Hello {{first_name}}. A comms lead said a version of this to me on a call this spring, and I've come back to it most weeks since:
"They said yes at 17. At 21 they may not feel the same."
This week, for the 3,484 of us here, it's about the stories you've already published, and the fact that consent doesn't stay still just because your website does.
In this edition
Last week’s poll results
Last week I asked what's hardest about telling the story of how your organisation began. Almost everyone who answered picked the same thing: the worry that it looks like you're using someone's grief or hardship to get attention.
What nobody picked is the interesting part. Not one person said they didn't know what to say. Nobody said it felt stale, or that they had no founding moment to point to, or that they weren't sure whose permission they needed.
So the block isn't craft. You know the story. You can write it. What stops you is a question about whether you're entitled to.
That instinct is worth keeping. It's just pointed at the wrong moment. Here's your action this week. Take the one story you've been hesitant about and ask a single question of it: if the person at the centre of this read it today, would they recognise themselves, and would they be glad?
If yes, publish it. If you don't know, that's what the rest of this edition is about.
THIS WEEK’S BIG IDEA
The consent that expires
"Once you put an image out there, or you put someone's words out there, you can't take them back.
Recently, I had two calls, a day apart, with people who'd never met and work in completely different parts of the sector. One runs communications for youth mental health services. The other leads a health programme within the NHS. Both, unprompted, told me the same thing.
The first put it like this: "If you tell me at 17 that you're really happy to be photographed, or to have me quoted, that may be how you feel at 17. But at 21 you may not feel quite so happy."
The second went further. "When people consent, they're consenting at that period of their life." Then she gave me the example I haven't been able to forget. Someone might be willing, at the time, to say publicly that they were in hardship and using a food bank. Years later, that's not an image they want on the internet of them and their children queuing for food.
Both of them were describing the same thing, and our sector has no name for it. So here it is.
Consent has a half-life.
It was given by a specific person, at a specific point in their life, in a specific world. All three of those move. Your published archive doesn't move at all.
The clause that protects nobody
At this point most people tell me they're covered, because their consent form says the person can withdraw at any time.
I've read a lot of those forms. Mine included. And the clause is real. But think about what it actually asks of someone.
To withdraw, they have to contact the organisation that helped them. Identify themselves, again, as the person in that story. Explain why they've changed their mind. Then ask a favour of an organisation they may still need, or may never want to hear from again.
The person most likely to want their story taken down is the person least likely to ask you to take it down.
That clause doesn't protect them. It transfers the work to the one person in the arrangement with the least power, and then lets everyone else feel covered. Nobody ever asks you to take it down, and you read that silence as consent. It isn't. It's the sound of a burden sitting somewhere it shouldn't.
The duty is yours. And it isn't a duty to wait. It's a duty to go and ask.
The other thing that changes
Sometimes it isn't the person who moves. It's the ground under them.
As I mentioned in last week's edition of this newsletter, since 2019 my foundation has run Out and Proud Parents Day on 30 July. Every year we publish the stories of parents who love their LGBTQ+ children, many from religious and culturally conservative backgrounds, and not all of them were accepting on day one. Some were physically sick when they found out. Those interviews go out with faces and names, because visibility is the entire point.
This year, for the first time in seven years, we asked parents not to appear publicly. We invited them to share anonymously instead.
Nothing about the stories changed. Nothing about the parents changed. What changed is that it's now too dangerous for some of those children, particularly trans children, and particularly families outside the UK.
The consent we hold from 2019 is still valid. The world it was given in is gone.
I sat with that for a while, because it points somewhere uncomfortable. Seven years of properly consented, willingly given, public stories are still online, and every one of them was agreed under conditions that no longer exist. I'm not writing this from the other side of the problem. I'm in it.
Why nobody catches this
You'd never keep a case file for seven years without reviewing it. You have a retention policy for data. You have a review cycle for safeguarding. You'd flag it immediately if a risk assessment hadn't been looked at since 2019.
Then you publish a photograph of a fifteen-year-old and it stays on your website until the site gets rebuilt.
The gap isn't ethical carelessness. Everyone I speak to about this cares enormously. The gap is that consent got filed as a legal formality rather than as a live record, so it went into a drawer instead of onto a calendar. A signed form feels finished. That's the whole problem.
And the archive doesn't sit still while you're not looking at it. It gets indexed. It gets scraped into training data. It shows up when a new employer searches a name, or when a classmate does. A story you published in 2021 is doing work in 2026 that you never planned and can't see.
What this doesn't mean
It doesn't mean publishing less. The sector already has too much of that reflex, and I've written before about what it costs an organisation to tell no human stories at all because silence feels safer.
Nor does it mean going back and stripping your website tonight.
And please don't read it as a reason to treat everyone whose story you've told as fragile. Most people, when you check, are glad it's still out there. Some will be pleased you asked. A few will want one detail changed rather than the whole thing pulled.
What it means is that a story needs a review date the same way a policy does, and that going back to ask is a normal piece of housekeeping rather than an admission that something went wrong.
We covered how to get consent properly in Edition 7 (Consent) -, and how to gather a story without harming the person in Edition 26 (Trauma-informed storytelling). Both are about the moment of asking. This is about the seven years afterwards, which is where almost all of the risk actually lives, and where almost nobody is looking.
Their yes was real. Go and find out if it still is.

Framework: The Consent Half-Life Review
Five moves. Move 1 takes a minute per story from now on. Moves 2 to 5 are how you deal with what's already published.
1. Give every story a review date, not just a consent date. At the moment you publish, write down when you'll look at it again. Twelve months is a sensible default. Make it six if the person was under 18, still using your services, or in crisis when they agreed. The date goes in the same place as the signed form, and it goes in a calendar.
2. Write down the triggers that override the calendar. Some events reset the clock straight away, whatever the review date says. Agree them when you gather the story. They usually include: the person turns 18, they leave your service, a legal case concludes, a perpetrator is released, their immigration status changes, or the public climate around their identity shifts. One of those happens, you review now.
3. Do the asking. Don't wait to be told. You go to them, not the other way round. It's one message and it doesn't need a preamble: "Your story is still on our website and still being used in our funding applications. Are you still happy with that?" Give them a genuine option to say take it down, change it, or leave it. Then honour whichever one they choose without asking them to justify it.
4. Know where it all is before somebody asks. Most organisations can't act on the withdrawal request they hope never comes, because no one holds the list. One shared record: the person, the story, every place it's published, the image file names, who signed it off, the review date. If someone rang tomorrow, you should be able to act in an hour, not a fortnight.
5. Retire honestly, and say what you can't undo. Printed annual reports, broadcast footage, press coverage and anything already scraped can't be recalled. Say so plainly at the start, not at the point someone asks. Then be specific about what you can do: remove it from the website, stop using it in bids, delete it from the image library, ask partners to take it down. Do those things, and then tell the person exactly what you did.

Template: The Story Review Record
One record per published story. Fill it in when you publish, and again at every review. It sits alongside the consent form from Edition 7, it doesn't replace it.
Who this story is about: [Name, or the reference you use internally. Their age when they consented.]
When they consented, and where the signed form is: [Date and location of the record.]
Everywhere it's currently published: [Every channel. Website page, bid documents, annual report, social posts, image library folder, partner sites, press coverage. Include file names for photographs and video.]
Their circumstances when they agreed: [Were they still using your services? In crisis? Under 18? Anything about their situation then that might not hold now.]
Triggers that mean review immediately: [The events agreed with the person that reset the clock, whatever the date says.]
Next review date: [Twelve months by default. Six if any of the circumstances above applied.]
Who owns this review: [A named person, not a team. Reviews with no owner don't happen.]
What we can and cannot withdraw: [Split it honestly. What comes down within a day. What stops being reused. What is permanently out of your hands, and whether they were told that at the time.]
Review log: [Date, who you spoke to, what they said, what changed as a result.]

AI Prompt: The consent expiry audit
Copy and paste the text below into your preferred AI tool. Works best in Claude or Gemini
Replace the [describe] placeholders with your content
For extra context, download my free Social Impact Storytelling Framework
(ogston.com/framework), then upload the PDF alongside this prompt. It will make the responses even more useful
You are an ethical storytelling and safeguarding adviser working with a UK
charity. I want to audit the stories we have already published about the
people we support, and find the ones where consent may no longer hold.
Use UK British English throughout.
BEFORE YOU ADVISE
Ask me for anything critical that is missing. Do not proceed on assumptions.
HARD RULES
- Never invent details about a person, an organisation, or a story.
- Do not state UK law, GDPR requirements or legal thresholds as settled fact.
Where a question is legal or data-protection related, say so plainly and tell
me it needs our data protection lead or a solicitor. Being useful matters
less than not being confidently wrong about the law.
- Assume we have never done a review like this before, and that our records
are worse than I have described. Most organisations' are.
- Do not recommend removing everything. Telling no human stories at all has
its own cost. I am trying to review, not retreat.
OUR SITUATION
- Who we support, and any vulnerability, dependence or power imbalance: [describe]
- Roughly how many published stories, and how far back they go: [describe]
- Where they are published: [website, funding bids, annual reports, social,
press, film, image library, partner and funder sites]
- How we record consent now, and whether we can find the forms: [describe]
- Have we ever gone back to anyone after publishing? [describe]
- Anyone who consented as a child and would now be an adult: [describe]
- Any story I am already uneasy about: [describe, no real names]
- Who would do this work, and how much time they realistically have a month:
[describe, and be honest]
DO THIS, IN ORDER
1. Give me a risk-scoring rubric I can apply myself to each published story,
scored out of 10. Base it on age at consent, dependence on us at the time,
how identifiable the person is, how long ago it was, and how exposed the
channel is. Do not rank my archive for me. You have not seen it. Give me
the tool and I will score it.
2. List the life events and external changes that should trigger an immediate
review for the specific groups we support. Be specific to our context.
Generic lists are no use to me.
3. Draft the message we send to someone whose story we published years ago.
Under 120 words, plain English, and it must:
- state clearly where their story currently appears
- offer three real options: leave it, change it, take it down
- make no reference to donations, our funding, or how much the story helped us
- not ask them to explain or justify whatever they choose
- not thank them so warmly that saying "take it down" feels ungrateful
Then tell me the one line most likely to make someone say yes when they
privately mean no, so I can watch for it in my own drafts.
4. Handle the cases where going back is not simple. For each, tell me what to
do and what not to do:
- the person cannot be traced, or our contact details are years out of date
- making contact could itself put them at risk, or reveal where they are
- the person has died
- they consented as a child and are now an adult we have no relationship with
- they are still using our services, so declining may not feel free to them
5. Tell me what to do when someone asks us to withdraw a story that is already
cited in a submitted funding bid, a published annual report, or press
coverage. What comes down, what cannot, what we tell the funder, and what
we should have told the person at the outset.
6. Build me a review schedule that fits the time I actually named above,
starting with the highest-scoring group from step 1. If the time I have is
not enough to do this properly, say so directly and tell me the smallest
version that is still worth doing.
7. Challenge me in both directions, and do not flatter me.
- Where am I relying on a withdrawal clause to do work it cannot do, or
reading silence as agreement?
- And where am I over-correcting, treating the people we support as too
fragile to be asked, or using ethics as a reason to publish nothing?
8. Close by reminding me that this does not replace our safeguarding lead's
judgement, our data protection obligations, or the wishes of the person
whose story it is.
FORMAT
Steps 1 and 6 as tables. Everything else as short prose or bullets. No preamble.WEEKLY POLL
If someone asked you to take their story down, how fast could you do it?
Poll results will be shared in next week's edition.
Final thoughts
If you do one thing with this edition, make it the smallest one. Pick a single story you published more than two years ago. Find out where it's still living. Then send one message to the person in it.
You'll almost certainly be told to leave it up. That's fine. The point isn't the answer. The point is that from now on, somebody is asking.
My newsletter, with a framework, a template and an AI prompt like these every Thursday: www.impactstoryteller.org
Until next week, please take care.
Warm regards,

Matt Mahmood-Ogston
Award-winning impact storyteller, photographer and charity CEO.
Follow me on LinkedIn
Work with me
Paid: Storytelling workshops for charities and social impact teams (online or in-person)
Paid: Photography for websites, social media and impact reports (London)



