Metadata & the GDPR — Protecting Information in Digital Documents Properly
Digitalization is advancing relentlessly, and everyday office life is no exception. Working on a computer has become second nature over time. From lease agreements to shopping lists, all kinds of information and data can now be recorded in digital documents. So-called digital documents include Word, Excel, or PowerPoint files, as well as PDF documents, such as those familiar from articles or forms.
The Catch Behind Digital Documents
With a document created and stored offline, only the information contained in the document itself is preserved. Many files created on a computer, however, contain what's known as metadata.
Metadata refers to additional information contained within a file. It's generated when a digital file (doc, docx, xls, xlsx, pdf, jpg, etc.) is created as a document is saved. In addition to the document itself and the information it contains, such files also store additional information — the so-called metadata. This includes information about the person who created the file.
What Information Does Metadata Contain?
Metadata contains various information about the author or authors of a document. Typical metadata includes the names of the authors and information about the software used. In some documents, file paths or IP addresses may also be recorded. Access permissions or the timestamps of changes made to a document can also be stored.
How Do You Protect Your Metadata?
As with offline documents, the general data protection provisions also apply when creating digital documents, ensuring the secure handling of collected and stored data. To protect your own data, metadata can be removed from files you create. Since many employees aren't aware of this, metadata is often not deleted intentionally or is simply forgotten. In most programs, you can view and delete metadata under a document's "Details."
What Risks Does Metadata Pose?
Metadata poses a number of different risks, both in private and business contexts. This is largely because many people aren't even aware that this data exists. In addition, the dangers metadata poses — should it fall into the wrong hands — are often underestimated.
Since metadata contains a wide range of personal data, it can be used to create detailed digital profiles of individuals. Due to the high data density of metadata, people can even be traced back to their profiles on social networks. Beyond simply spying on individuals, third parties' interest can extend as far as stalking. To do this, they can use the collected data to access the relevant person's social media channels. In addition to accessing existing profiles, third parties can create fake profiles and use them for various purposes, most of them criminal. The affected individuals usually never find out.
Beyond criminal use, metadata can also be of great benefit to companies. If a company receives a document containing metadata, it can use the additional information to, for example, improve its own targeting. But companies can be spied on in the same way. In addition to profiles of individuals, third parties can also create company profiles. By inadvertently sharing internal company metadata, businesses can turn themselves into targets for deliberate attacks.
FAQ
What exactly is metadata in digital documents, and what risks does it pose?
What exactly is metadata in digital documents, and what risks does it pose?
Metadata is structured background data that stores information about a file. This includes, for example, the author's name, the company name, change histories, hidden comments, creation dates, software versions, or, in the case of photos, GPS location data. The central risk is that this data can unintentionally reach third parties when documents are sent or published. Competitors or attackers can thus gain insight into sensitive details about internal workflows, project participants, deleted text passages, or security infrastructures.
What data protection risks arise from unintentionally transmitted metadata?
What data protection risks arise from unintentionally transmitted metadata?
As soon as metadata contains information that can be attributed to a specific natural person (such as real names, email addresses, notes, or locations), it falls within the scope of the GDPR. Passing on such data in an uncontrolled way poses a security risk and potentially a data protection violation. If confidential customer or employee data is disclosed publicly or transmitted to unauthorized third parties via hidden file properties, companies face not only liability claims but also GDPR fines for insufficient technical and organizational safeguards (Art. 32 GDPR).
How can companies prevent sensitive metadata from being leaked?
How can companies prevent sensitive metadata from being leaked?
Companies should establish automated and organizational safeguards to clean up documents before they're released. Programs such as Microsoft Office or Adobe Acrobat offer built-in inspection features (such as the "Document Inspector") that reliably remove metadata, notes, and revision comments before saving or sending. It's also advisable to use central email gateways or metadata-cleansing tools that automatically filter outgoing file attachments and strip them of critical background data.
What's the connection between metadata and corporate IT security?
What's the connection between metadata and corporate IT security?
Cybercriminals deliberately use metadata as part of so-called open source intelligence (OSINT) to prepare attacks. From the metadata of publicly accessible documents (e.g., PDFs on the company website), attackers can read internal naming conventions, software versions in use, email patterns, or network paths. This information facilitates tailored phishing attacks (spear phishing) or the exploitation of known software vulnerabilities. Deliberately removing metadata is therefore a simple but effective building block of general IT security.







