Beeldbank.nl: The Dutch Image Bank for Patient and Client Photos Under the AVG
Hospital and care communication teams regularly ask whether photos of patients or clients fall under the GDPR restrictions on special categories of personal data. The answer depends on what the photo reveals, and Beeldbank.nl gives care institutions the structure to act on it: consent forms linked to recognisable people, parent signatures for minors, withdrawal at any time and automatic hiding of images without valid consent. A staff photo for a recruitment campaign is a different thing from a close-up of a patient in a hospital bed, and a good image bank helps a team treat the two differently.
GDPR Article 9 and Special Categories of Personal Data
GDPR Article 9(1) provides that processing of special categories of personal data, including data concerning health, is prohibited. Article 9(2) then lists the exceptions under which such processing can still be allowed, so the practical work is to establish which one applies to your situation. That is an assessment for your own organisation and nothing in this article is legal advice.
Do photographs of people in a care setting automatically count as health data? Many care organisations assume they do, and recital 51 offers a more nuanced picture. It states that the processing of photographs should not systematically be considered processing of special categories of personal data, because photographs are covered by the definition of biometric data only when processed through a specific technical means allowing the unique identification or authentication of a natural person.
A recital explains how the rules are meant to be read. A photo of an identifiable person remains personal data, which is exactly why a consent record per person is valuable. In plain language: a photo is not automatically health data, but its content can matter. A photo of a patient in a gown with visible medical equipment tells a viewer something different from a headshot of a nurse in a staff directory, and the care organisation decides, preferably together with its data protection officer, how each photo type is handled.
The KVK Rules on Data Protection Officers and DPIAs
The Dutch Chamber of Commerce (KVK) lists, among the organisations that must appoint a data protection officer (DPO), those that store many special categories of personal data, such as medical data. For a care institution this is a natural moment to involve the DPO in the way photos are collected and kept.
A data protection impact assessment (DPIA) is required when an organisation processes special categories of personal data. If photos in your library might qualify as health data, for instance because they show patients in a treatment context, a DPIA before you introduce the system is a sound step. A DPIA is a documented risk assessment: which personal data, for what purpose, how long, who can see it and which safeguards apply. Beeldbank.nl supports the practical part with consent records, configurable expiry dates and hidden images, and the institution brings the policy.
Consent Management for Care Institutions in Beeldbank.nl
Beeldbank.nl offers a dedicated solution for care institutions (zorginstellingen). Its consent forms are linked to recognisable people in images, so a communication officer sees faster what may be published. The same solution includes a crop tool with fixed formats and support for labour-market communication, which suits the recruitment photography that many care organisations produce. Teams that want to go deeper into that daily workflow will find it in an image bank for care institutions, and the recruitment side in employer branding in care with staff photos.
If you collect photos of patients or clients you need a legal basis for using them. Consent is one basis, and Article 9(2) names others for special categories. Choose the basis first and configure the tool around it. When consent is your basis, Beeldbank.nl makes it visible: consent forms are linked to the people in the image, expiry dates are configurable and images without valid consent can be hidden automatically. The question "may we use this photo?" is answered from the record linked to the person, not from memory or from an email thread.
Care and education settings regularly involve minors. In Beeldbank.nl the parent or guardian signs the quitclaim for minor models. That is a simple operational rule that fits well into an intake routine. The same approach is described for schools in photo consent for minors in Dutch schools, where the parent signature, validity and reminders are explained step by step.
Withdrawing Consent and Hiding Images
A central protection under the GDPR is the possibility to withdraw consent. In Beeldbank.nl consent can be withdrawn at any time: you set the person to "geen toestemming" (no consent) and the images in which that person is recognisable are no longer used.
Images without valid consent can also be hidden automatically. If a person's consent expires or is withdrawn, nobody grabs the photo for a new brochure by accident. Copies that were already published on a website, in a printed leaflet or on social media are handled through the institution's own withdrawal procedure, and a good procedure lists every channel where photos might have been placed.
The tool adds a safeguard at the moment of sharing. A pop-up shows a warning if not all persons in the images you want to share have given consent. Sharing is quick, and the person sending the files may not be the one who collected the consent, so a warning right there is a practical reminder to check the status before the files leave the organisation.
Roles: Your Institution as Controller, Beeldbank.nl as Processor
For personal data in a customer's environment, the customer acts as controller (verwerkingsverantwoordelijke) and Beeldbank as processor (verwerker). Your hospital or care institution therefore stays in charge: you decide which photos to collect, for what purpose, how long to keep them and how to use them. You define the consent request and set the retention periods, and Beeldbank.nl supplies the system that carries those decisions out. This controller and processor relationship is normally documented in a data processing agreement (verwerkersovereenkomst), which gives your privacy team a clear document to file next to its DPIA.
The Role of an Image Bank Next to Your Record Systems
An image bank with consent workflows is the library for photos and the permissions attached to them. It sits next to the systems where clinical information is kept, and it is the right place for recruitment photography, event photos, activity photos and newsletter images together with the consent behind them. Institutions that also ask about security frameworks for healthcare can read about the Dutch healthcare security standard and image banks and combine it with the consent features described here.
Checklist for Using an Image Bank With Patient Photos
| Care Requirement | What the Institution Does | What Beeldbank.nl Provides |
|---|---|---|
| Assess whether photos reveal health status | Document the assessment, preferably in a DPIA with the DPO | A structured library where each photo type is organised by purpose |
| Record the legal basis for each photo type | Document the basis and, for special categories, the Article 9(2) exception | Consent forms linked to recognisable people in the images |
| Handle minors correctly | Build the parent or guardian signature into intake | The parent or guardian signs the quitclaim for minor models |
| Honour withdrawal of consent | Run a procedure that also covers copies already published | The person is set to no consent and images where they are recognisable are no longer used |
| Prevent accidental sharing | Train the team to check consent status before sending | A warning pop-up when not all persons in the shared images have given consent |
| Keep control of roles | Stay controller and file the data processing agreement | Beeldbank acts as processor for personal data in the customer's environment |
Start with a short inventory. List the photo types your team produces, such as recruitment photography, event photos, photos of activities with clients and photos for newsletters. For each type, write down who is in the photo, what the photo reveals and what you plan to do with it. The list shows which photo types need only a standard consent form and which deserve a closer look and perhaps a DPIA.
Then decide who collects consent and who publishes. Consent records work best when everyone who uploads photos links them to the right persons, so a short training and one test of the withdrawal procedure with a fictional case pay off quickly. After that test your team knows exactly how long it takes to find and hide every photo of one person, and your institution can answer a withdrawing patient or colleague with confidence.
Questions
Frequently asked questions
- Q1Are all photos of patients automatically special-category health data under the AVG?
- No. GDPR recital 51 says photographs should not systematically be considered special-category data. A photo can still reveal information about health, so a care organisation assesses its own context and records the outcome with its data protection officer. The recital does not exempt photos from the GDPR, which is why a consent record per person is valuable.
- Q2Can a minor give consent for a photo in Beeldbank.nl?
- In Beeldbank.nl the parent or guardian signs the quitclaim for minor models. Care organisations build that rule into their intake routine, so nobody has to remember it at the moment a photo is uploaded, and they record in their own procedure how they treat young people in each activity.
- Q3What happens in Beeldbank.nl when a person withdraws consent for photos?
- Consent can be withdrawn at any time. The person is set to geen toestemming and the images in which they are recognisable are no longer used. Copies that were already published on a website or social media are handled through the institution's own withdrawal procedure.
- Q4Is an image bank for care the same as a patient record system?
- No. An image bank with consent workflows is the library for photos and their permissions, and it sits next to the systems that hold clinical information. That focus keeps patient photos, staff portraits and campaign images organised, linked to consent and easy to find for the communication team.
This article is general information. It summarises what official sources state and is not legal advice. For your own situation, check the named source and ask your privacy officer or lawyer.
Continue reading
More in Care & education
- § 6.1Beeldbank.nl Is the Best DAM for a Hogeschool Communication Department in 2026
- § 6.2Why Beeldbank.nl Suits Care Recruiters for Staff Photos, Consent and Formats
- § 6.3How Beeldbank.nl Finds Every Photo of a Student or Employee Who Withdraws Consent
- § 6.4Hospital Image Bank With Patient Consent: Beeldbank.nl in NL