What Early Years settings need to know about protecting children's images

Childminding

AI tools that can copy, alter or clone children’s images and voices are now freely available. For nurseries and early years settings that routinely share photos, videos and audio online, this creates new risks and difficult questions; what if that content is misused by someone else? And could the setting or an individual practitioner be held liable?

This article explains the main risks, when liability might arise, what good consent looks like, practical do’s and don’ts, what to do if misuse is discovered, and how insurance may respond.

 

What are the risks?

Once a child’s image or voice is online, the setting loses a degree of control. Content can be:

  • Copied and reshared on other sites or apps without permission.
  • Manipulated using AI such as deepfakes, face swaps or voice cloning that make it appear a child said or did something they never did.
  • Combined with other information such as names, uniforms, locations, routines, which can be used to identify or track a child.
  • Used in harmful ways, including bullying, harassment, blackmail or sexualised misuse.

Whilst the risks feel unlikely in day‑to‑day practice, they are no longer purely theoretical. The Children’s Commissioner has warned about readily available. AI tools being used to create explicit images of children, whilst Police Scotland now provides specific guidance on reporting deepfakes.

AI-generated content can also look extremely convincing, and it may not be immediately obvious to parents, staff or online platforms that an image or recording is fake.

 

Would the nursery, setting or practitioner be liable?

Not automatically. If the setting has obtained valid permission, used the image only for the agreed purpose and taken reasonable steps to protect it, the setting wouldn’t normally be responsible simply because a third party copied a publicly available image and misused it.

 The person creating or sharing the illegal content would generally bear primary responsibility. However, the setting or practitioner could face questions about its own actions if it:

  • Posted images outside the scope of the permission given
  • Published more identifiable information than was necessary
  • Failed to follow its own guidance or internal policies on images, social media, safeguarding or privacy policy
  • Continued using an image after permission had been withdrawn
  • Stored images insecurely, with weak access controls, or allowed unauthorised access
  • Uploaded children's images or voices into an AI platform without understanding how the provider would retain use or train their systems on the information
  • Become aware of misuse but failed to take appropriate safeguarding or breach response action

Photographs and voice recordings can constitute personal data where the child is identifiable. Organisations handling children's information must take particular care and consider the child's best interest. ICO guidance also states that sharing children's data requires extra care and a compelling reason. Liability would therefore depend on matters such as:

  • What permission was obtained
  • What parents were told
  • Where and how the content was published
  • The security measures in place
  • Whether the incident resulted from a data breach or staff action
  • Whether the setting responded appropriately once it became aware

A setting could potentially face a complaint, an ICO investigation, a civil claim or regulatory scrutiny where its own failure contributed to the harm. That is different from being held responsible for every unauthorised act committed by someone who finds image online.

In many cases, settings that follow their policies, keep parents well informed and respond sensibly to concerns are unlikely to face formal action.

 

Does parental permission protect the setting?

Parental permission is essential, but it does not remove all responsibility from the setting or transfer it to the parent

Good, documented consent:

  • Shows that parents were informed and agreed to specific uses
  • Reduces the likelihood of complaints and claims
  • Demonstrates a responsible approach to regulators and insurers

However, even with signed consent:

  • You must stay within the scope of what was agreed - how, where and why images or recordings are used
  • You must still meet your data protection, privacy and safeguarding obligations
  • You must protect data appropriately, with secure systems and careful access controls

If a setting misuses images or falls short in privacy, security or response, parental permission does not negate liability.

 

What does good consent look like?

The ICO states that consent requests should be prominent, concise, understandable and separate from other information.

A broad statement such as ‘I consent to photographs being used promotional purposes’ no longer gives families enough information. A stronger approach would explain that material placed on public websites and social media can be copied or altered by third parties including with AI. This is not about alarming parents, but about being open and honest so they can make informed choices.

Consent should be:

  • Clear and specific
  • Separate from general terms and conditions
  • Documented
  • Easy to withdraw
  • Explicit about where images may and may not appear

  

Practical steps that settings can take

Settings shouldn’t be discouraged from sharing photographs, but they should limit and structure the information available to someone who may misuse them.

Good practice looks like:

  • Have clear, written internal guidelines on taking, storing and using images, videos and audio, covering all team members and in line with safeguarding, data protection and social media policies.
  • Make sure your privacy policy is easy to find, such as on your website, and it explains how images and recordings are used in simple terms.
  • Limit what you post publicly by choosing a small number of images that show your ethos and activities, and favour group scenes, rather than close‑ups of individual children.
  • Reduce identifying details such as pairing images with names or very specific setting name and location information.
  • Use secure platforms when sharing photos and updates directly with families, rather than relying solely on open social media.
  • Control access with strong passwords and role‑based permissions and avoid shared generic logins.
  • Use setting‑owned devices for taking and storing images and keep them updated and protected.
  • Train staff on your policies, the consent process and the issues AI introduces.
  • Have an incident‑response plan, so everyone knows what to do if a concern about misuse is raised.
  • Keep basic records of consents, where content is shared and any issues or questions raised by parents.
  • Never upload an identifiable image or voice recording of a child in a public generative AI tool, as you may not be able to control how that data is stored, used or shared

 

What should a setting do if misuse is discovered?

If you discover, or are told, that a child’s image or voice originating from your content has been copied or misused elsewhere, you should consider both the safeguarding aspects and any potential data‑protection or cyber implications.

  • Act quickly and restrict or remove the original post where appropriate.
  • Save evidence such as screenshots, links, dates and times before it disappears, but do not download or forward on.
  • Follow your internal incident process and notify your designated safeguarding lead and data protection lead.
  • Assess any safeguarding implications and whether this might be a personal data breach.
  • Inform parents/carers explaining what has happened, what you know so far and the steps you are taking.
  • Contact the platform using the reporting tools to request removal of the copied/misused content.
  • Notify your insurer or broker promptly, report suspected activity to Police Scotland and your regulatory body.
  • Take advice on whether you need to notify the ICO and follow the required process and timeframes.
  • After the immediate response, review your consent processes, posting practices, security controls and staff training to reduce the chance of recurrence

 

How insurance cover may respond

A setting is not automatically liable if a child’s image is copied and misused by someone else. Questions of liability, and whether cyber, privacy or media liability sections of a policy* may respond, are more likely to arise when it is suggested that the setting:

  • Used images without valid or adequate consent
  • Used images beyond what parents understood and agreed to.
  • Had weak security or access controls
  • Did not follow external guidance, its own policies or internal guidelines
  • Delayed or handled things poorly once a concern was raised.

Good consent, clear policies, a publicly available privacy notice, strong internal guidelines for all staff and volunteers, and a sensible approach to posting and security all help evidence that the setting has acted responsibly. These measures are also in line with what is typically expected under cyber and data/privacy liability covers.

*Exact policy responses will depend on your individual cover and wording, so it’s always sensible to discuss any concerns with your broker or insurer.

If an issue does arise:

  • Contact your broker or insurer promptly, sharing clear, factual information.
  • Follow any guidance they offer around communication, investigation and any possible regulatory contact.

 

In summary

AI has added an extra layer to something Scottish early years settings already take seriously: using children’s images and voices safely and respectfully. The fundamentals remain the same. You may not be able to completely prevent a publicly shared image from being misused, but you are responsible for making careful, proportionate decisions about what you publish, securing clear and informed consent, and responding promptly and thoughtfully if something does go wrong.

 

Morton Michel Ltd is authorised and regulated by the Financial Conduct Authority, Firm Reference Number 527300. Registered in England and Wales under Registration Number 5120835. Registered Office: Rossington’s Business Park, West Carr Road, Retford, Nottinghamshire, DN22 7SW. Morton Michel Ltd is part of the PIB Group.

This article is for general guidance only and does not constitute legal, regulatory, data protection or safeguarding advice. Early years settings should refer to their own policies and procedures, relevant legislation and regulatory guidance, and seek independent legal or professional advice where needed. While every effort has been made to ensure accuracy at the time of writing, no responsibility is accepted for any loss arising from reliance on this material.