In this post
Get the latest insights delivered to your inbox
Photos and videos help organisations tell stories that policies, reports and statistics cannot. They show real people, communities, services and outcomes.
But as your visual content library grows, it becomes harder to answer a basic question:
Are we allowed to use this image?
The consent form may exist, but it is often stored separately from the image. A staff member may know permission was provided but not which channels it covers. An older photo may still be circulating even though consent has changed.
Different versions might also be sitting in a shared drive, an inbox and an agency folder, with no clear indication of which one is approved.
Managing photo and video consent therefore involves more than collecting a signed form. Your organisation needs a practical way to connect consent information to the relevant content, make usage conditions clear and respond when something changes.
Why managing image consent becomes difficult
Consent is usually collected at the beginning of a process: during participant onboarding, before an event, as part of a photo shoot or when someone agrees to share their story.
The content then follows a very different path. It may be downloaded, renamed, edited, copied into campaign folders, sent to an agency or reused months or years later.
This separation creates several common problems:
- Consent forms and visual files are stored in different systems.
- Filenames do not identify the people shown or the permissions attached.
- Staff rely on someone’s memory to determine whether content is safe to use.
- Usage conditions are lost when files are downloaded, copied or shared.
- Older, unapproved or superseded versions remain accessible.
- The organisation cannot quickly identify affected content when consent changes or is withdrawn.
These risks increase when content is created across different programs, locations and events, or when staff, volunteers, agencies and external partners all need access.
What consent information should you record?
A record stating that consent was obtained may not give a communications team enough information to make a safe decision.
The intended use matters. The Office of the Australian Information Commissioner explains that if an organisation wants to use an identifiable image for a purpose the person was not originally told about, it may need to obtain consent for that additional use.
Depending on your organisation’s activities and policies, useful information may include:
- The person or people shown in the image or video
- When and how consent was obtained
- The purposes for which the content can be used
- Approved channels, such as your website, social media, email, print or internal communications
- Geographical, cultural or other usage restrictions
- Whether consent was provided by a parent or guardian
- A review or expiry date, where applicable
- The person or team responsible for the consent record
- What should happen if consent is changed or withdrawn
Your specific requirements should reflect your organisation’s privacy, safeguarding, records management and legal responsibilities.
The operational goal is to give authorised staff enough reliable information to make the right decision before using the content.
Connect consent information to the relevant images and videos
A consent form sitting in a document management system is not particularly useful if the person selecting a photograph cannot determine which form applies to it.
The relationship between the consent record and the digital asset needs to remain clear throughout the asset’s lifecycle.
Some organisations manage this through consistent identifiers, filenames and documented folder structures. Others use metadata fields within a digital asset management system to record consent status, approved uses, restrictions and review dates alongside the asset.
The right approach depends on:
- How much visual content your organisation manages
- How sensitive that content is
- How frequently it is used
- How many people need access
- How often content is shared externally
Whatever system you use, test it from the perspective of a busy staff member.
Can they find or open a file and quickly understand whether it is approved, what it can be used for and whether they need to check anything before publishing it?
Use clear and consistent consent statuses
Avoid relying on ambiguous notes, filenames or folder names. A small set of agreed statuses makes decisions easier and helps different teams follow the same process.
For example:
- Approved: Available for the uses recorded
- Awaiting approval: Not yet available for publication
- Restricted: Approved only for specified audiences, channels or purposes
- Internal use only: Not approved for public distribution
- Review required: Consent or usage conditions need to be checked
- Withdrawn or expired: Must not be used
The wording of the labels matters less than consistency. Everyone selecting, downloading or distributing content should understand what each status means and what action it requires.
Make approved content easy to find
Consent management should protect people without making useful content impossible to access.
If approved assets are difficult to find, staff may reuse whatever they already have, request the same content again or download files into personal folders where important information is easily lost.
Helpful search information can include:
- Program or service
- Location
- Event
- Campaign
- People shown
- Date created
- Content owner
- Consent status
- Approved channels
- Review or expiry date
Staff should also be able to distinguish current, approved assets from drafts, duplicates and outdated versions.
For agencies and external partners, consider providing access to a curated collection containing only the assets approved for their particular purpose. This can be easier and safer to manage than sending attachments or opening access to an entire shared drive.
Control access according to risk and need
Not everyone needs access to every file.
Content involving children, clients, health information or vulnerable people may require tighter controls than general event photography or brand assets.
A practical access model should allow your organisation to:
- Limit sensitive content to authorised people or teams
- Give staff, volunteers and partners appropriate levels of access
- Share approved assets without exposing the wider content library
- Remove access when someone changes roles or leaves
- Keep an appropriate record of changes and distribution
Access controls should support your consent process, but they should not be treated as a replacement for clear approvals, usage information and staff responsibilities.
Have a process for changed or withdrawn consent
Consent should not be treated as a form that disappears into an archive.
People may ask questions, change their preferences or withdraw consent. Your organisation needs a documented process that staff can follow when this happens.
That process could include:
- Confirming the request and identifying the content it affects
- Locating the relevant original files, edits and copies
- Changing the asset’s consent status
- Restricting future access and use
- Checking where the content has already been published or distributed
- Notifying teams, agencies or partners that need to take action
- Recording what was done and when
The faster your organisation can connect a person, their consent record and the affected assets, the easier it is to respond consistently.
Review the complete content lifecycle
A good image and video consent process covers more than final publication.
Review how content is:
- Captured
- Transferred
- Described
- Approved
- Stored
- Accessed
- Shared
- Reviewed
- Archived or removed
Useful questions to ask include:
- Who collects consent, and when?
- How is each consent record connected to the relevant files?
- Who confirms that content is approved?
- How can staff see restrictions before downloading or sharing?
- What happens to local copies and files already sent to partners?
- Who is responsible when consent changes?
- How often are older assets and permissions reviewed?
If your organisation cannot answer these questions easily, the problem may not simply be where the files are stored. It may be how content, consent information, permissions and access are managed together.
When shared folders are no longer enough
A carefully managed shared drive may be adequate for a small collection used by a small team.
Problems tend to emerge as the library grows, the content becomes more sensitive and more people need access. Folder structures become inconsistent, files are duplicated and consent information becomes separated from the assets it applies to.
Digital asset management technology can help by:
- Keeping approved master files in one place
- Attaching searchable metadata and usage conditions to assets
- Managing approval and expiry statuses
- Controlling who can access sensitive content
- Managing versions and reducing duplication
- Providing approved collections for different teams and external users
- Making affected assets easier to identify when consent changes
Technology does not replace good consent policies, informed decision-making or appropriate legal advice. It can, however, make an agreed process much easier for staff to follow consistently.
The first step is not necessarily buying new software. It is understanding where your current process breaks down, what information your staff need and what level of control is appropriate for your organisation.
Review how your organisation manages consent-sensitive content
Is your consent information connected to your content?
Use our practical checklist to review how your organisation manages consent-sensitive images and videos.
How databasics can help
databasics helps Australian and New Zealand organisations review how they manage images, videos and other digital content.
We can help you identify gaps, improve existing processes and determine whether your organisation needs better governance, a digital asset management system or improvements to the technology it already uses.
Disclaimer: This article provides general information about managing digital content and consent records. It is not legal advice. Organisations should obtain advice appropriate to their responsibilities, activities and jurisdiction.
For a more comprehensive discussion and real-life examples download our eBook: Managing Privacy and Consent in a DAM Solution .
.png?width=600&height=276&name=Privacy%20and%20consent%20book%20cover%20%20(2000%20x%201080%20px).png)