NOTHING IS UPLOADED — OPEN YOUR NETWORK TAB AND WATCH

Metadata is
personal data

A name and a location inside a file are personal data whether or not anyone meant to put them there.

Drop a file to see what is inside it

Get a privacy score, a plain-English list of what it gives away, and a clean copy. Read from your disk, never uploaded.

JPEG · PNG · HEIC · WEBP · PDF · DOCX · XLSX · PPTX

What you would actually see

An illustration of a typical result. No real file, name or location is used.

Before — what you would be sending
subject-access-response.pdfPDF
  • Author a.whitfield
  • Company Northgate Partners LLP
  • Comments and annotations 5 found
After cleaning
subject-access-response-clean.pdfPDF
  • Author removed
  • Company removed
  • Comments and annotations removed
No transfer to a third party, because the file never leaves the browser.

Intent does not change the classification

GDPR defines personal data by what it is, not by whether it was disclosed deliberately. An author name, a device identifier and a set of coordinates embedded in a shared file are personal data being processed, and they fall inside the same obligations as any field in a database.

Where it tends to matter in practice

Files published on a website. Documents attached to emails leaving the organisation. Photographs of staff or premises. Data shared with a processor or a partner. Responses to subject access requests, which are frequently exported as documents carrying the properties of whoever compiled them.

Transfers and third-party tools

Uploading a document to an online processing service is itself a transfer to a third party, and possibly out of the region. That is a separate assessment to make before using any cloud-based cleaning tool. Processing entirely in the browser avoids the question, because nothing is transferred.

Not legal advice

This is a description of a common gap, not a compliance opinion. Your data protection officer or counsel should decide what your obligations actually are.

In practice

Where this surfaces in practice

The recurring case is a subject access request. An organisation compiles a response, exports it as a document, and sends it. The export carries the name of the employee who compiled it, the organisation's name, and how long the work took. None of that was part of the response, and all of it is personal data about a third party disclosed to the requester.

Photographs of premises and staff

Images published on a company site are frequently taken by staff on their own phones. The published files then carry the coordinates of the office and the device details of an employee. It is a small disclosure individually and a systematic one at scale, and it is entirely avoidable with a single step in the publishing process.

Making it a process rather than a rule

A policy saying documents should be checked achieves very little. What works is putting the check where the file leaves: in the export step, in the publishing workflow, or in whatever tooling handles outbound attachments. The organisations that do not have this problem have automated it, not trained for it.

Common questions

Is EXIF data personal data under GDPR?

Where it identifies an individual, directly or in combination with other information, it generally falls within the definition. Take advice on your specific case.

Does uploading a file to a cleaning tool count as processing?

It involves transferring the file to a third party, which typically requires its own assessment. Processing locally in the browser avoids the transfer.

Is this page a compliance tool?

No. It is a free utility. Treat it as one input to a process your own advisers define.