Most businesses think carefully about what appears in the visible content of a file — the wording of a document, the composition of a photo — and never think about what travels invisibly alongside it. Every photo, video, and PDF carries a second layer of information called metadata, and it routinely reveals far more than the person sharing it realizes.
What is metadata, actually?
Metadata is data about data — information embedded in a file by the device or software that created it, separate from the visible content. You don't see it when you view the photo or read the document, but it travels with the file everywhere it goes, including when you upload it to a website, email it to a client, or post it on social media.
What it can reveal about you or your business
- GPS coordinates — the exact location where a photo or video was captured, often precise to a few metres.
- Device information — camera or phone make, model, and sometimes a serial number.
- Timestamps — precisely when a file was created and last modified.
- Author or owner name — frequently the real name tied to the device or software account that created the file.
- Software history — what editing tools touched the file, and when.
Where this becomes a business risk, not just a personal one
A business that publishes marketing photos, uploads scanned documents, or shares PDFs with external parties is routinely distributing metadata it never reviewed. A product photo taken at your office can quietly disclose its GPS location. A contract PDF can embed the real name of the staff member who drafted it, tied to their personal device account. None of this is visible on screen — which is exactly why it goes unnoticed until it becomes a problem.
A quick self-check
- Pick a photo or PDF your business has published or sent externally in the last month.
- Check its metadata fields (basic EXIF viewers are freely available; a proper audit uses forensic-grade tooling).
- Look specifically for GPS coordinates, device serial numbers, and personal names.
- If you find any of these on a file with no legitimate reason to disclose them, that's your answer.
Fixing it
The fix itself is simple: strip metadata from files before they leave the organisation, as a standard step before publishing or sending externally — not an afterthought applied only after something goes wrong. For a one-off batch, this can be done directly. For an ongoing publishing workflow, it's worth building into the process itself so it happens by default, not by memory.
Not sure where your business stands?
Book a free consultation and we'll map your specific obligations, tell you what's urgent, and give you a clear plan.
