343,303 photos processed
← Photo guides

Is GPS Data in Photos Personal Data Under GDPR? What Businesses Should Do Before Publishing

Location data is named in GDPR's definition of personal data, so the GPS hidden in a photo can count. When it matters, when it doesn't, and a simple routine for checking and removing it before photos go online.

Often, yes. GDPR defines personal data as any information relating to an identified or identifiable person, and it names location data as one of the things that can identify someone. The GPS coordinates hidden inside a photo can point to a person's home, and when they do, they're personal data.

That doesn't mean every photo with GPS in it is a legal problem. A photo of a public landmark, taken by you, isn't about anyone. But if your business publishes photos taken at customers' homes, of staff, or sent in by customers, the location data travelling with those files is worth a minute of your attention.

This is a practical explainer, not legal advice. If you have a data protection officer, they're the person to ask about your specific situation.

What the law actually says

Article 4(1) of the GDPR defines personal data like this:

"'personal data' means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person"

Location data sits right there in the list. The UK's version of the regulation, the UK GDPR, uses the same definition.

Two other parts of the law matter here.

The household exemption. Article 2 says the regulation doesn't apply to processing by an individual "in the course of a purely personal or household activity." Your holiday photos on your personal account aren't a GDPR matter. Photos your business publishes are.

Data minimisation. Article 5 says personal data should be "adequate, relevant and limited to what is necessary" for the purpose it's used for. This is the principle that makes the practical answer simple, as you'll see below.

Where this comes up in real businesses

The GPS in a photo is invisible, which is exactly why it gets overlooked. A few common situations:

  • Tradespeople and contractors posting before-and-after photos of jobs on their website or social media. Each photo may carry the coordinates of a customer's house.
  • Cleaners, carers, and home services sharing photos from inside clients' homes.
  • Companies publishing staff photos that were taken at employees' homes, for example remote-work shots or headshots taken on a phone at home.
  • Businesses reposting customer photos, like reviews or testimonials, from the files customers sent in.
  • Field reports shared outside the company, where the location is useful for the work but not for everyone who receives the report.

In each case, the photo itself may be perfectly fine to share. It's the location attached to it that goes further than intended.

The simple answer: take out what you don't need

Data minimisation turns this into a practical question: does the purpose of this photo need the location?

  • A marketing photo of a finished kitchen doesn't need the customer's coordinates. Remove them before it goes online.
  • An inspection or proof-of-work photo, where the location is the point, does need it. Keep it, but share it only with the people who need it, like the customer, the insurer, or the contractor.
  • A staff headshot doesn't need to say where it was taken. Remove it.

Separating "photos we publish" from "photos we keep as records" solves most of this without any clever tools.

Where location data survives, and where it doesn't

Some social platforms remove location data when you upload a photo, but not all do, and it can depend on how you send the file. We cover this in more detail in which platforms strip EXIF data.

The places that are easier to forget are the ones that keep the original file exactly as you gave it: your own website, a shared drive link, an email attachment, a download from cloud storage. If the file had GPS in it when you uploaded it, anyone who downloads it may get the GPS too.

Don't assume. Check a file from your own website the way a visitor would get it.

A five-minute routine before publishing

  1. Check one photo. Open it in an EXIF viewer and look at the GPS section. If there are coordinates, they'll be shown on a map.
  2. Check a whole folder at once, if you have many. The batch EXIF viewer lists the date, GPS, and camera for every photo in a table you can export.
  3. Remove only the location, if you want to keep the date and camera details. Remove GPS from a photo strips the geotag and leaves the rest.
  4. Remove everything, if you want a clean file. The EXIF remover strips GPS, date, camera, and author details.
  5. Stop it at the source. On an iPhone, you can turn off location for a single share by tapping Options at the top of the share sheet and switching off Location before you send.

All of these tools run in your browser, so the photos aren't uploaded to us or anyone else while you check them.

Don't forget what's visible in the picture

Removing metadata only removes the hidden data. It does nothing about what's in the picture itself: a house number on the door, a street sign, a car's number plate, or someone's face.

This applies to our own product too. A timestamp camera, like ours, prints the date, time, and street address on the image, which is exactly what you want for evidence and records. But that address is part of the picture, and no metadata tool will remove it. Keep stamped photos in your records, and use a clean, unstamped photo, or crop out the stamp, for anything you publish.

If you're in the UK or the EU

In the UK, the regulator is the Information Commissioner's Office. In the EU, each country has its own data protection authority. The definition of personal data is the same in both.

The short version

GPS in a photo is location data, and location data can be personal data. If your business publishes photos, get into the habit of asking whether the location needs to go with them. Most of the time it doesn't, and removing it takes seconds.

Sources: Regulation (EU) 2016/679 (GDPR), Articles 2, 4, and 5; UK GDPR, Articles 2, 4, and 5 (legislation.gov.uk).

Try the tools

Stamp a photo right now in your browser, or get the iOS app for live capture with GPS and atomic time.

Download on theApp Store
Open the web tool →EXIF viewer →
Is GPS Data in Photos Personal Data Under GDPR? What Businesses Should Do Before Publishing | TimeStamp Camera