Metadata is information that describes content, context, structure, origin, management, or use of other data. It helps systems organize, search, display, verify, and preserve information. Metadata is not inherently hidden or harmful, but fields that are appropriate internally may expose people, locations, devices, workflows, or confidential history when shared externally.
Common metadata examples
Photos and video: capture time, GPS coordinates, camera or phone model, orientation, creator, editing software, and thumbnails.
Documents and PDFs: author, organization, template, comments, tracked changes, revision history, custom properties, embedded files, and form data.
Email: sender and recipient addresses, message IDs, timestamps, relay path, authentication results, and client information.
Audio: artist, title, album, recording details, codec, duration, cover art, and location.
Filesystems and cloud services: owner, permissions, creation and modification times, hashes, sharing history, labels, and retention state.
Web content: page title, description, structured data, HTTP headers, analytics identifiers, and publication information.
What metadata can reveal
GPS and timestamps can reveal a home, workplace, routine, or current location. Document authors and internal paths can identify staff or infrastructure. Comments and revisions may expose deleted negotiations, legal advice, credentials, or names. Unique device and account identifiers can help correlate files across releases. Email headers can reveal routing and security details.
A field is not automatically a vulnerability. Assess who receives the file, what they already know, whether the metadata is necessary, and what harm could follow from correlation.
How to inspect metadata safely
Preserve the original. Work on a copy so required evidence, quality, and provenance are not destroyed.
Use a local or approved tool. File properties, photo information, document inspectors, PDF tools, and trusted metadata utilities expose different fields.
Inspect more than properties. Review comments, tracked changes, hidden sheets and slides, layers, attachments, form fields, cropped content, and embedded media.
Consider the destination. A platform may strip, retain, transform, or create metadata; verify its current behavior rather than assuming.
A random online “metadata remover” receives the uploaded file and may be inappropriate for confidential content. Prefer local processing or an organization-approved service.
Sanitize a sharing copy
remove photo or video location when it is not needed;
accept or reject tracked changes and delete comments, hidden content, and personal document properties;
use the application's document inspector or sanitization workflow before export;
redact sensitive content with a true redaction tool, not a black shape placed over text;
flatten or convert only when acceptable, recognizing that conversion can preserve some metadata and remove useful accessibility or authenticity information;
rename and package the output according to the recipient's needs.
The EU Publications Office recommends stripping personal metadata before public sharing and provides platform-specific examples in its metadata removal guidance.
Verify the actual output
Close and reopen the sanitized copy, inspect it with a second appropriate tool, search for sensitive names and strings, and review every page or media stream. Check that layout, accessibility, signatures, color, formulas, and required provenance still work. If the destination transforms uploads, download a test copy and inspect that version too.
For investigations, legal holds, medical records, signed files, or regulated archives, do not destroy metadata without authorization. Preserve the original and document each transformation, tool, version, operator, and checksum.
Metadata FAQ
Does taking a screenshot remove all sensitive information?
It can remove some embedded fields but may reveal visible notifications, usernames, coordinates, or other screen content and may create new image metadata.
Does social media always remove GPS data?
No universal rule applies. Platforms and sharing methods change, so remove unnecessary location before upload and verify the published copy.