Photos and videos help organisations tell stories that policies, reports and statistics cannot. They show real people, communities, services and outcomes.
But as your visual content library grows, it becomes harder to answer a basic question:
Are we allowed to use this image?
The consent form may exist, but it is often stored separately from the image. A staff member may know permission was provided but not which channels it covers. An older photo may still be circulating even though consent has changed.
Different versions might also be sitting in a shared drive, an inbox and an agency folder, with no clear indication of which one is approved.
Managing photo and video consent therefore involves more than collecting a signed form. Your organisation needs a practical way to connect consent information to the relevant content, make usage conditions clear and respond when something changes.
Consent is usually collected at the beginning of a process: during participant onboarding, before an event, as part of a photo shoot or when someone agrees to share their story.
The content then follows a very different path. It may be downloaded, renamed, edited, copied into campaign folders, sent to an agency or reused months or years later.
This separation creates several common problems:
These risks increase when content is created across different programs, locations and events, or when staff, volunteers, agencies and external partners all need access.
A record stating that consent was obtained may not give a communications team enough information to make a safe decision.
The intended use matters. The Office of the Australian Information Commissioner explains that if an organisation wants to use an identifiable image for a purpose the person was not originally told about, it may need to obtain consent for that additional use.
Depending on your organisation’s activities and policies, useful information may include:
Your specific requirements should reflect your organisation’s privacy, safeguarding, records management and legal responsibilities.
The operational goal is to give authorised staff enough reliable information to make the right decision before using the content.
A consent form sitting in a document management system is not particularly useful if the person selecting a photograph cannot determine which form applies to it.
The relationship between the consent record and the digital asset needs to remain clear throughout the asset’s lifecycle.
Some organisations manage this through consistent identifiers, filenames and documented folder structures. Others use metadata fields within a digital asset management system to record consent status, approved uses, restrictions and review dates alongside the asset.
The right approach depends on:
Whatever system you use, test it from the perspective of a busy staff member.
Can they find or open a file and quickly understand whether it is approved, what it can be used for and whether they need to check anything before publishing it?
Avoid relying on ambiguous notes, filenames or folder names. A small set of agreed statuses makes decisions easier and helps different teams follow the same process.
For example:
The wording of the labels matters less than consistency. Everyone selecting, downloading or distributing content should understand what each status means and what action it requires.
Consent management should protect people without making useful content impossible to access.
If approved assets are difficult to find, staff may reuse whatever they already have, request the same content again or download files into personal folders where important information is easily lost.
Helpful search information can include:
Staff should also be able to distinguish current, approved assets from drafts, duplicates and outdated versions.
For agencies and external partners, consider providing access to a curated collection containing only the assets approved for their particular purpose. This can be easier and safer to manage than sending attachments or opening access to an entire shared drive.
Not everyone needs access to every file.
Content involving children, clients, health information or vulnerable people may require tighter controls than general event photography or brand assets.
A practical access model should allow your organisation to:
Access controls should support your consent process, but they should not be treated as a replacement for clear approvals, usage information and staff responsibilities.
Consent should not be treated as a form that disappears into an archive.
People may ask questions, change their preferences or withdraw consent. Your organisation needs a documented process that staff can follow when this happens.
That process could include:
The faster your organisation can connect a person, their consent record and the affected assets, the easier it is to respond consistently.
A good image and video consent process covers more than final publication.
Review how content is:
Useful questions to ask include:
If your organisation cannot answer these questions easily, the problem may not simply be where the files are stored. It may be how content, consent information, permissions and access are managed together.
A carefully managed shared drive may be adequate for a small collection used by a small team.
Problems tend to emerge as the library grows, the content becomes more sensitive and more people need access. Folder structures become inconsistent, files are duplicated and consent information becomes separated from the assets it applies to.
Digital asset management technology can help by:
Technology does not replace good consent policies, informed decision-making or appropriate legal advice. It can, however, make an agreed process much easier for staff to follow consistently.
The first step is not necessarily buying new software. It is understanding where your current process breaks down, what information your staff need and what level of control is appropriate for your organisation.
Is your consent information connected to your content?
Use our practical checklist to review how your organisation manages consent-sensitive images and videos.
databasics helps Australian and New Zealand organisations review how they manage images, videos and other digital content.
We can help you identify gaps, improve existing processes and determine whether your organisation needs better governance, a digital asset management system or improvements to the technology it already uses.
Disclaimer: This article provides general information about managing digital content and consent records. It is not legal advice. Organisations should obtain advice appropriate to their responsibilities, activities and jurisdiction.
For a more comprehensive discussion and real-life examples download our eBook: Managing Privacy and Consent in a DAM Solution .