Sharing sensitive charity media safely

Loading the Elevenlabs Text to Speech AudioNative Player...

Sharing media safely and securely is a challenge for every organisation across all industries, but it’s particularly important for charities and nonprofits that need to share sensitive content.

In this article we’re going to look at what actually counts as sensitive media in a charity context, and what you can do to make sure you get it right.

What counts as sensitive media in a charity context?

In the context of the charity and nonprofit sector - in fact, in the context of any sector - sensitive media refers to any videos, images, audio or documents that contain personally identifiable data about living individuals.

For example, this can include:

  • Photographs
  • Case study notes
  • Interview recordings
  • Background information

All this media could potentially identify a service user, beneficiary, volunteer, or anyone involved in a charity’s work. Under the UK GDPR, the organisation is required to handle personal data appropriately.

Media that contains special category data has additional protection under UK GDPR, which refers to any information concerning a person’s health, racial or ethnic origin, or religious beliefs. Note that in order to lawfully process special category data (i.e., collecting, storing and using that data) you need to identify a lawful basis under Article 6 of the UK GDPR, and a separate condition for processing under Article 9.

READ MORE: Charity GDPR compliance: What you need to know

Why your cause area changes the risk level

Your organisation’s specific cause area impacts its risk level significantly, particularly in terms of this special category data.

If the charity is involved in specific healthcare research or support, images of identifiable beneficiaries (i.e., an image showing their face) could put the privacy of their health information at risk. If you’re working in a developing country or region, media could infer racial, ethnic or religious data.

The risks of identifying beneficiaries are even greater for other nonprofit cause areas, such as domestic abuse shelters or any charities working with children, where data protection laws are even stricter.

AI auto-tagging and facial recognition

A key point that some charity DAM Managers miss is around AI auto-tagging and facial recognition, which a number of DAM systems now provide as standard (including ResourceSpace). 

This is useful for finding media quickly, but you need to understand what happens to personal data when these tools are being used. If a third party system processes someone’s face to uniquely identify them, this is biometric processing and considered special category data. This means that automatically creating a facial tag without the person’s knowledge requires a lawful basis and, in some cases, a separate Article 9 condition.

With this in mind, you should check how your DAM provider processes facial data before enabling these features.

Getting consent right before you share anything

For consent to be considered ‘valid’ under GDPR, it should be specific, informed and freely given, but what does this actually mean?

  1. Beneficiaries should understand who is collecting their media, why it will be used, where it may appear and who may receive it.
  2. They should actively opt in and be able to refuse or withdraw consent without unfair consequences.

READ MORE: Simplifying charity story collection with smart uploads and consent

To make sure you’re doing this right, the point at which you capture the consent should identify the individual and clearly explain the specific uses being agreed to. It should also explain how long the consent is expected to apply, how consent can be withdrawn and provide relevant privacy information (either upfront or via a link). Consent needs to be specific for the processing involved, so it’s best to avoid using broad consent statements that try to cover multiple uses.

You should also record who consented, when and how they consented, and exactly what they were told at the time. Keep the signed form or digital record so you can easily demonstrate what was agreed if you’re ever required to, while you should also link the consent record directly to the relevant assets in your DAM. This can be achieved through specific consent metadata, for example a consent reference, approved uses, restrictions, expiry or review date and withdrawal status.

ResourceSpace supports consent management by allowing you to add multiple consent records per resource and to set license and consent expiry dates. These will be monitored by the system and administrators notified when these dates are approaching. ResourceSpace can even move files with expired consent out of general circulation automatically.

What happens when consent is withdrawn?

If a charity is relying on consent as the lawful basis for processing an asset, if that consent is withdrawn you need to act promptly and stop using the media as soon as possible.

Step 1: Search the DAM for every file featuring the individual in question, including derivatives and duplicate versions.

Step 2: Revoke any active share links, remove the asset from public-facing collections and restrict or delete it according to your retention policy.

Step 3: Record the withdrawal, the actions taken and when they were completed so there is a clear audit trail.

Of course, this is more difficult if the image has been used in printed materials, because you can’t necessarily retrieve physical media that’s already been distributed. However, there are some further steps you can and should take in this case:

Step 4: Stop further distribution of the media.

Step 5: Ask third parties who received the material to remove it where appropriate.

Setting permissions: Who can see what, and what they can do with it

Role-based permissions let you decide what different users can do with sensitive media, and this is particularly important when the DAM contains assets for internal teams, partner agencies and freelancers. The key principle is to only give each DAM user the specific level of access they need for their role.

Often, user permissions can be divided into three main access levels:

  • Read-only access—the user can view an asset but can’t download or redistribute the original file.
  • Download access—the user can save a copy to their device for an approved purpose.
  • Share access—the user can create or send links or otherwise make the asset available to other people.

In practice, this might mean a charity Stories Manager has full access to approved campaign media, while a freelance designer only has download access to the assets they need for a project.

Controlling what metadata DAM users can see

Access should also extend to the metadata DAM users can view and use, particularly sensitive and special category data.

For example, internal users might need to see consent status, subject notes, location and case reference number to understand how and where an asset can be used. However, external users won’t typically need to view this information unless critical to their work.

A DAM’s external users can usually be given access to practical descriptive information, but you should avoid exposing beneficiary names, detailed case notes, precise locations and other identifiable information.

You should check what your DAM system displays in its interface and in downloaded files too, because hiding metadata from view in the DAM doesn’t necessarily remove embedded EXIF data from the image itself. ResourceSpace offers a plugin to deal with this specific problem, offering the ability to strip an asset’s EXIF data at the point of upload.

Managing volunteer and third-party access without losing control

Volunteers, photographers and designers, and partner agencies should normally receive a limited guest or contributor role rather than broad access to the DAM. Give them access to the specific collections or assets they need, set an end date where possible and avoid granting download or sharing rights unless their role requires them. The ICO’s guidance here is to limit access to personal data, and putting in place processes to review permissions and remove access when it’s no longer needed.

Of course, the challenge is that once someone downloads a file, the DAM Manager can’t control what happens to that copy. With this in mind, make your acceptable-use rules for external users clear and use DAM audit logs to keep track of downloads and other activity. In addition to regularly reviewing permissions, regularly review external user profiles and thoroughly investigate unexpected downloads or sharing.

How to use watermarks and expiring links in practice

Watermarks and time-limited share links can add safeguards when sensitive media needs to be shared outside the charity. Watermarked versions of assets add an extra layer of security and prevent screen grabs and, once the asset has been approved, you can provide the clean file for download or publication.

For situations where someone needs access for a limited period, use a time-limited share link. This is particularly useful when sending media to a journalist, designer, event partner or other third party for a specific task.

It’s important to note that link expiry rules control access to the link, but don't recall files that someone has already downloaded. This means that a recipient could still retain, copy or redistribute a downloaded file after the link expires, so expiry should be treated as a sharing control rather than a compliance tool.

Where media is shared for a defined purpose or period, configure the share link expiry to reflect it. For example, if a beneficiary has consented to their photograph being used for a fundraising campaign running until 31 December, a link created for an external partner should not remain active beyond that date. ResourceSpace can send notifications to all users that have downloaded a specific file letting them know when it’s expired so that it can be withdrawn from use.

How a DAM system makes safe sharing manageable at scale

For Stories Managers, managing sensitive media safely becomes much harder when files, consent records and sharing permissions are siloed. An effectively configured DAM platform brings these tasks together so that access can be managed as part of the everyday workflow.

A DAM is able to achieve this in several ways:

  1. Metadata-driven search makes it possible to quickly locate every instance of a particular person's image, including different versions or related assets, which is particularly useful when consent is withdrawn or the permission to use an image ends or changes.
  2. Role-based permissions allow access to be configured at the collection, folder or even asset level, allowing charities to give a partner access to the files they need without opening up the wider media library.
  3. Audit logs provide visibility over how assets are being used, and depending on the DAM, these reports can show who has viewed or downloaded an asset.

Ultimately, a DAM like ResourceSpace allows charities and nonprofits to effectively and securely manage sensitive media all in one place.

To find out more about how ResourceSpace supports the charity sector, take a look at some of our nonprofit case studies, or book a call with one of our solutions experts below.

Article hashtags

Subscribe: RSS feed / e-mail