File Formats File FormatsAI
Journal Entry

The Files That Will Outlast the Software: What Digital Preservation Actually Requires

File Format Sustainability and Digital Preservation

Photo by William Bayreuther on Unsplash

The oldest surviving photograph—Louis Daguerre’s 1837 still life on a silver-coated copper plate—has outlasted every piece of equipment used to create it. The same cannot be said for a RAW file shot on a mid-2000s camera body whose proprietary format is no longer recognized by current software. Physical media at least fails visibly. A format becomes unreadable without a single byte changing.

That gap between persistence and accessibility is the central problem of digital preservation. A file doesn’t have to be deleted to be lost.

What “Sustainable” Means When Applied to a File Format

Sustainability, in archival terms, isn’t about compression efficiency or color gamut — it’s about the likelihood that a format can be decoded accurately by software that doesn’t yet exist, running on hardware that hasn’t been built, in institutions that may have none of the original creation tools. That’s a different set of criteria from what most photographers use when choosing a format.

The Library of Congress’s digital preservation program evaluates formats along several dimensions, and their framework is worth understanding concretely. Disclosure matters: is the specification publicly documented so that a future developer could write a decoder from scratch? Self-description matters: does the file carry enough internal metadata to identify what it is and how it’s encoded? Adoption matters, though not unconditionally — a widely-used format has more institutional momentum, but a widely-used format with an undisclosed specification is still a fragile bet over decades.

JPEG clears some of these bars. The JPEG standard (ISO/IEC 10918) is publicly documented, the format is widely supported, and the DCT-based compression scheme is well understood. What JPEG doesn’t handle well is the self-description problem: a standard JPEG file embeds metadata in EXIF or IPTC fields, but that metadata is fragile, inconsistently supported across software, and can be silently stripped during export or platform upload. The image data survives; the context for interpreting it often doesn’t.

Proprietary RAW Formats: The Quiet Risk

Proprietary camera RAW formats represent the sharpest version of this risk. A Canon CR2, a Nikon NEF, a Sony ARW — each is a manufacturer-specific container whose decoding depends on reverse-engineering efforts by open-source projects like LibRaw, or on continued software support from the manufacturer. When a manufacturer stops releasing updates for older sensors, or when a software company changes its RAW processing pipeline, files shot years earlier can suddenly render incorrectly or not at all.

This is not a theoretical concern. Adobe’s DNG (Digital Negative) format was introduced precisely to address it — a documented, publicly specified container that embeds the raw sensor data alongside a standardized structure. After more than two decades, DNG has recently been adopted as an official RAW standard, which gives it meaningfully stronger institutional standing than manufacturer-proprietary alternatives. Whether any individual photographer should restructure their workflow around it is a separate question, but from a pure preservation standpoint, a format with a public specification beats one whose decoding is inferred from the binary output.

The practical wrinkle: DNG converts sensor data into a standardized structure, which means some manufacturer-specific calibration data embedded in proprietary RAW files may not carry over intact. Photographers who care about preserving not just the image but the exact processing metadata baked into the original file face a real tradeoff.

TIFF, PNG, and the Open-Format Tier

For images that have already been processed and edited, the question shifts. TIFF is the institutional standard for archival deposits across libraries, museums, and government agencies — not because it’s technically superior in every respect, but because its specification is openly published, it supports uncompressed storage (eliminating any lossy step), and it handles high bit depth and wide color spaces without forcing a conversion. A 16-bit TIFF preserves the tonal information that a JPEG’s 8-bit depth discards. For preservation purposes, that headroom matters less for display and more for future reprocessing: if the color profiles or rendering standards change over time, a higher bit depth file gives future archivists more to work with.

PNG occupies a similar position for images with transparency or graphics content. Its compression is lossless, its specification is open, and browser support has been stable for long enough that it’s reasonable to consider it a safe archival format for the near-to-medium term. What PNG lacks is support for color profiles beyond sRGB in common implementations, and it doesn’t handle photographic-resolution images as efficiently as formats designed specifically for continuous-tone content — the files are large without being meaningfully more detailed than a well-encoded TIFF.

HEIF and AVIF are the current generation’s efficiency leaders, but their archival status is genuinely uncertain. Both are capable formats — the technical tradeoffs between HEIF and JPEG are real and documented — but “efficient and capable” is not the same as “institutionally supported for long-term preservation.” AVIF in particular is recent enough that its track record at archival institutions is thin. That doesn’t make it a bad format for distribution; it does mean that relying on it exclusively for irreplaceable images is a bet on future support that hasn’t yet been validated.

What Actually Fails First: The Storage Layer

Format sustainability discussions sometimes skip past the more mundane problem: physical storage fails before format obsolescence does, in most real-world cases. A TIFF on a dead hard drive is as inaccessible as a corrupted proprietary RAW. The documented collapse of a cloud vendor that erased a PBS station’s 70-year archive is a reminder that the storage relationship matters as much as the format choice.

Archival practice in institutional settings typically follows the 3-2-1 model: three copies, across two different storage media types, with one copy geographically separated. For individual photographers, a rigid implementation isn’t always realistic, but the underlying principle holds. Format choice and redundancy are both parts of the same preservation system — optimizing one while neglecting the other produces a false sense of security.

There’s also the matter of bit rot: storage media can develop silent read errors over time without any visible sign of failure. Verification checksums (MD5, SHA-256, or similar) allow a future reader to confirm that a file’s bytes are identical to what was written. Without a checksum recorded at the time of creation, silent corruption is undetectable until the file is actually opened. Institutional digital preservation workflows treat checksum verification as routine; most individual photographers skip it entirely.

The Practical Hierarchy

For photographers building a preservation-aware workflow today, the format decisions resolve into a rough hierarchy:

The distribution format doesn’t need to be the preservation format. Conflating the two — shooting JPEG because that’s what gets uploaded — is the structural error that causes collections to degrade.

The next step: pull up the specification page for whichever format you’re currently using as a master and check whether the format is openly documented. If the answer isn’t clearly yes — or if the specification link leads to a standards body paywall you’ve never actually cleared — that’s worth resolving before the collection grows any larger.

More File Formats material is indexed in the Journal and on the File Formats page.