Vacation Bible School wraps up on a Friday. A volunteer with a good eye has taken about two hundred photos over the week, and by Sunday afternoon forty of them are on the church Facebook page and a dozen more are on the homepage. They’re lovely pictures. Kids painting, kids laughing, the closing-night crowd shot.
On Monday morning a mother calls the office. Her son is in the third photo in the album. She had asked, at registration, that he not be photographed. She did ask — it’s written on the form, in the box provided, and the form is in the binder where it belongs.
Nobody did anything wrong on purpose. The form was filled out correctly and filed correctly. The volunteer holding the camera simply had no way to know.
That’s the whole problem in one sentence, and it’s almost never a paperwork problem.
Consent that lives in a filing cabinet is not consent that the person holding the camera can see. A signed release is necessary. It is not remotely sufficient. The failure is in the distance between the form and the moment.
Why the form is the easy part
Most churches have a photo release. It’s usually bundled into the registration packet, alongside the medical authorization and the emergency contacts, and most parents sign it without much thought. That’s fine — it’s the legal foundation, and you need it.
But look at what happens after the signature. The form goes in a binder or gets scanned into a folder. The child comes to programs for the next four years. In that time, the volunteer roster turns over twice, a new children’s director arrives, VBS is run by a team of eleven people who have never seen the binder, and the church switches from Facebook to Instagram and adds a livestream.
The consent has not moved. The organization has moved a long way.
There’s a second issue, quieter but just as real: circumstances change. A family’s situation in September is not necessarily their situation in March. A custody arrangement changes. A parent leaves an abusive relationship. A foster placement begins. A blanket consent signed once, four years ago, does not reflect where that family is now — and no one has asked.
What a workable system looks like
Four pieces. None of them require software you don’t already have.
Record the consent per child, in the check-in system. Not per family, per child — siblings can have different situations, particularly in blended and foster families. If your church management software has a custom field or a flag, use it. The point is that the answer travels with the child automatically, every time they’re checked in, without anyone consulting a binder.
Make it visible at the moment it matters. This is the piece nearly everyone skips, and it’s the one that would have prevented the phone call on Monday morning. The volunteer with the camera needs to know without asking anyone. The common approaches: print the flag directly on the check-in label (“NO PHOTOS” in bold), or use a different colored wristband or lanyard for children who aren’t to be photographed. Whichever you choose, brief every volunteer on what it means in the first two minutes of their orientation, every time.
A note on dignity: don’t make the flag conspicuous to the other children in a way that singles anyone out. A label detail or a wristband color that only volunteers understand does the job. A child should never have to explain why they’re wearing the different color.
Refresh it annually. Once a year, at registration or the start of the program year, ask again. One line: has anything changed about photo permission for your child? This catches the situations that have shifted and costs nothing.
Name one person who reviews before anything is published. Not a committee. One person — usually the children’s director or the communications volunteer — who looks at every photo before it goes on the website, the social account, the newsletter, or the annual report. They’re checking two things: is every child in this frame cleared, and does this image follow the publishing rules below. A single named reviewer is the difference between a policy and an intention.
Publishing rules worth writing down
These apply to every child, including ones with full consent on file.
No full name next to a face. First names only in captions, and preferably not even that for identifiable close-ups. A photograph plus a full name is a substantially different piece of information than a photograph.
Nothing that identifies where a child will be, and when. No school names or logos, no jersey numbers with a team name, no captions like “the Wednesday 5:30 group.” The concern isn’t the single photo — it’s the combination. A face, a first name, a school, and a weekly schedule is a complete picture for someone with bad intent.
Be careful with anything that reveals a routine. A recurring photo of the same child in the same place at the same time each week is a pattern. The single crowd shot from the picnic is not.
Prefer wide shots and activity shots. A room full of children painting communicates the ministry just as well as a close-up portrait, and carries far less risk.
Handle foster, adoptive, and custody situations separately and seriously. For some children, a published photograph is not a privacy preference — it is a safety issue. A child in foster care may have a biological parent who is not permitted contact. A family may have relocated to get away from someone. A protective order may be in place. In these cases the answer is simply no photos, no exceptions, and the flag in the check-in system should say so without explaining why. The reason is nobody’s business but the family’s, and the fewer volunteers who know the circumstances, the better.
Make it easy for a parent to say no without a conversation. Some families cannot explain their situation to a church volunteer at a check-in desk. A checkbox they can tick in private is a kindness.
The data hidden inside the picture file
Here is the technical piece, and it’s simpler than it sounds.
EXIF — short for exchangeable image file format — is a block of information the camera writes inside the image file itself. It records the date and time, the camera model, the settings, and, if location services were on, the GPS coordinates of where the picture was taken. The National Security Agency’s guidance on location exposure states it plainly: pictures posted on social media may have location data stored in hidden metadata.
For a photo taken in the church building, the coordinates are your own address, which is already public. The risk shows up elsewhere: the youth retreat at a cabin, the small group meeting at a family’s house, the photo a volunteer took at a child’s home during a pastoral visit. Those coordinates are a home address, embedded in a file you published.
Three things to do about it, in order of how much effort they take:
Turn location off in the camera app on the phones used for ministry photography. On both iPhone and Android this is a per-app permission for the camera. Thirty seconds, and it solves the problem at the source.
Don’t assume the platform handles it for you. Some social networks process images on upload in ways that discard the metadata; others don’t, and their behavior changes without announcement. Your own website is the bigger concern regardless — on WordPress and most similar platforms, the original file you upload is stored on the server and is often the one served, metadata and all.
Check one file to see where you stand. Right-click an image on a Windows PC and choose Properties, then Details; on a Mac, open it in Preview and choose Tools, then Show Inspector, and look for a GPS tab. If you see coordinates, your images carry them. Many website platforms have a free plugin that strips metadata on upload; ask whoever manages your site to add one.
When someone asks you to take a photo down
Treat this as a normal, expected request, not a complaint. Say yes, do it quickly, and don’t ask for a reason. Someone asking may be in a situation they cannot describe.
Remove the original first. Take it off the page, the album, the gallery, the newsletter archive, and the livestream recording if the child appears in it. Removing it from the website while it stays on Facebook accomplishes nothing.
Then deal with the copies. This is the part people don’t anticipate. A published image can persist in a search engine’s cache and in the image results for a while after the original is gone. If the page is yours, Google’s Search Console has a removals tool that lets a verified site owner request temporary suppression and speeds up the refresh. If the image is on a page you don’t control — a partner ministry’s site, a community news roundup — Google publishes a Refresh Outdated Content tool specifically for people who don’t own the page, which works once the content has actually been removed at the source. Both are free.
Be honest about the limits. Anything that was public may have been downloaded or reshared, and you cannot recall that. Say so plainly and kindly. What you can promise is that it’s gone from everywhere you control, promptly, and that the child’s record is updated so it doesn’t happen again.
Update the flag. A removal request is a consent change. Record it in the check-in system the same day, or you will have this conversation twice.
Get it in front of your insurer and your lawyer
Consent requirements for photographs of minors are not uniform. They vary by state, and your denomination or insurer may impose additional standards that are stricter than state law. Some liability policies and child-protection programs have specific requirements about media releases and how they’re documented.
Write your policy first — it’s a one-page document — then send it to two people: your attorney, and whoever handles your liability insurance. Ask them plainly whether your release form and your process meet what they expect. This article describes the general shape of the problem and is not legal advice; the specifics belong to someone licensed to give them.
While you’re at it, ask about your background check and volunteer screening records too. They live in the same binder and raise the same retention questions.
What to do this week
Open your check-in system and find out whether it can hold a per-child photo permission flag that prints on the label. Most can. If yours can, turn it on and spend twenty minutes entering what you already have on file. If it can’t, buy a pack of colored wristbands and write the rule on an index card taped to the check-in desk.
Then name your reviewer — one person, by name, who sees every photo before it’s published — and tell them.
That’s under an hour, and it closes the gap between the form and the camera.
Photos are one category among several worth a second look. MissionDefend’s free assessment walks through how your organization handles member data, children’s information, email, and donations in plain English, and hands back a baseline score with a ranked list of what to address first.
No spam and no sales calls — just one email when it’s live.
Related reading
- the seasonal helpers holding the camera and the tablet
- children’s faces on a stream anyone can join
- protecting the rest of what families hand you
MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.
Sources: National Security Agency, Limiting Location Data Exposure; Google, Refresh Outdated Content tool; Google, Removals and SafeSearch reports tool.


