Metadata is the data a file carries about itself — who created it, when it was last modified, what device made it, and how it travelled. In litigation it is frequently more probative than the document's contents, because it records what happened rather than what someone wrote.
Three kinds, and they behave differently
System metadata is maintained by the file system: created, modified and accessed timestamps, file size, path. It is not stored inside the file, which is why copying a document to a new location can change it and why forensic collection exists.
Application metadata is embedded in the file by the program that made it: author, company, revision count, tracked changes, comments, the printer it was last sent to. It travels with the file wherever it goes.
Embedded content metadata is format-specific — EXIF data in a photograph recording camera model, settings and often GPS coordinates; header data in an email recording every server that handled it.
Why it decides cases
A document says what its author chose to write. Metadata says when they wrote it, what they wrote it on, what they changed, and sometimes where they were standing.
That makes it the usual evidence for backdating (a contract "signed" in March whose creation timestamp is June), for authorship disputes, for establishing that a file was copied to external media before a resignation, and for demonstrating that two documents produced as independent are the same file with the author field edited.
Email headers are their own category. The routing path, message IDs and authentication results in a full header are what distinguish a genuine message from a fabricated or spoofed one — and they are exactly what is destroyed when an email is produced as a PDF.
How it gets destroyed
Almost always by accident, and almost always early:
- Copying files. Drag-and-drop collection updates system timestamps across everything moved.
- Opening documents. Access times change, and some applications rewrite embedded metadata on open.
- Converting formats. Producing to PDF or TIFF discards most of it. This is the single most common way a party destroys the evidence it was ordered to produce, while believing it has complied.
- Cloud sync. Sync clients frequently rewrite timestamps to the sync time rather than preserving the original.
None of these are reversible, which is why form of production belongs in the ESI protocol rather than in a later motion.
Metadata is evidence, not proof
It can be altered, and a competent examiner will say so before opposing counsel does. Timestamps can be changed by tools, by clock drift, by time-zone handling in processing software, and by a machine whose system clock was simply wrong.
What makes metadata persuasive is corroboration across independent sources: a file timestamp that agrees with a server log, a badge record and a message sent the same afternoon. A single timestamp offered on its own invites a straightforward attack, and it usually deserves one.
A newer failure mode
Generative tools introduce a variant worth knowing about: documents produced or summarised by an AI system may carry metadata describing the generating process rather than the underlying facts, and can present fabricated attributes with the same confidence as real ones. Metadata from a pipeline that included a model is not self-authenticating, and treating it as if it were is a mistake that will be made more than once before it is widely understood.
From our work
Dealing with metadata in a live matter?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
