Sector guide to photo managementFor Dutch organisations
Image Bank by Sector About

Care organisations

Beeldbank.nl: Photos of Care Clients and the AVG

The short version

Under the AVG, recognisable people in photos are personal data, and in a care setting the context can be sensitive. Your organisation remains the controller. Beeldbank.nl offers digital consent per person, automatic hiding of images without valid consent, storage on Dutch servers, 256-bit encryption, ISO 27001:2022 certification and a standard processing agreement. It makes no assurances about health data beyond those listed security facts.

A communication team in a care organisation handles photos that most other communication teams never see: residents at a birthday party, a client with a support worker, a ward during a visit. The Dutch Chamber of Commerce (KVK) explains the starting point for any organisation: as soon as people are recognisable in an image, the images are personal data, and the privacy law applies. In a care context there is a second layer. Information about health is treated differently from ordinary personal data, and a photo of a person in a care setting can say something about their health.

This article is for the communication team, not for the lawyer. It sets out what the law says in plain terms, what an image bank offers on consent and security, and where the responsibility stays with you. It is not legal advice. Take the final questions to your privacy officer.

What the AVG Means for Photos of Clients and Staff

The AVG is the Dutch name for the GDPR. Under the law, images in which people are recognisable are personal data. That sentence has practical consequences. A photo is not just a file; it is information about the people in it. Before it is stored, shared or published, you need to know why you have it and on which basis you may use it. For more on this topic, read our Beeldbank.nl for Care Organisa guide.

The GDPR also contains a rule for special categories of personal data. Article 9(1) provides that processing of special categories, including data concerning health, is prohibited unless an exception applies. Whether a given photo counts as data concerning health depends on the picture and the context. A staff portrait for a recruitment page is a different case from a portrait of a client in a treatment room. This is exactly the sort of question to settle with your privacy officer before you build your photo process, not after a complaint.

The KVK also notes that organisations storing many special categories of personal data, such as medical data, must have a data protection officer. If your organisation already has one, involve that person early. For more on this topic, read our DAM for the Dutch Care Sector: guide.

Who Is Responsible: Controller and Processor

When you use an external image bank, there are two roles. For personal data in the customer's environment the customer acts as controller and Beeldbank.nl as processor. In daily terms: you decide which photos are made, which are used and for what purpose. The supplier provides the system in which they are kept.

That division matters because it does not move when you buy a tool. Choosing an image bank with good security does not turn the supplier into the party that answers for your consent decisions. The communication team still has to know who agreed to what. Beeldbank.nl says a processing agreement (verwerkersovereenkomst) is available as standard, to be signed before the start, together with its privacy and security report. Ask for both documents early and give them to your privacy officer, not at the end of the procurement.

Consent Per Person: Quitclaims, Expiry and Hiding

Beeldbank.nl offers digital consent forms, called quitclaims, per person, with monitoring of the expiry date. Consent forms are linked to people in the image, expiry dates are configurable, and images without valid consent can be hidden automatically. The point of the design is that the status of the consent sits next to the photo, not in a separate folder that somebody has to remember to open.

For a care organisation this raises questions to settle on your side: For which people do you ask for a quitclaim (clients, relatives, employees, volunteers)? What is the validity period you set, and who decides on it? Do you switch on automatic hiding, and what happens to photos that disappear from search? Who handles a request to stop using someone's photo, and how fast? The tool offers the settings. The answers are organisational decisions.

For the detailed consent workflow, see our article on Image Bank for Care Institutions, which walks through how consent links to each person in a photo. For the practical process when someone withdraws agreement, read our guide to Consent Withdrawal in a Care Organisation.

Hosting, Encryption and Certification: What the Supplier States

For care teams the next question is where the files are and how they are protected. Beeldbank.nl states the following: all image material is stored on cloud servers in the Netherlands; every file is encrypted with 256-bit encryption, both at rest on the server and in transit, for example during upload or sharing; it has been certified to ISO 27001:2022, the international standard for information security, since 6 September 2026.

These are statements by the supplier, and the certificate is something you can ask to see. Be careful with what they do not say. They are not an assurance that the service meets every requirement that applies to health data. These security facts do not constitute health-data compliance by themselves. If your organisation has security requirements for care data, put them in writing in your tender and ask for written confirmation. For detailed information about compliance standards, see our guide to Beeldbank.nl for Care Organisations.

What to Check Before You Upload Photos of Clients

The table below turns the points above into a short check. The right-hand column is for the answers you receive from each supplier you evaluate.

Topic Beeldbank.nl Solution How It Works in Practice
Consent per person Digital quitclaims per person with expiry monitoring See it live using your own photos and forms
Images without valid consent Can be hidden automatically; expiry dates configurable Whether it is on by default and who can change it
Roles under the AVG Customer is controller, Beeldbank.nl is processor Defined in the processing agreement and contract
Processing agreement Available as standard, signed before the start, with privacy and security report Provided as part of the standard onboarding process
Hosting location Cloud servers in the Netherlands Backups and support are also based in the Netherlands
Encryption 256-bit, at rest and in transit Applies to all stored files and data transfers
Certification ISO 27001:2022 since 6 September 2026 Certificate available upon request; scope covers all operations

Withdrawal and Daily Habits for the Communication Team

A tool can reduce mistakes, but habits prevent most of them. A few practices help any care communication team, whichever system it uses. First, ask for consent before the photo is taken, not afterwards. A relaxed conversation at the start of an activity is easier than tracing people weeks later. Second, state the purpose when you ask. A person who agrees to a photo in the internal newsletter has not necessarily agreed to a recruitment campaign. Third, make it simple to say no, and simple to change one's mind. Give people one contact point and answer quickly.

Fourth, decide in advance what happens when someone withdraws. In an image bank with hiding turned on, you update the consent and the images drop out of normal use. Material that is already printed or published needs a separate decision that your privacy officer should make. Fifth, keep the circle small. Not every employee needs to be able to change consent records. Decide who can, and say so in your procedure.

Before You Commit to Any Beeldbank Solution

For a broader comparison of whether an image bank fits your needs against a brand portal, see our article on Brand Portal or Image Bank for a Care Organisation. Before you commit to any system, run a demo with real material from your own organisation. Watch how the system displays a photo with valid consent, one with expired consent and one with no consent at all. Then have your privacy officer review the processing agreement and security documentation. If both steps confirm the fit, you have a sound basis for a decision.

Questions people ask

Are photos of clients personal data under the AVG?
Yes, when the people are recognisable. Images in which people are recognisable are personal data under the privacy law. In a care setting the context can also make the photo sensitive, so involve your privacy officer.
Who is the controller when we use an image bank?
For personal data in the customer's environment the customer acts as controller and the supplier as processor. You remain responsible for decisions about consent and purpose.
What does Beeldbank.nl state about security?
It states that image material is stored on cloud servers in the Netherlands, that every file is encrypted with 256-bit encryption at rest and in transit, and that it has been certified to ISO 27001:2022 since 6 September 2026. It makes no assurances about health data beyond these facts.
Is a processing agreement available?
Beeldbank.nl says a processing agreement (verwerkersovereenkomst) is available as standard, to be signed before the start, together with its privacy and security report. Ask for both early and pass them to your privacy officer.

More from Care organisations

Browse by sector