Is It Legal to Find Where a Photo Was Taken?
· 5 min read
Short answer
Whether it is legal to find where a photo was taken depends on what you do next. Analysing an image you own or one already published is generally lawful; using the result to locate, monitor, approach or intimidate a person can be stalking or harassment regardless of method.
This is not legal advice, and the answer genuinely varies by country. But the shape of the answer is consistent almost everywhere, and it is not the shape people expect: the analysis is rarely what the law cares about.
Is analysing a photo itself illegal?
Generally no. Examining an image you were given or one published publicly, including reading its metadata, is not usually restricted. The file was handed to you, and looking carefully at something you were given is not an intrusion.
Metadata is part of the file. When someone sends you a photograph, they send you everything in it — including the GPS tags, whether or not they realised those were there. Reading them is not circumvention of anything.
What changes the picture is how you obtained the image. Accessing a private account, a device or a cloud store without authorisation is an offence in most countries independently of what you then do with what you find.
When does it become stalking or harassment?
When the purpose shifts from the place to the person. Repeatedly establishing where someone is, showing up, contacting them about it, or making them fear for their safety meets the definition of harassment in most jurisdictions.
The legal tests generally turn on a course of conduct and its effect on the target, not on the technical difficulty of the method. Someone who assembles a person's routine from their public posts has done something the law recognises, and "the photos were public" is not a defence to it.
| Activity | Usually lawful? |
|---|---|
| Locating your own photo | Yes |
| Locating a published news or travel photo | Yes |
| Verifying whether an image is what it claims | Yes |
| Playing a geolocation game | Yes |
| Building a profile of one person’s movements | No — usually stalking |
| Contacting or approaching someone based on it | No |
| Accessing a private account to get the photo | No — separate offence |
| Publishing someone’s home location | No — doxxing, often criminal |
Does data protection law apply?
It can. Under GDPR and similar regimes, location data tied to an identifiable person is personal data, so collecting or publishing it can create obligations — including where the location came from a photograph rather than a database.
The purely personal or household exemption in Article 2 of the GDPR, in force since 2018, covers ordinary private use — which is where most curiosity sits. It stops covering you once the activity becomes systematic or the results are published, and the exemption is narrower than people assume.
What about journalism and research?
Both are widely recognised as legitimate purposes, and geolocating imagery is standard practice in verification work. Protection generally depends on public interest, proportionality and care — not on calling the activity research.
Established practice in that field is instructive regardless of whether you are a journalist — the workflow, including where to stop: verify before publishing, publish the place rather than the person where possible, and consider the consequences for anyone visible in the frame who did not choose to be there.
What is a defensible way to use these tools?
Work on your own images, on already-published material, or on puzzles. Stop at the place. Do not aggregate across a person's posts, do not publish precise locations of homes, and do not act on what you find.
- Ask what you would do with the answer before you look for it.
- Treat any result about a private individual as something to stop at, not act on.
- Never combine location with other personal data to build a profile.
- Remember that a city-level estimate is not evidence of anything — and that is all these tools produce.
- If you would not be comfortable explaining the search to the person in the photo, do not run it.
The same reasoning applies from the other direction. If you would rather your own photos did not carry coordinates, removing metadata before sharing is the practical step, and the privacy risks explain what is at stake.
Frequently asked questions
- Is it illegal to check the EXIF data of a photo someone sent me?
- Generally no. The metadata is part of the file you were given, and reading it is not circumvention. Acting on a location you find, in a way that affects the sender, is where the risk begins.
- Analysing it is usually lawful. Repeatedly tracking one person across posts, or using the result to approach or intimidate them, can amount to stalking or harassment in most jurisdictions.
- Does GDPR cover photo location data?
- Location data linked to an identifiable person is personal data. Purely personal use is exempt, but that exemption narrows once the activity becomes systematic or the results are published.
- Is it legal to publish where a photo was taken?
- It depends heavily on what the location reveals. Identifying a landmark is normally fine; publishing someone’s home address is doxxing and is a criminal offence in a growing number of jurisdictions.
Sources
- Regulation (EU) 2016/679 (GDPR) — Article 2, material scope — EUR-LexSource for the personal/household activity exemption referred to above.
- Exif 3.0 (CIPA DC-008-2023) — Camera & Imaging Products AssociationDefines the location data at issue.
Keep reading
How to Find Out Where a Photo Was Taken
Four ways to work out where a photo was taken: GPS metadata, reverse image search, AI geolocation and reading the image itself. What each can and cannot do.
· 6 min read
The Privacy Risks Hidden in Photo Metadata
What a geotagged photo gives away, why camera serial numbers matter as much as coordinates, and which habits cut the exposure without losing your archive.
· 4 min read