nanalLabs Blog

← Blog

Backing up an electronic research notebook — what actually needs to survive to prove anything

2026-09-19research notebookelectronic research notebookbackupregulation

Search "research notebook backup" and most of what comes up is generic advice about saving OneNote or Samsung Notes to the cloud. What's harder to find is what Korea's national R&D research notebook guidelines actually require of electronic notebooks around backup, and what a researcher needs to secure in advance if the electronic-notebook vendor they use shuts down. This post covers both: the guideline text, and vendor risk.

The guidelines ask for less than "backup" suggests

The technical requirements the guidelines place on electronic research notebooks are signature authentication, automatic recording of the entry timestamp, and a permanent modification marker when something is edited. All three aim at the same question — can you tell who wrote what, when, and whether it was touched afterward? That's a requirement to leave tamper evidence, not a requirement to replicate data so it doesn't get lost. The two problems sit next to each other, but they aren't the same problem.

For ordinary (non-security) projects, the guidelines themselves don't specify a backup interval or method. Instead, they hand that responsibility to the head of the research institution, who is expected to "use these guidelines to establish and operate its own rules for preparing, storing, and managing research notebooks." In other words, the backup interval is set by the institution's own internal rules, not by the national guideline. That's why universities and research institutes each maintain their own research-notebook management regulations. The guideline text itself is available from Korea's National Law Information Center.

It's different when a project involves a designated national core technology or an institution classifies it as a security project. There, the Common Security Management Guidelines for National R&D Projects explicitly require encryption, storage inside a protected zone, and a separate backup system — covered in more detail in how a security project notebook differs. This is exactly where ordinary-project researchers tend to assume "we have no backup obligation at all." No mandatory clause isn't the same as no consequences for treating the notebook carelessly.

A paper notebook and an electronic one mean something different by "backup"

For a paper research notebook, the original is the only copy that exists. Backup as a concept doesn't apply — what matters is preventing damage or loss in the first place, which is covered separately in losing or damaging a research notebook. An electronic notebook is the opposite: because it's a file, copying it is genuinely possible, but the risk that it gets silently overwritten without leaving a trace grows right alongside that convenience. "A backup exists" and "you can prove that backup is identical to the original" are two different claims.

Storage locationLoss riskLeak riskIntegrity proof
Local PC / laptopHigh (single point of failure)MediumHard without extra measures
Institution's internal server (department-managed system)LowLow (access controls)Relies on system logs
Commercial ELN serviceLow (while operating)Depends on vendor policyCan disappear along with the service
Personal cloud (personal account)MediumHigh (if the account is compromised)Edit history usually isn't kept

The column worth focusing on is "integrity proof." Even with a well-chosen storage location, if you can't separately prove the file inside hasn't changed since a given point in time, the backup can't back up a claim like "this was the content back then" in a dispute.

If your electronic notebook vendor disappears, what happens to your records

Unlike the government-run research notebook portal, a commercial ELN (Electronic Lab Notebook) vendor can take your access to your own data down with it when it shuts down — the same structure as an e-book platform closing and taking the books you bought with it. Three things are worth checking in practice.

  1. The contract's data-return and export clause — does it specify

what format you get the original files back in, and within what deadline, if the contract ends or the service is discontinued?

  1. Your own periodic backups — are you using the service's export

feature (PDF, original files) to download your records regularly and keep them somewhere separate, such as an institutional server or external storage? A record that exists only inside the service can vanish along with it.

  1. Proof the exported file is unchanged — to later claim an exported

file is exactly what it was at export time, it helps to record a hash value the moment you download it, or attach a separate proof step such as a trusted timestamp (RFC 3161). Moving where something is stored and proving its contents haven't changed since are separate tasks.

What to check right now

specify a backup interval and method for electronic notebooks?

zone storage, and a separate backup system actually in place?

contract include a data-return and export clause?

feature and storing them somewhere separate?

since export (such as a recorded hash value)?

The interval and method for backing up an electronic research notebook are set by your institution's own internal rules. Before applying the general points in this post, check them against your institution's research-notebook management regulations and the National R&D Project Research Notebook Guidelines text itself.

nanalStamp — automatically seals your Obsidian notes the moment they settle and anchors the proof into Bitcoin, so anyone can verify your records are tamper-free. About the service · 75 free record kits