Access rights and licences
Controlled values and legal tools used to describe access conditions, permissions, restrictions and reuse rights for research data and related digital objects.
This resource explains how to distinguish access status from licensing, select appropriate controlled values and record rights information in a clear and machine-readable form.
Access and licensing decisions should be documented separately for data, software, documentation, models and other components of a research package.
Resource information
Resource type: Rights and licensing guidance
Primary audience: Researchers, data stewards, repository managers, metadata specialists, legal and research-support staff
Coverage: Access status, access conditions, data licences, software licences, public-domain tools, rights statements and controlled-use permissions
Primary uses: Dataset publication, repository deposit, metadata creation, licence selection, access management and catalogue exchange
Main sources: COAR, Creative Commons, SPDX, DataCite, RightsStatements.org, W3C ODRL and GA4GH
Last reviewed: July 2026
Purpose and scope
Access metadata explains whether a resource is currently available and what procedure is required to obtain it.
Licence metadata explains which acts of copying, redistribution, adaptation or commercial reuse are permitted after lawful access has been obtained.
Rights statements communicate a known or uncertain copyright status, particularly where the organisation describing the object is not granting a new licence.
Important: open access does not automatically mean unrestricted reuse. A resource may be freely downloadable but lack a clear licence.
Conversely, a standard licence does not override privacy, confidentiality, contractual, ethical, security or personal-data restrictions.
Access and rights concepts
Access status
Indicates whether the resource is open, embargoed, restricted or represented only by metadata.
Access conditions
Describe authentication, request, approval, agreement or secure-use requirements.
Licence
Grants permissions and defines conditions for lawful reuse of a protected resource.
Rights statement
Communicates a known, limited or uncertain copyright and reuse status.
Controlled access-status values
| COAR value | Meaning | Persistent URI |
|---|---|---|
| open access | The resource is immediately and permanently available online without financial or technical barriers. |
http://purl.org/coar/access_right/c_abf2
|
| embargoed access | Only the metadata are available until the resource is released openly on a specified date. |
http://purl.org/coar/access_right/c_f1cf
|
| restricted access | The resource exists in the system but access requires authentication, a request, approval or membership of a defined community. |
http://purl.org/coar/access_right/c_16ec
|
| metadata only access | The metadata record is available, but the resource itself is neither directly accessible nor linked to an openly accessible copy. |
http://purl.org/coar/access_right/c_14cb
|
Selecting the access status
Open now
Use open access when the complete resource is available without an access request or future release date.
Open later
Use embargoed access and record the date on which the resource will become openly available.
Available on request
Use restricted access and document who may request the resource and how access is approved.
Description only
Use metadata only access when users can discover the record but cannot obtain the resource.
Access status and access conditions
| Element | Example value | Purpose |
|---|---|---|
| Access status | restricted access | Provides a controlled high-level category. |
| Access procedure | Submit a data access request | Explains how users initiate access. |
| Eligibility | Researchers affiliated with recognised institutions | Defines who may receive the resource. |
| Approving authority | Data Access Committee | Identifies the person or body that decides on access. |
| Agreement | Data Use Agreement required | Identifies contractual obligations. |
| Access environment | Secure remote analysis environment | Specifies where and how data may be used. |
| Contact point | Role-based repository address | Provides a maintained access contact. |
| Embargo end date | 2027-07-31 |
Defines when embargoed access changes to open access. |
Access status is not a licence
| Question | Access metadata answers | Licence metadata answers |
|---|---|---|
| Can I obtain the resource? | Yes | No |
| Must I submit a request? | Yes | No |
| May I redistribute it? | No | Yes |
| May I adapt or transform it? | No | Yes |
| Is commercial reuse permitted? | No | Yes |
| Must attribution be provided? | No | Yes |
Creative Commons licences and tools
| Licence or tool | Main condition | General effect |
|---|---|---|
| CC0 1.0 | No licence conditions | Waives copyright and related rights to the fullest extent permitted by law. |
| CC BY 4.0 | Attribution | Permits sharing and adaptation, including commercial reuse, with attribution. |
| CC BY-SA 4.0 | Attribution and ShareAlike | Adaptations must be shared under the same or a compatible licence. |
| CC BY-NC 4.0 | Attribution and NonCommercial | Permits sharing and adaptation only for non-commercial purposes. |
| CC BY-NC-SA 4.0 | Attribution, NonCommercial and ShareAlike | Non-commercial adaptations must use the same or a compatible licence. |
| CC BY-ND 4.0 | Attribution and NoDerivatives | Permits redistribution but not sharing adapted versions. |
| CC BY-NC-ND 4.0 | Attribution, NonCommercial and NoDerivatives | Permits non-commercial redistribution without sharing adaptations. |
Creative Commons licence elements
BY — Attribution
Reusers must provide appropriate credit and retain the licence information.
SA — ShareAlike
Shared adaptations must be distributed under the same or a compatible licence.
NC — NonCommercial
Uses primarily intended for commercial advantage or monetary compensation are not licensed.
ND — NoDerivatives
Adapted material may be created privately but cannot be shared under the licence.
CC0 and CC BY for research data
CC0
Maximises legal reuse and machine aggregation without imposing a licence-based attribution condition.
CC BY
Permits broad reuse while making attribution a binding licence condition.
Citation
Dataset citation supports scholarly credit independently of whether attribution is legally required.
Repository policy
The selected tool must be consistent with repository, funder, institutional and collaboration requirements.
Restrictions that reduce interoperability and reuse
NonCommercial: may create uncertainty about use by commercial research partners, publishers, infrastructure providers and mixed public–private projects.
NoDerivatives: may prevent distribution of converted, cleaned, translated, integrated or otherwise adapted versions.
ShareAlike: may create compatibility requirements when datasets or content from different sources are combined.
Custom licences: require individual interpretation and are harder to process automatically than established legal tools.
Software licences and SPDX
| Software licensing goal | Example SPDX identifier | General characteristic |
|---|---|---|
| Permissive reuse | MIT |
Broad permission with attribution and licence-notice requirements. |
| Permissive reuse with patent terms | Apache-2.0 |
Permissive licence including an express patent grant. |
| Strong copyleft | GPL-3.0-only |
Distributed derivative software must comply with GPL requirements. |
| Strong network copyleft | AGPL-3.0-only |
Adds source-availability obligations for specified network use. |
| Public-domain-style dedication | CC0-1.0 |
Waives copyright and related rights to the extent legally possible. |
Licensing a research data package
| Package component | Typical legal tool | Where to record it |
|---|---|---|
| Research data | CC0, CC BY or another suitable data licence | Dataset metadata and LICENSE file |
| Metadata | Often CC0 to facilitate aggregation and exchange | Repository terms and metadata record |
| Software and scripts | SPDX-identified software licence | Software repository and source files |
| Documentation | Creative Commons licence | README, documentation site or document footer |
| Trained model | Model-specific or established open licence selected after rights review | Model card and licence file |
| Third-party content | Original licence or separate permission | Attribution and third-party notices |
Rights statements
In copyright
Indicates that copyright protection is known or reasonably presumed to apply.
No copyright
Indicates that copyright does not apply, while other legal or contractual limitations may remain.
Copyright undetermined
Indicates that available information is insufficient to establish the copyright status.
Other restrictions
Communicates known non-copyright restrictions affecting reuse of the digital object.
Controlled-use permissions
General research use: the dataset may be used for research purposes within the stated governance framework.
Health or medical research: use is limited to defined health, medical or biomedical purposes.
Disease-specific research: use is limited to a stated disease or condition.
Population constraints: use may be limited by population, ancestry or geographic conditions.
Non-commercial restriction: specified secondary uses may exclude commercial purposes.
Ethics approval: access may require approval by an ethics body or Data Access Committee.
Machine-readable rights metadata
{
"accessRights": {
"label": "open access",
"uri": "http://purl.org/coar/access_right/c_abf2",
"vocabulary": "COAR Access Rights",
"vocabularyVersion": "1.1"
},
"licence": {
"name": "Creative Commons Attribution 4.0 International",
"identifier": "CC-BY-4.0",
"identifierScheme": "SPDX",
"schemeUri": "https://spdx.org/licenses/",
"uri": "https://creativecommons.org/licenses/by/4.0/"
}
}
Example of a restricted-access record
{
"accessRights": {
"label": "restricted access",
"uri": "http://purl.org/coar/access_right/c_16ec"
},
"accessConditions": {
"procedure": "Submit a data access request",
"eligibility": "Researchers from recognised research institutions",
"approvalAuthority": "Data Access Committee",
"agreementRequired": true,
"accessEnvironment": "Secure analysis environment",
"contact": "data-access@example.org"
},
"reuseConditions": {
"licence": null,
"dataUseAgreement": "https://example.org/data-use-agreement",
"additionalRestrictions": [
"No participant re-identification",
"No redistribution",
"Use only for the approved research purpose"
]
}
}
Structured policy expressions
Permission
Describes an action that a defined party is allowed to perform.
Prohibition
Describes an action that is not permitted under the policy.
Duty
Describes an action that must be completed to exercise a permission.
Constraint
Limits a policy by purpose, date, location, user category or another condition.
Authority to apply a licence
Identify the rights holder: determine whether rights belong to the researcher, employer, institution, publisher, funder or another party.
Review employment terms: works created within employment may be owned or controlled by the employer.
Review collaboration agreements: jointly created data may require approval from several partners.
Separate third-party material: exclude or clearly mark components for which reuse rights have not been obtained.
Check personal and confidential data: copyright ownership does not authorise disclosure of protected information.
Required licence metadata
| Element | Example |
|---|---|
| Licence name | Creative Commons Attribution 4.0 International |
| Licence identifier | CC-BY-4.0 |
| Licence URI |
https://creativecommons.org/licenses/by/4.0/
|
| Identifier scheme | SPDX |
| Licensed object | Dataset files and documentation |
| Rights holder | Person or organisation controlling the licensed rights |
| Attribution statement | Preferred citation or credit statement |
| Excluded material | Third-party images, software or confidential content |
Example landing-page notice
Access: Open access
Licence: Creative Commons Attribution 4.0 International
Licence URI: https://creativecommons.org/licenses/by/4.0/
Attribution: Cite the dataset using the citation provided on this page.
Scope: The licence applies to the dataset files and accompanying documentation unless a file is marked otherwise.
Exclusions: Third-party materials retain their original rights status.
How to select access and licence information
1. Assess access
Determine whether the resource can be open, embargoed, restricted or metadata only.
2. Confirm authority
Identify the rights holder and verify permissions for all package components.
3. Select legal tools
Choose appropriate data, software, documentation and model licences separately.
4. Publish structured metadata
Record controlled access values, licence identifiers, URIs and any additional conditions.
Validation of access and rights metadata
Access validation
Check that the selected category matches the actual availability of the resource.
Licence validation
Check the licence name, identifier, version and authoritative URI.
Scope validation
Check which files, documentation and third-party components are covered.
Authority validation
Confirm that the depositor is authorised to grant the stated permissions.
Common implementation errors
Using open access as the licence: availability and legal permission are confused.
Using a licence as the access status: the metadata does not explain whether the files are actually obtainable.
Using “all rights reserved” without explanation: users cannot determine whether access requests or limited reuse are possible.
Applying one licence to the entire package: software, data, documentation and third-party materials may require different licences.
Applying a CC licence to software: compatibility with established software-licensing practice is reduced.
Omitting the licence version: users cannot identify the applicable legal terms precisely.
Linking only to a licence image: machine-readable metadata lacks a stable licence identifier or URI.
Using a rights statement as a licence: a descriptive status statement is mistaken for permission granted by the rights holder.
Publishing restricted data under an open licence: licensing does not remove ethical, confidentiality or data-protection restrictions.
Inventing a local licence: users and machines must interpret unfamiliar legal terms separately.
How to use this resource
Identify availability
Select the COAR access category matching the current resource status.
Document conditions
Record embargo dates, request procedures, agreements and secure-access requirements.
Select the legal tool
Choose a recognised licence, public-domain tool or rights statement appropriate to the object.
Verify before publication
Confirm authority, scope, third-party content and machine-readable identifiers.