(3/10) Sharenting: Finding the Balance Between Proud Parenting and Digital Privacy
Digital Safety Series: Ep. 3
Humans have always needed a village to raise a child. Now that families have scattered across cities and time zones, social media has become the village square. A 2021 Security.org survey of 1,000 parents found something like three-quarters of them post photos or stories of their kids online. Most use their real names doing it. They’re not posting to show off. They’re posting because they’re proud, and because they’re looking for somewhere to put that pride.
The internet parents are posting into today is not the internet they started posting into. Something’s shifted under everyone’s feet and most haven’t even noticed there’s a question to ask. Nobody handed them the memo that the ground has moved. The actual question underneath it is harder: how do you celebrate a kid without handing tomorrow’s version of them a problem you are creating today? Most parents haven’t sat with that question yet. They don’t know they should be sitting with it. They’re still operating on “cute photo or not.”.
The internet parents are posting into today is not the internet they started posting into. Something’s shifted under everyone’s feet and most haven’t even noticed there’s a question to ask. Nobody handed them the memo that the ground has moved. The actual question underneath it is harder: how do you celebrate a kid without handing tomorrow’s version of them a problem you are creating today? Most parents haven’t sat with that question yet. They don’t know they should be sitting with it. They’re still operating on “cute photo or not.”
The internet got hungrier.
If you’ve never heard the word “sharenting” before, here’s what it means. It’s the name for something you’ve probably watched happen constantly, or done yourself without a second thought. It’s a blend of “sharing” and “parenting.” It showed up around 2012 to describe parents posting photos, videos, or stories about their kids online. Most people doing it regularly have never heard the term. That makes sense. Nobody sat anyone down and said, “This thing you do constantly has a name, and researchers study it.”
It’s easy for someone online to throw the word around like it’s a diagnosis. Like admitting to it means admitting to doing something wrong. I don’t think that’s fair. When digital photo albums first showed up, they felt exactly like the sticky-page albums grandparents kept on the coffee table. Just easier to send across the world.
So no, I don’t think parents got reckless. I think the technology got more invasive underneath them. Data scraping. Facial recognition. AI tools that can build a profile out of nothing but a few years of birthday posts. A photo isn’t just a photo anymore. It’s data. What feels like a sweet update reads, to something built to harvest it, as raw material. Barclays forecast that by 2030, “sharenting” could be behind close to two-thirds of identity fraud hitting young people.
If that phrase doesn’t mean much yet, here’s the plain version. Identity theft isn’t someone breaking into an account that already exists. It’s someone collecting enough real details — full name, birthdate, hometown, mother’s maiden name — to convincingly become that person on paper. With those pieces, someone can open a credit card in a child’s name. Take out a loan. Pass a security check meant to confirm they’re really them. It usually doesn’t surface for years. A kid’s identity sits unused and unchecked until they’re old enough to apply for their first credit card or apartment. That’s exactly when they find out someone’s already been using their name.
That’s what the Barclays forecast is actually about. Not some vague future risk — the birthdays, hometowns, and mother’s maiden names sitting in years of posts, becoming the exact toolkit someone needs. Pulled together patiently, one caption at a time.
None of this is a case for paranoia. It’s a case for noticing that the ground has moved.
Here’s what nobody quite spells out
“Be careful what you post” gets repeated so often it’s stopped meaning anything. So let’s actually sit with why. Most people aren’t connecting these dots automatically. Two things are happening at once, and they’re different problems.
The identification problem, explained plainly. Once a company can reliably match a photo of a face to a name, it can find that same face anywhere else it turns up online — in someone else’s photo, on a different platform, in a context the original poster never imagined. A birthday photo posted for grandma stops being a private moment between family and becomes a searchable entry point into a person’s whole identity. That’s what “identification” means here: not that a stranger saw one photo, but that one tagged photo can now unlock everything else connected to that face.
Here’s how it already happened, not hypothetically. A company called Clearview AI scraped billions of photos off public social media — Facebook, Instagram, wherever a face happened to show up. It used them to build a facial-recognition tool, then sold access to that tool to police departments and businesses. Nobody whose face was in there knew it was happening. The UK’s data regulator, the ICO, fined the company £7.5 million in 2022. Clearview challenged the fine, and the case has moved through UK tribunals since; a 2025 ruling restored the ICO’s authority to pursue it, though a lower tribunal is still finalizing the fine itself as of this writing. France, Italy, and Greece have each fined Clearview roughly €20 million outright — and, notably, none of those regulators have actually collected a cent. Australia investigated the company too. This isn’t a hypothetical. It already happened, to real people’s photos, quietly.
And that’s really the point Clearview proves: it’s not a one-off villain, it’s a demonstration of what’s possible. Clearview only became visible because journalists and regulators eventually caught up to it. For every company regulators catch, there’s no way to know how many others are running the same quiet collection and simply haven’t gotten caught yet — smaller data brokers, apps with vague terms of service, tools nobody’s heard of that exist specifically to scrape and resell what’s public. None of them need permission to start. They just need a public photo and time.
That’s what makes this different from a one-time risk. A stranger downloading a single photo creates a bad moment. An unknown company patiently building a profile on a child for years, unnoticed, creates something else entirely — because that profile doesn’t do anything today. It just sits there, complete and waiting, until the day that child is old enough to open a bank account or sign a lease. Nobody sends a warning when someone finally uses it. The years of quiet collection and the moment of misuse can sit a decade apart, which is exactly why it doesn’t feel urgent now. The absence of visible harm today doesn’t prove nobody’s collecting anything — it’s often exactly what unauthorized collection looks like while it’s happening.
The permanence problem, explained plainly. Normally, if you regret posting something, you delete it and it’s gone. Training data doesn’t work that way. Once a company has trained an AI model on a photo, deleting the original post doesn’t undo what the model already learned from it. The lesson the model absorbed — this is what a face looks like, this is how it ages, this is the pattern of a name attached to a place — stays baked into the system whether or not the photo is still online. You can take back the post. You can’t take back what it taught.
In 2024, Meta changed its policy to let its AI train on public Facebook and Instagram posts and photos. It made the opt-out process complicated enough that most people never got around to it, and even where opt-outs exist, they’ve mostly covered EU and UK users under stronger local privacy law — US users have much weaker footing to object at all. Even the people who did opt out found the request only covered what happens going forward. Whatever the model had already used, stayed used.
A photo someone posts is a moment. It has a beginning and an end. You can delete it if you regret it. The training data that photo becomes isn’t a moment anymore. It’s a permanent ingredient in something else — something a company built for a purpose nobody agreed to, and can’t undo. A kid’s birthday photo, posted for grandma, doesn’t just sit there. It can become one small piece of a system that learns to recognize faces, target ads, or predict behavior — a system a company built without ever having a conversation with that child, using a face they didn’t get a vote on.
Most people are used to thinking about who can see a post. Almost nobody’s used to thinking about what that post can turn into, simply because nobody framed it as the real question
Things people say to wave this off
1.“They already have everything anyway.”
This is understandable. There’s some truth buried in it. Data brokers already hold huge amounts on all of us. A single new photo probably isn’t the difference between private and not private in some absolute sense. So why bother?
Here’s where that logic quietly breaks. “They have some of your data” and “they have your face, matched to your name, matched to your child’s face, matched to a decade of locations and routines” are not the same category of exposed. Most of what’s already out there is scattered. Fragments. Probabilities. Patterns. A clear, tagged photo of a specific child’s face is not a fragment. It’s a key. It turns everything else scattered about them into something matchable, searchable, identifiable in a crowd. A stranger could theoretically piece together a kid’s school, routine, and face from scraps across the internet, if they tried hard enough. A tagged, named, dated photo now can do that work for them quite conveniently. Every post doesn’t just add to a pile. It makes the pile easier to search.
There’s also a version of this argument that quietly gives up on a child’s choice. “There’s nothing to hide anyway” assumes the decision has already been made for them. Even if total privacy isn’t on the table anymore for anyone, the amount of searchable, identifiable material tied to a specific child, by the time they’re old enough to have an opinion about it, is still something being actively chosen. One photo at a time.
2.“There’s nothing worth stealing.”
The instinct behind it is understandable. Most people grew up thinking of “valuable” as money in an account, or an expensive thing someone could physically take. Data doesn’t feel like that. It doesn’t feel like property in the same way. Losing control of it doesn’t register as a loss. However, a child’s data doesn’t need to be worth anything to their parent for it to be worth something to somebody else.
A name, a birthdate, a school, a face — none of that pays for itself directly. But it’s the raw material for things that do make money. Data brokers buy and sell exactly this kind of information in bulk. Not because any single kid’s birthday is valuable, but because a complete, accurate profile of a real person is.
Remember the identification and permanence problems from earlier. Identity theft isn’t about stealing money directly out of an account. It’s about stealing enough real information about a person to convincingly become them. The Barclays forecast isn’t warning about someone hacking a bank. It’s warning about someone using a kid’s own birthday, hometown, and mother’s maiden name — collected patiently over years of posts — to impersonate them later. The theft isn’t of data. The data is just the tool. What gets stolen at the end is money, credit, or reputation, using pieces that child never knew had been handed over.
So “there’s nothing valuable to steal” isn’t really the right question. The better one is this: does this information make it easier for someone to become this child, or to profit off knowing everything about them, without that child ever getting a say?
Not every post is a catastrophe. There’s room to be wrong about exactly where the real risk sits. “it’s already out there” or “it’s not worth anything” have always felt like reasons to stop trying, not actual arguments that trying doesn’t matter.
The gift kids aren’t being given
There is a different way to look at the situation, not as a restriction but as something parents are actually capable of giving.
Think back to anyone’s own late teens. There was room to mess up. To change your whole personality twice. To walk into adulthood mostly unwritten. That blank slate was a privilege, even if nobody called it that at the time.
Kids today are inheriting a version of themselves they didn’t write. A 2017 study, referenced by the American Academy of Pediatrics, found that teens judge their parents’ posts about them far more harshly than they judge posts from friends.
Long before they apply for a job or open a bank account, there’s already a searchable record of their tantrums, their milestones, sometimes their medical stuff. Put there with love, without a second thought. Pulling back on what gets posted isn’t hiding a kid. It’s leaving them room to tell their own story later, in their own words.
Nobody has to disappear. There’s a middle ground.
None of this means going dark. Privacy isn’t all-or-nothing. Plenty of families are finding a version that works:
Post the vibe, not the face. Hands, muddy boots, the back of a small head at the park.
Cover the face with an emoji if the moment should be public but the biometrics shouldn’t.
Move the real archive somewhere closed, a private group chat, a family-only app and save the public feed for the parts anyone would be fine with someone finding in ten years.
Before hitting share — three seconds
Next time a thumb’s hovering over the share button, ask yourself three question with no judgment attached.
Is there operational information in this — a school uniform, a house number, a full birthdate?
Would this be okay on a billboard outside your own office?
Is this being shared for the kid, or for the parent?
This is the first generation figuring it out in real time. There’s room to be wrong about exactly where the line should sit. There’s no clean answer here, but the shift is simple, even if the questions aren’t: share the moment, not the identity.
References
Security.org, Parents’ Social Media Habits: 2021 — security.org/digital-safety/parenting-social-media-report
Barclays / Techmonitor, Sharenting to Reach £676 Million by 2030 (2018) — techmonitor.ai
Blum-Ross, A., & Livingstone, S. (2017). “Sharenting,” parent blogging, and the boundaries of the digital self. Popular Communication, referenced via American Academy of Pediatrics — aap.org
TIME, Why Regulators Can’t Stop an AI Company That Scraped Billions of Photos — time.com
The Conversation, Australia’s privacy regulator just dropped its case against Clearview AI — theconversation.com
MIT Technology Review, How to opt out of Meta’s AI training (2024) — technologyreview.com
