# 2257 records: what US creators have to keep on file

> What US record-keeping rules mean for creators: whose ID you need, what a model release is for, how long records are kept and who the producer is.

Source: https://impulse.management/en/blog/record-keeping-2257-for-creators/
Updated: 2026-09-18

---

**Short answer:** If you produce sexually explicit content in the US, federal law expects records proving that everyone depicted was an adult — a government ID and a signed release per person, kept and retrievable. For solo content this is largely handled by your own platform verification. The moment a second person appears, it is on you. This is orientation, not legal advice; the details are worth one session with a lawyer.

## What the rule is for

The requirement comes from 18 U.S.C. §2257 and the regulations under it. Its purpose is narrow and serious: to make it provable, after the fact, that nobody depicted in explicit material was a minor.

It is not a licence, not a registration and not something you apply for. It is a duty to *hold records* — and the only time it matters is the time you cannot produce them.

## Who counts as a producer

This is the part that surprises people. "Producer" is not limited to a studio. Broadly, it covers whoever creates the material and, in a secondary sense, whoever publishes it.

In practice:

- **Solo content, your own account.** You are the producer. Your own age verification with the platform does most of the work here.
- **A second person in the frame.** You are the producer for that material too — and the records now have to cover them, not just you.
- **Content someone sends you to publish.** You are publishing material you did not shoot. The records still have to exist.

The middle case is where creators get caught out: a collaboration is arranged over Instagram in an afternoon, filmed the same evening, and nobody thinks about paperwork until much later.

## What a record actually contains

Per person appearing, kept together:

| What | Why |
| --- | --- |
| Government-issued photo ID | proves age and identity at the time of production |
| Every name they have used, including stage names | so a record can be found from any of them |
| Signed release: consent to film and to publish | consent, scope, and where it may appear |
| Date of production | connects the record to the material |

Two practical points. **Copy the ID at the time**, not later — people become hard to reach. And **write the scope into the release**: what may be published, where, and whether it may be resold. A release that says "anything, anywhere, forever" tends to be worth less than one that is specific, and it makes collaborators reasonably nervous.

## How long, and where

The rules speak in years, not months, and the useful answer is: keep them for as long as the material could conceivably still be online, plus a margin. Deleting a post does not delete the obligation for the period covered.

Where matters too — the records have to be retrievable, which means:

- One place, not "somewhere in my phone".
- Encrypted, because it is a folder full of other people's identity documents. That is a data-protection duty of its own, and a breach there is a worse day than the original question.
- Backed up.

## What platforms do and do not cover

OnlyFans verifies you, and it requires a release for anyone else appearing in your content before it can be published. That process helps, and it is not a substitute: the platform holds what it needs for its own compliance. The producer's own records are the producer's own.

Treat the platform's release form as the minimum, and keep your own copy of everything you upload to it.

## Setting it up once

It takes an afternoon and then it is done:

1. One encrypted folder, one subfolder per person.
2. A release template — have a lawyer look at it once; it is the cheapest legal spend in this business.
3. A rule for yourself: **no ID and signed release, no shoot.** Not "we'll do it after". The rule only works if it has no exceptions.
4. A short note per shoot: date, who, what.

If you work with an agency, ask how they handle this before you sign — specifically: who collects the ID and the release, where are they kept, and do you get your own copies?

For us the answer is: the ID and contract of every model, chatter and VA sit on our own server, on an encrypted disk and in a locked-down folder — in the portal only management and the person concerned can see them. For **collaborations with third parties** we keep no register of our own: our models shoot alone as a rule, and something nobody needs is something in the way. If someone brings that case with them, we build it. Until then those records are yours, and the rule above applies to you.

## In short

- The obligation attaches to production, and it follows you into every collaboration.
- ID plus a signed, specific release, per person, at the time.
- Kept in one encrypted, retrievable place for years.
- Platform verification helps; it is not your record-keeping.
- One lawyer session on the template is worth it.

## Sources

- [28 CFR Part 75 — record keeping requirements](https://www.ecfr.gov/current/title-28/chapter-I/part-75)
- [18 U.S.C. § 2257 — the statute itself](https://www.law.cornell.edu/uscode/text/18/2257)
- [18 U.S.C. § 2257A — the exemption for simulated conduct](https://www.law.cornell.edu/uscode/text/18/2257A)
- [OnlyFans: Terms of Service](https://onlyfans.com/terms)
