NearScrub

2026-08-08

Before you post that back-to-school photo: what FBI, CNIL, and Ireland's DPC actually warn parents about

Every August, the same photo shows up across social feeds: a kid in a new backpack, standing by the front door or the school gate, captioned "first day of 3rd grade!" It's also the photo two government privacy regulators have specifically singled out. Ireland's Data Protection Commission runs a recurring "Pause Before You Post" post every back-to-school season, and France's CNIL published a detailed breakdown of the risks on November 28, 2025 — both pointing at the same file, not just the caption under it.

What the regulators are actually flagging

The Irish DPC's back-to-school guidance asks parents to check four things before posting, including what's sitting in the frame: "If you took the photo outside your front door, is your house number visible, or have you got location data on?" CNIL's November 2025 page is more direct about the file itself: "Photos and videos often contain information about the location and time at which the image was taken (thanks to the metadata of a photo or video, particularly GPS data)" — data CNIL says can reveal "their point of interests or the places they frequently attend." CNIL also cites a 2023 survey putting the share of French parents who've posted content about their kids at 53%, and the DPC's companion page cites a Barclays estimate that sharenting will account for two-thirds of identity fraud by 2030.

None of this is a new warning dressed up for a news cycle. The FBI's Cyber Division published close to the same advice in 2011, after its Innocent Images Intelligence Unit started tracking how embedded location data in kids' photos was being used to build a "pattern of life" — clustering posts by geography to work out where a child usually is at a given time. The advice hasn't changed because the underlying file format hasn't changed: a photo taken on a phone still carries more than the picture, unless something removes it.

Two separate things are hiding in a back-to-school photo

Both regulators are actually describing two different risks that happen to live in the same file, and the fix for one doesn't touch the other.

What's hiding in a back-to-school photo ✕ Visible in the frame — check it yourself House number, school crest, name on a blackboard sign Other kids in the background who never consented to a post A content decision — cropping or reframing, not a file fix ✓ Invisible in the file — NearScrub clears it EXIF / GPS coordinates, camera make and model XMP metadata, IPTC/Photoshop fields, embedded comments Removed entirely in the browser — the photo never leaves your device
The Irish DPC's "what's in the background" tip and CNIL's GPS-metadata warning are two different risks in the same file. A metadata scrubber like NearScrub only reaches the right-hand side — the frame is still on you.

What NearScrub actually clears from the photo

Drop a JPEG or PNG onto NearScrub and it works entirely inside the browser tab — nothing uploads, which matters specifically here, since a folder of kids' photos is exactly the kind of thing a parent shouldn't want passing through some third-party server just to get the GPS tag removed. For a JPEG, NearScrub drops the entire EXIF block (including GPS coordinates), any XMP metadata, IPTC/Photoshop fields, and comment segments, while leaving the pixel data untouched — the photo looks identical, the coordinates are gone. For a PNG (the format a screenshot of a school announcement or class photo usually comes in), it drops the text and timestamp chunks the same way. You can drop a whole afternoon's worth of first-day photos in at once — a report shows which files actually carry EXIF/GPS data or XMP before you scrub anything, and a multi-file batch comes back as a single zip.

The catch: iPhone photos are usually HEIC, not JPEG

This is worth being upfront about, because it trips up exactly the phone most parents are using. Since iOS 11, an iPhone's default camera format is HEIF (saved as a .heic file), not JPEG — Apple's own support documentation confirms High Efficiency is still the default capture format on current devices. NearScrub reads JPEG, PNG, PDF, and Office files; it doesn't parse HEIC. A photo pulled straight from an iPhone's camera roll and dropped onto NearScrub as-is will show up unsupported, with nothing removed.

The fix is usually already happening without you noticing: Apple's own documentation says that sharing HEIF media "using other methods, such as AirDrop, Messages, or email" to a device that doesn't support the newer format converts it "in a more compatible format, such as JPEG" automatically. If a photo arrived in your camera roll via text, AirDrop from someone else's phone, or a download, there's a decent chance it's already a JPEG. If it's not, Settings → Camera → Formats → Most Compatible switches new photos to JPEG going forward (existing HEIC photos still need converting manually — Photos or Preview's File → Export lets you save a copy as JPEG). Either way, check the file extension before assuming NearScrub has scrubbed something it never actually read.

What's still on you

Clearing the file's metadata doesn't answer the Irish DPC's actual question — "is there anything in the background of your photo that might lead to oversharing information about your child?" A visible house number, a school crest on the uniform, a name spelled out on a blackboard sign in the trend the DPC's own guidance calls out by name, another parent's kid caught in frame without their consent — none of that lives in EXIF or XMP, so no metadata tool touches it. That part is still a look-at-the-photo-before-you-post decision, the same one both regulators are actually asking parents to make. Metadata removal and content review are two different jobs that happen to apply to the same photo, and only one of them is something software can do for you.

Before it goes anywhere

For a back-to-school photo specifically: check the frame first — crop or reshoot if the house number, school name, or another child is visible and you don't want it out there. Confirm the file is actually a JPEG or PNG, converting from HEIC first if it isn't. Then run it through NearScrub so the GPS coordinates, camera details, and any XMP or IPTC fields are gone before the photo exists anywhere but your own device — not after it's already sitting on a server somewhere, waiting on someone else's code to decide whether to strip it.

Sponsored
← NearScrub

This page shows ads only if you consent.