September 13, 2026Bob van Soest • 19 min read

GDPRintheSwimmingSchool:Photos,StudentDataandParentalConsent[2026]

What is allowed for swimming schools regarding photos and data of children? Consent per purpose, health data, retention periods, and what parents can ask from you.
GDPR in the Swimming School: Photos, Student Data and Parental Consent [2026]

Summary

  • A photo showing a recognizable child is personal data. Publishing is only allowed with a legal basis, usually parental consent.
  • In the Netherlands, children under 16 cannot give valid consent themselves; in Belgium and some other EU countries the limit is 13.
  • Consent applies per purpose. One checkbox for website, social media, brochure and private app together is not valid.
  • Asthma, eczema, medication and disabilities are health data. These require explicit consent and a place in your processing register.
  • In the Swimmigo app only the linked parent and accepted instructor see a student’s data, and retention periods are fixed.

New groups, new parents, new lists: September is the busiest time of year at every swimming school. And precisely then, questions arise that you never wrote down an agreement about. A parent replies that no photos of their daughter may be shared. Someone saw a photo of her child in swimwear on your Instagram. On the poolside lies a printout with allergies and who is not allowed on the high diving board.

This is what the law requires from you, what parents may expect from you, and how you can get it in order in an afternoon.

Why this is extra sensitive in swimming lessons

A photo of a child in swimwear carries more weight

ZwembadBranche points out that you must be extra careful with photos of children in swimwear, because the law prescribes that people in that situation must be able to feel unobserved. This applies to your own social media post, but equally to the parent in the stands who makes a video showing half the group.

About half of the parents do not always give consent

In April 2025, the Radar Panel surveyed 1513 parents with children under 16 years old. 92 percent had been asked whether photos of their child could be taken and used, from school, daycare, sports club or religious community. Of those parents, 31 percent always give consent, half per situation, and 18 percent in no case. Statistically, in a group of ten children, there are two whose images you may not publish.

What happens if a parent says no

15 percent of parents say there are consequences if they do not give consent. 3 percent report their child was not allowed to participate in an activity, and about 5 percent of parents who do not always give consent say their child was actually refused. More often it is subtler: the child must step aside or be out of sight during the group photo. Parents experience that as exclusion, and that is exactly what the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) does not want. Consent must be freely given, without disadvantage for those who say no.

Swimmigo

What the law requires

A recognizable child in a photo is personal data

A photo is not automatically personal data. It becomes personal data as soon as someone is recognizable in the image. From that moment, the GDPR rules apply: you need a reason to make and use the image, and you must be able to explain what that is. This applies to publication on your website, in a brochure and on social media. For images that remain internal only, such as an atmosphere photo in your own folder, it is different than for a post that the whole world can see.

The exception for personal use does not apply to you

The GDPR excludes photos for personal and household use. That exception is not intended for companies and organizations. As soon as you as a swimming school create visual material for your website, your brochure or your social media channels, you fall under the regular rules and need a legal basis, usually parental consent.

Which data you record determines how strict it is

A name, date of birth and swimming level are ordinary personal data. As soon as you note that a child has asthma, eczema, epilepsy or a disability, it concerns health data. The Dutch Data Protection Authority calls this special personal data, and these are extra protected. Moreover, for the use of such data, ordinary consent is not enough: a stricter form applies, explicit consent.

In practice, this does not mean you may not record anything. An instructor must know that a child cannot tolerate swim goggles or has medication with them. It means you only record what is really necessary, do not leave it lying on a note, and write down why you keep it.

Type of dataExample from swimming lessonsHow strictWhat you must arrange
Ordinary personal data Name, date of birth, group, level, attendance Standard protection Record purpose, do not record more than necessary, choose retention period
Special personal data Asthma, eczema, epilepsy, allergies, medication, disability Extra protected Explicit consent, only what is strictly necessary, protected storage, include in your processing register
Visual material Photos and videos of children during the lesson Personal data as soon as recognizable Consent per purpose, record who gave it, allow withdrawal
Payment data Lesson packages, invoices, payments from parents Standard protection with fiscal retention obligation Keep administration for seven years, no card data in own systems

Who may give consent

Up to 16 years: one of the parents or guardians

In the Netherlands, children under 16 cannot give valid consent themselves for processing their data. Consent is only valid if given by a parent or guardian, and you must be able to prove it was really that parent. Sometimes a child in a swimming lesson group has two households. Then it is wise to know who signs, and to let the other parent follow the progress instead of relying on word of mouth.

In some EU countries the age limit is 13

The GDPR allows countries to set the age limit for online services lower. The Netherlands keeps 16 years, Belgium and Denmark choose 13. For a school working with multilingual families or just across the border, that difference is relevant once data runs through an app or online portal. Swimmigo is available in five languages and notifications are shown in the recipient’s language, so parents who do not read Dutch get the same information about what happens with their child’s data.

Four requirements a consent must meet

According to the Dutch Data Protection Authority, consent must be freely given, unambiguous, informed and specific. Freely means you do not disadvantage a parent who says no. Unambiguous means a clear active action: a pre-checked box is not allowed, and silence even less so. Informed means you tell beforehand who you are, what your purpose is, which data you use and that withdrawal is always possible. Specific means you ask consent separately for each purpose. If you work with a form in multiple languages, the text in each language must have the same meaning.

Withdrawal must be as easy as giving consent

A parent may always withdraw consent, without giving a reason, and that must be as easy as giving it. The Dutch Data Protection Authority provides a sample letter for parents. What happens then: images already in a brochure or on a banner may no longer be distributed. You remove the photo from the material or put the material away. What is online you delete, and if another organization has received the image from you, you notify them of the withdrawal.

The checkbox almost every school gets wrong

A signature at registration does not cover all purposes

Most swimming schools arrange this with one line on the registration form, for example: I give consent for the use of visual material. Such consent is too broad to be valid, because the purpose may not change along the way. A parent who says yes for photos in the private app has not thereby given consent for Facebook, your website or a newspaper article.

Parents think per channel, not in one yes or no

You see that difference reflected in the figures. In the Radar study, a parent says they agree with photos in the daycare app because otherwise they get nothing of their child, but not with publication on the website or in the newspaper. Another parent wonders what the sixty other parents in the portal do with the photos. Asking per purpose yields more usable yeses and less discussion than offering one big checkbox.

PurposeWhat you do with itWhat you need
Private channel to parents Share photos of the lesson with the parents of that group Own consent for this purpose, even if the group is private
Own website Atmosphere images and an explanation about your lessons Separate consent per parent, with the possibility to say no without consequences for the lesson
Social media Posts and videos on Instagram, Facebook or TikTok Separate consent, preferably with agreement on how long a post remains
Brochure, flyer or banner Printed material that circulates for a long time and cannot be recalled Separate consent, plus agreement that printed material is withdrawn if someone withdraws consent
Newspaper or local news An interview or report about your school Separate consent, even if you are not the photographer yourself

What you must be able to show if questions arise

Record who gave consent, when and for what

The GDPR works with an accountability obligation: you must be able to prove you follow the rules. For consent that means two things. You keep the consent yourself, and you keep the information the parent received at that moment, so it is clear what that yes meant. A folder with completed forms, or a field in your system with date, purpose and the version of the text the parent saw, is enough. Oral consent is allowed but hard to prove.

A privacy statement is always mandatory

Every organization must have a privacy statement stating which data you use, why, how long you keep it and how parents can exercise their rights. For a swimming school that is one page in plain language, not legal work. Put it on your site and mention it at registration, so you do not have to explain every time why you record something.

A data breach register, and a report for serious breaches

Even small organizations keep a data breach register. Think of the most common practical examples: a phone with photos of the group that gets lost, a participant list sent to the wrong parent, a spreadsheet accidentally public. You report a serious breach to the Dutch Data Protection Authority, and sometimes also to the involved parents.

The group chat, the notebook and the phone by the poolside

Medical data do not belong on a printout by the pool

The list with allergies and medication is the most common place where health data is scattered. It often contains more than necessary: not only the allergy, but also the whole story from the parents, a phone number and a note from last season. Write down what an instructor in the water must know and keep the rest in a protected file. A substitute taking over the group needs to know that a child cannot tolerate earplugs, not that an investigation is ongoing.

A group chat with photos is not a secure channel

Private feels safe, but a group of sixty parents is not a protected environment. No one controls what someone does with a downloaded photo, and those who leave the group keep the photos. Moreover, photos in an app also start conversations that you as a school cannot control, with questions about someone else’s child. For progress and sharing a photo of one’s own child there are channels you control yourself, and for the rest an agreement suffices: no photos of other children in the group.

How that conversation goes at many schools is described in our article about WhatsApp chaos in swimming lessons.

Prohibition signs do not work, agreements do

Rules about phones in the pool are hard to enforce; this emerges from a survey among pools and playgroups in Overijssel. A prohibition sign on the fence stops no one. A pool in Steenwijk solved it with extra checks and house rules, and with the rule that no children in the background may be recognizable without consent. That last agreement removes most work: it is rarely your camera, usually that of another parent at a birthday party or during free swimming.

Top view of pool tiles with parents and child heading to the changing room, faces not visible

Who can access the data

Data minimization sounds like a term from a handbook. In practice it is about one question: who can access which data. A shared login account used by four people is the weakest link, because then it is impossible afterwards to see who changed or downloaded something. Work with individual accounts per person, with rights fitting the role, and remove access the day someone leaves.

What parents may ask from you

Access, correction and deletion

Parents have the right to access the data you have about their child, to correct if something is wrong, and in some cases to deletion. You do not need a three-page form for that, but an agreement about who answers and within what timeframe. A clear answer within a few days almost always prevents a complaint.

You cannot fully retrieve photos already online

This is the point where honesty works best. You remove a photo from your site or brochure, but for a post that has been saved, forwarded or screenshotted there is no full reversal. Say that beforehand instead of afterwards. Organizations that positively surprised parents do so with post-selection: photograph the lesson, choose afterwards the images showing only children for whom you have consent, and if necessary make a face unrecognizable. The other point established by the Dutch Data Protection Authority and the British NSPCC: a child may never be excluded from an activity because there is no consent. Those not allowed in photos simply participate.

And if things go wrong: a complaint to the Dutch Data Protection Authority

A parent who thinks you have handled data carelessly may file a complaint with the Dutch Data Protection Authority. Practice shows that almost all such cases start with a conversation that went wrong: a request to remove a photo that was handled too late, or a response like that post will disappear by itself. Responding within a day and taking the photo offline takes five minutes.

A fifteen-minute privacy check

Step 1: review your own channels

Open your website, your social media accounts, the folder with printed material and paid advertisements. Note everywhere children are recognizable. That is your starting point.

Step 2: split your consent request per purpose

Make one question into four or five separate questions, in the parents’ language. Add what you do with the image and how someone can withdraw consent.

Step 3: record who sees which data

Look per person in your team at the data they need. Instructors need progress and medical points, not the payment status of a family. Those doing administration do not need to see photos.

Step 4: choose retention periods and write them down

Agree how long you keep photos, how long a deregistered child remains in your system and what happens when a family stops. Record it in one document, even if short.

Step 5: schedule one moment per year

You do not have to ask consent again every school year for the same purpose. Check whether old consents are still valid, if new channels have been added and if new parents have seen the question. For new families arrange it at registration, at once with the rest of the intake.

What the Swimmigo app arranges for this

A processor agreement instead of separate agreements

In the Swimmigo app, the swimming school is the data controller for the student and lesson data it records itself. Swimmigo processes that data on behalf of the school, and a processor agreement is concluded with each school. The account data of parents, such as login and settings, fall under Bobika as data controller. That distinction is exactly what the GDPR requires from a party working with children’s data.

Three roles, three types of access

Within a school there are roles for owner, administrator and instructor, each with their own rights. An instructor sees the groups and students assigned to them; administration and revenue are for the administrator. Other parents cannot see your student: only the linked parent and the instructors accepted by the school have access to progress. When changing schools, old access is revoked, and a parent can break the link themselves via settings.

Messages in the app instead of the group chat

Messages between parents and school run through the app, with read receipts. The school decides whether that function is on; if off, the parent sees contact is by email. That is a different consideration than the group chat where everything mixes, and it is the place where you can repeat agreements about photos instead of mentioning them once at registration. Notifications are shown in the recipient’s language, from five languages, so the explanation does not arrive only in Dutch.

Retention periods that are fixed

Parents who delete their account disappear immediately and permanently. A parent account without a linked swimmer is automatically deleted after seven days, with a warning on day four. If a school stops using the app, the link is immediately broken and the school has thirty days to export its own data, after which everything is automatically deleted. Backups remain for a maximum of thirty days, and the school’s own administration remains under its fiscal retention obligation. A school that wants to make a student photo mandatory turns that on as a setting; if off, the photo is optional.

Where the data is stored

Storage is in the European Union, with databases at MongoDB Atlas and image storage in an S3 environment in France. Payments run via Stripe Payments Europe in Ireland; card data does not enter the app and is not stored by Swimmigo. Email and product statistics use parties that may process data in the United States, under the safeguards that apply, such as the EU-US agreements and standard contractual clauses. The full list of parties and retention periods is in the statement, and parents can exercise their rights in the app settings or via a message to Swimmigo.

What else is in the app for managing groups, progress and parent contact is on the features page, on the page for swimming schools and instructors and on the page for parents. How to move from separate lists to one system is in our article about administration, communication and payments in one app. For recording medical points per student, the explanation about swimming lessons with eczema is a useful follow-up.

Swimmigo

Conclusion

Photos and student data are not a legal dossier requiring a lawyer, but they do require agreements that you write down once and then follow. Ask consent per purpose in the parents’ language, record who sees what, note only the medical information an instructor in the water really needs, and make withdrawal as easy as giving consent. If you do that, you can give every parent who asks a clear answer, and you do not have to figure out on a busy Saturday morning who agreed to what.

Sources

Bob van Soest

Bob van Soest

As an expert in operating sports facilities (such as swimming pools) and developer of, among others, Swimmigo.com, I am passionately committed to making swimming lessons simpler, more fun and more insightful for parents, swimming instructors and everyone who wants to learn to swim.

Frequently Asked Questions

Only if you have a legal basis for it, in practice consent from a parent or guardian. Ask that consent separately for your website, apart from consent for the private app or social media, and record who gave the consent.
There is no legal number for that. Choose a period that fits your purpose, write it down and discard what you no longer need. For your financial administration it is seven years, for photos and medical notes usually much shorter.
Not for the same purpose, as long as the parent knows what the consent is for. Check whether old consents are still valid, if new channels have been added and if new parents have seen the question.
An overview of which personal data you process, why, how long you keep it and with whom you share it. Organizations with fewer than 250 employees are generally exempt, unless they process special data such as children’s health data.
A name or swimming level is ordinary personal data. Data about health, such as asthma, eczema or a disability, are special personal data and receive extra protection under the GDPR. A stricter legal basis applies.
No. For publication on the website, social media or printed material, consent is required from a parent as long as your child is under 16. You may also withdraw that consent, and that must be as easy as giving it.
No. A child may never be excluded because there is no consent for visual material. Ask the school to select photos afterwards or make a face unrecognizable, instead of sidelining your child.
What is needed to give lessons: name, level, progress and attendance. Medical information such as an allergy may only be recorded if really necessary for safety in the water, and stricter rules apply.
If you record children’s health data, such as allergies or a disability, yes. Organizations with fewer than 250 employees are exempt, except when the processing is not occasional or concerns special personal data.
You can ask for a recognizable photo so instructors quickly recognize children. Make clear why you ask for the photo, where it is stored and what happens if a parent does not want it, because a requirement may not be disguised pressure.
Record per parent who gave consent, with which date, for which purpose and which text they saw. Also keep the information you gave beforehand, because the Dutch Data Protection Authority may ask for it.

Discover Swimmigo

The all-in-one app for swimming lesson progress. For parents, swim schools, and adult swimmers.