What GDPR considers personal data
The GDPR definition (Article 4) covers any information relating to an identified or identifiable natural person. That includes obvious things like names, email addresses, and ID numbers. It also includes information that can identify someone indirectly, such as location data, online identifiers, device identifiers, and combinations of fields that together point to an individual.
Most file metadata fits this definition. A document author field with a person's name is personal data. A photo's GPS coordinates combined with a timestamp is personal data. A device serial number that has been linked to a registered user is personal data.
Where personal data shows up in files
A few examples of metadata fields that commonly count as personal data:
- Author and last-modified-by in Office documents and PDFs
- GPS coordinates in photos and videos
- Device identifiers and serial numbers in photos and videos
- Username paths in embedded image references and template paths
- Email addresses in document properties or comments
- Editing time and revision number when combined with other fields can identify a user
None of this is unusual. Word, PowerPoint, Excel, PDF, JPEG, and MP4 all carry some of these fields by default.
How metadata removal connects to GDPR principles
Two principles are most relevant:
Data minimisation (Article 5(1)(c)). You should only process personal data that is adequate, relevant, and limited to what is necessary. If you're sending a contract to a client, you need to send the contract. You don't need to send the editing history and the file path of every embedded image. Removing metadata is a practical way to reduce the personal data attached to a file to only what's needed.
Integrity and confidentiality (Article 5(1)(f)). Personal data should be processed in a way that ensures appropriate security. Stripping metadata before files are shared externally, particularly with third parties or via public channels, limits the personal data that could be exposed in the event of a leak, mis-send, or breach.
Other articles come into play depending on the situation: data subject rights (right of access, erasure), breach notification, processor obligations. None of those are solved by metadata removal alone, but reducing the personal data in shared files makes most of them easier.
Practical scenarios
A law firm sending document drafts to opposing counsel. Author and reviewer names in the metadata can be considered personal data of the firm's staff. Cleaning before sending reduces what's disclosed and limits questions about who worked on what.
A company publishing PDFs on a website. The author field and software fingerprint identify employees and the firm's IT estate. Cleaning before publishing keeps that information internal.
A media organisation publishing photos from a contributor. GPS coordinates and device identifiers in the EXIF data may identify the photographer's location and equipment. Stripping EXIF before publication is standard practice for outlets that handle source-sensitive material.
A SaaS platform accepting user-uploaded photos. EXIF data in user uploads is often personal data of the user. Strip it before storing or displaying it to others, or be ready to handle it under your privacy policy.
What Metacleaner does
The cleaner removes metadata fields from supported file formats. The visible content is preserved. Files are uploaded over an encrypted connection, processed to remove metadata, and not stored beyond the request.
For organisations that need to clean files at scale or as part of a workflow, the API provides programmatic access on the advance and enterprise plans.
What Metacleaner doesn't do
A few honest limits:
- It doesn't make a file GDPR-compliant on its own. Compliance is about how you handle personal data across your organisation, not about a single tool.
- It doesn't remove personal data from the visible content of the file. If a Word document contains a person's name in the body text, that text stays. Cleaning is metadata-only.
- It doesn't replace your data protection policies, your data processor agreements, or your breach response.
- It doesn't certify your processes. There is no GDPR certification scheme that any tool can grant.
What it does is one specific job: remove the hidden metadata that travels with files and that often contains personal data you didn't intend to share.
Frequently asked
Does using Metacleaner make me GDPR-compliant?
No tool makes an organisation GDPR-compliant. Metacleaner removes metadata from files, which helps with data minimisation. It's one piece of a larger picture.
Where are my files processed?
Files are processed by Itson Group Ltd, the operator of Metacleaner. Details of data handling are in the Privacy Policy.
Do you act as a data processor for my organisation?
For the basic, advance, and enterprise plans, this is something to discuss directly. Contact us for a data processing position appropriate to your use case.
Is metadata removal required by GDPR?
GDPR doesn't list metadata removal as a specific requirement. It does require data minimisation and appropriate security, both of which are easier to demonstrate when you remove unnecessary personal data from files before sharing.
Can I rely on this for legal proceedings or formal compliance audits?
This page is general information. For formal positions on compliance, get advice that's specific to your organisation.