Metadata is information (data) that describes your data. For example, metadata may include:
- Important date/timestamps: such as when a file was created, last modified, last accessed
- The original author of the file (perhaps many years, revisions, and firms ago)
- The location a photo automatically captured from a phone GPS
- Email From/To, Dates, Subject, Attachments (email routing, timestamps, & IP addresses) history
- Edit History (such as with “Track Changes” enabled) or Comments
From a preventative standpoint, opinion 07-03 advises lawyers must “take reasonable precautions to prevent the information (metadata) from coming into the hands of unintended recipients.” This opinion also provides some data scrubbing procedure recommendations as well as providing some advice regarding the use of metadata management software and informed client consent in forgoing the use of this software.
Technology and your risk profile both continually evolve. How well are you and your firm keeping on top of and managing your metadata risk?
Some questions you might consider in performing your review of your metadata risks and management policy:
- Have there been changes to your firm profile (areas of law, types of clients, changes in staff, risks) that require an evolution of your metadata policies and procedures?
- Do your policies and procedures adequately address risks associated with Microsoft Office Track Changes & Comments? Other metadata risks?
- Do you have metadata management software in place?
- Is it actively running/working? (test it)
- Is it effective? Is it efficient/easy to work with?
- Have you evaluated if there are any newer, better technology and/or approaches?
- Has the firm considered the risks associated with the use of BCC (blind carbon copy) in sending email?
- Is your employee training and education regarding metadata risks sufficient?
For more information on how to protect your firm’s data, contact us directly at 602-412-5025 or info@totalnetworks.com.
