Skip to main content
Category: Digital Preservation

Trusted Digital Repository

Also known as: TDR, Trustworthy Digital Repository
Simply put

A trusted digital repository is a system, together with its supporting organization, whose purpose is to provide reliable, long-term access to digital materials it manages on behalf of the community it serves. The word 'trusted' signals that the repository can be assessed against recognized criteria for its ability to preserve and provide access to those materials over time. It is concerned not only with storing digital content but with maintaining its usability and accessibility into the future.

Formal definition

A trusted (or trustworthy) digital repository is an organization and technical infrastructure whose stated mission is to provide reliable, long-term access to managed digital resources for a defined designated community, both now and into the future. The concept is closely associated with the Open Archival Information System (OAIS) reference model and is operationalized through audit and certification frameworks intended to assess repository trustworthiness. Notably, ISO 16363 (Audit and certification of trustworthy digital repositories) provides recommended practice for assessing trustworthiness, and it developed alongside earlier work such as the Trustworthy Repositories Audit & Certification (TRAC) metrics for OAIS-compliant repositories. Assessment against such criteria typically addresses factors including long-term preservation, accessibility, and continued usability of managed digital resources; the specific requirements and certification approaches applied may vary depending on the framework adopted and organizational context. This term is distinct from general document or data storage systems, as trustworthiness here refers to demonstrable, often externally assessed, capacity for sustained preservation and access rather than mere data retention.

Why it matters

Digital materials are inherently fragile in ways that physical records are not. File formats fall out of support, storage media degrade, software dependencies vanish, and the contextual information needed to interpret content can be lost long before the bits themselves become unreadable. An organization that simply retains data on servers or in cloud storage has not thereby ensured that those materials will remain authentic, intelligible, and accessible years or decades later. The concept of a trusted digital repository responds to this gap by shifting the question from 'is the content stored?' to 'can this organization and its infrastructure demonstrably preserve and provide access to these materials over the long term for the community it serves?'

Who it's relevant to

Archivists and digital preservation specialists
Those responsible for the long-term stewardship of digital collections use the trusted digital repository concept to structure preservation programs and to demonstrate, against recognized criteria, that their systems and organizations can sustain access over time. Familiarity with OAIS and with frameworks such as ISO 16363 and TRAC helps them articulate and evidence repository trustworthiness.
Records managers and information governance officers
Where digital records must remain reliable and usable across extended retention periods or into permanent preservation, this concept helps distinguish mere data retention from demonstrable long-term preservation. It supports decisions about where records of enduring value should reside and how continued authenticity, integrity, and usability can be assured.
Depositors and data producers
Individuals and organizations placing materials of enduring value with a repository can use trustworthiness criteria to compare candidate repositories and to gain assurance that deposited content will remain preserved and accessible for the intended community, rather than simply stored.
Funders, regulators, and oversight bodies
Parties that require preservation guarantees, or that assess whether preservation commitments are being met, may reference trusted digital repository criteria as an assessable basis for confidence. The availability of audit and certification frameworks allows preservation capacity to be evaluated on evidence rather than assertion, though the applicable requirements will depend on jurisdiction, sector, and the framework adopted.

Inside TDR

Organizational and governance framework
The documented commitment, policies, and administrative responsibilities that provide accountability for the repository's ongoing operation and stewardship of digital materials over time. This typically includes governance structures, funding sustainability, and succession or continuity planning, though the specifics depend on organizational and institutional context.
Preservation function
The processes and strategies intended to maintain the authenticity, integrity, and usability of digital objects across time, often addressing format obsolescence and media degradation. Note that preservation in this sense goes beyond simple backup or storage and is aligned with disposition outcomes involving permanent retention rather than routine retention alone.
Integrity and authenticity controls
Mechanisms such as fixity checks, audit trails, and access controls that support the claim that held objects remain what they purport to be and have not been altered without authorization. These controls underpin the properties that distinguish an authoritative record from a mere copy or transitory information.
Metadata and documentation
Descriptive, structural, technical, and provenance metadata that support the identification, management, retrieval, and continued interpretability of digital objects. Provenance and chain-of-custody information are typically emphasized because they support authenticity and usability over the long term.
Access and usability provisions
The arrangements that enable authorized designated users to locate, retrieve, and interpret held materials over time, subject to any applicable access restrictions. Access requirements often vary by jurisdiction, sector, and organizational policy.
Trustworthiness evaluation basis
The criteria or audit frameworks against which a repository may be assessed or certified as trustworthy. Certification schemes and audit criteria exist in this area, but their scope and recognition vary, and organizations should confirm the applicability of any particular scheme to their context.

Common questions

Answers to the questions practitioners most commonly ask about TDR.

Is a trusted digital repository just a secure backup system or storage platform?
No. While secure storage is a component, a trusted digital repository is distinguished by its commitment to the long-term preservation of digital records and its ability to maintain their authenticity, integrity, reliability, and usability over time. A backup system typically focuses on data recovery and business continuity, not on sustained preservation, format management, or the provision of authoritative access to records as evidence. The trust in a trusted digital repository derives from documented policies, procedures, and organizational accountability, not merely from technical redundancy.
Does calling a repository 'trusted' mean it has been formally certified?
Not necessarily. The term describes a repository's demonstrated capacity to preserve digital materials and maintain their trustworthiness, which rests on transparent policies, procedures, and organizational commitments. Formal certification against recognized criteria may support such claims, but the label 'trusted' is often used descriptively rather than as evidence of any particular accreditation. Whether certification exists, and what it covers, depends on the framework applied and the choices of the operating organization, so the term alone should not be read as a guarantee of independent audit.
What organizational elements are typically needed to establish a trusted digital repository?
Beyond technology, establishing a trusted digital repository typically requires documented preservation policies, defined roles and responsibilities, sustainable funding and governance arrangements, and procedures covering ingest, storage, and access. Organizational accountability and continuity are often emphasized as much as technical capability, since preservation obligations frequently extend over long periods. The specific arrangements depend on the repository's mandate, the nature of the records held, and applicable organizational or jurisdictional requirements.
How does a trusted digital repository handle records at ingest?
At ingest, a repository generally captures records along with sufficient metadata to support their identification, management, and future usability, and it may apply checks to confirm that received material is complete and unaltered. Practices such as validating file formats, recording provenance, and generating integrity information are commonly described in preservation frameworks. The exact procedures depend on the repository's policies and the characteristics of the material being accepted, so implementations vary.
How can a repository maintain the integrity of records over long retention periods?
Maintaining integrity over time typically involves monitoring for unintended change, using integrity-checking mechanisms, and managing the risks posed by technological obsolescence, for example through format management strategies. These activities are usually supported by documented procedures and periodic review. It is important to note that maintaining integrity is distinct from disposition decisions; the length of retention and whether records are eventually transferred, preserved permanently, or destroyed depends on retention schedules and organizational policy rather than on repository capability alone.
How does a trusted digital repository support access and use of preserved records?
A trusted digital repository generally aims to provide access to records in a usable form for those authorized to use them, which may involve managing formats, maintaining descriptive and technical metadata, and applying access controls. The balance between providing access and enforcing restrictions often reflects privacy, security, and other obligations that vary by jurisdiction and sector. Consequently, access arrangements are shaped by both the repository's policies and any applicable legal or regulatory requirements.

Common misconceptions

A trusted digital repository is essentially a secure storage system or backup archive.
Trustworthiness in this context depends on far more than storage or backup. It typically rests on governance, sustainability, integrity and authenticity controls, metadata, and preservation processes that maintain usability over time. Reliable storage is necessary but not sufficient, and it does not by itself preserve the evidential qualities of records.
Placing records in a trusted digital repository is the same as retaining them for their retention period.
A repository intended for long-term or permanent preservation addresses a disposition outcome distinct from routine retention. Retention concerns keeping records for a defined period, whereas the preservation function of such a repository is generally directed at maintaining materials designated for permanent or long-term keeping, which is a different lifecycle concern.
Any repository can call itself 'trusted' simply by asserting reliability.
The designation typically implies that the repository can demonstrate trustworthiness against recognized criteria or through evaluation, rather than by self-assertion alone. The degree of external validation varies, and organizations should not treat the label as a guarantee without confirming the basis on which it is claimed.

Best practices

Establish and document a governance framework that assigns clear accountability for the repository and addresses long-term sustainability, funding, and continuity, rather than relying on technical measures alone.
Implement integrity and authenticity controls such as fixity checks, audit trails, and access controls, and maintain provenance metadata so that authoritative records can be distinguished from copies, drafts, and transitory information.
Treat preservation as a distinct function from backup and routine storage, planning explicitly for format obsolescence and media degradation to sustain usability over time.
Align the repository's handling of materials with defined disposition outcomes, keeping the distinction between routine retention and long-term or permanent preservation explicit in policy and practice.
Where trustworthiness claims are relevant, seek evaluation against recognized criteria and confirm the scope and applicability of any certification or audit framework to your organizational and jurisdictional context.
Define designated user communities and access provisions clearly, taking into account that access requirements and restrictions often vary by jurisdiction, sector, and organizational policy.