Location Metadata & Uploaded Media Privacy Standard
PCL One does not require embedded GPS/EXIF location metadata for core municipal finance, tax, utility, HR or payroll workflows. For PCL-managed photo upload paths governed by this standard, unnecessary precise-location and device metadata is removed before persistent application storage unless the customer has explicitly approved a documented use case to retain it.
Purpose
Digital photos can contain embedded EXIF metadata such as capture time, device information and precise GPS coordinates. This standard defines how PCL One minimizes that metadata so an attachment does not disclose more location information than the business process requires.
Standard handling
| Scenario | Baseline treatment |
|---|---|
| Photo uploaded through a PCL-managed portal or application route | Strip unnecessary EXIF fields that may expose precise GPS location or device identifiers before the application-managed copy is persistently stored. |
| Business process explicitly requires geolocation | Retain only the location information required for the documented purpose, with customer approval, appropriate notice and role-based access. |
| Location entered as a normal form field | Treat as ordinary customer data under the configured retention, access and audit controls. This is separate from hidden EXIF metadata. |
| Original evidentiary file must be preserved | The original may be retained only where the customer has a documented records/evidence requirement; access must be restricted and the presence of embedded metadata understood. |
| External document repository, bulk import or integration bypasses PCL media processing | Metadata may remain in the source file. The source-system/integration design must define responsibility for metadata minimization. |
Use limitation
- Embedded location metadata is not used for advertising, generalized profiling or unrelated analytics.
- Embedded location metadata is not provided to an AI service unless the customer has approved a use case that requires it and the applicable data controls permit it.
- Where metadata is stripped, the visible photo content is preserved; stripping does not remove location information that is visibly present in the image itself.
Verification and exceptions
This control applies to PCL-managed media-processing routes where metadata minimization is enabled. Third-party repositories, external integrations and routes outside PCL-managed media processing may preserve source-file metadata; responsibility is defined in the service design. Any exception to retain embedded location metadata is documented with purpose, scope, retention and access controls.
Assurance records
- Upload-path configuration / design record
- Sample metadata validation test showing before/after treatment
- Approved exception record where metadata is intentionally retained
- Privacy impact / data-flow documentation for location-dependent features
Applicability
This document states PCL One’s public assurance baseline. A customer agreement, service schedule, applicable law or regulator requirement may set additional or stricter obligations; those terms take precedence for the applicable service. Service-specific architecture, residency and retention settings are documented in the relevant service schedule.