Rights and licensing determine what an organisation may lawfully do with an asset and what it may permit others to do. A DAM that stores media without recording its rights status is a liability: it invites infringement, blocks legitimate reuse through uncertainty, and cannot demonstrate compliance. The goal is to attach clear, machine-actionable rights metadata to every asset and to enforce it at the point of access.

Ownership, licences and clearances

  • Copyright and ownership: record the rights holder, the basis of the organisation's rights, and any territorial or time limits.
  • Licences in, licences out: distinguish what you are permitted to do (inbound licence, e.g. a photographer's contract) from what you grant users (outbound licence, e.g. Creative Commons or RightsStatements.org).
  • Model, property and privacy releases: capture consents for identifiable people and places, and flag culturally sensitive material - for example using Traditional Knowledge (TK) Labels for community-held content.

Expressing rights so systems can act on them

Standardised statements make rights portable and unambiguous. Creative Commons licences and the RightsStatements.org vocabulary (used widely by Europeana and DPLA) give human- and machine-readable status; ODRL (the W3C Open Digital Rights Language) expresses permissions, prohibitions and duties that a DAM can enforce programmatically. PREMIS carries rights alongside preservation metadata for long-term custody.

Access control and enforcement

Rights metadata is only useful if the system honours it. Combine role-based access control with rights-driven rules so that, for example, a high-resolution master is downloadable only by licensed staff while the public sees a watermarked derivative. Log access and downloads to support audit and any obligations under data-protection regimes such as the GDPR and comparable international laws.

In practice. Adopt a controlled rights-status field with a fixed pick-list (e.g. "In copyright", "In copyright - reuse permitted", "No known copyright", "CC BY", "CC0"). Never leave it blank: an explicit "rights undetermined" status is a task on someone's worklist, whereas an empty field is an accident waiting to be published.

Key takeaways

  • Distinguish inbound licences (what you may do) from outbound licences (what you grant others).
  • Use standard vocabularies - Creative Commons, RightsStatements.org, ODRL, PREMIS rights - so status is portable and machine-actionable.
  • Enforce rights with role-based access, watermarked derivatives and access logging; never leave rights status blank.

Check your understanding

Last modified: Saturday, 1 August 2026, 10:37 AM