Enabling Access (CPP-025)

CPP-IdentifierCPP-025
CPP-LabelEnabling Access
AuthorMikko Laukkanen, Johan Kylander
ContributorsKris Dekeyser
EvaluatorsMatthew Addis, Felix Burger, Maria Benauer
Change historyComments
Version 1.0.0 - 2025-08-29Milestone version
Version 1.1.0 - 2026-03-27Migration to XML

1. Description of the CPP

The TDA gives access to its Information Objects to authorised internal users or end users.

Inputs and outputs

Input(s)
Data
Request for a DIP
Metadata
Request Metadata specifying the kind of digital Objects to be accessed (master Files or derivatives)
Documentation/guidance
Access policy
Output(s)
Data
DIP
Metadata
Technical metadata

Definition and scope

Data access in digital preservation refers to the ability to retrieve, view, and use preserved digital materials in meaningful ways over extended periods of time. The access as a whole involves several aspects. This CPP concentrates on the aspects within technical accessibility, and leaves out aspects like Enabling Discovery (CPP-024) and delivery methods (e.g. user interfaces and APIs). A TDA must implement access to the data it preserves to consumers that are authorised to access the data in question.

Technical accessibility means ensuring that digital Files remain readable and usable despite technological change. This requires maintaining compatibility with current systems through File Migration (CPP-014), emulation strategies (CPP-015 Emulation and Rendering Tools), or preservation of legacy hardware and software environments. The preserved data must be retrievable from storage systems and renderable in forms that users can actually engage with.

From a technical point of view, Enabling Access is about providing DIPs containing the requested data in appropriate Representations. The TDA, upon receiving a request, creates and provides a DIP from one or more AIPs stored in the TDA. The TDA also, if it supports this, provides access to derivatives that are Representations of the preserved data that are specifically created for use, viewing, or interaction, rather than giving them access to the master data. The derivatives can be created at different stages of digital preservation: in pre-ingest phase, during ingest, within the preservation lifespan, or on the fly when the derivative is needed. This approach is TDA-dependent and can be enforced by a policy. In any of these cases, however, the access process should always provide the data in the form of a DIP by a TDA to a consumer (e.g. end user; portal or aggregator; data publication platform or some other service or system communicating with the TDA).

The accessed data may include restrictions or sensitive, confidential or rights-protected parts (CPP-020 Rights Management). Also, an organisation’s data can be non-public, and/or non-accessible for other organisations. Therefore, access should incorporate authentication and authorisation functions to control who can access what data, implementing necessary restrictions while enabling legitimate use. Restrictions on accessing data (particularly digital Objects) are usually different from restrictions to find and discover data (CPP-024 Enabling Discovery).

Process description

Trigger event(s)

Trigger EventCPP-identifier
Request for a DIP

Step-by-step description

NoSupplierInputStepsOutputCustomer
 sequence
1DIP requestThe TDA receives a DIP request specifying the type of data to be accessedRequester info from the request
2Requester info from the requestThe TDA authenticates the requestAuthenticated request (step 3)
Rejected request (return rejection message to requester, got to step 4 and then end the process after logging it)
3Requester info from the requestThe TDA authorises the requestAuthorised request (step4)
CPP-020 (Rights Management)Rights statementRejected request (return rejection message to requester, got to step 4 and then end the process after logging it)
4DIP requestThe TDA logs the request for statistical reporting and auditingAccess log
5 alternative - Authentication and authorisation of the DIP request
5.aAuthenticated and authorised requestThe TDA locates the AIP or set of AIPs, from which the DIP is createdAIP or a set of AIPs
5.bNon-authenticated or unauthorised requestThe TDA responds with errorError response
6AIP or a set of AIPsThe TDA ensures that the selected AIP or set of AIPs is valid and intact (e.g. performs checksum validation and other potential checks)AIP or a set of AIPs
7CPP-020 (Rights Management)AIP or a set of AIPsIf the request includes derivatives that should be created, the TDA uses CPP-028 (Creation of Derivatives) to create the copies on the fly (if the TDA supports this)AIP or a set of AIPs
8AIP or a set of AIPsThe TDA creates a DIP from the AIP or set of AIPs ( AIP to DIP transformation) and the potential derivatives DIP
9 DIP The TDA checks that the created DIP is valid according to its specifications before making it available DIP
10 DIP The TDA makes the DIP available to the requester or consumerDelivered DIP

Rationale(s) and worst case(s)

RationaleImpact of inaction or failure of the process
Data access is an essential functionality of a TDA, because of its purpose to maintain the long-term availability of the preserved information. Preservation aims to ensure that information remains discoverable, accessible and usable.Without access, digital preservation becomes just an expensive storage. Thus, the TDA fails to fulfill its purpose to maintain the long-term availability of digital Objects over time.

2. Dependencies and relationships with other CPPs

Dependencies

CPP-IDCPP-TitleRelationship description
CPP-002Checksum ValidationDuring the access process, the fixity of the provided digital Object is validated.
CPP-005Identifier ManagementAccessing digital Objects, Files or Metadata should be based on identifiers as parameters.
CPP-020Rights ManagementThe TDA must assess access rights to check it is authorised to provide access to the requester.

Other relations

RelationCPP-IDCPP-TitleRelationship description
Required byCPP-015Emulation and Rendering ToolsThe access request is the trigger to invoke the rendering process or start up the emulated environment.
Required byCPP-017DisposalDisposal prevents access to the Objects. Also, preventing access can be considered as "logical disposal".
Required byCPP-028Creation of DerivativesThe request for access can trigger the creation of a derivative for rendering purposes (e.g. derivatives may be created on the fly if Access cannot rely on an existing derivative).
Affinity withCPP-013Object Management ReportingAccess of contents includes providing Provenance metadata, statistical data and quality reports to the consumer.
Affinity withCPP-019Data Quality AssessmentDIPs should conform to the quality aspects specified by the TDA.
Affinity withCPP-024Enabling DiscoveryEnabling Discovery is about making data findable, while Enabling Access is about providing the data to a consumer. Data may have different restrictions for discovery and access.
Not to be confused withCPP-006AIP Batch ExportEnabling Access does not export the data from TDA.

4. Reference implementations

Publicly available documentation

InstitutionOrganisation typeLanguageHyperlink
TIB – Leibniz Information Centre for Science and Technology and University Library, DENational library
Non-commercial digital preservation service
Research infrastructure
Research performing organisation
Englishhttps://wiki.tib.eu/confluence/spaces/lza/pages/93608366/Access
CSC - IT Center for Science Ltd., Finland, FINon-commercial digital preservation serviceEnglishhttps://urn.fi/urn:nbn:fi-fe2023062157386
(section 2.2, Principles 3 and 5)