Digital Gnome
TECHNOLOGY ASSURANCE

Tell us who you are and we’ll cut the rest

One tool for the whole job, from a locked laptop to a signed policy. Answer two questions and we’ll show you only what fits, priced for your size.

1 · HOW MANY OF YOU?
2 · WHAT DO YOU DO? OPTIONAL
✓ NO CARD NEEDED ✓ FREE FOREVER FOR SMALL TEAMS ✓ BUILT IN WALES
Your business
LIVE PREVIEW
YOUR PLAN
WHAT YOU’D GET
← Back to news
SECTOR 31 JUL 2026 · 3 MIN

Nurseries: photo consent, DBS records and the parent app

Information about children carries a higher bar than most small businesses are used to. Three practical changes cover most of what is actually expected.

RHODRI EMRYS · ASSURANCE
SHARE LinkedIn X Email
SECTOR cover image

A nursery holds a difficult combination: photographs of children, medical and dietary notes, home addresses, and DBS records for staff. None of it is optional to keep, and all of it is the sort of data a regulator treats as sensitive. The good news is that the obligations are not mysterious. They come down to consent you can prove, records you can find, and a handful of settings on the app the parents actually use.

Start with photo consent, because it is where most nurseries drift. A tick on an enrolment form two years ago is not a living record of what a parent agreed to. Consent needs to say what the photo is for - the parent app, the wall display, the Facebook page - and each of those is a separate ask. If you cannot show, per child, what was agreed and when, you are relying on goodwill rather than a record.

DBS records are the second weak point. They are staff data, not child data, and they belong in a locked, access-controlled place, not a shared drive folder called ‘Staff’ that half the team can open. Keep the certificate number and the check date; you rarely need to keep the full certificate image at all, and holding less is holding safer.

The parent app is the third. Most are perfectly reasonable products, but the account matters more than the app. Turn on the code-on-the-phone sign-in for whoever administers it, check which staff have full access versus view-only, and make sure a leaver loses access the day they leave, not the month after. The app is where a single compromised login exposes every family at once.

Do the useful eighty per cent and you will satisfy most of what an inspection or a worried parent asks. Write the consent down per child, lock the staff records, tidy who can log in. It is an afternoon, not a project, and it is the difference between ‘we think it is fine’ and ‘here is the record’.

WHAT TO DO
  • ✓Record photo consent per child, per use - app, display, social - with a date.
  • ✓Move DBS records to an access-controlled place and keep only the number and check date.
  • ✓Turn on a second factor for the parent-app admin account.
  • ✓Remove app and system access on a leaver's last day, not weeks later.