The conversation about digital asset libraries usually gets sold on productivity: the team finds photos faster, stops requesting them by email, and nobody works off an outdated version of the logo again. All of that is true, and no institution changes platforms for that reason alone.
What has been driving decisions over the last two years comes from somewhere else. At universities and healthcare institutions across the region, the question that unlocks budget comes from legal, and it sounds roughly like this: that photo of the student on the homepage, until when are we allowed to use it?
At most organizations, nobody can answer that. And the answer, when it exists, lives in a scanned paper form someone saved in a shared folder named after the event.
Why the question got urgent
The personal data framework across the region has been in force for years, but the level of enforcement has changed.
Comparable frameworks apply in markets esinergia's enterprise clients operate in and sell into: GDPR in the European Union and CCPA in the United States both require that personal data processing rest on a clear, time-bound basis, and both give the data subject the right to know how their information is used and for how long. The pattern that matters for an image library is the same one driving Latin American frameworks: data has to stay accurate, current, and relevant to the purpose it was collected for.
That last part is what turns a photo archive into a governance problem. If a consent was given for a specific admissions campaign, using that image three years later, in a different piece, stops being covered by the original consent. The photo is still on the server and still perfectly usable from a technical standpoint. What expired is the permission.
For a healthcare institution the problem scales, because an image of a patient in a clinical context falls into the sensitive data category, with stricter requirements. And for a university with twenty years of accumulated photo archive, inventorying what can keep being published and what cannot is work nobody has ever done.
The four questions your library should answer
This is the actionable part, and it works as a quick diagnostic without buying anything. Take the image currently on your homepage and try to answer these four questions with the information you already have.
Who is in this image, and what exactly did they authorize? The question sounds obvious and almost never has an answer stored next to the file. The consent usually exists somewhere, signed, but disconnected from the asset it covers.
Until when is that authorization valid? This is where most inventories fall apart. An authorization with no recorded expiration date is, in practice, an authorization whose validity nobody can prove when asked.
On which sites and in which pieces is this image published today? At an institution with several sites, the same photo tends to live on the main portal, on the school's microsite, and in two campaign pieces. If it has to come down tomorrow, someone has to know where it all is.
Who gets notified when the authorization expires? An expiration that reaches nobody is an expiration that gets discovered when the complaint arrives.
If your organization answers all four with documentation on hand, your library's order is better than most enterprise institutions in the region, and this topic can wait. If it falls apart on the second one, you already have the argument the budget committee needed, and it is worth bringing it in those terms rather than in terms of the creative team's productivity.
What changes when the library lives connected to the platform
The technical answer to the four questions has a generic name, digital asset management, and a meaningful difference depending on where it is installed.
A library that lives apart from the site answers the first two questions. It lets you attach metadata to the asset, store the authorization next to the image, and record an expiration. Questions three and four slip through, because the system does not know where each asset is published. Someone has to maintain that relationship by hand, and that is exactly the task that stops happening after six months.
A library integrated into the platform layer answers all four, because the asset published on the portal is a reference to the original and the system keeps the link. That link is what lets you ask which pages an image is on, and it is what makes removing it from the inventory take effect on the sites where it is running. At an institution with several portals on the same platform, that property is the difference between a procedure and a hunt.
Acquia DAM is the option that shows up most often in this scenario within the Drupal ecosystem, for its native integration with the platform and because it lists rights management and version control among its capabilities, along with compliance certifications such as SOC 2 Type II. It is worth verifying with the vendor how it implements rights expiration specifically, because the level of notification automation varies, and that is exactly question four.
It is also worth saying this is an architecture decision with more than one valid path. Drupal solves a good part of media management with core capabilities, and for an institution with a single portal and a modest archive, that route can be enough without adding another piece to the stack. Dropsolid and other ecosystem providers pose their own compositions. The question that orders the decision is how many portals share the same assets, and how large the uninventoried historical archive is.
The multi-portal case
This scenario is worth stopping on, because it is the most common one among enterprise institutions in the region, and the one that is hardest to solve by hand.
A university running a main portal, school microsites, and graduate program sites tends to have the same assets loaded independently in each one. The same campus photo lives as a separate file in five places, with five upload dates and no relationship between them. When an image needs to come down, the team has to search site by site, and the only guarantee of finding it everywhere is whoever published it remembering.
The same applies to a health network with several service lines, where a large share of the photographic material was produced in clinical contexts, so consent carries stricter conditions and the cost of a mistake is higher.
In these cases consolidation changes in nature. It stops being a convenience upgrade for the creative team and becomes the condition for answering question three at all, which has no possible answer without a shared reference across sites. It is also where the effort math tips in your favor: the inventory work happens once and serves every portal, instead of repeating in each one.
What to check before deciding
Three criteria that, in our experience, separate an implementation that holds up from one that gets abandoned in the first year.
The expiration field has to be required at upload, not optional. If the system lets you upload an asset with that date left blank, the archive fills back up with undated assets within months. This gets set in the platform's configuration, within reach of the team that administers it, and it is the adjustment that carries the most weight on the outcome.
The initial load needs a cutoff criterion. Migrating twenty years of photo archive with complete metadata is a project that never ends. The path that works starts with the assets published today, which are usually a small fraction of the total, and leaves the historical archive in a repository marked as not publishable until someone reviews it.
The process owner has to be named before the purchase. Asset governance holds up when there is a named responsible party, and that tends to be the factor that decides the outcome more than the tool's capabilities. If marketing uploads, communications publishes, and legal audits, someone has to decide which of the three teams owns keeping the expiration field filled in, and write it into the procedure.
The last one is the one we have seen decide the outcome the most. Across the more than 40 enterprise portals we support in production across Latin America, several multisite and some with more than eight years of continuous operation on the same platform, the pattern repeats with real consistency: libraries that stay organized two years in are the ones that had a named owner from day one.
What comes next
The direction of regulatory change across markets points toward more traceability requirements, not less. Being able to prove an image's rights are current is heading toward the same status accessibility compliance already has for an institutional portal.
By 2028, an institution's ability to demonstrate the validity of every published image's rights is going to be part of the normal state of operating a portal. Organizations that run the inventory while the archive is still manageable are going to reach that point with a procedure in place. Those that leave it for when the first formal request lands are going to do the same work with a deadline attached.
The four-question exercise takes under an hour and can run this week on your portal's homepage, without buying anything and without convening anyone. It is the most accessible starting point for knowing where you stand.
For the general product overview before getting into the governance angle, see Transform Your Digital Content Management with Acquia DAM. And if your organization's conversation is about giving the marketing team autonomy over the platform, that ground is covered in Acquia Site Studio: How It Can Help Marketing Teams.