Long-Term Digital Preservation

Long-term digital preservation is the continuing management of collection photographs so that they remain intact, authentic, understandable, discoverable and usable despite storage failure, software change, account loss and the passage of time. It is not the same as keeping old files, buying more cloud storage or running an occasional backup.

For a serious collector, photographs can become part of the collection record itself. They may document identity, condition, provenance, restoration, completeness, serial numbers, signatures, insurance evidence and the state of an object before sale, loss or damage. Preservation therefore protects more than pixels: it protects the continuing relationship between the image, the owned item and the evidence that gives the image meaning.

Preservation target

What must survive?

A usable photographic archive is a compound record. It includes the image data, the source file, any preservation master, useful derivatives, metadata, item links and enough preservation history to explain what has happened to the files. Treating the image folder as the whole archive leaves the most fragile layer—the meaning—outside the preservation plan.

Evidence

Original capture or received file

The untouched camera, scanner, phone or third-party file. It may contain pixels, EXIF data, timestamps, colour information and source evidence that later versions no longer retain.

Longevity

Preservation master

A stable, high-quality version retained for future rendering, migration or reproduction. It may be the native RAW, a validated DNG, a simple TIFF or the best available original JPEG.

Use

Working and access derivatives

Crops, corrected copies, thumbnails, marketplace files and web images should be generated from protected sources rather than becoming the only surviving versions.

Meaning

Metadata and relationships

Identifiers, captions, view types, rights, provenance and links to the specific owned item are part of the preservation target. Pixels without context can survive while the record still fails.

Boundary

Backup is necessary, but it is not preservation

Backup mainly protects against loss and permits recovery to an earlier state. Preservation additionally requires an inventory, checksums, metadata, exportable relationships, format awareness, permissions, storage migration, documented procedures and tested restoration. Three copies of the same corrupted or unintelligible archive are still three failed copies.

Backup answers

  • Can I recover a deleted or failed file?
  • Do earlier versions exist?
  • How quickly can I restore working access?

Preservation also answers

  • What files exist and which version is authoritative?
  • Have they changed since they entered the archive?
  • Which item, condition state and evidence do they represent?
  • Can a future person open, understand and migrate them?

Risk diagnosis

How digital image archives fail

Loss and deletion

Accidental deletion, failed media, account closure and synchronised deletion can remove every convenient copy at once.

Silent change

Corruption, interrupted transfers, ransomware or software faults may alter a file without producing an obvious visual warning.

Obsolescence

A file may remain intact while its format, catalogue software, storage interface or proprietary export becomes difficult to use.

Context decay

IMG_4827.JPG may be clear today and meaningless to an executor, buyer or future researcher twenty years later.

Security failure

Photographs can reveal locations, serial numbers, alarms, personal documents and high-value holdings. Public access and preservation access should not be treated as identical.

Organisational failure

An archive can be technically sound yet unusable because nobody knows where it is, which copy is authoritative, how to restore it or who can access the credentials.

Formats

Choose sustainable forms without destroying source evidence

Preservation format decisions should consider openness, documentation, adoption, metadata support, compression, colour management, software support and migration options. There is no rule that every collector must convert every image to TIFF. Retain what you received before normalising it, and create additional formats only when they serve a defined preservation or access purpose.

Native source

RAW

Retains extensive sensor data and editing latitude, but may depend on manufacturer-specific decoding. Preserve the native RAW for significant work even when a rendered master is also created.

Normalised RAW

DNG

Broadly supported and publicly documented, but conversion should be validated. For important files, retaining both the proprietary RAW and the DNG may be justified.

Rendered master

TIFF

Mature, high-quality and widely supported. Prefer simple, well-documented TIFFs without unnecessary layers, exotic compression or proprietary features.

Interoperable original or access copy

JPEG

Lossy but extremely well supported. An original JPEG should be preserved as an original; converting it to TIFF does not restore information already lost through compression.

Graphics and annotations

PNG

Useful for screenshots, diagrams, transparent backgrounds and annotated details. It is not normally a replacement for RAW capture of ordinary photographic subjects.

Phone capture

HEIF / HEIC

Efficient and common, but less universally supported. Retain the native file and consider creating a validated, broadly renderable companion copy.

Fixity

Checksums prove sameness, not truth

A checksum is a value calculated from a file's contents. If the contents change, the checksum will almost certainly change. SHA-256 is a practical, widely supported choice for collector archives. Use checksums when files enter the archive, after copying, before and after storage migration, after restoration and during scheduled integrity audits.

A checksum can showA checksum cannot show
Whether a copied file is byte-for-byte identicalWhether the photograph was truthful when created
Whether silent corruption or alteration occurredWho created the image or owns its copyright
Which backup contains the known-good copyHow to repair damage without another verified copy

Copy strategy

Build independence, not just quantity

A strong baseline is three independent copies, on at least two storage systems, with one copy geographically separate. Add one offline, immutable or strongly versioned copy and aim for zero unverified backup errors. The numbers are useful only when the copies do not share the same failure modes.

Stronger arrangement

  • Primary archive on computer or NAS
  • Local removable backup disconnected after use
  • Encrypted off-site backup with version history

Weaker arrangement

  • Primary folder on one drive
  • Second copy on another partition of the same drive
  • Cloud synchronisation of the same live folder

Migration

Move storage routinely; change formats only for a reason

Media or storage migration

Move the same files from an ageing drive, NAS, optical disc or cloud provider to a current storage system.

The file contents should remain unchanged and be confirmed through checksum comparison.

Format migration

Transform content from one format to another, such as HEIC to TIFF or a proprietary catalogue export to CSV.

The checksum will change, so significant properties such as dimensions, colour profile, bit depth, orientation, transparency and metadata must be validated.

Meaning and context

Preserve the catalogue with the photographs

The image archive and the collection database form a compound record. A durable export should include items, variants, owned copies, image records, image-to-item relationships, captions, subjects or view types, original filenames, rights, timestamps, checksums, status flags and controlled vocabulary definitions. A pile of images is not a complete export of a digital collection.

/archive/
  /images-original/
  /images-master/
  /images-access/
  /metadata/
    items.csv
    images.csv
    image-item-links.csv
    controlled-vocabularies.csv
  /manifests/
    sha256-manifest.txt
  /documentation/
    README.txt
    preservation-policy.pdf
    data-dictionary.csv
    export-notes.txt

Workflow

A collector-oriented preservation ingest

1

Transfer

Copy files from the camera, scanner, phone, seller or auction source without editing the only copy.

2

Inspect

Confirm expected file count, openability, completeness and malware risk where relevant.

3

Preserve originals

Place received or captured source files in a protected area and treat them as read-only evidence.

4

Assign stable identifiers

Connect each significant image to the owned item, image role and photographic set.

5

Capture metadata

Record subject, view, date, creator, source, rights and purpose while the context is fresh.

6

Calculate checksums

Create a fixity baseline, commonly using SHA-256, before files are copied onward.

7

Create masters and derivatives

Produce preservation-quality renders where justified and disposable access versions for routine use.

8

Replicate and verify

Copy to independent local and off-site storage, then verify the transfer rather than assuming it succeeded.

9

Record completion

Mark the ingest as complete so files do not remain indefinitely in an unresolved incoming folder.

Collector judgement

Prioritise by evidential value

Highest priority

Unique photographs, condition evidence, authenticity details, provenance records, pre-restoration views, lost or sold objects, rare variants and legally or financially significant images.

Medium priority

Routine collection views, repeated but useful detail sets, display and exhibition history, event documentation and research working sets.

Lower priority

Regenerable thumbnails, duplicate exports and temporary marketplace crops—after confirming that they carry no unique context or publication history.

Maturity

A practical progression for private collectors

Level 1

Recoverable

Two copies exist, one is separate from the working computer, filenames are understandable, essential images are linked to items and a basic catalogue export exists.

Level 2

Resilient

At least three independent copies exist, one is geographically separate, originals are separated from derivatives, backups are automated and restoration is tested.

Level 3

Verified

Checksums, manifests, periodic fixity checks, format identification and verified storage migrations provide evidence that files have not silently changed.

Level 4

Sustainable

Format risk is monitored, metadata and relationships are openly exportable, procedures are documented, immutable protection exists and succession arrangements are workable.

Maintenance

A realistic preservation schedule

At every import

  • Preserve originals unchanged.
  • Assign stable item and image identifiers.
  • Record essential metadata and rights information.
  • Calculate checksums and make independent copies.
  • Confirm that transfer and linkage succeeded.

Monthly or quarterly

  • Review failed backup jobs and unresolved incoming files.
  • Inspect unexpected formats and missing catalogue links.
  • Confirm that open catalogue exports are being produced.
  • Restore a small representative image set.

Annually

  • Run a broader fixity audit.
  • Review storage health, capacity and account recovery.
  • Export catalogue data and image relationships.
  • Update the README, data dictionary and succession notes.
  • Confirm off-site copies and test estate-access instructions.

When risk requires

  • Replace ageing storage media.
  • Migrate to current storage systems.
  • Assess declining format or software support.
  • Test a full recovery and document the result.

Security and succession

Protect access without making recovery impossible

Collector photographs may expose home interiors, storage locations, serial numbers, personal papers and high-value holdings. Use least-privilege access, multi-factor authentication, separate administrator credentials, encrypted transport and storage, and reduced-metadata public derivatives. Keep fuller private evidence only where justified.

Common failure patterns

Myths that weaken otherwise careful archives

Myth

It is in the cloud, so it is preserved

Reality

Cloud accounts can be deleted, altered, locked, discontinued or left inaccessible after death.

Myth

RAID means I have a backup

Reality

RAID improves availability after some disk failures; it does not create an independent historical recovery copy.

Myth

The files open, so they are healthy

Reality

Visible opening is not a substitute for checksum comparison, validation and tested restoration.

Myth

My collection app stores everything

Reality

The application may omit originals, embedded metadata, relationships, deletion history or complete exportability.

Myth

RAW is the original, so I need nothing else

Reality

RAW may require specialist interpretation. A rendered master, metadata and an open catalogue export may also be essential.

Myth

I will organise it later

Reality

Context decays faster than files. Identity, source and purpose should be recorded during ingestion.

Minimum standard

A strong baseline for a serious collector

  1. Preserve all significant original captures and received files unchanged.
  2. Maintain high-quality masters for important scans and edited photographs.
  3. Generate disposable access derivatives from protected sources.
  4. Assign stable identifiers to owned items and significant images.
  5. Store descriptive, technical, rights and preservation metadata.
  6. Maintain at least three independent copies, including one geographically separate.
  7. Keep one copy offline, immutable or strongly versioned.
  8. Calculate and periodically verify SHA-256 checksums for preservation files.
  9. Export catalogue data and image relationships into open formats.
  10. Document the archive in a plain-text README and test restoration.
  11. Monitor formats and migrate only when justified.
  12. Document credentials, encryption and succession arrangements.

Key takeaways

  • Preservation protects the image, its identity, its context and the evidence that connects it to a particular collectible.
  • An untouched original, a preservation master and an access derivative perform different roles and should not be silently collapsed into one file.
  • Backup is necessary but incomplete without fixity, metadata, exportable relationships, restoration testing and preservation planning.
  • No storage medium is permanent; long-term survival comes from verified copying, replacement and migration.
  • A future owner must be able to discover, understand, open, verify and lawfully use the archive without relying on the present collector's memory.

Continue learning

Related topics