Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is metadata?

Metadata is information that describes other data. It can record a file's structure, content, origin, dates, location, ownership, format or processing history, but each field must be interpreted through the system that created it.

Metadata is not one single hidden record. Different systems create and store different metadata for different purposes.

The short version

Metadata adds context to a digital object or record. It can be absent, changed, copied or generated automatically, so its source and field meaning control what it proves.

Where metadata can be stored

Metadata may be:

  • embedded inside a file;
  • held by the file system around the file;
  • stored in an application database;
  • recorded by a cloud or online service;
  • added by an export or forensic tool; or
  • held separately in a catalogue, case system or provider record.

These sources can describe different events. A date embedded by a camera is not necessarily the same as the date a file was created on its current device or uploaded to a service.

Common kinds of metadata

File-system metadata

A file system may record a file's name, size, location, permissions and timestamps. The exact fields and their meaning depend on the file system and operating system.

Terms such as “created”, “modified” and “accessed” sound universal, but their technical meaning can differ between systems and can change when a file is copied, extracted or restored.

Embedded metadata

Some file formats can store metadata within the file itself.

Photographs may contain Exif metadata, such as camera make and model, exposure settings, dimensions, orientation, dates and sometimes location. Documents may contain author names, software information, revision details or document properties. Audio and video files may contain codec, duration, creation and descriptive fields.

Not every file contains these fields, and not every device or application preserves them.

Application metadata

Applications often store descriptive information in databases rather than inside the visible item. A messaging application might record an internal message identifier, account identifier, delivery state and timestamp alongside the displayed text.

An export or reader report may combine those fields into one presentation even though they came from several underlying records.

Service and cloud metadata

Online services can record upload time, account, version, sharing state, originating device, processing events and other service-specific information.

Cloud metadata can differ from device metadata because the two systems may be describing different copies or events.

Metadata is not necessarily created by a person

Much metadata is generated automatically by devices, software and services. A field labelled with a person's name may have been taken from an account profile, document template or device setting rather than typed for that particular file.

Likewise, a location field may come from a sensor, a network estimate, a user selection or another file. The label alone does not explain how the value was produced.

Metadata can change without the content visibly changing

Opening, copying, downloading, editing, exporting, synchronising or converting a file can alter some metadata while leaving the visible content apparently the same.

The reverse is also possible: some embedded metadata may be copied into a new file even though the file now exists on a different device or at a later time.

Metadata can also be deliberately edited or removed. Its presence is not automatic proof that it is accurate, and its absence is not proof that it never existed.

The same label can describe different things

A field called created might mean:

  • when content was first captured;
  • when the current file was written;
  • when an application record was created;
  • when a copy reached a device; or
  • when a service received an upload.

The field name must therefore be interpreted using its source, data model and surrounding records.

What metadata can and cannot contribute

Metadata can help:

  • distinguish files or versions;
  • place an object within a system or application;
  • identify technical characteristics;
  • suggest when or how an object was created or processed;
  • connect related records; and
  • reveal inconsistencies that require explanation.

It does not automatically prove who created the content, who possessed the device at the time or whether a recorded value is correct. Those conclusions require provenance, system context and corroborating evidence.

The point to remember

Metadata adds context to data. Before relying on it, understand which system created the field, what event it describes and what could have changed it.

Explore related guidance

Go deeper

Investigator First - back to the investigation

Reference: LOG-155Logs, Records & Provider Evidence