Nonprofits
Managing Photo Consent and Usage Rights for Nonprofits
If you're second guessing whether to use that photo or not, you should probably read this guide

Topics
Creative Workflows
Abstract
Consent, copyright, and internal approval answer different questions about whether a nonprofit can use an image. A dependable workflow records the evidence, permitted uses, restrictions, review dates, and withdrawal status with the asset, then shows that information before anyone downloads or publishes it.
A photo can be easy to find but still be difficult to use. Typical cases include the subject having agreed to one campaign but not another or the photographer may have licensed the image for a limited term. There's instances where a program participant could later ask the organization to stop using their story.
When those decisions live in forms, inboxes, spreadsheets, or staff memory, the photo library cannot answer the question that matters: is this asset cleared for use?
This article covers the operational side of that problem. The organization’s legal or privacy lead should define the policy and applicable requirements. The asset workflow should make those decisions visible and enforceable.
For a broader system, read The Nonprofit Digital Asset Playbook: Organize, Protect, Reuse.
Separate consent, ownership, and approval
These terms are often grouped together, but they cover different risks.
Check | Question it answers |
|---|---|
Subject consent or other lawful basis | Can the organization collect and use the person’s image for this purpose? |
Copyright or license | Does the organization own the photo or have permission from the creator to use it? |
Internal approval | Has the organization cleared this version, message, and context for publication? |
Brand and program restrictions | Is the asset appropriate for this audience, channel, location, and campaign? |
An asset may pass one check and fail another. A signed release doesn’t transfer copyright from the photographer and ownership of the file doesn’t settle how an identifiable person’s image may be used.
Privacy and image-use requirements vary by jurisdiction and circumstance. In Canada, specifically, the Office of the Privacy Commissioner’s meaningful-consent guidance emphasizes clear purposes, understandable information, accessible choices, and ongoing review. Your organization should translate the rules that apply to it into a documented policy.
Use a status model people can understand
A yes-or-no field is rarely enough. Give every asset a status that tells users what action to take.
Status | Meaning |
|---|---|
Pending | Evidence or review is still required; do not publish |
Approved | Cleared for the uses recorded on the asset |
Restricted | Available only for named channels, audiences, regions, or purposes |
Expired | The approved term or license has ended; review before reuse |
Withdrawn | Future use has been stopped following a request or policy decision |
Unknown | The record is incomplete; keep out of shared and public collections |
Use language that staff, volunteers, and partners can interpret without legal training. The detailed evidence can remain available to authorized reviewers, while everyday users see a clear status and any relevant restrictions.
Record the information needed at reuse
The asset record should preserve both the decision and the evidence behind it. A workable consent and rights record usually includes:
Field | What to capture |
|---|---|
Subject or group | Person, guardian, participant group, or event associated with the record |
Evidence | Release, agreement, notice, intake record, license, or policy reference |
Purpose and channels | Website, email, social, paid media, print, press, internal use, or another defined use |
Geography and audience | Any regional, program, partner, or audience limits |
Term | Start date, expiry date, review date, or approved campaign period |
Restrictions | Sensitive context, attribution, cropping, editing, or distribution conditions |
Owner and reviewer | Person or role responsible for the record and its approval |
Withdrawal history | Request date, action taken, affected versions, and completion status |
Tip: Avoid collecting unnecessary personal information. The goal is to support the organization's policy and publishing decisions.
Connect consent to the asset at intake
The easiest time to capture context is when the photo or video immediately enters the organization.
Confirm the source
Record who created the content, which event or program produced it, and where the original evidence is stored. If one release covers several files, connect the record to the full set rather than relying on similar filenames.
Assign a status before wider access
New content should enter a review area at least at the beginning. Assets with approved terms can move into the appropriate shared collection. Pending, unknown, or restricted content should remain visible only to the roles responsible for resolving it.
Surface the decision at selection and download
People should see the current status, permitted uses, restrictions, and expiry before they reuse the asset. Add notes where needed with timestamps.
Keep the record with every version
Crops, retouched files, alternate formats, and video edits should remain connected to the source asset and its rights record. Otherwise, a restricted original can produce a derivative that appears unrestricted.
Create a withdrawal process before you need one
When a person asks a nonprofit to stop using their image, the team needs a clear route from request to action.
Record the request, change the asset status, remove it from shared or public collections, and identify related derivatives or duplicate downloads where possible. Assign an owner to confirm the action is complete. Preserve the audit record even if the asset itself is no longer broadly available.
The process should also cover downstream uses. A withdrawal may affect a live webpage, scheduled campaign, partner toolkit, printed material, or social post. The required response will depend on the policy and context, but the asset library should help the team identify where the file has been used.
Apply extra care to children and sensitive stories
Some content needs more than a standard release process. Images that reveal a person's health, location, family circumstances, immigration status, or participation fall under the sensitive program. The potential harm can change even when permission was originally recorded.
For stories involving children, UNICEF's ethical guidelines for reporting on children recommend explaining the intended use, seeking permission from the child and guardian where appropriate, avoiding coercion, and considering whether publication could create harm.
Translate these principles into review flags your team can use. A sensitive asset may require a shorter review period, a limited audience, an identity-protecting edit, or approval from a designated program or safeguarding lead.
Handle old photos with an explicit decision
Historical libraries often contain strong images with incomplete records. Don't let absence of information look like approval.
Mark the asset as unknown or restricted. Search for supporting evidence using the event, program, date, photographer, and former owner. If the record cannot be established, follow the organization's policy for archival, internal, anonymized, or non-use status.
This keeps useful historical content available for review without presenting it as ready to publish. It also gives the team a clear signal to improve intake for new material.
How contentcloud supports the workflow
contentcloud can connect consent, license, expiry, approval, and restriction fields to the asset record. Role-based access and controlled collections can keep pending or sensitive files away from broad audiences, while version relationships help carry the same rules to derivatives.
The platform supports the record and access process. Your organization remains responsible for defining the policy, deciding which basis applies, and completing any required legal, privacy, or safeguarding review.
Explore contentcloud for nonprofits to see how rights and consent controls fit into a wider asset-management system.
How should nonprofits track photo consent?
What is the difference between photo consent and image usage rights?
Can a nonprofit reuse a photo that was published before?
What should happen when consent is withdrawn?
Should unclear historical photos be deleted?




