Skip to main content

Metadata can give you away

Hiding the features is not enough if the metadata tells people what and where they are. GIS portals, web maps, files and services often expose descriptive information that users overlook during a sensitivity review.

What can leak

MetadataPossible disclosure
Dataset titleidentifies a sensitive subject or locality
Descriptionexplains what the hidden layer contains
Thumbnailshows the landscape or map extent
Geographic extentnarrows the search area
Owner or authoridentifies a knowledge holder or researcher
Tagsreveal cultural categories
Attachment filenamecontains a person or place name
Service URLexposes a backend endpoint or layer name
Field namesreveal that restricted categories exist
Schemaexposes relationships or classifications
Edit historyidentifies who supplied or changed information
File pathexposes machine, share or database names
Search indexmakes an otherwise obscure item discoverable

A layer called Restricted_Sites_Final is not harmless metadata merely because the geometry is private.

Web GIS creates an item as well as a map

Modern GIS platforms frequently store an item record containing title, owner, thumbnail, description, tags, extent and other details. That item can have different visibility from the underlying feature service or map.

This creates two reviews:

  1. can the user access the spatial data?
  2. what can the user learn from the item, catalogue or search metadata?

Both matter.

Extent can be sensitive

A bounding box can reveal a small search area even where precise coordinates are hidden. A thumbnail may do the same visually.

For highly sensitive material, a generic thumbnail and non-locational description can be safer than automatically generating a preview map.

Filenames survive longer than expected

Attachments, exports and emailed files often retain names created for internal work. Before external sharing inspect:

  • attachment names
  • zipped folder names
  • layer names
  • database table names
  • PDF titles
  • image EXIF metadata
  • embedded document properties

A well-generalised map can still be undermined by Urupa_exact_locations.xlsx sitting beside it.

ArcGIS item details

Esri's current ArcGIS Online documentation confirms that item details can include title, summary or description, owner information, thumbnail, tags and geographic extent. Esri also documents metadata-management and export tools because machine paths, database information and other details may need to be removed before metadata is shared externally.

The practical lesson is not specific to Esri. Any catalogue or portal should be reviewed as an information source in its own right.

A metadata publication review

Before releasing a sensitive map or service:

  1. Search the portal while signed out.
  2. Check the title and description.
  3. Inspect the thumbnail.
  4. Inspect the displayed extent.
  5. Review owner and author names.
  6. Review tags and categories.
  7. Check attachment filenames.
  8. Inspect service and API endpoints where visible.
  9. Review field names and pop-up configuration.
  10. Download a permitted export and inspect its embedded metadata.
  11. Check search-engine indexing if the item is public.

Do not assume the map viewer is the only place a user will encounter the item.

Public and internal metadata can differ

An organisation may need rich internal provenance while exposing a smaller public metadata record. Preserve the authoritative metadata internally. Create a public-safe description deliberately rather than deleting source context from the authoritative record.

Sources

Last verified: 16 August 2026

Māori GIS example

For an iwi or hapū project, the map can be hidden while its title, thumbnail, extent or item description still reveals the kaupapa or place. This is especially relevant to whenua, marae and historical-research collections. Pair this page with Metadata and documentation and Map sharing and data access.