Metadata and personal data: the legal side

Updated: September 4, 2026

For an individual, metadata is a matter of personal comfort: you would rather not publish your home address along with a photo of a sofa. For an organisation it is already a regulatory matter: the very same fields fall under the definition of personal data, and handling them comes with rules.

Below: why that is, which ordinary work situations it surfaces in, and what can be fixed by process rather than by heroic effort from individual employees.

This is an overview, not legal advice. Requirements differ between jurisdictions and depend on the circumstances; consult a lawyer about your specific situation.

Why metadata falls under the law at all

Data protection law defines personal data broadly: any information relating to a directly or indirectly identifiable natural person. The key word is «indirectly». Data does not have to contain a name to meet the definition; it is enough that a person can be singled out from it.

GDPR explicitly names location data among its examples of identifiers. Coordinates of a residential building combined with the time of the shot are exactly that case: there is no name in the file, but the set of people the record relates to narrows to a single flat.

With documents it is more direct still. Fields such as author and last editor usually carry an employee's full name in plain text — no reasoning about indirect identifiability required.

Where it surfaces in ordinary work

Almost always in routine correspondence rather than through a breach. The typical situations:

  • HR sends candidates documents that still carry the name of the internal employee who prepared the template;
  • the legal team sends a counterparty a contract whose last-editor field shows exactly who made the changes, and whose editing time shows how long it took;
  • an agency publishes photos from a client site without stripping the coordinates;
  • a contractor delivers a PDF report that reveals the organisation and the software where it was actually produced;
  • an employee sends a work file from a personal device, and their personal account lands in the metadata;
  • documents go public: onto a website, a tender platform, a disclosure filing.

All these cases share one thing: the file was prepared for one audience while the service fields were meant for another — an internal one. When it goes out, that boundary is simply never checked, because it is invisible.

What to build into the process

Relying on one person's attentiveness works poorly here: metadata is invisible, so it gets forgotten. It is more sensible to close the question at the procedure level.

  1. Identify which file types regularly leave your organisation: contracts, proposals, reports, site photos, presentations.
  2. Write metadata cleaning into the preparation procedure for those documents — as a distinct step before sending, not as a suggestion.
  3. Fix the point at which the step happens: before sending to a counterparty, before publishing on the site, before uploading to a platform.
  4. Spot-check: take a few recently sent files and look at their properties. That also shows whether the procedure works in practice.
  5. Put the rule in writing and explain to staff why it exists — a step whose purpose is unclear is the first one skipped.

What cleaning metadata does not replace

Do not overrate the measure. Cleaning removes service fields and does nothing to the content: if personal data is printed in the contract text, in a signature, or visible in a photograph, it stays there. That is a separate job, solved before the file is exported rather than after.

Equally, cleaning does not remove your other obligations — lawful bases, notifications, retention periods, incident response. It closes one specific and fairly narrow leak channel, but precisely the one nobody usually watches, simply because it cannot be seen.

Frequently asked questions

  • Are office coordinates personal data too? The organisation's own address usually is not. But a shot taken at an employee's home, or a photo from a site visit that reveals a specific person's movements, is a different conversation.
  • We only send files internally — does this still matter? The risk is lower, but a single procedure is simpler: files sent «internally only» regularly end up forwarded outside.
  • Is cleaning a document once enough? Clean the version that actually goes out. Any later edit in an editor writes the author and time back in.
  • Who is responsible for metadata in a sent file? The sending side: the file left you, in the state you sent it. Which is why the cleaning step belongs at the end of preparation.
  • Is there any point cleaning archived documents? The point appears when a document is sent somewhere again. Reprocessing an archive for its own sake is usually unnecessary.

You can check your own file right now — free, no sign-up.

Clean a file

More guides