The student decides
One competent adult, deciding about their own face
Everything on this site follows from that sentence. It sounds obvious until you notice that almost every system an institution is offered was designed for a world where somebody else decides, and that the difference shows up in the parts nobody demonstrates.
What the decision covers, and what it does not
It covers publication. Whether a person’s image may be shown to somebody who is not them: on a public page, in a recruitment brochure, to a partner organisation, in an alumni mailing. That decision is theirs, it defaults to no, and it stays a no until they say otherwise.
It does not cover the operational record. Your institution needs a photograph attached to a person to run a card system and a front desk. That exists because you have to identify people, and it is bounded by what you told the person it was for. It is not a general licence and it is not a marketing library.
Where those two get confused is nearly always in the same direction: somebody in a marketing office discovers that a card system already contains a usable photograph of every enrolled student. It is quick, and it is a use nobody agreed to.
What it actually requires of an institution
Three things, and only one of them is software.
Somewhere for a request to land. An adult subject can ask what you hold and can ask you to stop. In a school that request comes from a guardian to an office that still has the student on its roster. Here it arrives by email, from a person who transferred out last spring, to whichever address they could find on your site. If that address is a general enquiries inbox, the request will sit there.
A way to establish who is asking. This is yours rather than ours, and it is the part institutions most often have not thought about. A request to release or delete somebody’s images from an unverified address should fail, and it should fail deliberately rather than because nobody got round to it.
A way to act on it that is not a search. This is the part that is software. If your imagery is folders, then acting on a withdrawal means somebody going through folders, and the honest outcome of that is “probably most of them”. If a photograph is attached to a person, acting on it is the ordinary thing the system does.
What a withdrawal reaches, and what it cannot
Being precise about this is more useful than being reassuring, because the reassuring version is not true.
| Where their image is | Does the withdrawal reach it? | What actually happens |
|---|---|---|
| A public gallery on your site | Yes, at the next view | The check runs when somebody looks, not when the link was made |
| An arrangement you gave a partner | Yes, at the next use | Permissions are consulted each time it is used |
| A brochure at the printer | Only if you catch it | The material is composed from the gated library, so a rebuild excludes them |
| Ten thousand printed prospectuses | No | Nothing recalls a printed object, and we will not claim it does |
| A screenshot somebody took | No | The same is true of every system anybody will sell you |
The bottom two rows are why the moment of agreement matters more than the mechanics of withdrawal. A specific agreement, made by an adult who understood the use, is the thing that prevents the situation. A withdrawal is the remedy, and remedies are always partial.
How a photograph reaches the right person
A permission-checked lookup against your own roster: a name and an id. Your staff already know who was at an event they organised, so the interesting alternative — sorting by recognising faces — would answer a question the roster has answered, and pay for it with a stored biometric template for every enrolled adult.
That capability exists in the wider platform. It is off unless the subject switches it on for themselves, which at this level is a genuine choice by the person concerned rather than by a guardian. Where it is on, the template is a set of numbers derived from a photograph rather than a saved picture of a face; it stays inside the private cloud we run ourselves and is never sent to an outside service. Withdrawal stops the matching at the point of asking.
The part we have not finished. Destroying one of those stored templates at the end of its retention window is not something we can demonstrate from one end to the other. So we will not tell you it happens nightly, on withdrawal, or at the end of the window.
How it is built to fail is what we can tell you: the cleanup stops and raises a standing alarm rather than marking a template gone when it cannot actually destroy it, and that alarm stays where the institution can see it. When the whole chain can be shown, this will say so.
The questions this raises
Who actually holds the decision?
The person in the photograph. Not a guardian, not the institution, and not whoever runs the account it was going to be posted to. That is the single change that arrives with adulthood, and almost every practical difference on this site follows from it.
Does an institution ever override it?
Not for publication. There are operational uses -- a card, a roster screen -- that exist because the institution needs to identify people, and those are limited to what the student was told they were for. Anything beyond that is a separate agreement with the person.
Can a student withdraw after they leave?
Yes. It applies from that point, at the next time anybody looks. It does not reach a printed prospectus that is already in circulation, and we are not going to tell you it does -- a system that claimed to un-print something would be lying about the one thing everybody can check.
What if we cannot verify who is asking?
Then you do not act on it, and that is the correct answer rather than an unhelpful one. A request to release or delete somebody's images that arrives from an unverified address is exactly the shape of a request that should fail. Having a defined way to verify is part of what an institution needs before it needs software.
Is any of this facial recognition?
Not by default. Face matching exists in the wider platform, it is off unless the subject switches it on for themselves, and the everyday way a photograph reaches the right person is a permission-checked lookup against your own roster. Where it is on, the template is a set of numbers derived from a photograph rather than a saved picture of a face, it stays inside the private cloud we run ourselves, and it is never sent to an outside service.
What have you not finished?
One thing, and it is here rather than in a footnote. Destroying a stored face template at the end of its retention window is not something we can demonstrate from one end to the other. The cleanup stops and raises a standing alarm rather than marking a template gone when it cannot actually destroy it. When the whole chain can be shown, this will say so and not before.