Twinkle and Blink Services
← All insights

Data Governance

The Hidden Metadata in Your Photos, Videos, and Documents — and Why It's a Privacy Risk

8 September 2026 · 6 min read

Most businesses think carefully about what appears in the visible content of a file — the wording of a document, the composition of a photo — and never think about what travels invisibly alongside it. Every photo, video, and PDF carries a second layer of information called metadata, and it routinely reveals far more than the person sharing it realizes.

What is metadata, actually?

Metadata is data about data — information embedded in a file by the device or software that created it, separate from the visible content. You don't see it when you view the photo or read the document, but it travels with the file everywhere it goes, including when you upload it to a website, email it to a client, or post it on social media.

What it can reveal about you or your business

  • GPS coordinates — the exact location where a photo or video was captured, often precise to a few metres.
  • Device information — camera or phone make, model, and sometimes a serial number.
  • Timestamps — precisely when a file was created and last modified.
  • Author or owner name — frequently the real name tied to the device or software account that created the file.
  • Software history — what editing tools touched the file, and when.

Where this becomes a business risk, not just a personal one

A business that publishes marketing photos, uploads scanned documents, or shares PDFs with external parties is routinely distributing metadata it never reviewed. A product photo taken at your office can quietly disclose its GPS location. A contract PDF can embed the real name of the staff member who drafted it, tied to their personal device account. None of this is visible on screen — which is exactly why it goes unnoticed until it becomes a problem.

Personal data isn't limited to what sits in your customer database. Under Nigeria's data protection framework, personal data embedded in ordinary files you distribute — GPS tags, device identifiers, author names — is still personal data, and the same security and minimisation obligations apply to it.

A quick self-check

  1. Pick a photo or PDF your business has published or sent externally in the last month.
  2. Check its metadata fields (basic EXIF viewers are freely available; a proper audit uses forensic-grade tooling).
  3. Look specifically for GPS coordinates, device serial numbers, and personal names.
  4. If you find any of these on a file with no legitimate reason to disclose them, that's your answer.

Fixing it

The fix itself is simple: strip metadata from files before they leave the organisation, as a standard step before publishing or sending externally — not an afterthought applied only after something goes wrong. For a one-off batch, this can be done directly. For an ongoing publishing workflow, it's worth building into the process itself so it happens by default, not by memory.

This article is general educational guidance on metadata and digital forensics, not legal advice on evidentiary admissibility. Metadata findings should be independently verified by qualified counsel before being relied on for legal, insurance, or regulatory purposes.

Not sure where your business stands?

Book a free consultation and we'll map your specific obligations, tell you what's urgent, and give you a clear plan.