Why imagery is governed rather than merely collected
Before and after photography is the most persuasive material a clinic publishes and the least controlled. It is usually captured opportunistically, stored informally, published selectively and labelled not at all, and each of those four steps introduces a problem that surfaces later.
Consent is the serious one. A patient who agreed to photographs "for our records" has not agreed to appear in a paid advertisement, and the distinction is not technical. Consent needs to name the uses, and the patient needs to have been able to choose among them. A clinic that cannot show which uses a given patient agreed to is exposed regardless of how carefully it behaved in every other respect.
The second problem is evidential. An unlabelled pair asserts a timescale and a treatment without stating either, which makes it an implied claim the clinic has not substantiated. Adding the interval and the treatment detail converts an impression into a statement, and statements can be supported.
The third is data protection. Clinical photographs are personal data of a sensitive kind, and the obligations around storing, limiting access to and retaining them apply whether or not the images are ever published. The ICO's guidance for organisations is the reference point.
How to score this instrument
Select five published pairs at random rather than five you are proud of. Random selection is the difference between an audit and a demonstration.
For each pair, attempt to retrieve the consent record. Time yourself. If retrieval takes more than a few minutes for any pair, the retrievability criterion scores 1 at most.
For comparability, view each pair side by side at the same size and look for differences in lighting direction, distance, head angle and expression. Differences in any of these produce an apparent change that is not the treatment, and once you start looking they are common.
For the retouching criterion, score 0 if any published image has been altered beyond neutral cropping, including through a camera's automatic enhancement. Scoring this accurately requires asking the person who took the photographs rather than inspecting the file.
For storage, look at where the originals actually live today, not where policy says they live. Personal phones are the usual answer and score 0.
Common scoring errors
Scoring consent by the existence of a form. The criterion asks whether the form covers the use. A form permitting "use in clinic materials" does not cover a paid social advertisement.
Selecting the best pairs to score. Score randomly selected pairs. The purpose is to find out what the process produces, not what the clinic can produce when trying.
Treating a filter as neutral because it was applied to both images. Applying the same enhancement to both does not restore comparability, and the enhanced pair is still edited material presented as documentary.
Labelling the treatment loosely. "Filler" is not a treatment label. Product, quantity, sites and number of sessions are what make the pair interpretable.
Assuming social media is out of scope. Images published to a social account are published. Include them in the sample.
Building a protocol worth following
A capture protocol does not need to be elaborate. Three fixed distances, one fixed background, one lighting setup, a marked floor position, neutral expression, no jewellery, no make-up, and the same camera. Written on one page and taped inside the cupboard door where the camera lives.
The labelling convention matters as much. Record the interval, the treatment, the product, the quantity, the number of sessions and any concurrent procedure at the moment of capture, not at the moment of publication, because by then nobody remembers.
Storage should be somewhere with access control and a retention rule, and the rule should be one the clinic can actually apply. A retention period nobody enforces is worse than a longer one that is enforced, because it misdescribes what the clinic is doing with the data. Score this alongside the data protection readiness assessment.
Finally, decide and publish your position on representativeness. If you cannot say that published results are typical, say what they are: results achieved by these patients, under these conditions, in this interval. That is a smaller claim, and it is one you can defend. The claim substantiation checklist covers how to record the basis for it.