What metadata do images contain?

An overview of EXIF, IPTC and XMP, common privacy risks and the limits of a technical image metadata inspection.

Images can contain technical, editorial and descriptive metadata. This information is embedded in the file container and is not always visible in a normal image viewer. The available fields depend on the camera, editing software, export settings and publishing platform.

EXIF, IPTC and XMP

EXIF commonly stores camera and capture information. Typical fields include make and model, capture time, exposure, lens and orientation. Devices can also add GPS coordinates or serial numbers.

IPTC-IIM is used in editorial workflows. It can contain a title, description, keywords, byline, rights information, location and source. These fields are useful to agencies and newsrooms but can also disclose names or internal workflow information.

XMP is a flexible XML-based metadata model. Editing applications use it for fields such as creator tool, creation and modification time, rights, descriptions and custom namespaces. A technical disclosure can also be embedded as XMP.

Images may additionally contain ICC color profiles, thumbnails and C2PA/JUMBF data. These formats have different purposes and should be reported separately from EXIF, IPTC and XMP.

Potentially sensitive fields include location, device serial numbers, names and internal workflow details. Whether a field is sensitive depends on the publishing context.

Why “no metadata found” is not a provenance result

Metadata may already be absent at export or removed by messengers, social platforms and image optimizers. Its absence does not establish that an image was created anonymously, remained unmodified or did not involve AI. Likewise, a single software field does not prove that all pixels were created by that application.

An inspector should distinguish between “absent”, “present”, “unsupported” and “not fully readable”. A bounded browser inspection can reveal common fields, but it is not a complete forensic analysis of every vendor-specific structure.

A controlled publication workflow

  1. Inspect a copy of the source file with the Metadata Inspector.
  2. Review location, identity, device and internal description fields.
  3. Decide which rights or provenance information should intentionally remain.
  4. Clean sensitive data from an export copy rather than the original.
  5. Re-inspect the exported file.
  6. Repeat the check after uploading to and downloading from the destination platform.

Cleaning should be deliberate because some provenance or rights information may be intentional. Preserve the original and record the export policy that was applied.