Checking provenance with C2PA and IPTC
Provenance tools for buyers, from C2PA credentials to IPTC metadata, showing how an image's history can be checked before publication safely today.
· The editorial team of The Rights Desk · Finding and Provenance

You can test the origin of a picture before you license it by reading its IPTC description and its C2PA provenance record, where those records have been kept. This guide shows what each tool records, why the two work side by side, and what to ask for when neither record is complete.
Why provenance matters before you pay
When you buy a picture for a book, a pack, a site or a stand, you are buying permission to use a file that someone else made. If the name of the maker, the date of creation or the history of edits have been lost, you cannot be sure that the seller holds the rights that you need. That doubt creates practical risk around orphan works checks for buyers, around releases for people and property, and around limits that apply to editorial use.
Provenance does not replace a licence. It gives you a way to check the story that sits behind the licence offer. A description that travels inside the file tells you what the picture is said to show and who claims it. A separate provenance record tells you how the file came to be and whether it has been changed since. When both are present, you can compare them with the invoice, the caption and the terms, and you can see where you need to ask a further question.
What does the C2PA actually do?
The Coalition for Content Provenance and Authenticity is a project of the Joint Development Foundation, a Washington-based 501c6 non-profit organisation. It joined the work of the Content Authenticity Initiative and Project Origin to concentrate on open and global technical standards for provenance and authenticity. Its published task is to set out what provenance has to cover, turn those needs into specifications, and prepare best practice and reference designs that show how the specifications can be applied.
The same programme aims to see selected specifications recognised as global standards, to encourage use of provenance methods across devices, systems and services, and to encourage use of the specifications by social and media platforms. A further task is to keep content accessible when provenance methods are applied, so that readers who rely on assistive reading or other access methods are not shut out by the added data.
How open standards help you as a buyer
An open standard matters to you because you do not control the whole chain. A photographer may use one camera or software, an agency another system, and your own team a third. If each step uses a shared and public method for writing provenance, the record has a better chance of surviving the move from capture to edit to delivery. If each step uses a closed method, the record tends to break at the first change of hands.
The charter for the coalition describes this problem as one of scale for publishers, creators and consumers, at a time when information sharing has moved to digital form. It says the specifications are shaped by scenarios, workflows and requirements gathered from industry experts and partner organisations, including Project Origin and the Content Authenticity Initiative among others. For you, the value lies in that workflow view. It looks at what happens in real production, not only at what should happen in theory.
Where the IPTC fits beside Content Credentials
The IPTC publishes freely available open standards for the global news media. One part is described as the global standard to describe pictures. Other parts cover video management, a subject taxonomy for the media, a high-level data model for the news ecosystem, exchange of text, images, video, audio, events and sports data and packages of those items, and a rights expression language for the media industry. In plain terms, this family of standards carries the descriptive and rights information that picture desks have used for years.
Content Credentials and IPTC description answer different questions, which is why buyers are asked to read both. You can learn how the coalition works alongside that descriptive layer, then apply the same habit to every file. One layer tells you the who, what and rights terms attached by people in the chain. The other layer tells you the how, with a technical record of origin and change that software can display and check.
What should you ask your supplier to keep?
Ask what will still be inside the file when it reaches you. Some systems strip embedded data on export, on resize or on upload, and a picture that left the maker with a full record can arrive with almost nothing. You can ask the supplier to deliver the file with embedded description intact, to name the fields it has checked, and to state in writing any edit or conversion that it has made after receipt.
You can also ask how the supplier handles a mismatch. If the descriptive information names one maker and the provenance record names another, or if one date appears in the caption and another in the file data, you need to know which one the supplier stands behind. A clear answer lets you pause, seek another image, or ask for a further warranty in the licence terms. An unclear answer tells you that the chain is not controlled.
Can provenance travel through social platforms?
Many pictures offered to you have passed through a social or messaging service, where files are often recompressed, renamed or stripped of data. The coalition programme includes work with social and media platforms and with messaging platforms, and work toward an ecosystem of applications that can write and read provenance. For buyers, that work points to a simple check. You should treat a file taken from a feed as weaker evidence than a file supplied directly with its records intact.
The steering approach also covers education of creators, publishers, media consumers, regulatory bodies and governmental agencies, and the growth of applications that support provenance across devices, systems and services. Those aims do not give you a guarantee on any single image. They explain why support varies. Some tools will show a full history, some will show only that a record exists, and some will show nothing at all.
How do you keep access and privacy in view?
Two limits are built into the published guidelines. One concerns privacy and data for creators, publishers and consumers. Provenance can carry names, places and device information that a maker may not wish to share, and a buyer in the United Kingdom has to handle that information with care. You should read only what you need for the licensing decision, store it safely, and avoid republishing personal data in captions or credits unless you have a clear reason.
The other limit concerns access. The guidelines ask that provenance methods do not harm the accessibility of content, so the picture and its alternative text, caption and reading order still work for all readers. Add a provenance line to your next image request, ask for files with description and provenance kept intact, and file the replies with the licence so your AI images and copyright rules and your release checks can be audited later.


