DISCLAIMER: Privacy regulations evolve constantly, and this overview cannot substitute for professional legal counsel. While we’ve outlined key considerations, photographers should regularly research their state’s specific requirements and consult with an attorney specializing in privacy law before implementing any data collection practices. This article merely scratches the surface of a complex legal landscape that deserves thorough examination.

Privacy Policies and School Photography

In this era of pervasive biodigital surveillance—where cameras track pupils dilating and algorithms map the unique vascular patterns beneath our skin—it has become absolutely imperative that we disclose comprehensive privacy policies to anxious parents when using automated package ordering systems.

This is especially crucial for sophisticated models that employ facial geometry recognition and the latest biodigital software, which can identify a child from thirty paces by their distinctive gait alone.

ARE PHOTOGRAPHERS DISCLOSING THE PRIVACY POLICIES?

Our investigation suggests most photographers aren’t. After examining the privacy policies of major product-ordering software companies, we’ve found concerning gaps. Unlike these new systems—which bombard parents with texts and emails to drive purchases and maximize upsells—we maintain traditional practices for principled reasons.

Just last week, we attended a webinar where a representative openly admitted that profit maximization was their primary objective. This runs counter to everything we stand for. While we certainly aim to sustain our business, we believe that when financial gain becomes your sole focus in this industry, you’ve lost sight of why this work matters. If that’s your priority, perhaps this message isn’t for you.

PHOTOGRAPHERS BEAR RESPONSIBILITY

As professional photographers, we bear a sacred responsibility when selecting our ordering systems. When you choose invasive digital platforms that compromise the privacy of our youngest and most vulnerable subjects, you betray the fundamental trust parents place in you—a violation we cannot and will not condone.

PARENTS RARELY SCRUTINIZE THE PRIVACY POLICIES

Perhaps we’re unusually vigilant about privacy in an age when most dismiss these concerns with a shrug. This article exists to sound an alarm you may not have heard. Some will argue that parents bear the responsibility to review privacy policies before consenting. But consider the reality: these are children’s data at stake, and their parents navigate exhausting daily marathons of work, childcare, and school commitments. They rarely have time to scrutinize the fine print of software you’ve strategically placed before them.

ONE MAJOR BRAND

We won’t be naming specific companies here. In our litigious climate, those who speak truth to power often find themselves served with cease-and-desist letters before their coffee goes cold. Corporate legal departments with unlimited resources have made an art form of silencing well-intentioned whistleblowers through strategic lawsuits designed to exhaust both finances and resolve.

We implore you to check the privacy policy before signing up. These are just a few things you will find among the privacy policies of the major companies. Some good, and some not so good.

ONE COMPANY WRITES DON’T LIKE IT, DON’T USE US

If you do not want us to use or disclose Personal Information collected about you in the manner identified in this Privacy Policy, you may not use the Service.

They are collecting biodigital data on your child with thier facial recognition software. The point is, you need to be aware of what policies are before doing business with companies, so you may take steps to protect yourself.

MORE EXAMPLES OF CONCERNING PRIVACY POLICIES

Information You Provide About Others
“The content you choose to upload to our service, including your photos and the information you store in your address book, may include personal information of others. If you choose to share your photographs or other information with someone else through a feature we offer, we will use the personal information you provide (for example, the e-mail address of the recipient) to fulfill your request and for other purposes described in this Privacy Notice. Before you upload and/or share personal information of others through our service, please ensure that you have the consent of such persons to do so.”

Kids are using this service. Do you think they are calling thier friends to get permission?

SOME COMPANIES HAVE GOOD POLICIES

Federal Children’s Online Privacy Protection Act of 1998 (COPPA, 15 U.S.C. § 6501 et seq.), we do not knowingly solicit, or accept personally identifiable information from users known to be under thirteen (13) years of age without the consent of their educational institution or the child’s parent or guardian.

SOME WILL NOT SHARE YOUR PHOTOS

The good companies advise that they share the data for order fulfillment only, and those companies can’t use it for any other purpose.

BIODIGITAL DATA: THE WAY OF THE FUTURE


WHAT IS BIOMETRIC DATA?
Biometric data is any physical trait that can identify you, like fingerprints, voice, face shape, or eye scans. It is also referred to as biometric identifiers.

A photograph itself doesn’t constitute biometric data; however, when companies apply facial recognition algorithms and other analytical technologies to these images, they extract unique biological identifiers that absolutely qualify as biometric information.

PHOTOGRAPHY STUDIOS AND BIOMETRIC DATA

One major company puts this in the policy.

Our photography studio customers (collectively, “Studios”) are responsible for developing and complying with their own biometric data retention and destruction policies as may be required under applicable law.

This shifts legal responsibility for biometric data collection entirely onto the individual photography studios.

They write: “Our Studio customers are responsible for compliance with applicable law governing their collection, storage, use, and/or transmission of biometric data, and where required by law, must obtain written consent to collect, store, use, and/or transmit biometric data prior to the collection of such data.”

The company has a good policy and does NOT share biometric data outside of their system, but they say the following, and who is paying attention to this?

Prior to collecting, storing, using and/or transmitting biometric data, and prior to submitting, or causing the submission of, such biometric data to (the company) systems or software, you have provided each individual to whom such biometric data relates a copy of this Policy and have obtained such individual’s written consent as required by law; (3) you are solely responsible for ensuring that all features and functionality you utilize that enables or relies on the collection or use of biometric data comply with all applicable law; and (4) you have provided notice of this Policy to each individual from whom you have collected biometric information.

THEY SAY THE STUDIO MUST SUPPLY A WRITTEN NOTICE

The automation is relentless. Your child smiles for the camera on picture day, and within hours, your phone buzzes with promotional texts while your inbox fills with purchase options. Yet amid this digital barrage, when exactly do photographers distribute the written privacy policy explaining how your child’s biometric data will be used? This critical information seems conspicuously absent from the automated workflow.

During the webinar we attended, a photographer described the process: “Once you upload the photos, first comes the notification, then the orders start rolling in—one after another after another. The system handles everything automatically.” So, where is the studio supplying the copy of the policy and receiving their written consent?  They don’t mention this. It doesn’t mean they are not doing this, but why would this not be discussed in the workflow if it is “BY LAW”?

WHAT IS THE BOTTOM LINE?

We consider the protection of children’s data an absolute requirement. Our studio refuses partnerships with any educational institution or software ordering service unwilling to demonstrate stringent privacy safeguards or whose data security protocols raise concerns.

OUTDOOR SPORTING EVENTS AT SCHOOLS

According to:

Brian FarkasAttorney · Benjamin N. Cardozo School of Law
Updated: Jun 12th, 2017 “School Districts Protect Children.”

States and municipalities have the right to make their own laws regarding issues such as photographing children. School districts can restrict filming and photography on their grounds and the use of images without parental consent. However, some schools might not prohibit group photos if the photographer does not identify any of the children when publishing them, or photos of certain extracurricular activities, such as sporting events.

Private schools, summer camps, and other private institutions can also enforce their own policies restricting the use of videos or photographs on their premises. Because these are privately owned, the owners have greater ability than the government to prevent individuals from taking photos or videos of children.

Consequently, as long as a photographer uses the images for editorial purposes, and if the photographer took them while your child was in a public setting, the photographs are generally within the law even if you do not give your consent. An example would be a newspaper article about the condition of playgrounds in public parks; a journalist could publish a photo that includes your child playing in the public park without your consent.

RECENT PRIVACY EVENTS – CHINESE DATA COLLECTION ON CHILDREN!

The Department of Justice recently settled a case against Apitor, a Chinese company making app-connected toys for children. The lawsuit, filed in California, alleged that Apitor permitted a Chinese analytics firm to collect location data from children under 13 without parents’ knowledge or permission—a clear violation of the Children’s Online Privacy Protection Act. The company now faces a $500,000 fine and must implement strict oversight measures while surrendering all improperly gathered information.

In early September 2025, a company agreed to pay $10 million to settle Federal Trade Commission charges that it violated COPPA regulations. According to federal regulators, the entertainment giant failed to mark its child-oriented YouTube content with the required “Made for Kids” designation, enabling the company to harvest children’s personal information and deploy targeted advertisements without securing parental permission.

CHECK THE LAWS IN YOUR STATE

BUT… things change, and states enact new laws, so be sure to check the laws in your state. When in doubt, consult legal advice.

This article is in no way whatsoever any kind of legal advice.

error: Content is protected !!