Schools Warned After Criminals Manipulate Children’s Photos from Websites

Many school websites and social media feeds contain photographs of students in a variety of settings; from participating in lessons or sports to performing on stage or enjoying educational visits. This practice is often justified on the basis that such images showcase achievement and attract prospective families. Some have even said to this author, “It looks good with Ofsted.” But the dangers of this practice have been highlighted recently by the Internet Watch Foundation (IWF) and the National Crime Agency (NCA).  

The IWF and NCA report an increase in criminals exploiting publicly available images of children to create realistic sexualised content using Artificial Intelligence. Analysts found 3,440 AI-generated videos of child sexual abuse in 2025, compared to just 13 in 2024. Most worryingly, IWF report that an unnamed UK secondary school was recently subjected to a blackmail attempt after criminals downloaded photos of children from the school’s website or social media accounts and then, using AI tools, turned them into child sexual abuse material. The criminals then demanded payment from the school to prevent the images from being shared online. 

The IWF and NCA are recommending that educational institutions remove identifiable pictures of children from their websites and social media accounts.  

AI Enabled Sextortion 

Blackmailing people over intimate images, also known as sextortion, has a become increasingly prevalent in recent years following the trend to share the most intimate details online. Children, especially young girls, are particularly vulnerable. Sometimes they face pressure from boys to show their “commitment” to a relationship by sharing intimate images.
The Children’s Charity, The NSPCC, and The Report Remove service, which allows children in the UK to confidentially report sexual images and videos of themselves and remove them from the internet, have recently reported a sharp rise in children being blackmailed over sexual images. There have also been cases of British teenagers who have killed themselves after receiving extortion threats

The advancement in Generative AI tools now mean that any image, no matter how innocent, can be sexualised. Readers may remember the controversy involving Grok; the AI companion built into X, Elon Musk’s social media platform.  It began in May 2025 when users prompted Grok to alter photos of real women into sexualised images. By late 2025 it had escalated dramatically; users simply replied to public photos with requests like “put her in a bikini,” and Grok posted the generated images directly to X, publicly and instantly. Estimates suggest it produced around 4.4 million images in nine days, with 41 to 65 per cent sexualised. Some of those images involved children. X has since made changes to Grok to prevent abuse. More recently Meta was forced to withdraw its new AI tool Muse Image, following a public backlash. It could generate new photos using other people’s social media profile photoswithout telling them.  

Data Protection  

Publishing photos of children is also a data protection issue and so needs to comply with the UK GDPR. Like all processing of personal data it needs to be, amongst other things, fair, lawful and transparent. Data subjects, including children, have rights including the right to object and receive a copy of their data, including images, and ask for them to be deleted (subject to some exceptions).  

The Information Commissioner’s Office guidance about photos in schools emphasises the importance of complying with the UK GDPR but needs an update to cover the dangers of AI. Most schools will have a privacy policy and a procedure for collecting consent from parents before publishing images of their children. However research by Northumbria University, and published by Defend Digital Me, a children’s rights campaign group, states that only 7% of education authorities who disclosed their schools image guidance (following FOI requests) mentioned that posting photographs on social media may pose a risk to children’s privacy. The research authors suggest that parents are therefore being asked to provide consent to photographs being shared online without being told of the risks that this may pose. 

Raising Awareness 

There is a clear need here to educate parents, children and schools about the dangers (as well as the legal issues) posed by AI when it comes to public images of children. 

The Internet Watch Foundation and the National Crime Agency have produced a new guide for parents and carers which recommends amongst other things, reviewing privacy settings on apps, talking to their children, and knowing what to do if something goes wrong. This follows similar advice they issued to education professionals last year, on how to protect student images from AI manipulation. 

In the Guardians of Data podcasts we delve deeper into the issues raised here:  

  • In Episode 2 we explore the Grok AI controversy. 
  • In Episode 6  we discuss the legal, ethical and societal issues around taking photographs in public for social media.  
  • In Episode 8 we analyse the Government’s plans for our children’s data, discuss children’s privacy in the internet age and the role Big Tech is playing in the collection storage and analysis of all our data.  

Our GDPR Essentials E Learning course is ideal for school staff and education professionals who require foundational knowledge about GDPR compliance and the key risk areas. Click here to watch a preview.

See also our workshop: Working with Children’s Data

Facial Recognition in Schools: ICO Reprimand

For a number of years schools have used biometrics, particularly fingerprint scanning, to streamline various processes such class registration, library book borrowing and cashless catering. Big Brother Watch (BBW) raised privacy concerns about this way back in 2014. Recently some schools have started to implement facial recognition technology (FRT).

FRT is even more problematic. In May, BBW launched a fundraiser to support two members of the public to bring legal challenges after FRT wrongly flagged them as criminals. And in January 2023, the ICO issued a letter to North Ayrshire Council (NAC) following their use of FRT in school canteens. The Financial Times reported that, “nine schools in North Ayrshire will start taking payments for school lunches by scanning the faces of pupils, claiming that the new system speeds up queues and is more Covid-secure than the card payments and fingerprint scanners they used previously.”

Last week the ICO issued a reprimand to Chelmer Valley High School, in Chelmsford, after it started using FRT to take cashless canteen payments from students. The ICO said that the school failed to complete a Data Protection Impact Assessment (DPIA), in compliance with of Article 35(1) of the UK GDPR, prior to introducing the system.

As readers will know, when processing any form of biometric data, a data Controller requires a lawful basis under Article 6 of the UK GDPR as well as Article 9 due to the processing of Special Category Data. In most cases, the only lawful basis for FRT usage is express consent (see the GDPR Enforcement Notices issued to public service provider Serco Leisure, Serco Jersey and seven associated community leisure trusts  requiring them to stop using FRT and fingerprint scanning to monitor employee attendance)

In March 2023, Chelmer Valley High School sent a letter to parents with a slip for them to return if they did not want their child to participate in the FRT. Positive opt-in consent (express consent) was not sought, meaning until November 2023 the school was wrongly relying on assumed (opt out) consent. The ICO noted most students were old enough to provide their own consent and therefore, parental opt-out deprived students of the ability to exercise their rights and freedoms.

The ICO also noted that the School has failed to consult its Data Protection Officer or the parents and students before implementing the technology. The reprimand included a set of recommendations:

  1. Prior to new processing operations, or upon changes to the nature, scope, context or purposes of processing for activities that pose a high risk to the rights and freedoms of data subjects, complete a DPIA and integrate outcomes back into the project plans. (see our DPIA workshop). 
  1. Amend the DPIA to give thorough consideration to the necessity and proportionality of cashless catering, and to mitigating specific, additional risks such as bias and discrimination.
  1. Review and follow all ICO guidance for schools considering whether to use facial recognition for cashless catering.
  1. Amend privacy information given to students so that it provides for their information rights under the UK GDPR in an appropriate way. (see our Children’s Data workshop). 
  1. Engage more closely and in a timely fashion with their DPO when considering new projects or operations processing personal data, and document their advice and any changes to the processing that are made as a result.

All the recent GDPR developments will be discussed in detail on our forthcoming GDPR Update workshop. We have a few places left on our Advanced Certificate in GDPR Practice course starting in September.

GDPR is coming but don’t panic!

GDPR General Data Protection Regulation

The General Data Protection Regulation (GDPR)will come into force in 3 weeks time. 25thMay though is not a cliff edge; nor is it doomsday when the Information Commissioner will start wielding her 20million Euro (fine) stick!

In December, the Commissioner addressed some of the myths being peddled about GDPR:

“I‘ve even heard comparisons between the GDPR and the preparations for the Y2K Millennium Bug…

In the run up to 25 May 2018 there have been anxieties too, albeit on a less apocalyptic level. Things like we’ll be making early examples of organisations for minor breaches or reaching for large fines straight-away and that the new legislation is an unnecessary burden on organisations.

I want to reassure those that have GDPR preparations in train that there’s no need for a Y2K level of fear…”

There are a number of steps that you should be doing to prepare for GDPR. Remember, failure to have completed these tasks by 25th May will not lead to a 20 million Euro fine. However, to quote the commissioner at the ICO Conference this year, “It’s important that we all understand there is no deadline. 25th May is not the end. It is the beginning.”

  1. Raising awareness about GDPR at all levels. Our GDPR e learning course is ideal for frontline staff.
  2. Carrying out a data audit and reviewing how you address records management and information risk in your organisation.
  3. Reviewing information security polices and procedures in the light of the GDPR’s more stringent security obligations particularly breach notification.
  4. Revising privacy polices in the light of the GDPR’s more prescriptive transparency requirements. See our policy
  5. Writing polices and procedures to deal with new and revised Data Subject rights such as Data Portability and Subject Access.
  6. Considering whether you need a Data Protection Officer and if so who is going to do the job. Our GDPR certificate course is ideal for new DPOs.

Done everything? Have a go at the ICO’s GDPR Self Assessment Toolkit. Read the Commissioners full speech here.

Please get in touch if Act Now can help with your GDPR preparations. We provide audits, health checks and can offer a gap analysis, all followed by a step by step action plan!

 

The school that didn’t learn its lesson.

In 2011 I received a gorgeous CD through the mail from a school. It invited me to send my children (at the time aged 30, 29 and 25) to their school (35 miles away from my house). Read the full story on Act Now website ( a Northern school). I did complain to the ICO but his decision was in favour of the school. This was my conclusion to the affair.

“A school/college with no prior relationship with me buys my name from a list broker as I am apparently rich and with junior age children (wrong on both counts) and then sends me unsolicited marketing material through the post. When I exercise my right to subject access they ignore it for two and a half weeks then fail to give me what I ask for because they don’t know from where they obtained my personal data.

The ICO when asked to look into the case decides the college did nothing wrong.

Moral – keep bad records, mail who you like even those with no relevance to your product, fail to respond to individuals exercising their right to access promptly and you’ll be fine rather than fined. “

I put it down to experience never expecting to hear from the school again but today they emailed me. Despite me reporting them to the ICO and an investigation taking place and their promise to delete my name and address from their database they emailed me with an offer I couldn’t refuse.

I will complain again. This time I have PECR on my side as they have strayed into electronic marketing as well as basic section 11 stuff. The school is also now a serial offender. Will the ICO listen, take action or will I get a similar response 5 months after I complain. See you around Xmas time.

It’s time to name and shame Queen Ethelburgas. Look out for the information notice.

It gets worse.  I chose to report the message as spam as they invited me to. Here’s the screenshot of  their procedure. Only a few errors in spelling and punctuation.

usub

Playground Duty

Teaching? A mugs game. The (mythical) long holidays, the (mythical) 3-30 finish, the (mythical) relaxed and friendly environment as you helped the enthusiastic next generation prepare for adult life…

Playground duty was the bane of my life when I was a teacher. Once a week you had to forgo the 15 minutes of peace in the staff room and that warm cup of coffee and patrol the school playground, breaking up fights, solving Rubik’s cubes and avoid being caught by those awful children’s jokes (If a bottle of medicine cures a cough what does half a bottle of medicine cure?).

So on a recent training session for schools in a northern council we talked to the delegates – mostly Headteachers – about the Publication scheme. We looked at the definition document listing the material the ICO recommended schools to pro-actively publish, we gave them the two common sense Act Now solutions (1. find all the relevant documents and put a paper copy of them in a ring binder in the school office then photocopy on demand or 2. turn them into PDFs and put them on the website so people can download what they want).

After considering all this and thinking for a moment or two one of the delegates (a headteacher no less) said  ” I don’t think we’ll bother with this. It’d take too long.”

What’s the punishment for forgetting to do playground duty?

Opprobium, embarrassment,  ridicule, double duty next week.

What’s the punishment for failing to carry out a duty under section 19 of the Freedom of Information Act for seven and a half years?

Over to you….

(The answer is 50% of a cough. Whatever you do don’t say half a cough).

Marion. The FOI exemption for schools.


We delivered some training today to a school in the north – we have a briefing for schools covering DP & FOI in a half day – and as usual prior to the training we did some research which included making a FOI request to the school. Right at the very end of the afternoon after the case studies and the questions the trainer asked if the school had received any FOI requests in the last 7 years. The head teacher sitting bravely on the front row shook his head. Others chimed in and consensus was milliseconds away when the trainer showed on the screen the screen grab of the request that had been made by email 19 days ago using the school’s contact us page.

Silence and almost simultaneously darkness fell.

‘Looks like a request to me” intoned the trainer, “it’s asked for a biography of the Headteacher and details of his reimbursement package for the last financial year”.

Then Marion the school secretary who’d been sitting at the back spoke. “I might have seen that one” she chirped, ” but I delete anything that looks dodgy”.

“What’s dodgy?” ventured the trainer,

“The name, the email address – I don’t allow hotmail ever”, replied the determined administrator.

The trainer tested out a few requests that he knew had been sent to schools in general – the knife incident request, “deleted that” , The CRB question, “deleted that” and the realisation that Marion had set up a foiwall that had yet to be penetrated settled on the room.

Add in the lack of publication scheme, lack of privacy policy and lack of training and it’s clear there’s a lot of work to do in schools. We have a range of services from an online session to a full day in school with audit, policy work & training. See our website.

Marion is of course a pseudonym. Her real name was Margery.