Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Italian DPA July 15, 2026 3 min

Children's photos on social media: both parents must consent

The principle restated by the Italian DPA reaches families, schools, sports clubs and anyone publishing images of children. How to turn it into procedures

TL;DR for the DPO

Principle from the Italian DPA (newsletter 17/6/2026): publishing a minor's images on social media requires both parents' consent (shared parental responsibility); one parent's dissent blocks publication. For bodies handling minors' images the practical consequence is: double-signature consent forms and a procedure for withdrawals and disagreements.

The three points that matter

  • Parental responsibility is shared: one parent's consent is not enough, and the other's dissent prevails. This applies to the school's social profile exactly as to mum's or dad's.
  • The scope is wider than social media: school and sports events, recitals, summer camps, newsletters and websites - wherever the child's image becomes 'publication'.
  • Typical practices to fix: release forms signed by one parent only, 'lifetime' consent collected at enrolment, no withdrawal procedure, WhatsApp/social groups where photos circulate unchecked.

What to do now, in practice

For schools, nurseries, sports clubs and clients publishing minors' images: 1) DOUBLE-signature forms (or a declaration of acting with the other parent's consent, at the signer's responsibility); 2) granular consent: website, social media, promotional material as separate items; 3) a written procedure for withdrawal and later disagreement (who removes, within what time); 4) training for whoever runs the organisation's social channels.

Why it matters for your clients

It is one of those principles that generates concrete, immediate work for the DPO: almost every organisation dealing with minors has single-signature forms. Updating them is a quick, visible, easily explained fix - and it prevents both parental complaints and trouble when family conflicts arise.

Official source:Italian Data Protection Authority - newsletter of 17 June 2026

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Italian DPA
12keuro

Misconfigured document register: 12,000 euro fine for the Metropolitan City of Sassari

Following a data breach notification and a complaint, the Italian data protection authority fined the Metropolitan City of Sassari for misconfiguring its electronic document register, making documents containing personal data accessible to staff who, given their role and duties, were not authorised to process them. The fine is 12,000 euro, but the principle applies to every public body and every company running a document management system: filing is not a neutral activity, and a default of total visibility breaches the principles of integrity and confidentiality.

Jul 29, 2026 6 min
Italian DPA
STOPcopie

Italian DPA to hoteliers: do not keep copies of guests' ID documents

In a notice addressed to the hospitality sector, the Italian DPA reiterated that hoteliers may not keep copies of guests' identity documents: the legal duty (Art. 109 of the Italian public-security code) is to identify the guest and transmit the data to the police via the Alloggiati Web portal - after that, document copies must be destroyed or deleted. A widespread habit becomes a concrete sanction risk.

Jul 14, 2026 3 min
Italian DPA
37,7MEUR

Italian DPA annual report: collected fines +54.5%, almost 7 data breaches notified per day, AI at the centre

On 2 July 2026 the Italian DPA presented its 2025 activity report to Parliament: 807 collegial decisions, 506 corrective and sanctioning measures, over EUR 37.7 million in fines collected (+54.5% on 2024), 2,415 data breaches notified (+10%), 130 inspections. AI takes centre stage: from DeepSeek to deepfakes, from facial recognition at the airport to worker surveillance.

Jul 02, 2026 4 min