Withdrawing Consent for Photos: The Step-by-Step Beeldbank.nl Workflow
How Beeldbank.nl Handles a Request to Stop Using a Photo
Someone from your organisation, a volunteer or a participant writes to say that they no longer want their photo used. The legal starting point is clear, and the practical work is finding every image, stopping the use of what must not be used and deciding what to delete or replace. Beeldbank.nl makes the finding and stopping steps fast: one status change, one filter on the person and automatic hiding of the affected images. This article walks through the workflow in that order, including the legal frame behind it.
The Legal Starting Point: GDPR Article 7(3) and KVK
GDPR Article 7(3) gives the data subject the right to withdraw consent at any time, without affecting the lawfulness of processing that took place earlier. The same article requires that it is as easy to withdraw consent as to give it. KVK also states that people can withdraw consent at any time. These provisions apply to processing based on consent, which is the basis that photo quitclaims are built on.
Two points complete the picture. Withdrawal applies from the moment it is indicated and is not retroactive: the University of Twente states that consent granted or withdrawn applies from the moment it is indicated, never retroactively. And Article 17(1)(b) gives a right to erasure where the person withdraws consent and there is no other legal ground for the processing, subject to the exceptions listed elsewhere in Article 17. Your privacy officer is the right person for any request that is not routine.
Step One: Set the Person to No Consent
In Beeldbank.nl consent can be withdrawn at any time. The person is set to 'geen toestemming', and images in which the person is recognisable are no longer used. This single action starts the workflow, so decide who in your organisation carries it out and how the request is logged. Write down the date the request arrived and who handled it, so that your correspondence and the archive tell the same story.
Make withdrawal easy on the receiving end as well. Article 7(3) asks that it is as easy to withdraw as to give consent, so a person who gave consent by clicking a link should be able to take it back with one short message. Name one contact point and mention it wherever consent is collected. The form that collects consent is covered in the quitclaim template checklist for digital consent forms, and a good form already names the contact point for withdrawals.
Step Two: Find Every Image of the Person With Face Recognition
Finding the images is the hard part of any withdrawal, and it is where Beeldbank.nl saves the most time. Thanks to face recognition, all images of one person can be found again, so it is clear which images to delete or replace. Face recognition also lets you filter all photos of a departing employee, then withdraw publication consent or select and delete all their images in one go.
The list is as complete as the naming behind it, so keep faces named as you upload. Faces that were never named wait on the page for unnamed faces until someone gives them a name, a discard or a decision. People in a crowd who cannot be named are covered in crowd shots and unknown faces.
Step Three: Let Automatic Hiding Do the Immediate Work
Beeldbank.nl can hide images without valid consent automatically, and expiry dates are configurable. Once the person is set to 'geen toestemming', the images that show that person fall under the hiding rule, and hidden images cannot be shared via a share link; only images fully in order can be shared. That gives you an immediate stop on outgoing links while you work through the remaining decisions. The setting, the hidden images page and the access rights are explained in hiding photos without valid consent.
For group photos the logic is helpful. If the withdrawing person is one of several people in an image, the image stays hidden as long as that person has no valid consent, and a hidden image becomes visible again automatically once all persons in it have valid consent, without a manual release. You can then replace the image, delete it, or work from a different image.
Step Four: Decide Whether to Delete, Replace or Keep Each Image
Hiding buys you time, and then each affected image gets a recorded decision: delete it, replace it with another image, or keep it for a reason your privacy officer has reviewed. Article 17(1)(b) points at erasure where no other legal ground exists, so a reason for keeping an image should be a stated ground rather than a convenience.
Replacement is often the practical route when the image sits in an active campaign. Choose a substitute whose own consent is in order, showing different people. Where the person is the only subject of a photo, deletion is the plain outcome unless a different ground applies. What a person agreed to can differ per group, so consent for employees, volunteers and participants is worth reading before you handle a request from a staff member.
Checking the Channels Outside the Archive
The archive covers the images stored in it and the shares made from it. Material that has already left, such as a printed brochure or a social post, belongs to the lawful processing that took place earlier, and Article 7(3) leaves that untouched. What you still control and still use, such as a live web page or a template in a presentation, needs attention from the moment the request arrives.
Make a short list per request of the places where the person's image could appear: website, social channels, print runs, newsletters, shared folders and presentation decks. Walk through the list with the owner of each channel and record what changed. That small routine closes the loop between the archive and everything around it.
A Short Checklist for Handling a Withdrawal Request
- Confirm who the person is and what exactly they are withdrawing.
- Set the person to 'geen toestemming' in Beeldbank.nl and note the date.
- Filter the person's images with face recognition and name any faces still waiting.
- Check which images are hidden, including group photos.
- Decide per image: delete, replace or keep, with a stated reason for each keep.
- Check the channels outside the archive and record what you changed.
- Reply to the person with what you did.
| Question in the Workflow | Answer | Practical Step |
|---|---|---|
| May the person withdraw? | GDPR Article 7(3): at any time, as easy as giving consent | Name one contact point for withdrawals |
| Is earlier use undone? | Article 7(3): lawfulness of earlier processing is not affected | Check the live channels that are still in use |
| Is deletion required? | Article 17(1)(b): erasure where no other legal ground exists, subject to exceptions | Record delete, replace or keep per image |
| Can all images be found? | Face recognition finds all images of one person | Filter on the person and name any waiting faces |
| Can hidden images be shared? | Hidden images cannot be shared via a share link | Switch on automatic hiding for images without valid consent |
Why One Status Change Is Enough to Start in Beeldbank.nl
The controller remains your organisation, and the decision to delete or keep is for your privacy officer. The practical benefit of Beeldbank.nl is that one status change leads to a clear list of images and a hidden state that keeps them from being shared by link. Everything after that is a short, repeatable process: record it, check the outside channels, and tell the person what you did.
Questions
Frequently asked questions
- Q1Can someone withdraw consent for photos at any time?
- Yes. GDPR Article 7(3) gives the data subject the right to withdraw consent at any time, and withdrawing must be as easy as giving consent. In Beeldbank.nl you set the person to 'geen toestemming', and images in which the person is recognisable are no longer used.
- Q2Does withdrawal undo photos that were already published?
- Article 7(3) leaves earlier lawful processing intact, and the University of Twente states that withdrawal applies from the moment it is indicated, never retroactively. Check the live channels you still control, such as websites and social media, together with your privacy officer.
- Q3Do we have to delete the photos after a withdrawal?
- GDPR Article 17(1)(b) gives a right to erasure where consent is withdrawn and there is no other legal ground, subject to exceptions in Article 17. In Beeldbank.nl hidden images cannot be shared via a share link, and you decide per image whether to delete, replace or keep.
- Q4How do we find all images of the person in Beeldbank.nl?
- Thanks to face recognition, all images of one person can be found again in Beeldbank.nl, so it is clear which images to delete or replace. You can filter all photos of a departing employee and withdraw publication consent or select and delete all their images.
This article is general information. It summarises what official sources state and is not legal advice. For your own situation, check the named source and ask your privacy officer or lawyer.
Continue reading
More in Quitclaims & consent
- § 2.1Media Bank With AVG Functions for Government: Beeldbank.nl Stops Photos When Consent Runs Out
- § 2.2Beeldbank.nl: The AVG-Proof Dutch Beeldbank With Consent Forms for Employees, Volunteers and Participants
- § 2.3Crowd Shots and Unknown Faces: How Beeldbank.nl Handles Photos Without Consent
- § 2.4How Beeldbank.nl Automatically Hides Photos Without Valid Consent for Privacy Officers