Home · Blog · Workflow & Gear

Photo archiving guide: a ten year plan

Osmel Contreras · Founder, Kepla · August 12, 2026 · 9 min read
A reception table
Workflow & Gear

Most photographers have a backup routine and no archive at all. The two are not the same job. A backup is there for the drive that dies on Tuesday. An archive is there for the couple who email you in 2036 asking for a full resolution file from a wedding you barely remember. This is how to build the second one: what goes in it, what format it lives in, where cold copies sit, and how you prove ten years from now that it still opens.

01 · BACKUP VS ARCHIVE

An archive is not a backup

A backup answers a question about this week. A card corrupts on Sunday, a drive dies on Tuesday, you overwrite the wrong folder on Thursday. You reach for the copy, you put it back, you carry on. A backup is a living system. It changes every day, and the whole point is that it mirrors what you have right now.

An archive answers a question nobody asks you until years later. A couple wants a print for a tenth anniversary. A venue wants the full resolution file for a rebrand. A client's house floods and the only surviving copy of their wedding day is the one in your studio. None of that is about Tuesday. It is about whether a set of files you stopped thinking about in 2026 still opens on a computer nobody has designed yet.

Those two jobs pull in opposite directions. A backup wants to be automatic, connected, and constantly in sync. An archive wants to be finished: written once, checked, disconnected, and left alone. That difference matters more than any product choice, because if your only long term copy lives inside the folder your sync software watches, then anything that damages the live copy has a clear path to the copy you were counting on. That includes you, tired, at 1am, tidying up.

This guide assumes the weekly side is already handled. If it is not, start with our backup workflow for photographers and come back. Everything below picks up where that stops.

02 · WHAT GOES IN

Decide what goes in the archive before you decide where it lives

People buy the drive first and then argue about the policy forever. Do it the other way round. A wedding day typically produces 2,000 to 4,000 RAW frames and around 400 to 800 of them get edited and delivered. That gap is the entire archiving question. Everything else is shopping.

There are three tiers worth naming, and they do not need the same treatment:

Write your answer down as one sentence per tier, with a retention period attached, and put it in the same document as your delivery standards. If you are unsure what a normal gallery size looks like before you set the policy, our piece on how many wedding photos to deliver has the ranges. A policy you can say out loud beats a hard drive you keep meaning to sort.

03 · FORMATS

Formats: pick what will still open in 2036

An archive of proprietary RAW files is a quiet bet that your camera manufacturer will still care about a discontinued body in fifteen years. Sometimes that bet pays. Sometimes a format from a company that left the camera business becomes a hunt for old software on a machine that can still run it.

The mainstream hedge is DNG. Adobe publishes the DNG specification publicly, grants a royalty free right to build software that reads and writes it, and offers a free converter. Adobe's own framing is that an open specification helps archival confidence, and it is one of the few claims in this space you can check yourself by reading the license. That does not make DNG compulsory. It makes it the format with the fewest single points of failure.

A workable rule for each archived shoot:

That last point is the one that catches people. A catalog is software, not an archive. If the only record of your edits is a database file tied to one application version, you have made your work dependent on that application still installing a decade from now. Metadata written into the files themselves travels much better, and our guide to photo metadata covers what is worth embedding.

04 · COLD STORAGE

Cold storage, in plain terms

Cold storage just means a copy that is not plugged in, not syncing, and not waiting for a command from your computer. Its resilience comes mostly from being disconnected. The old rule still holds: three copies of anything you care about, on two different kinds of media, with one of them somewhere else entirely.

MediumGood atWatch out for
External hard drives, kept offlineCheap per terabyte, simple, works everywhere, no account to lapseDrives fail whether or not they are spinning. Never keep only one, and never keep both in the same building
SSDsFast to write, physically tough, good for a copy that travelsNot designed to sit unpowered for years. Fine as a working or transit copy, poor as the ten year copy
Cloud archive tiersOffsite by default, survives fire, flood and theft at your addressRestores can be slow and are often charged. Read the retrieval terms before you need them, not after
LTO tapeBuilt for long shelf life, the format film and broadcast archives actually useThe drive costs far more than the tapes, and you must keep a working drive and a way to read that generation
Archival optical discsWrite once, so nothing can quietly change or encrypt them laterSmall capacity per disc, and you need a reader still attached to a computer in ten years

Prices for all of this move constantly, so work them out for your own volume rather than trusting a number in an article. Measure one of your own RAW files, multiply by your unpicked frames per shoot, multiply by shoots per year, and you have your annual growth. Then compare that against drives or against your provider's next tier, and against what one shoot earns. Our breakdown of cloud storage for photographers goes through the options in detail.

The mistake worth avoiding

A second copy on a second drive sitting next to the first one is not two copies. It is one copy with a spare enclosure. Fire, theft, flood, a bad power supply and a burst pipe do not care that you bought two drives.

05 · STRUCTURE

Make each shoot explain itself

The person who has to understand your archive is you, ten years older, with no memory of the job and no access to the software you were using at the time. Possibly it is not even you. An archive that only makes sense to someone with the catalog open is an archive with a dependency.

Two habits fix almost all of it. First, folder and file names that carry meaning on their own: date first so things sort chronologically, then client, then shoot type. Anything you can read from the filename is something you never have to open an application to find. We lay out a full scheme in our photo file naming system.

Second, a plain text file inside each archived shoot folder. Not a document, not a spreadsheet, just a text file that any computer since 1980 can open. Five lines is enough:

That fourth line does more work than it looks like. A count and a size are how you notice later that something is missing, which is the failure mode nobody plans for: not a drive dying loudly, but a folder that quietly came back short from a copy three years ago.

06 · CHECKING IT READS

The part everyone skips: proving it still reads

An archive nobody has opened is not an archive, it is a hope. Files decay in undramatic ways. A copy interrupted halfway through, a drive with a handful of bad sectors, a cloud sync that hit a permissions error at 2am and gave up on one folder. None of it announces itself. You find out on the day someone asks for the files, which is the worst possible day to find out.

Two practices cover it, and both are boring by design.

Checksums. When you seal a shoot, generate a manifest of file hashes and store it in the folder with the images. Most backup and ingest tools will do this for you, and both macOS and Windows can produce hashes from the command line without installing anything. A year later you re-run the check and compare. Identical means the bits are intact. A mismatch means you replace that file from another copy today, while another copy still exists.

Restore drills. Once or twice a year, pick a random shoot from a random archive medium and actually restore it. Open a RAW file. Open a delivered JPEG. Read the text file. Time how long the whole thing took. You are testing three things at once: that the media reads, that the software still opens the format, and that you still remember how your own system works. If a drill fails, you have found the problem while it is a chore rather than an emergency. If it fails badly enough that files are gone, our guide to recovering deleted photos covers what to do next and, more importantly, what not to do first.

07 · TEN YEAR PLAN

A ten year plan you can actually keep

Nothing here survives a decade because the media is good. It survives because you kept copying it forward onto whatever is current before the old thing became unreadable. Migration is the whole strategy. Everything else is housekeeping.

How oftenWhat you do
Every shootTwo copies before the cards are reused, counts compared, nothing formatted until both copies verify
MonthlySeal finished shoots: write the text file, generate checksums, copy to the offline set
Twice a yearRestore drill on a random shoot. Take the offsite copy out and confirm it mounts
YearlyVerify checksums across the archive, replace any file that fails, review whether your formats still open cleanly in current software
Every 3 to 5 yearsCopy the entire archive forward onto current media, verify, then retire the old set rather than trusting it
Every 10 yearsAsk the honest questions: is this format still widely read, does this medium still have working readers, is this policy still worth what it costs

One more thing shapes how big all of this gets: what your selection process does to the frames that did not make the gallery. If your workflow physically discards them, your archive is smaller and permanently missing the frames a client might ask for years later. If it only marks which photos were picked and leaves every original in place, your archive is complete and the decision stays reversible. That is the approach we are building Kepla around: it picks your best shots and hands you a shortlist, and it never deletes, moves or renames a single file. The picking app for iPhone, iPad and Mac is still in development. The booking page is live and free today while we build the rest.

08 · COMMON QUESTIONS

FAQ

What is the difference between a photo backup and a photo archive?

A backup mirrors what you have right now and changes daily, so it can restore Tuesday's mistake. An archive is a finished, disconnected copy of completed work, made once and kept for years. Backups protect against failure this week. Archives protect against a request in a decade. Most photographers have the first and assume it covers the second, which it does not.

Should I archive RAW files or convert everything to DNG?

You do not have to choose. Keep the camera's own RAW files, and if you want insurance against a proprietary format losing support, keep a DNG version alongside rather than instead. Adobe publishes the DNG specification publicly and licenses it royalty free, which is why it is the common hedge. Always store edit settings as sidecar files, not only inside a catalog.

How long should photographers keep client photos?

There is no legal standard, so pick a period and put it in writing. Many photographers keep delivered galleries indefinitely because they are small, keep picked originals for several years, and set a shorter window for everything else. What matters most is that clients are told the policy up front, so nobody assumes you are holding their files forever by default.

How do I know my archive files are not corrupted?

Generate checksums when you seal a shoot, store the manifest beside the images, and re-run the check once a year. A mismatch tells you to replace that file from another copy while another copy still exists. Pair that with a restore drill twice a year: pick a random archived shoot and actually open the files.

Is cloud storage enough on its own for archiving?

It is a strong offsite copy and a weak only copy. Accounts lapse, payment cards expire, terms change, and a large restore can be slow and expensive at exactly the moment you are in a hurry. Treat cloud as one of your copies, keep at least one offline copy on physically separate media, and read the retrieval terms before you rely on them.

How often should I replace archive hard drives?

Do not think in terms of drive lifespan, think in terms of migration. Copy the whole archive forward onto current media every three to five years, verify it after the copy, then retire the old set instead of leaving it as a silent third copy you trust without checking. Drives fail unpredictably, including ones that have been sitting unplugged.

FOUNDING COHORT · 100 SEATS

Never sort photos at 1 AM again.

Kepla for Mac clears the obvious misses from a card, names the reason on every frame it sets aside, and leaves the choosing to you. Nothing is ever deleted, moved or renamed. Free through the private preview · the first hundred photographers keep it at $99 a year.

Request Founding Access
KEEP READING