2026-08-22
Is it legal to remove a photo's metadata? What DMCA Section 1202 and two photographer lawsuits actually say
Every other post on this blog argues, one way or another, for removing metadata before a file leaves your device. It's worth turning the question around once: is removing metadata itself always allowed? The bytes a scrubber deletes aren't only surveillance data. For a working photographer, the same embedded fields are how a file carries their name, their copyright notice, and their licensing terms — and United States copyright law has a provision, written in 1998 as part of the DMCA, that is specifically about removing that kind of information. This post isn't legal advice; it's a plain reading of what that statute says and what two federal appeals courts actually did with it in cases about photo metadata.
The same bytes have two jobs
The privacy posts on this blog treat a JPEG's metadata as risk: GPS coordinates, device model, timestamps. But the IPTC Photo Metadata Standard — the one professional photo workflows and newsrooms use — exists mostly for the opposite reason. Its own user guide describes a Creator field that holds the photographer's name and a Copyright Notice field that declares who currently holds the rights, alongside credit-line and licensing fields. All of that rides inside the same file, in the same EXIF, IPTC, and XMP blocks a metadata scrubber removes. One person's privacy leak is another person's ownership label, and the two travel in the same segments of the same file.
What Section 1202 actually prohibits
The provision is 17 U.S.C. § 1202, "Integrity of copyright management information." Its subsection (b) says that no person shall, "without the authority of the copyright owner or the law," intentionally remove or alter any copyright management information, or distribute works knowing their CMI has been removed — and that this applies when the person knows, or has "reasonable grounds to know," that doing so "will induce, enable, facilitate, or conceal an infringement." Subsection (c) defines copyright management information broadly: the work's title, the author's name, the copyright owner's name, terms and conditions for use of the work, and identifying numbers or links to such information — while explicitly excluding personally identifying information about a user of a work. The stakes are real: under § 1203(c)(3)(B), a court can award statutory damages of $2,500 to $25,000 per violation.
Two things in that text matter for anyone holding a scrubber. First, the prohibition starts with "without the authority of the copyright owner" — the copyright owner's own authority is built into the rule. Second, removal alone isn't the violation: courts call the rest a "double scienter" requirement — the removal must be intentional, and the person must know or have reason to know it points toward infringement. Both halves got tested in court, in two cases that came out opposite ways.
Stevens v. CoreLogic: automated stripping, without more, wasn't enough
The Ninth Circuit's Stevens v. CoreLogic (No. 16-56089, decided June 20, 2018) is the closest a federal appeals court has come to ruling on exactly what a metadata scrubber does. Robert Stevens and Steven Vandel photographed homes for real estate agents, embedding their CMI in the files. The agents uploaded those photos to multiple listing services running CoreLogic's software — which downsized images for display using code libraries that didn't read or write EXIF, so the resized copies simply came out without the metadata. The photographers sued under § 1202(b).
They lost, and the reason is instructive. The court held that a plaintiff must show the defendant knew, or had reasonable grounds to know, that the removal would likely lead to infringement — a "pattern of conduct" or something concrete, not the mere possibility. As the opinion put it, "The Photographers have not offered any specific evidence that removal of CMI metadata from their real estate photographs will impair their policing of infringement." The court also made an observation that echoes what this blog's platform-testing posts found from the privacy direction: "A party intent on using a copyrighted photograph undetected can itself remove any CMI metadata, precluding detection through a search for the metadata." Embedded credit is a label, not a lock — a bad actor can strip it themselves, which is exactly why courts wanted evidence, not inference, before treating routine automated stripping as a DMCA violation.
Mango v. BuzzFeed: when Section 1202 does bite
Two years later the Second Circuit showed the other face of the statute in Mango v. BuzzFeed (970 F.3d 167, decided 2020). Gregory Mango, a freelance photographer, had licensed a photo to the New York Post, which ran it with his name in the "gutter credit" beneath the image. BuzzFeed then published the same photo without permission — with Mango's credit removed and a different attribution in its place. BuzzFeed argued its way up the same statute and lost at every step. The court held that a gutter credit printed next to a photo counts as copyright management information even though it isn't embedded in the file, and even though Mango hadn't affixed it himself. And on the knowledge element, the Second Circuit held that § 1202(b)(3) doesn't require proof that some future third party would be misled — knowingly concealing your own infringement is enough.
Put the two cases side by side and the statute's shape is clear. An automated pipeline that strips metadata incidentally, with no evidence linking the removal to infringement, survived. A publisher that used someone else's photo without permission and swapped out the credit did not. The law isn't aimed at the scrubbing; it's aimed at the taking that the scrubbing hides.
Scrubbing your own files is the case the statute steps around
Which brings this back to what a NearScrub user is actually doing. The ordinary case — your own phone photo, your own resume, a PDF you wrote — is one where you are the copyright owner of the work in question (photos you took, documents you authored, setting aside employment work-for-hire situations). Section 1202(b)'s prohibition applies to removal "without the authority of the copyright owner or the law," and both halves of the knowledge requirement assume the removal points toward someone's infringement. Stripping your own GPS trail and your own name out of your own file before posting it is the copyright owner exercising exactly the authority the provision carves out, with no infringement anywhere in the picture. That's not a loophole; it's the statute working as written.
The case to leave alone: other people's work
The picture flips when the file isn't yours. A photographer's image you found online, a licensed photo you're only permitted to display, someone else's illustration — the Creator and Copyright Notice fields in those files are precisely the copyright management information § 1202 protects, and running such a file through a scrubber before republishing it is the Mango pattern, not the vacation-photo pattern. NearScrub can't tell whose file it's been handed; the person dropping the file onto it can. The honest statement of what this tool is for: cleaning files that are yours to clean, before they leave your device — not laundering the credit off work that belongs to someone else. And for photographers reading from the other side, Stevens carries its own sober lesson: courts know embedded credit can be stripped by anyone, so treat IPTC fields as a marker that supports enforcement, not as protection by itself.
Why NearScrub can't keep the copyright and drop the GPS
One structural detail follows from how the tool works. NearScrub removes metadata as whole blocks: for a JPEG, the entire EXIF APP1 segment (re-inserting only the orientation flag so portrait shots don't render sideways), the entire XMP segment, the entire IPTC/Photoshop APP13 block, and comment segments; for PNG, the text and timestamp chunks; for PDF, the Info dictionary and the XMP stream; for Office files, the docProps parts. It does not parse individual fields inside those blocks, so there is no mode that keeps a Copyright Notice while dropping GPS — the copyright fields live in the very segments being removed. For the privacy use case, that wholesale removal is the point: nothing left behind, nothing missed. But it means the output of a scrub is a file with the ownership labels gone too. If you're a photographer who wants your name to stay in a copy you're distributing, a scrubber is the wrong tool for that copy — and that's worth knowing before, not after.
The button is the same; the file decides
So: is it legal to remove a photo's metadata? For the files this tool is built around — your own, cleaned for your own privacy before they go anywhere — the statute's own text answers the question in its first clause, and no court case says otherwise. For someone else's work, republished without permission with the credit stripped, a federal appeals court has already affirmed liability, at $2,500 to $25,000 per violation in statutory damages. The scrubbing is the same button either way; whose file is dropped on it is what the law turns on. None of this is legal advice, and anyone facing a real dispute over metadata and copyright should talk to a lawyer who can look at their actual facts — but the shape of the rule is public, and it's worth knowing by anyone who removes metadata on purpose.