Denne siden finnes også på bokmål.

Photos of children

Photos of children in the class and the team.

The trip was lovely and the photos came out well. Before they are shared, whoever shares them has to be able to answer three questions: Do we have consent? Who sees the photos where they end up? And can they be deleted again?

What Datatilsynet asks for

The advice is short, and it holds in closed groups too. You do not share photos of other people's children without consent from the guardians. A group that takes photos itself is responsible for them, and the consent has to say what the photos are to be used for. Datatilsynet (the Norwegian Data Protection Authority) has a consent form template you can use as it is.

The child should be heard too, and more the older it gets. If the child says no, the answer is no. And a consent can be withdrawn, so a photo has to be findable again and possible to delete.

Finally, Datatilsynet asks you to consider the channel the photos are shared in: who sees them there, and what they are used for.

The checklist

  1. Get written consent from the guardians before the first sharing, with a clear purpose. The template above can be used as it is.
  2. Ask the child too, at the child's level, and respect the answer.
  3. Choose a channel where you know who sees the photos, and where they are not used for anything else.
  4. Have a way to delete: the person who asks for a photo to be removed should not need to know where everything sits.
  5. Treat name lists and absences as carefully as photos, because who was not at training is also a detail about a child.

What the choice of channel means

‘Consider the channel’ is the advice most often left unanswered, so here are the questions to ask, whichever service you land on. Do you know who can see the photos, as a list of names? Are they used for anything other than being shown to the group, advertising or profiling for instance? Can search engines find them? And do they actually go away when you delete them?

An open stream answers all four badly. A closed circle with a list you run yourselves answers them well.

How kauke answers

  • The access list is the channel. Only the people on the list see the photos, and the pages are never indexed by search engines.
  • The photos are not used for anything else. No advertising, no profiling, and we do not sell data.
  • Deleting is an action, not an application. Someone in charge can delete a photo or remove a person's access at any time.
  • Guardians are included with no detour. They are invited with an e-mail address or a mobile number, log in with a link by e-mail or with Vipps, and reply for their children on events.
  • The data is stored in Europe. More about what we store and why is on the privacy page.

What kauke does not solve

The consents are still yours. kauke does not know who has consented to what, so the group has to keep the forms and the overview itself, and whoever puts up a photo has to know that the consent exists. And a photo that has been downloaded to somebody's phone is outside every service's control. Share accordingly, here too.

Set up a group Read about privacy