communication off public platforms and gives you far more control than posting to Instagram or Facebook ever would.
But here’s what settings need to understand: private doesn’t mean the image stops there.
Once a parent receives an image through a closed app, they can still screenshot it, forward it, or share it on their own social media. You’ve done everything right on your side. Your settings are correct, your permissions are in place. But the moment that image lands on a parent’s phone, your control over it ends.
This isn’t a flaw in the software. It’s the nature of digital sharing — and it’s why your image policy can’t begin and end with “we use a secure app”.
Policy comes before technology
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.
What you actually need to do
The four essentials
- Written consent from parents — what photos are taken, where they're shared, and who else might see them.
- A privacy policy — how you use photos, that the app is run for you by your provider, and what families' rights are.
- A record of consents — so you can prove what each family agreed to.
- A process for withdrawals and requests — so you can act quickly when a parent wants images removed or restricted.
Getting consent right
Consent works best when parents understand why it matters, not just what they’re ticking. As Princess Souassou Tsiagbe notes in the Nursery World piece, settings need to work in partnership with parents. Parents who understand the risk are far less likely to casually screenshot and share. The IWF and NCA’s new guide for parents and carers is a useful thing to send directly — it explains the risks in plain terms, including how to limit who can see images and what to do if a child is targeted.
Under UK GDPR, consent has to be three things:
- Clear — parents understand exactly what they’re agreeing to. No legalese, no buried clauses.
- Freely given — they have a real choice, and saying no doesn’t penalise them.
- Specific — you ask for consent for each distinct purpose, not a blanket “I agree to photos”.
It also has to be recorded. You need to be able to prove a parent gave consent, what they agreed to, and when. A signed form, an online tick box, or a clear email reply all work. Don’t rely on a verbal yes. And remember consent can be withdrawn at any time — if a parent changes their mind, you need to act on it.
A sample consent checklist
Storing personal information
Using photos and videos
Parents' responsibilities
Photography that's harder to misuse
You don’t have to stop taking photos — you can take them more thoughtfully. The strongest learning stories often don’t need a face in frame. Close-ups of hands, feet and materials, shots from behind or over the shoulder, and group photos where no one face is clearly identifiable all tell a rich story and are far harder to misuse if they end up somewhere they shouldn’t. Some settings choose to avoid face-on shots in any shared or public context. That’s a decision for your setting, but it’s worth putting to your team.
Two practical points that often get missed:
Staff should use nursery devices, not personal phones. Images of children should be taken on nursery-issued devices that are secured and password-protected, then transferred to the app and deleted from the device. Personal phones create real safeguarding and data risks. If you do allow them, your policy needs to spell out exactly how that’s controlled.
Strip metadata before sharing externally. Every photo taken on a phone or tablet carries hidden data — date, time, device, sometimes GPS location. Images inside ParentZone sit on secure servers and aren’t publicly accessible, so the risk there is limited. But if you export anything for a newsletter, display or website, strip the metadata first. Most photo apps and operating systems can do this.
What your privacy policy needs to say
A consent form tells parents what they’re agreeing to. Your privacy policy tells them what you’re committing to. They’re not the same thing, and you need both. Most nurseries already have a policy; if not, the ICO publishes a free template.
On images specifically, it should make clear:
- Who does what — that you’re the data controller and your software provider (for ParentZone, that’s Connect Childcare) acts as data processor, storing and managing data on your instruction. That distinction matters under UK GDPR, and parents are entitled to know it.
- What images are used — photos and videos taken by staff, images uploaded by parents from home, and anything used for marketing or display.
- What they’re used for — daily updates, learning journeys, the keepsake journal, and any marketing use. Marketing is a separate purpose from a learning observation and needs its own consent.
- Who can see them — the child’s parents and linked carers, your staff, and, for group photos, the parents of other children in the same image.
- How long you keep them — set a retention period (often the child’s time with you plus a defined period after, commonly two years — check your own policy), after which images are deleted.
- Families’ rights — and that parents can come to you to exercise any of them.
Families' rights
Under UK GDPR, parents acting for their child can ask to:
- be informed about what data you hold and why
- access a copy of it
- have it corrected
- have it erased where appropriate
- restrict how it’s used
- take it elsewhere (portability)
- withdraw any consent they’ve given
- complain to the ICO
These rights apply directly to you as the nursery. Your software provider will support you where the data sits on their systems, but the responsibility to respond is yours. Respond within one calendar month. If a request is genuinely complex you can extend by two months, but you must tell the parent. For most nursery requests — a copy of photos, deletion of a child’s record — a month is plenty.
How ParentZone protects privacy
Not all platforms treat this the same way. Some allow group observations where parents can see the first names of other children in the same photo — and if another parent likes or comments, their name can show too. A first name paired with a photograph is personally identifiable information. That means families are being exposed to data about children they have no relationship with. Our advice is to always set up a test parent account on whatever parent app you use, so you can see exactly what your parents will see.
In ParentZone, we made a deliberate decision not to work that way. You can add multiple children to a group observation — it saves time when uploading — but each parent only ever sees the group photo, not the other children’s or parents’ names. It’s a small design choice, rooted in the principle this whole conversation comes back to: children’s privacy should be protected by default, not as an afterthought.
ParentZone also lets you disable the ‘Save Photos’ permission, which stops parents downloading images directly through the app. It’s a simple switch, and it’s worth having on by default unless you’ve a specific reason not to. Be clear on what it covers, though: it prevents direct downloads, but it can’t stop a screenshot on certain devices — that’s controlled by the device, not the software. No platform can prevent that entirely, which is why the setting works best as part of a wider approach, not a standalone fix.
Your strongest protection is still a clear, up-to-date policy your whole team understands and your parents have genuinely read — not just ticked a box on.
A practical checklist
Before parents start using the app
Once it's live
Ongoing
Common questions
What if a parent says no to photos?
Their child's images can't be used at all — including group photos where they might appear in the background. In practice this usually means their child isn't photographed during shared activities. Some settings manage this by keeping the child out of frame; others find a closed app isn't the right fit for that family. Either approach is fine as long as it's applied consistently.
What about photos a parent uploads of their own child?
These are still personal data, and the parent keeps rights over them — they can ask for them to be deleted at any time. Make clear in your guidance that parents shouldn't upload images including other children unless they have permission.
What if a parent screenshots and shares images on social media?
That's a breach of your consent terms. Your agreement with parents should make clear it will result in their app access being revoked. Follow through on it — it protects every family in your setting and makes clear your policies mean something.
Can AI tools really manipulate images from a closed app like ParentZone?
The primary risk is from publicly available images — your website, open social media, anything a search engine can find. Images in ParentZone are access-controlled and not publicly visible, which significantly reduces that risk. The concern is what happens once an image lands on a parent's device. Once it's there, you can't control where it goes — which is why parent education and clear consent terms matter as much as the software itself.
Should we stop using children's photos altogether?
That's a decision for your setting. Some providers have stopped using identifiable images in any context; others have reduced face-on photography without removing photos entirely. But a private, access-controlled app is a world away from posting publicly online — sharing a child's learning with their own parents through the app is a very different thing. What matters is that your policy is clear, your consent is properly obtained, and your parents understand their responsibilities.
What if our software provider gets a request from a parent directly?
They should redirect the parent to you. As a data processor, a provider can only act on the instruction of the data controller — you. You'll always be the first port of call for any parent request.
Do we need a Data Protection Impact Assessment (DPIA)?
The ICO recommends one where processing is likely to result in a high risk to individuals. For most nurseries using an app like ParentZone in line with this
Where to get more help
- Information Commissioner’s Office (ico.org.uk) — the best starting point for UK GDPR guidance, free templates and a helpline.
- UK Safer Internet Centre (saferinternet.org.uk) — guidance on protecting children’s images in early years and education settings, including a checklist for responding to image-based incidents.
- Internet Watch Foundation and the National Crime Agency (iwf.org.uk) — guidance for parents and carers on AI image misuse, worth sharing directly with your families. The IWF is also Europe’s largest hotline for reporting child sexual abuse imagery found online.
- Connect Childcare — for anything about how ParentZone handles data on your behalf, talk to your account manager or visit our helpdesk.
Share this article
About the Author
Marketing Lead at Connect Childcare
Latest Posts
Newsletter sign up
Get all the latest Connect news and updates to your inbox.