Social-Media Background Clues and EXIF Data

Nobody meant to publish any of that. It was in the background.

Law Firm Cybersecurity · Chapter 12~6 min read

The firm posts a photo from the holiday party. Behind the smiling associates: a whiteboard with a case caption still on it, a monitor showing an open matter, a stack of files with a client name visible on the spine. Nobody meant to publish any of that. It was in the background.

And depending on how the photo was taken and posted, the image file itself may carry the coordinates of where it was shot and the exact time — the same EXIF metadata we met in Chapter 4, now attached to a candid photo instead of a legal document.

Two problems in one photo

The background. Everything visible but unintended: whiteboards, screens, documents, calendars, sticky notes, the view out a window that pins down a location. Imagery analysis is the practice of examining a photo to extract information about the subject, their surroundings, and their activities, and to geolocate where it was taken.1 An analyst is trained to read the whole frame, not the subject. So is an attacker.

The metadata. Photographs can carry EXIF data: timestamp, device, camera settings, and often GPS coordinates.2 As we noted in Chapter 4, most major social platforms now strip this on upload to protect users — genuinely good news — but that protection applies only where the platform applies it.3 A photo emailed directly, posted to the firm's own website, or shared somewhere that doesn't strip it can arrive carrying exactly where and when it was taken.

Put the two together and an ordinary firm photo can disclose a client name, a matter, a location, and a timestamp — none of it in the caption.

Interactive — read the whole frame

A staged "firm social post." Caption: "Great turnout at the Calloway & Beaumont summer social! 🥂" What can someone learn from it?

Entirely staged and invented — no real firm, client, or coordinates. Nothing uploaded or collected. To check a real photo's EXIF, use your own device's photo-info view — don't upload it to anyone's website, including ours.

Why firms specifically should care

Marketing wants the firm to look active and human — team photos, event posts, courthouse-steps shots, office tours. That instinct is fine and worth keeping. The risk isn't posting; it's posting without looking at the whole frame first, and without knowing whether the file is carrying location data. A single careless image can undo a lot of careful confidentiality.

This is Chapter 4's metadata problem and Chapter 7's public-footprint problem, converging on the firm's social media.

What this means for your professional obligations

In the United States

Rule 1.6(c)'s reasonable-efforts standard covers inadvertent disclosure4 — and a client name legible on a file spine in a public photo, or coordinates embedded in an image, is disclosure by inadvertence. The duty of confidentiality under Rule 1.6 is broad: it isn't limited to documents marked confidential, and it certainly isn't waived because the leak happened in the background of a party photo.5

In Canada

The confidentiality duty covers all information about a client's affairs acquired in the professional relationship, without an exception for accidental background disclosure.6 The competence commentary reaches the risks of the platforms and tools the firm publishes through.7

What actually fixes this

1. Review the whole frame before posting. Make it a habit and a checklist item: before any photo goes out, scan the background for screens, documents, whiteboards, file labels, and location giveaways — not just whether everyone looks good.

2. Strip EXIF from images before they're published. For anything going onto the firm's own website, this should be automatic in the upload workflow (same fix as Chapter 4). For staff posting to social from phones, rely on the platform's stripping but don't assume it — and never email original photos externally without scrubbing.

3. Set a simple social-media policy. Who can post on the firm's behalf, what gets a second look, and the standing rule that client-identifying details — including in backgrounds — never appear. Keep it short enough that people actually follow it.

4. Mind live and real-time posting. Posting a courthouse or location shot in real time also discloses where your people are, right now. Usually harmless; occasionally not, depending on the matter.

5. Audit what's already up. Photos already on the firm's site and feeds were posted under old habits. Worth a review of what's already public — including whether anything on the firm's own site still carries EXIF.

Request an image-exposure audit

We crawl the images published on your website, check for retained EXIF/location metadata, and flag obvious background disclosures for human review. We only look at what's already public.

Your firm's social-media / image checklist

Spencer McLennan
Spencer McLennan is the founder and lead webmaster of LegalWebmasters, and has handled websites, hosting, and security for law firms and professional practices across the United States and Canada since 2007. He holds an MBA, a PCM from the American Marketing Association, and is a graduate student in intelligence studies. He writes the Law Firm Cybersecurity and Law Firm SEO & Design guides. Connect on LinkedIn.

Footnotes

  1. Rae Baker, Deep Dive: Exploring the Real-World Value of Open Source Intelligence 169–83 (Wiley 2023).
  2. Id. at 156–57.
  3. Id. at 157.
  4. Model Rules of Pro. Conduct r. 1.6(c) (Am. Bar Ass'n 2023).
  5. Id. r. 1.6.
  6. Model Code of Pro. Conduct r. 3.3-1 (Fed'n of L. Soc'ys of Can.).
  7. Id. r. 3.1-2 cmts. [4A]–[4B].

Trusted by professionals like you.

Crease Harman LLP Borders Law Group David Aujla, Immigration Lawyer