Check before you share
Media Literacy Guide

Sharenting Safely: Posting About Your Children with Consent and Privacy Settings

How to share family photos online without building an irreversible digital footprint for a child who cannot consent, with exact privacy settings per platform.

The Photo You Post at 3pm Is Still Searchable When Your Child Turns 18

Stop posting photos of your child until you have locked down every account. That is the first instruction. You snap a photo of your child in their school uniform after the Primary One orientation, post it to your Instagram story, and six people reply with heart emojis. That same image is now part of a permanent trail that your child cannot consent to, cannot edit, and cannot delete. The phrase sharenting posting about kids safely Singapore describes the tension every parent on social media faces: you want to share the joy of family life, but the child in the frame has no say in whether that joy becomes public data. The numbers back up the concern. A 2022 Google survey found 56 percent of Singapore parents had posted photos or videos of their children online. The same survey found that 72 percent of Singapore internet users worry about their online footprint. The gap between what parents do and what they worry about is the problem this page solves.

Sharenting Risks: The Searchable Identity Your Child Cannot Outgrow

Every photo you post creates a shadow that extends far beyond your friends list. That shadow includes the image itself, the metadata embedded in the file, the location data from your phone, the timestamp, and the facial recognition profile that platforms build without asking. Once that data is public, it is archived by search engines, copied by other users, and indexed by data brokers who sell profiles to advertisers and insurers. A child whose face appears in a thousand public photos by age ten has a searchable identity that no amount of later settings adjustments can fully retract.

The risks go beyond inconvenience. Identity thieves use the combination of a child's full name and birthdate to open fraudulent accounts. Predators scrape family photos from public accounts and repurpose them. The phenomenon called digital kidnapping, where strangers take a child's image and use it for fake profiles or role-playing, is documented in academic research from 2015 onward. In Singapore, the Personal Data Protection Commission issued advisory guidelines on children's data in March 2024 that explicitly address these risks. The guidelines do not set a fixed age for when a child can consent to data sharing, but they make clear that the parent or guardian must give that consent until the child has the capacity to understand what they are agreeing to.

That capacity is absent in a two-year-old whose bath photo goes viral, and it is questionable in a twelve-year-old who does not yet grasp that a screenshot is permanent. The PDPA consent obligation, which requires organisations to obtain meaningful consent before collecting or using data, applies conceptually here even if enforcement against private individuals is limited. The principle matters: you are making a decision about someone else's data that they will have to live with for decades.

Posting Children Photos: Consent In Singapore Under The PDPA

Singapore's Personal Data Protection Act 2012, last amended in February 2021, does not have a specific age of online consent like the GDPR's 16. Instead, the PDPC advisory guidelines from March 2024 say that where a child below 18 does not have the capacity to consent, the organisation must obtain valid consent from the parent or guardian. Capacity is assessed case by case based on whether the child understands the nature and consequences of giving consent. A teenager who can explain what happens to their data after they post a photo may have capacity. A toddler does not.

You Are The Consent-Giver

The practical effect for a parent is straightforward. You are the consent-giver for every photo you post of your child. That means you are also the person who must assess the risk. The PDPA's accountability obligation requires organisations to take responsibility for the data they collect. As the person who controls the image and the platform account, you carry that same responsibility in a moral if not always legal sense. The PDPC's advisory guidelines on social media services accessed by children under 18 say organisations should implement child-appropriate protections. You should do the same for your own account.

Section 15 of the PDPA includes a provision for deemed consent by disclosure: if someone voluntarily provides their data, they are deemed to have consented to its collection and use. When you post a photo of your child, you are voluntarily disclosing their data. The question is whether you have thought through what that disclosure means.

Child Privacy Settings On Social Media: Locking Down Each Platform

The controls on your social media accounts are the difference between sharing with your mother and sharing with the entire internet. Most platforms default to public or broad visibility. You must change them manually. The settings path differs by platform, but the goal is the same: limit every post about your child to a hand-picked list of trusted contacts.

Facebook

Go to Settings & Privacy, then Privacy Shortcuts. Change 'Who can see your future posts' from Public to Friends. Turn off the option that allows search engines to link to your profile. For each photo album containing your child, set the audience to Custom and deselect 'Friends of Friends'. Facebook's facial recognition setting, found under Face Recognition in Privacy, should be set to Off. This stops the platform from building a face template of your child.

Instagram

Switch to a private account from the Privacy settings. Turn off 'Show Activity Status'. Under Stories, disable 'Allow Sharing' and 'Allow Reshares to Stories'. Under 'Close Friends', build a list of the people you actually want to see your child's photos and post family content only to that list. Do not use the public archive for any image that contains your child's face.

TikTok

Set your account to Private. Under Privacy, turn off 'Suggest your account to others'. Disable 'Allow Downloads' for your videos. Under 'Direct Messages', restrict incoming messages to No One or Friends. TikTok's algorithm will surface your content to strangers if your account is public, so private is the only safe setting for family content.

WhatsApp

WhatsApp status updates are visible to all your contacts by default. Go to Settings, Privacy, Status, and change the audience to 'My Contacts Except' and select the people you do not want to see your child's photos. For shared photos in groups, assume every member of the group can save and forward the image. Send sensitive family photos only in one-to-one messages or groups you personally curate.

These settings do not prevent screenshots. They do not prevent a trusted contact from downloading the image and sharing it elsewhere. They reduce the audience from the entire platform to a known group. That reduction is the single most effective protection you have.

Five Concrete Rules For Sharenting That Protect Your Child

Privacy settings are useless if the content you post is inherently identifiable. These five rules address the content itself, not just the audience.

No Full Names With Birthdates

A photo captioned 'Happy 10th birthday, Marcus Tan Wei Jie' gives a stranger your child's full legal name, their exact age, and their date of birth. That combination is the foundation of identity theft. Use a nickname or first name only, and never include the birthdate in the caption or in the image itself.

No Bath Or Partially Clothed Photos

An image of a child in the bath, in a swimsuit, or in underwear has a high risk of being misused. Predators scrape these images from social media accounts and share them on forums. The child also has a reasonable expectation of bodily privacy that posting does not respect. Keep these images off social media entirely.

No School Uniforms

A photo of a child in their school uniform identifies the school. Combined with the location tag that your phone's camera may embed in the EXIF data, a stranger can determine where your child spends their day. Crop the uniform out of the frame or wait until the child has changed before posting.

No Location-Tagged School Events

Posting a photo from the school sports day with the geotag enabled tells anyone who sees it exactly where your child will be at a specific time. Turn off location services for your camera app before taking photos at school events. Remove the location metadata from the image before posting, or use a photo editing tool that strips EXIF data.

No Photos That Could Embarrass A Teenager Later

A photo that is cute when your child is three may be humiliating when they are thirteen. Bed-wetting stories, tantrum videos, and messy-eating shots are all content that will exist online when your child starts secondary school and their friends search for them. Ask yourself whether the image would be okay if your child were an adult and someone else had posted it without their permission. If the answer is no, do not post it.

The Durability Problem: Archived Content, Screenshots, And Data Brokers

Even after you delete a photo, it may still exist. The platform may keep it in its archived content. A friend may have taken a screenshot. A data broker may have indexed it into a profile. A search engine may still show the thumbnail in its cache. This is not paranoia; it is the architecture of the internet.

The PDPA gives individuals the right to request that an organisation delete their data under Section 22. That right has exceptions, and it only applies to organisations that the PDPA covers. It does not apply to the screenshot your aunt took and posted to her own account. It does not apply to the image that a data broker scraped and sold to an advertising network before you hit delete.

The 2023 Singapore Police Force scam statistics recorded 46,563 scam cases with total losses of SGD 651.8 million. Phishing scams alone accounted for 8,500 cases with SGD 14.2 million in losses. Scammers use publicly available data, including photos, names, and locations, to craft targeted impersonation attempts. A child whose full identity is publicly searchable is easier to target when they start using the internet independently.

What To Do Instead: Alternatives That Preserve Privacy

You do not have to stop sharing family moments. You do have to change how you share them. The simplest alternative is a private, invite-only photo-sharing app that does not have public search, algorithmic feeds, or data-sharing partnerships. Use a service that explicitly states in its policy that it does not sell user data or share it with third parties. Treat the app as a family album, not a social media account.

Strip The Metadata First

For moments you do share on mainstream platforms, strip the metadata first. EXIF data in a photo can include the GPS coordinates of where the photo was taken, the device model, the date and time, and the camera settings. Free tools such as the built-in photo editor on your phone or online EXIF removers can strip this data before you upload. On an iPhone, go to the Photos app, select the image, swipe up, and tap 'Adjust' under the map preview to remove location data. On Android, use the Google Photos app, select the image, tap the three-dot menu, and choose 'Remove location'. For a thorough clean, use a dedicated EXIF removal tool before posting anything that includes your child.

Blur Or Crop Faces

Blur or crop faces in images you post publicly. A photo of your child at the playground from behind, or with their face blurred, does not contribute to facial recognition databases and does not give a stranger a searchable image. If the point of the post is the activity, not the child's face, the blur does not reduce the value of the story.

Sharenting Risks: What The Research Says

The academic research on sharenting is consistent and sobering. Multiple studies published between 2018 and 2024 identify the same core risks: identity theft, digital kidnapping, metadata exposure, the creation of a permanent online record for the child, and the misuse of images by predators. The research does not claim that every shared photo leads to harm. It claims that the cumulative effect of hundreds of shared photos creates a searchable identity that the child cannot control.

In Singapore, the GUSTO study from the National University of Singapore found that children aged 3 to 7 spend an average of 2.5 hours per day on screens. The 2021 Google-Temasek study found that 68 percent of children aged 8 to 12 own a smartphone. These children are growing up with online identities that their parents started building before they could speak. The PDPC's 2024 advisory guidelines on children's data explicitly recommend that organisations operating social media services likely to be accessed by children under 18 implement child-appropriate protections. The same logic applies to parents: treat your child's data with the same care you would expect from a bank or a government agency.

Posting Children Photos Consent Singapore: Your Legal And Moral Obligation

Singapore's PDPA does not directly regulate what a parent posts on their personal social media account. The Act covers organisations, not individuals acting in a purely personal capacity. But the principles the Act enshrines, consent, purpose limitation, protection, and accountability, are a useful framework for thinking about your own behaviour. The PDPC's advisory guidelines on children's data state that organisations must obtain valid consent from the parent or guardian where a child below 18 does not have capacity to consent. As the parent, you are the consent-giver. You are also the person who will have to explain to your teenager why their entire childhood is publicly searchable.

The accountability obligation under the PDPA requires organisations to take responsibility for the data they collect. Translate that into your own practice: take responsibility for every photo you post. Ask yourself what purpose the post serves. Is it for your own sense of connection? Is it for the validation of likes and comments? Is it for the child's benefit? If the purpose is your own gratification and the benefit to the child is zero or negative, the post should not go up.

The Honest Caveat: You Cannot Fully Protect A Child You Post About

The hard truth is that no privacy setting, no metadata scrub, and no cropping technique can completely protect your child once their image is online. A trusted contact with a screenshot, a platform data breach, or a future AI model trained on public images can all expose a photo you thought was private. The only way to guarantee that your child's image never enters a data broker's database, never feeds a facial recognition model, and never embarrasses them at age 15 is to not post it at all. Every parent must decide where on that spectrum they are comfortable. The rules and settings on this page reduce the risk. They do not eliminate it. The single thing that most often goes wrong is that parents underestimate how permanent and how searchable a single photo is, and they overestimate how much control they have after they hit post.

Common Questions

What is the difference between a digital footprint and a digital shadow?

A digital footprint is the data you actively leave: posts, uploads, comments. A digital shadow is the data collected about you passively: browsing history, location tracking, data broker profiles. For a child whose parent posts photos publicly, the child has a footprint before they have ever touched a device, and a shadow built by the platforms that analyse those photos.

At what age can a child consent to having their photo posted under Singapore's PDPA?

The PDPA does not set a fixed age. The PDPC advisory guidelines from March 2024 say capacity is assessed case by case based on whether the child understands the nature and consequences of giving consent. A child who can explain what happens to their image after it is posted may have capacity. A child who cannot understand that a screenshot is permanent does not.

Can I be legally liable for posting photos of my child without their consent?

The PDPA primarily applies to organisations, not individuals acting in a personal capacity. However, the Protection from Harassment Act covers doxxing, publishing personal information with intent to cause harassment, alarm, or distress. A photo shared with malicious intent could fall under POHA. For most parents, the risk is not legal liability but the permanent online record they create for their child.

Does deleting a photo remove it from the internet?

No. The photo may still exist in the platform's archived content, in screenshots taken by other users, in search engine caches, and in data broker databases. The PDPA gives individuals the right to request deletion from an organisation under Section 22, but that right does not apply to content already copied and shared by third parties.

What EXIF data should I remove before posting a photo of my child?

The most sensitive EXIF data is the GPS coordinates, which reveal exactly where the photo was taken. Also remove the device model, date and time, and any other metadata that could identify your child's location or routine. Free tools and built-in phone editors can strip this data before upload.

How do I know if someone has taken a screenshot of my child's photo?

Most platforms do not notify you when someone takes a screenshot. Instagram and Snapchat notify for screenshots of disappearing content such as stories or direct messages, but not for regular feed posts. The safest assumption is that any photo you post can be screenshotted by anyone who sees it.

What should I do if I find my child's photo being used by a stranger?

Report the account to the platform for impersonation or misuse. If the use involves harassment or threats, file a police report under the Protection from Harassment Act. Document the misuse with screenshots before reporting. The PDPC handles complaints about organisations misusing data, but a stranger's personal account may not fall under their jurisdiction.