Rights Management (CPP-020)
| CPP-Identifier | CPP-020 |
| CPP-Label | Rights Management |
| Author | Bertrand Caron |
| Contributors | Johan Kylander |
| Evaluators | Felix Burger, Maria Benauer, Matthew Addis |
| Change history | Comments |
|---|---|
| Version 1.0.0 - 2025-08-29 | Milestone version |
| Version 1.1.0 - 2026-03-26 | Migration to XML |
1. Description of the CPP
The TDA manages rights related to the Information Objects, both for agents inside its scope (access, migrate, etc.) and for end users (access, reuse, etc.)
Inputs and outputs
| Input(s) | |||||
|---|---|---|---|---|---|
| Data |
| ||||
| Metadata |
| ||||
| Output(s) | |||||
| Metadata |
| ||||
| Documentation/guidance |
| ||||
Definition and scope
Rights Management is the process of performing rights assessments for Objects and Metadata preserved by the TDA, and managing a rights registry that describes rights basis applicable to these. The rights assessment process must investigate and, if possible, obtain rights applying to both the TDA for retaining and performing its preservation activities, and the consumer for accessing and reusing the Objects.
The entity responsible for creating rights statements is the TDA, based on input from the rights stakeholders. Managing rights can be complex and involve multiple and conflicting perspectives. For example, a TDA will typically seek the rights to preserve its holdings and provide open access to the widest possible community, but it also needs to respect rights that limit what it can do and what access it can provide (e.g. data privacy under GDPR). This adds extra complexity, for example a TDA will often be a data processor for the data it is holding and providing access to on behalf of others, but it may also be a data controller if ownership has been assigned to it or if it is directly involved in data collection. Furthermore, in order to perform its mission, it may collect further data about its users (e.g. to allow it to better understand and meet the needs of its designated community) and this usage data also has rights associated with it.
The process of rights assessment consists in determining the rights status of a specific Object or Metadata regarding different rights basis. Rights basis, as defined as PREMIS, are of different types:
- Copyright and intellectual property
- Laws
- Licenses
- Patents
- TDA institutional policies
- Contracts and service level agreements with the TDA partners
- Etc.
The output of rights assessment is a rights statement that defines:
- The rights basis applicable to the Object and Metadata;
- The period of time during which the Object is governed by said rights basis;
- The rules these rights basis prescribe.
Rules are actions (e.g. migrate, give access to, reuse, share, etc.) allowed, prohibited or required by a certain agent (e.g. rights holder, grantor, data controller etc.) to a certain agent (i.e. assignee), and conditions or restrictions limiting the scope of such rules. Among these actions, retention is a crucial one that might be limited in time as Objects may be subject to a retention schedule. After that time they can become a liability and may be deleted.
The output of Rights Management is used to define the rights of the TDA to perform several other processes. Only the most obvious ones are mentioned as direct customers for the rights statement: Ingest, Enabling Access, Format Migration, Normalisation, File Repair, Enabling Discovery, and Disposal. In other words, TDAs must ensure to obtain the right to perform preservation actions from laws, licenses or explicit rights assignment from rights stakeholders (i.e. rights holders, data subjects, data controllers, regulators, funding bodies, etc.). They should also clarify to their consumers the actions they are allowed to perform with the Objects. This implies that TDAs must provide rights statements to the consumers.
Although Rights statements are commonly attached to Intellectual Entities (IE), they may also apply to specific Representations of such IEs. They should also apply to all Metadata provided to internal users or consumers, in particular to discovery Metadata. This is especially important in cases where the Metadata contains personal data. Complying with the restrictions set in rights statements forms a part of how a TDA manages information security.
Rights management, as the production of rights statements, is a recurrent activity. A minimal rights assessment must be performed at the ingest phase, but a more comprehensive assessment may be postponed to a later time in the Object’s life cycle, in particular, when a request for access is made to the TDA. In some cases the outcome of a rights assessment process triggers a TDA to facilitate the update and management of Metadata (e.g. cases where data must be pseudonymised or anonymised) or even disposal, if the legal basis for preserving the data has changed. External events can also trigger rights re-assessment activities (e.g. legislative holds for compliance reasons, changes in consent, or notifications of possible infringement for example copyright). In other cases, rights management can trigger or schedule changes in access given to Objects for a designated community (e.g. embargoes and leases on research data). A lease is the opposite of an embargo. An embargo restricts access until a given time, for example a dataset can be publicly accessible but only after a given date. A lease says that a dataset can be made accessible but only before a given date and afterwards access is restricted or removed. Likewise, rights may inform retention schedules that trigger future events such as transfer or disposal. Therefore, it is important that the temporal aspect of rights are properly tracked and managed.
A single rights basis usually applies to several Objects or Metadata (e.g. a Creative Commons license). Thus, the Rights Management process also consists in managing a rights basis registry.
Process description
Trigger event(s)
| Trigger Event | CPP-identifier |
|---|---|
| Appraisal or re-appraisal | |
| Any process that requires rights clearance to act upon an Object, if a comprehensive rights assessment was not performed at ingest | CPP-025 (Enabling Access), CPP-029 (Ingest), CPP-014 (File Migration), CPP-026 (File Normalisation), CPP-027 (File Repair), CPP-024 (Enabling Discovery), CPP-017 (Disposal) |
| In particular, access request | CPP-025 (Enabling Access) |
| Revision after the end of a fixed-term rule (e.g. embargo, lease, etc.) | |
| Changes in legislation, changes in consent, infringement or take down requests, etc. |
Step-by-step description
| No | Supplier | Input | Steps | Output | Customer |
|---|---|---|---|---|---|
| sequence | |||||
| 1 | Object | Determine which rights basis apply to the Object or Metadata | Applicable rights basis | ||
| Metadata | |||||
| Input from producer, rights holder and data controller | |||||
| 2 | Applicable rights basis | Determine (if possible by negotiation with producer, rights holder and data controller) the rules implied by the rights basis (action, assignee, duration, restrictions or conditions) | Applicable rules | ||
| Input from producer, rights holder and data controller | |||||
| 3 | Applicable rights basis | Determine (if possible by negotiation with producer, rights holder and data controller) the applicable dates of the rights basis (start and end date) | Time-delimited status | ||
| Input from producer, rights holder and data controller | |||||
| 4 | Applicable rights basis | Optional: If needed (depending on the the existing status of the Object and the applicable rights basis and rules) negotiate with the producer new rights assignment | New rights basis (e.g. contract, license, etc.) | ||
| Applicable rules | |||||
| Time-delimited status | |||||
| 5 | New rights basis (e.g. contract, license, etc.) | Optional: If a new rights basis had to be created (e.g. a new contract, new license, etc.), preserve its complete documentation | Rights basis documentation | ||
| 6 | Object | Associate the Object with the rights statement | Rights statement | CPP-025 (Enabling Access) CPP-029 (Ingest) CPP-014 (File Migration) CPP-026 (File Normalisation) CPP-027 (File Repair) CPP-024 (Enabling Discovery) CPP-017 (Disposal) | |
| Applicable rights basis | |||||
| Applicable rules | |||||
| Time-delimited status | |||||
| 7 | Rights statement | Optional: Optionally, encode / map rights statement into machine-actionable form and record it as Rights metadata | Rights metadata | CPP-016 (Metadata Ingest and Management) | |
| 8 | Metadata | Optional: If the updated rights statement requires, trigger one of the following
processes:
| CPP-016 (Metadata Ingest and Management) CPP-017 (Disposal) CPP-025 (Enabling Access) | ||
| Information Packages | |||||
Rationale(s) and worst case(s)
| Rationale | Impact of inaction or failure of the process |
|---|---|
| A minimal rights assessment at the ingest phase is required, although a more comprehensive process may be carried out at a later time in the Object life cycle. | Without rights assessment, a TDA might be incapable of performing preservation actions.Its consumers might be discouraged to use the Object if no explicit rights statement is provided by the TDA.The TDA might be exposed to liability or legal and financial harm.The TDA may end up retaining data for longer than needed or allowed, which can increase costs (e.g. storage). |
2. Dependencies and relationships with other CPPs
Dependencies
| CPP-ID | CPP-Title | Relationship description |
|---|---|---|
| / | / | / |
Other relations
| Relation | CPP-ID | CPP-Title | Relationship description |
|---|---|---|---|
| Required by | CPP-016 | Metadata Ingest and Management | Any information regarding the rights for the TDA and the end users needs to be stored and should be searchable and retrievable for all data. |
| Required by | CPP-025 | Enabling Access | The TDA must assess access rights to check if it is authorised to provide access to the requester. |
| Required by | CPP-029 | Ingest | Some minimal rights assessment must be performed during ingest to verify that the TDA should be in charge of preserving the content of the SIP. |
3. Links to frameworks
Certification
| Certification framework | Term used in framework to refer to the CPP | Section |
|---|---|---|
| CTS Link | Rights management | R02. The repository maintains all applicable rights and monitors compliance |
| Nestor Seal Link | Monitor[ing] and document[ing] conformity with relevant regulations | C7 Legal conformity |
| ISO 16363 Link | / | 3.5.1.1 The repository shall have contracts or deposit agreements which specify and transfer to it all necessary preservation rights, and those rights transferred shall be documented. |
Other frameworks and reference documents
| Reference Document | Term used in framework to refer to the process | Section |
|---|---|---|
| OAIS Link | No exact matching term exists in the OAIS functional model. | Among many rights considerations, OAIS reserves a specific treatment to Access RIghts Information in its informational model (section 4.3.2.4.3 “Preservation Description Information”). In addition, the section 3.3.3 “Obtains sufficient control for long term preservation” describes one of the OAIS’ responsibilities, providing some insights into the rights management process for the TDA internal needs. |
| PREMIS Link | No exact matching term exists in PREMIS | PREMIS describes all metadata elements required to describe a comprehensive rights statement in its section on the Rights Entity. The topic of rights management is also covered in another section, “More on Rights”. |
4. Reference implementations
Use cases
Negotiating Rights for Born-Digitals at the National Library of France
| Institutional background | |
|---|---|
| Institution | Bibliothèque nationale de France (BnF), France, FR |
| Hyperlink | / |
| Description | |
| Trigger event | The born-digital acquisitions and donations process at the National Library of France collects Objects from creators (filmmakers, graphic designers, photographs, etc.). The Objects aim to document the creative processes that eventually produced a work of art, some of which being collective. Rights of different nature may apply to these archives. Therefore, the process includes a mandatory step consisting in assessing rights applicable to the collected Objects. |
| Problem statement | The assessment usually leads to the signature of a contract which allows BnF to collect, copy, give access, migrate and exhibit Objects. In the case where the producer released the Object under an open license, it may allow BnF to perform such actions on the content without negotiating an explicit contract with the rights holder(s). |
| Proposed solution | Rights negotiations cover primarily access rights (remotely and without any restriction via the digital library Gallica, on-premise via Gallica Intra Muros or on the library’s public workstations via an access request), retrieval (download) and reuse rights. |
Publicly available documentation
| Institution | Organisation type | Language | Hyperlink |
|---|---|---|---|
| TIB – Leibniz Information Centre for Science and Technology and University Library, DE | National library Non-commercial digital preservation service Research infrastructure Research performing organisation | English |
https://wiki.tib.eu/confluence/spaces/lza/pages/93608951/Metadata#Metadata-ADMAdministrativemetadata" (Rights metadata) |
| CSC – IT Center for Science Ltd., FI | Non-commercial digital preservation service | Finnish | https://urn.fi/urn:nbn:fi-fe2024051731943 (Service contracts) |
| English | https://digitalpreservation.fi/en/toms (Technical and Organisational Measures in the Digital Preservation Services) | ||
| Archivematica, CA | Digital preservation system | English |
https://www.archivematica.org/en/docs/archivematica-1.17/user-manual/ingest/ingest/#add-premis-rights (Rights statements) |
| Rosetta, IL | Digital preservation system | English |
https://www.archivematica.org/en/docs/archivematica-1.17/user-manual/ingest/ingest/#add-premis-rights (Acess rights) |