GDPRintheSwimmingSchool:Photos,StudentDataandParentalConsent[2026]
![GDPR in the Swimming School: Photos, Student Data and Parental Consent [2026]](/_next/image?url=https%3A%2F%2Fzvblogpostimages.s3.eu-west-3.amazonaws.com%2FAUTOMATISCH_UPLOAD%2F1_a2fde2d473f6.jpg&w=3840&q=75&dpl=dpl_GWyfLj8UVegbQ18STkVQms8Vj7LD)
Summary
- A photo showing a recognizable child is personal data. Publishing is only allowed with a legal basis, usually parental consent.
- In the Netherlands, children under 16 cannot give valid consent themselves; in Belgium and some other EU countries the limit is 13.
- Consent applies per purpose. One checkbox for website, social media, brochure and private app together is not valid.
- Asthma, eczema, medication and disabilities are health data. These require explicit consent and a place in your processing register.
- In the Swimmigo app only the linked parent and accepted instructor see a student’s data, and retention periods are fixed.
New groups, new parents, new lists: September is the busiest time of year at every swimming school. And precisely then, questions arise that you never wrote down an agreement about. A parent replies that no photos of their daughter may be shared. Someone saw a photo of her child in swimwear on your Instagram. On the poolside lies a printout with allergies and who is not allowed on the high diving board.
This is what the law requires from you, what parents may expect from you, and how you can get it in order in an afternoon.
Why this is extra sensitive in swimming lessons
A photo of a child in swimwear carries more weight
ZwembadBranche points out that you must be extra careful with photos of children in swimwear, because the law prescribes that people in that situation must be able to feel unobserved. This applies to your own social media post, but equally to the parent in the stands who makes a video showing half the group.
About half of the parents do not always give consent
In April 2025, the Radar Panel surveyed 1513 parents with children under 16 years old. 92 percent had been asked whether photos of their child could be taken and used, from school, daycare, sports club or religious community. Of those parents, 31 percent always give consent, half per situation, and 18 percent in no case. Statistically, in a group of ten children, there are two whose images you may not publish.
What happens if a parent says no
15 percent of parents say there are consequences if they do not give consent. 3 percent report their child was not allowed to participate in an activity, and about 5 percent of parents who do not always give consent say their child was actually refused. More often it is subtler: the child must step aside or be out of sight during the group photo. Parents experience that as exclusion, and that is exactly what the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) does not want. Consent must be freely given, without disadvantage for those who say no.
What the law requires
A recognizable child in a photo is personal data
A photo is not automatically personal data. It becomes personal data as soon as someone is recognizable in the image. From that moment, the GDPR rules apply: you need a reason to make and use the image, and you must be able to explain what that is. This applies to publication on your website, in a brochure and on social media. For images that remain internal only, such as an atmosphere photo in your own folder, it is different than for a post that the whole world can see.
The exception for personal use does not apply to you
The GDPR excludes photos for personal and household use. That exception is not intended for companies and organizations. As soon as you as a swimming school create visual material for your website, your brochure or your social media channels, you fall under the regular rules and need a legal basis, usually parental consent.
Which data you record determines how strict it is
A name, date of birth and swimming level are ordinary personal data. As soon as you note that a child has asthma, eczema, epilepsy or a disability, it concerns health data. The Dutch Data Protection Authority calls this special personal data, and these are extra protected. Moreover, for the use of such data, ordinary consent is not enough: a stricter form applies, explicit consent.
In practice, this does not mean you may not record anything. An instructor must know that a child cannot tolerate swim goggles or has medication with them. It means you only record what is really necessary, do not leave it lying on a note, and write down why you keep it.
| Type of data | Example from swimming lessons | How strict | What you must arrange |
|---|---|---|---|
| Ordinary personal data | Name, date of birth, group, level, attendance | Standard protection | Record purpose, do not record more than necessary, choose retention period |
| Special personal data | Asthma, eczema, epilepsy, allergies, medication, disability | Extra protected | Explicit consent, only what is strictly necessary, protected storage, include in your processing register |
| Visual material | Photos and videos of children during the lesson | Personal data as soon as recognizable | Consent per purpose, record who gave it, allow withdrawal |
| Payment data | Lesson packages, invoices, payments from parents | Standard protection with fiscal retention obligation | Keep administration for seven years, no card data in own systems |
Who may give consent
Up to 16 years: one of the parents or guardians
In the Netherlands, children under 16 cannot give valid consent themselves for processing their data. Consent is only valid if given by a parent or guardian, and you must be able to prove it was really that parent. Sometimes a child in a swimming lesson group has two households. Then it is wise to know who signs, and to let the other parent follow the progress instead of relying on word of mouth.
In some EU countries the age limit is 13
The GDPR allows countries to set the age limit for online services lower. The Netherlands keeps 16 years, Belgium and Denmark choose 13. For a school working with multilingual families or just across the border, that difference is relevant once data runs through an app or online portal. Swimmigo is available in five languages and notifications are shown in the recipient’s language, so parents who do not read Dutch get the same information about what happens with their child’s data.
Four requirements a consent must meet
According to the Dutch Data Protection Authority, consent must be freely given, unambiguous, informed and specific. Freely means you do not disadvantage a parent who says no. Unambiguous means a clear active action: a pre-checked box is not allowed, and silence even less so. Informed means you tell beforehand who you are, what your purpose is, which data you use and that withdrawal is always possible. Specific means you ask consent separately for each purpose. If you work with a form in multiple languages, the text in each language must have the same meaning.
Withdrawal must be as easy as giving consent
A parent may always withdraw consent, without giving a reason, and that must be as easy as giving it. The Dutch Data Protection Authority provides a sample letter for parents. What happens then: images already in a brochure or on a banner may no longer be distributed. You remove the photo from the material or put the material away. What is online you delete, and if another organization has received the image from you, you notify them of the withdrawal.
The checkbox almost every school gets wrong
A signature at registration does not cover all purposes
Most swimming schools arrange this with one line on the registration form, for example: I give consent for the use of visual material. Such consent is too broad to be valid, because the purpose may not change along the way. A parent who says yes for photos in the private app has not thereby given consent for Facebook, your website or a newspaper article.
Parents think per channel, not in one yes or no
You see that difference reflected in the figures. In the Radar study, a parent says they agree with photos in the daycare app because otherwise they get nothing of their child, but not with publication on the website or in the newspaper. Another parent wonders what the sixty other parents in the portal do with the photos. Asking per purpose yields more usable yeses and less discussion than offering one big checkbox.
| Purpose | What you do with it | What you need |
|---|---|---|
| Private channel to parents | Share photos of the lesson with the parents of that group | Own consent for this purpose, even if the group is private |
| Own website | Atmosphere images and an explanation about your lessons | Separate consent per parent, with the possibility to say no without consequences for the lesson |
| Social media | Posts and videos on Instagram, Facebook or TikTok | Separate consent, preferably with agreement on how long a post remains |
| Brochure, flyer or banner | Printed material that circulates for a long time and cannot be recalled | Separate consent, plus agreement that printed material is withdrawn if someone withdraws consent |
| Newspaper or local news | An interview or report about your school | Separate consent, even if you are not the photographer yourself |
What you must be able to show if questions arise
Record who gave consent, when and for what
The GDPR works with an accountability obligation: you must be able to prove you follow the rules. For consent that means two things. You keep the consent yourself, and you keep the information the parent received at that moment, so it is clear what that yes meant. A folder with completed forms, or a field in your system with date, purpose and the version of the text the parent saw, is enough. Oral consent is allowed but hard to prove.
A privacy statement is always mandatory
Every organization must have a privacy statement stating which data you use, why, how long you keep it and how parents can exercise their rights. For a swimming school that is one page in plain language, not legal work. Put it on your site and mention it at registration, so you do not have to explain every time why you record something.
A data breach register, and a report for serious breaches
Even small organizations keep a data breach register. Think of the most common practical examples: a phone with photos of the group that gets lost, a participant list sent to the wrong parent, a spreadsheet accidentally public. You report a serious breach to the Dutch Data Protection Authority, and sometimes also to the involved parents.
The group chat, the notebook and the phone by the poolside
Medical data do not belong on a printout by the pool
The list with allergies and medication is the most common place where health data is scattered. It often contains more than necessary: not only the allergy, but also the whole story from the parents, a phone number and a note from last season. Write down what an instructor in the water must know and keep the rest in a protected file. A substitute taking over the group needs to know that a child cannot tolerate earplugs, not that an investigation is ongoing.
A group chat with photos is not a secure channel
Private feels safe, but a group of sixty parents is not a protected environment. No one controls what someone does with a downloaded photo, and those who leave the group keep the photos. Moreover, photos in an app also start conversations that you as a school cannot control, with questions about someone else’s child. For progress and sharing a photo of one’s own child there are channels you control yourself, and for the rest an agreement suffices: no photos of other children in the group.
How that conversation goes at many schools is described in our article about WhatsApp chaos in swimming lessons.
Prohibition signs do not work, agreements do
Rules about phones in the pool are hard to enforce; this emerges from a survey among pools and playgroups in Overijssel. A prohibition sign on the fence stops no one. A pool in Steenwijk solved it with extra checks and house rules, and with the rule that no children in the background may be recognizable without consent. That last agreement removes most work: it is rarely your camera, usually that of another parent at a birthday party or during free swimming.

Who can access the data
Data minimization sounds like a term from a handbook. In practice it is about one question: who can access which data. A shared login account used by four people is the weakest link, because then it is impossible afterwards to see who changed or downloaded something. Work with individual accounts per person, with rights fitting the role, and remove access the day someone leaves.
What parents may ask from you
Access, correction and deletion
Parents have the right to access the data you have about their child, to correct if something is wrong, and in some cases to deletion. You do not need a three-page form for that, but an agreement about who answers and within what timeframe. A clear answer within a few days almost always prevents a complaint.
You cannot fully retrieve photos already online
This is the point where honesty works best. You remove a photo from your site or brochure, but for a post that has been saved, forwarded or screenshotted there is no full reversal. Say that beforehand instead of afterwards. Organizations that positively surprised parents do so with post-selection: photograph the lesson, choose afterwards the images showing only children for whom you have consent, and if necessary make a face unrecognizable. The other point established by the Dutch Data Protection Authority and the British NSPCC: a child may never be excluded from an activity because there is no consent. Those not allowed in photos simply participate.
And if things go wrong: a complaint to the Dutch Data Protection Authority
A parent who thinks you have handled data carelessly may file a complaint with the Dutch Data Protection Authority. Practice shows that almost all such cases start with a conversation that went wrong: a request to remove a photo that was handled too late, or a response like that post will disappear by itself. Responding within a day and taking the photo offline takes five minutes.
A fifteen-minute privacy check
Step 1: review your own channels
Open your website, your social media accounts, the folder with printed material and paid advertisements. Note everywhere children are recognizable. That is your starting point.
Step 2: split your consent request per purpose
Make one question into four or five separate questions, in the parents’ language. Add what you do with the image and how someone can withdraw consent.
Step 3: record who sees which data
Look per person in your team at the data they need. Instructors need progress and medical points, not the payment status of a family. Those doing administration do not need to see photos.
Step 4: choose retention periods and write them down
Agree how long you keep photos, how long a deregistered child remains in your system and what happens when a family stops. Record it in one document, even if short.
Step 5: schedule one moment per year
You do not have to ask consent again every school year for the same purpose. Check whether old consents are still valid, if new channels have been added and if new parents have seen the question. For new families arrange it at registration, at once with the rest of the intake.
What the Swimmigo app arranges for this
A processor agreement instead of separate agreements
In the Swimmigo app, the swimming school is the data controller for the student and lesson data it records itself. Swimmigo processes that data on behalf of the school, and a processor agreement is concluded with each school. The account data of parents, such as login and settings, fall under Bobika as data controller. That distinction is exactly what the GDPR requires from a party working with children’s data.
Three roles, three types of access
Within a school there are roles for owner, administrator and instructor, each with their own rights. An instructor sees the groups and students assigned to them; administration and revenue are for the administrator. Other parents cannot see your student: only the linked parent and the instructors accepted by the school have access to progress. When changing schools, old access is revoked, and a parent can break the link themselves via settings.
Messages in the app instead of the group chat
Messages between parents and school run through the app, with read receipts. The school decides whether that function is on; if off, the parent sees contact is by email. That is a different consideration than the group chat where everything mixes, and it is the place where you can repeat agreements about photos instead of mentioning them once at registration. Notifications are shown in the recipient’s language, from five languages, so the explanation does not arrive only in Dutch.
Retention periods that are fixed
Parents who delete their account disappear immediately and permanently. A parent account without a linked swimmer is automatically deleted after seven days, with a warning on day four. If a school stops using the app, the link is immediately broken and the school has thirty days to export its own data, after which everything is automatically deleted. Backups remain for a maximum of thirty days, and the school’s own administration remains under its fiscal retention obligation. A school that wants to make a student photo mandatory turns that on as a setting; if off, the photo is optional.
Where the data is stored
Storage is in the European Union, with databases at MongoDB Atlas and image storage in an S3 environment in France. Payments run via Stripe Payments Europe in Ireland; card data does not enter the app and is not stored by Swimmigo. Email and product statistics use parties that may process data in the United States, under the safeguards that apply, such as the EU-US agreements and standard contractual clauses. The full list of parties and retention periods is in the statement, and parents can exercise their rights in the app settings or via a message to Swimmigo.
What else is in the app for managing groups, progress and parent contact is on the features page, on the page for swimming schools and instructors and on the page for parents. How to move from separate lists to one system is in our article about administration, communication and payments in one app. For recording medical points per student, the explanation about swimming lessons with eczema is a useful follow-up.
Conclusion
Photos and student data are not a legal dossier requiring a lawyer, but they do require agreements that you write down once and then follow. Ask consent per purpose in the parents’ language, record who sees what, note only the medical information an instructor in the water really needs, and make withdrawal as easy as giving consent. If you do that, you can give every parent who asks a clear answer, and you do not have to figure out on a busy Saturday morning who agreed to what.
Sources
- Dutch Data Protection Authority: visual material, when you may take and publish photos and videos, consulted September 2026
- Dutch Data Protection Authority: visual material in education, consent per purpose and security, consulted September 2026
- Dutch Data Protection Authority: legal basis consent, requirements, proof and withdrawal, updated December 2024
- Dutch Data Protection Authority: accountability obligation, processing register, data breach register and privacy statement, updated December 2024
- Dutch Data Protection Authority: health data are special personal data, updated January 2025
- Dutch Data Protection Authority: sample letter for parents to withdraw consent for visual material of their child (pdf), consulted September 2026
- ZwembadBranche: posting photos of children and the GDPR, swimwear and parental consent, consulted September 2026
- Radar (AVROTROS): survey among 1513 parents about consent for photos of children, April 2025, 28 April 2025
- NSPCC Learning: photographing and filming children, consent, retention and never excluding, updated July 2026
- Information Commissioner's Office: taking photographs, data protection advice for schools and small clubs, consulted September 2026
- RTV Oost: taking photos in a swimming pool, rules, control and enforcement, 20 June 2017
- Italian Journal of Pediatrics: sharenting, 75 percent of parents post content about their child online, 30 July 2024
- Swimmigo: privacy statement, roles of school and platform, retention periods and security, updated September 2026

Bob van Soest
As an expert in operating sports facilities (such as swimming pools) and developer of, among others, Swimmigo.com, I am passionately committed to making swimming lessons simpler, more fun and more insightful for parents, swimming instructors and everyone who wants to learn to swim.
Frequently Asked Questions
Discover Swimmigo
The all-in-one app for swimming lesson progress. For parents, swim schools, and adult swimmers.


![Swimming School or Swimming Instructor: Manage Everything in the Swimmigo App [2026]](/_next/image?url=https%3A%2F%2Fzvblogpostimages.s3.eu-west-3.amazonaws.com%2FAUTOMATISCH_UPLOAD%2F1_464c55238661.jpg&w=3840&q=75&dpl=dpl_GWyfLj8UVegbQ18STkVQms8Vj7LD)