Skip to content
Try Raven →
All posts
EthicsBy the Raven team8 min read

Is Photo Geolocation Legal? What the Law Says

Working out where a picture was taken is rarely illegal in itself. What you do next usually decides that. A plain-language look at metadata, data protection and the line into harassment.

Short answer

Photo geolocation is generally legal when you analyse your own images or pictures shared publicly. The law turns on purpose and effect rather than technique: identifying a living person's home or movements, then contacting or following them, engages data protection and harassment rules in most countries regardless of the tool used.

Abstract dark panel with concentric arcs closing over a level baseline, suggesting a boundary rather than a barrier.

The question comes up almost immediately once people realise a photograph can be placed on a map. Is that allowed? It is a fair thing to ask, and the honest answer is less dramatic than either extreme: working out where a picture was taken is rarely an offence by itself, and what you do with the answer is usually what the law actually cares about.

What follows is general information rather than legal advice, and rules differ meaningfully between countries. The shape of the reasoning, though, is remarkably consistent — most legal systems arrive at similar conclusions by slightly different routes.

Is it illegal to work out where a photo was taken?

In almost every jurisdiction, no. Looking at a picture and reasoning about the architecture, signage or plants in it is observation, and observation of something shown to you is not restricted. The technique is not what the law regulates.

Start with the obvious case. You have a photograph, you look at it, and you notice the script on a shop sign is Georgian and the number plate is the wrong shape for Turkey. You have just geolocated a photo, using nothing but your eyes. No sensible legal system prohibits that, and none of them try to. The same holds when a model does the noticing instead of you — the act of drawing an inference from a visible image is not the regulated thing.

The same is broadly true of metadata that arrived with a file you were given. If somebody emails you a photograph and it still carries GPS coordinates, opening the file's properties is not an intrusion; they handed you the file. Whether they meant to include the coordinates is a separate and often more interesting question, which is why stripping them before sharing is such a useful habit — the mechanics are in how to remove location data from photos.

At the point it becomes about a person rather than a place. Once you are building a picture of where a named individual lives, works or travels, most data protection regimes treat that as processing personal data, and harassment law becomes relevant if the person is then contacted or followed.

European data protection rules name location data explicitly as an identifier capable of turning information into personal data, and they have applied across the EU since May 2018. The important nuance is that "processing" covers far more than storing a database. Collecting, organising and combining count too. Assembling several of someone's photographs to establish a routine is processing personal data about that person, and doing it without a lawful basis is the problem — not the geography.

Systems outside Europe reach a similar place through a different door. Many rely on a test of reasonable expectation of privacy: a person photographed on a public street has limited grounds to object to being seen there, while the inside of a home sits at the opposite end. What repeatedly matters is not one clever deduction but a pattern of attention, which is exactly how stalking offences are framed in most countries — defined by persistence and effect on the victim, not by the tool.

Does it change anything if the photo was posted publicly?

Far less than most people expect. Publishing an image makes it visible; it does not grant permission to profile the person who published it. Data protection authorities have consistently held that personal data collected from public sources remains personal data with the same protections.

"It was public" is the most common justification and the weakest one. The reasoning fails because visibility and consent are different things. Someone posting a picture of their lunch has consented to you seeing their lunch. They have not consented to you determining their neighbourhood, cross-referencing it with three other posts and working out which building is theirs. Regulators have taken action against exactly that pattern of aggregation from public sources more than once, and the fact that each individual piece was freely visible has not been treated as a defence.

A practical way to think about it

  • Your own photographs. No issue at all. It is your picture and your curiosity.
  • A friend's holiday photo, with them in the room. Fine, and usually the most fun version of this.
  • A public landmark or scenic shot with nobody identifiable. Generally unproblematic; you are placing a location, not a person.
  • A stranger's photo, out of idle curiosity, once, then forgotten. Legally quiet in most places, but worth asking why you want to know.
  • Anything that builds toward identifying where a specific living person is. This is the line. Purpose is what changes the character of the act, and crossing it does not require any special software.

That list is deliberately about intent, because intent is what the law keeps returning to. The same deduction — this photo was taken in a particular suburb — is unremarkable when applied to your own childhood album and serious when applied to someone who has asked you to leave them alone.

Where does a tool like Raven sit?

Firmly on the entertainment side, by construction. It reads only what is visible in the frame, never metadata, keeps no image, and returns a guess that is often wrong. It cannot identify a person, and its output is too unreliable to be evidence of anything.

The design choices matter here, and they are not marketing. A tool that never reads Exif cannot leak a precise coordinate a photographer forgot to strip. A tool that discards the image cannot build a corpus about anybody. And a tool that reports low confidence honestly is far less dangerous than one that always sounds certain — the difference between a guessing toy and an investigative instrument is largely a matter of what the builder chose not to do, which is the subject of why entertainment-only matters.

That does not make the ethics automatic. A tool being harmless in design still leaves the user free to misuse it, and the harder judgement calls are gathered in the ethics of AI photo analysis and the broader picture in AI and photo privacy.

Try it the way it is meant to be used — on a photo from your own camera roll.

Upload a photo →

The short version: the technique is not the offence, the purpose usually is. Reasoning about your own pictures is ordinary curiosity that people have exercised since photographs existed. Turning that same reasoning on a person who has not invited it is where every legal system, by whatever route, ends up drawing its line.

Frequently asked questions

Is it illegal to look at the Exif data in a photo someone sent me?
No. Reading metadata that was included in a file sent to you is not an offence in itself. The file was handed over voluntarily, and inspecting its properties is no different from looking at the picture.
Can I get in trouble for guessing where a stranger's photo was taken?
You can, depending on why and what follows. A one-off curiosity is very different from building a record of where someone lives or goes. The second is the pattern harassment and data protection rules are written for.
Does it matter that the photo was posted publicly?
Less than people assume. Public posting makes the image visible; it does not hand over consent to profile the person who posted it. Regulators have repeatedly treated data scraped from public pages as still being personal data.
Is Raven a legal risk to use?
Not for its intended use — guessing where your own photos were taken, for fun. It reads only what is visible in the frame, never metadata, and it is frequently wrong. Pointing any tool at a stranger to locate them is the part that creates risk.

Sources

  1. Art. 4 GDPR — Definitionsgdpr-info.euLocation data is listed explicitly among the identifiers that make information personal data; the regulation has applied since 25 May 2018.
  2. Expectation of privacyWikipediaThe legal test that separates a public street from a private space in most common-law systems.
  3. StalkingWikipediaHow repeated attention and monitoring are treated as an offence across jurisdictions, independent of the technology involved.

Reminder

Raven is built for entertainment and curiosity. Its guesses are AI estimates that can be wrong, and it must never be used to track or identify real people. Uploaded photos are processed in memory and immediately discarded — never stored.

Get Geospy AI for iPhoneDownload free