What is metadata: metadata explained for evidence and claims work
Metadata is data about data: the descriptive, technical and administrative information attached to a file rather than contained in what the file shows, such as when a photograph was taken, on what device and with what settings.
In evidence work it occupies an awkward position. It is the first thing an investigator looks at and the last thing that should be relied on alone.
The confusion worth clearing up early: metadata describes the file, and the file describes the scene. Those are two separate chains of reasoning, and only one of them is about the damage.
What does metadata mean in practice?
Three kinds turn up in a case file, and they are not equally trustworthy:
- Descriptive metadata. Titles, captions, keywords, the reference number someone typed in. Human-entered, therefore as reliable as the human.
- Technical metadata. Recorded by the device or software: dimensions, format, compression, camera model, exposure, embedded timestamps. This is where EXIF data lives.
- Administrative metadata. Generated by systems handling the file: upload time, uploading account, access records, retention class, audit entries.
The third kind is the one most people overlook and the one that survives scrutiny best, because it is written by a system the sender does not control.
Where metadata sits and how it travels
Some metadata lives inside the file, embedded in the header. Some lives outside it, in a database, a document management system or a server log. That distinction decides what survives a journey.
Embedded metadata travels with the file and is therefore fragile: it can be edited, stripped or overwritten by anything that touches the file. External metadata stays behind in the system that recorded it, which makes it harder to tamper with and useless once the file leaves.
Why metadata goes missing without anyone tampering
This is the point most often misunderstood by people judging a submission, so it is worth stating plainly. Metadata disappears constantly through entirely ordinary handling:
- Messaging apps and social platforms remove it from the copy the recipient receives, generally for privacy reasons and to reduce file size.
- Screenshots destroy it. A screenshot of a photograph is a new image with new, unrelated metadata.
- Re-saving and editing rewrite it. Cropping, resizing or converting a file changes the technical fields, and older software discards what it cannot interpret.
- Printing and scanning erase it completely. The scan carries the scanner's data, not the camera's.
So a photograph arriving with no metadata is unremarkable. Treating its absence as an indicator of dishonesty produces false accusations against customers who simply used WhatsApp.
Metadata explained: a practical example
A handler opens two images of water damage. The first carries a full set of camera fields including a capture time of 08:14 on 3 March. The second carries almost nothing.
The first looks stronger and is not. Those fields were written by the file itself and can be rewritten in under a minute with free software. The second image, submitted through a system that recorded a server-side receipt time and hashed the file on arrival, has external metadata the sender never had access to. That is the more defensible record, even though it looks emptier.
How metadata differs from provenance
Metadata is raw material. Provenance is the argument you build from it plus everything the receiving system recorded independently. Metadata that agrees with the account is mild support. Metadata that contradicts it is a reason to look harder, never a conclusion on its own.
The formats themselves are standardised, which at least makes the fields legible across tools. The most common photographic set is defined in the Exif specification maintained by the Camera and Imaging Products Association, published as CIPA DC-008 and developed jointly with JEITA, with version 3.1 issued in January 2026. Standardisation governs how fields are written and read. It confers no protection against those fields being wrong.
Reading metadata without overreading it
Three habits keep a team out of trouble. Compare embedded values against records the sender could not touch, such as server receipt times and access logs. Treat contradictions as questions for a person rather than triggers for an automatic decision. And write down what your process actually infers from metadata, because an inconsistent standard is difficult to defend when a customer complains.
Manipulated files are a live concern rather than a theoretical one, as our explainer on AI-generated insurance fraud sets out. Metadata is one input into that problem. It is not a solution to it, and no combination of fields makes a file impossible to fake.