Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Figshare Data Repository: Features, Certification, and DMP Fit

A practical look at figshare as a generalist data repository: features, certification status (ISO 27001 vs CoreTrustSeal), and how to use it in a DMP.

Figshare is a commercial, discipline-agnostic (“generalist”) repository, operated by Digital Science, that lets researchers, institutions, publishers, and funders deposit datasets, code, figures, presentations, posters, and other research outputs and receive a citable, DataCite-minted DOI in return. It is one of the repositories most frequently named alongside Zenodo and Dryad when a data management plan (DMP) or a journal’s data-availability policy asks for “an appropriate public repository,” and it is also sold directly to universities as branded infrastructure (“Figshare for Institutions”). This guide covers what the platform actually provides, how its certification and security posture compare to what a trustworthy-repository standard requires, and how to reason about whether it is the right choice for a specific dataset rather than a default one.

What figshare actually is

Figshare was founded in 2011 by Mark Hahnel, originally as a personal tool for organizing and publishing the outputs of his PhD research; the platform has been developed and commercially backed by Digital Science since its relaunch in January 2012. It now operates as a generalist repository spanning the humanities and social sciences, life sciences, natural sciences, and engineering — the opposite of a discipline-specific repository built around one field’s metadata conventions and community norms. CASRAI’s own dictionary entry for Figshare (concept) gives the short operational definition; this guide goes further into what that means in practice for someone deciding whether to use it.

What the platform provides

  • Persistent identifiers. Every publicly shared item receives a DataCite DOI, and figshare exposes metadata via Dublin Core, DataCite’s own schema, and Schema.org markup — the combination that lets datasets get indexed in Google Dataset Search and Google Scholar.
  • Storage limits that differ by account type. A free figshare.com account currently allows individual file uploads up to 20GB and 20GB of private storage before publication. An institutional Figshare for Institutions account raises the individual file limit to 5TB, with private storage allocations set per institutional contract. Figshare+ is a separate paid tier aimed at very large datasets tied to a specific journal submission, typically bundled with Digital Science’s publisher partnerships.
  • Licensing choice. The default license on figshare.com is CC-BY, with CC0 also available; institutional and Figshare+ instances support a broader Creative Commons suite (CC-BY-SA, CC-BY-NC, and others) where a publisher or institution needs to mandate something other than the default. See CASRAI’s Creative Commons licenses for research data guide before choosing.
  • Embargo and access control. Items can be deposited privately, shared under a reviewer-only link during peer review, or embargoed until a set date — useful when a DMP or funder mandate requires eventual openness but not immediate publication at the point of deposit.
  • Usage and impact metrics. Views, downloads, citations, and Altmetric attention data are tracked per item, which is one of the reasons figshare is commonly cited in a data availability statement rather than an institutional file share.

Figshare.com vs. Figshare for Institutions vs. Figshare+

These are three different products built on the same underlying platform, and conflating them is a common source of confusion when reading a DMP requirement or a library’s repository guidance:

  • figshare.com — the free, public, individually-managed service. Anyone can create an account and deposit outputs directly; there is no institutional gatekeeping and no mediated curation review before publication.
  • Figshare for Institutions — a licensed, branded instance a university or research organization buys and operates for its own researchers, typically with institutional quota, single sign-on, administrator-configured metadata fields, and closer integration into the institution’s research information system (see the section on CRIS integration below).
  • Figshare+ — a paid, per-submission tier aimed at very large or complex datasets, usually where a publisher requires the data to be reviewable and citable alongside a specific manuscript.

Certification and trust: what figshare does and doesn’t hold

Whether a repository counts as sufficiently “trustworthy” for a funder or journal mandate usually comes down to specific, checkable certifications rather than general reputation. For figshare, the accurate picture is:

  • ISO/IEC 27001 — figshare (and its parent, Digital Science) holds this information-security-management certification, covering how data is stored, encrypted, and access-controlled. This is a real, independently audited certification of the platform itself.
  • CoreTrustSeal — figshare.com and Figshare for Institutions are not themselves CoreTrustSeal-certified as a platform. Figshare’s own documentation is explicit that it supports institutional customers who want to pursue their own CoreTrustSeal certification for their branded instance (providing template text for the infrastructure-requirement sections), but the core service is not a certified trusted digital repository the way, for example, a discipline-specific archive whose whole mission is long-term preservation might be. This distinction matters if a grant condition or a journal specifically requires deposit in a CoreTrustSeal-certified repository — check the specific instance, not the figshare brand generally.
  • COPE alignment. figshare states it operates in line with Committee on Publication Ethics (COPE) principles of transparency and best practice, relevant mainly to how it handles retraction/correction requests on deposited items.

Does figshare meet NIH/OSTP’s “Desirable Characteristics of Data Repositories”?

In May 2022, the White House Office of Science and Technology Policy’s National Science and Technology Council published Desirable Characteristics of Data Repositories for Federally Funded Research — a framework of what a repository should provide (unique persistent identifiers, sufficient metadata, curation and quality assurance, free/open access, broad and measured reuse, clear provenance and versioning, security, and long-term sustainability) to reduce ambiguity for researchers complying with federal data-sharing mandates. The NIH’s 2023 Data Management and Sharing Policy explicitly points investigators toward repositories that “exemplify” these characteristics when a discipline-specific or NIH-designated repository isn’t available.

Measured against that framework, figshare’s own published self-assessment (consistent with what’s independently verifiable) is a mixed but mostly strong picture: it fully covers persistent identifiers (DataCite DOIs), rich machine-readable metadata, free public access, version tracking, and security (ISO 27001). It is weaker, by its own account, on curation — figshare.com has no pre-publication peer or editorial review of deposited data (Figshare+ adds an expert-review step), and on sensitive data, where the platform prohibits identifiable human-subjects data outright rather than providing the access-tiering and data-use-agreement infrastructure that a dedicated sensitive-data repository or a biorepository is built for. In other words: figshare is a reasonable default for open, non-sensitive, non-discipline-specific outputs, and a poor fit the moment a dataset needs pre-publication curation or contains anything that requires controlled access.

When a generalist repository like figshare isn’t the right call

Figshare’s breadth is also its limit. A funder, journal, or field society may specifically expect deposit in a named discipline repository (GenBank for sequence data, ICPSR for social-science survey data, PDB for macromolecular structures) precisely because those repositories apply subject-specific metadata schemas, quality checks, and long-term stewardship commitments that a generalist platform doesn’t attempt. CASRAI’s guide to choosing an open data repository walks through that decision in more detail, including how to check re3data.org and FAIRsharing.org for the field-appropriate option before defaulting to a generalist. As a rule of thumb: check for a relevant discipline-specific repository or domain repository first; use a generalist repository like figshare, Zenodo, or Dryad when none exists, when the output type doesn’t fit any domain repository’s scope (code, posters, supplementary figures), or when institutional policy specifically directs deposit there.

Using figshare in a data management plan

If figshare is named as the intended repository in a data management plan, be specific about which product (public figshare.com vs. an institutional instance) and address the points a reviewer will actually check:

  • Persistent identifier commitment — state that deposited outputs will receive a DataCite DOI at the point of publication, not merely “a figshare link.”
  • License — name the license explicitly (CC-BY is the figshare.com default; state if a different license applies) rather than leaving it to the platform default by omission.
  • Embargo period, if data can’t be open immediately — figshare supports this natively; state the planned duration and trigger for release.
  • Metadata standard — figshare exposes DataCite and Dublin Core metadata by default; if the funder or field expects a richer schema, note that this is a limitation and describe any supplementary documentation planned. See CASRAI’s guide to choosing a metadata schema.
  • Institutional CRIS integration — Figshare for Institutions instances typically expose an API and OAI-PMH feed that a research information system (CRIS) can harvest to link a deposited dataset back to the researcher’s ORCID iD and the funding award record, which is what actually makes a dataset “count” in institutional reporting rather than sitting as an orphaned link.

For citing a dataset already deposited on figshare — in a manuscript, not a DMP — see CASRAI’s how to cite a dataset guide and the FAIR checklist for what else a well-formed deposit needs beyond just a DOI.

Frequently asked questions

Is figshare free to use?

Yes, for individual researchers depositing under a personal figshare.com account: 20GB of private storage and unlimited public storage at no cost. Figshare for Institutions is a paid product an institution licenses on behalf of its researchers, and Figshare+ is a paid per-submission tier for large datasets tied to journal publication.

Does figshare curate or peer-review deposited data?

Not on the public figshare.com service — there is no mediated pre-publication review of what gets deposited, which is one of the “partially met” points against the NIH/OSTP desirable-characteristics framework discussed above. Figshare+ adds an expert-review step for the datasets that go through it.

Is figshare CoreTrustSeal certified?

The platform itself is not. Figshare holds ISO/IEC 27001 information-security certification and provides documentation support to help individual institutional customers pursue CoreTrustSeal certification for their own branded instance, but “figshare” as a brand is not a certified trusted digital repository. Check the specific instance if certification is a hard requirement.

How is figshare different from Zenodo and Dryad?

All three are generalist repositories that mint DataCite DOIs and accept broad, non-discipline-specific outputs. Zenodo is operated by CERN (developed under OpenAIRE), is free for all users including institutions, and applies a per-record size limit on free preservation. Dryad is a non-profit repository, run in partnership with the California Digital Library, that specifically curates datasets linked to a published paper and applies a review step before publication; its preservation copy lives in Merritt, a CoreTrustSeal-certified digital repository. Figshare is commercially operated by Digital Science, sells a branded institutional product, and does not curate deposits on its free public tier. None of the three is a strict substitute for a relevant discipline-specific repository when one exists.

Can I deposit sensitive or human-subjects data on figshare?

Figshare’s policies prohibit depositing identifiable sensitive information; de-identified human-research data may be accepted where properly documented and consented, but the platform doesn’t provide the tiered, controlled-access infrastructure (data-use agreements, approval workflows) that a dedicated sensitive-data repository is built around. Check institutional policy and IRB/REC guidance before using a generalist repository for anything derived from human subjects.

Does figshare count as an “established repository” for NIH’s Data Management and Sharing Policy?

NIH’s policy prioritizes NIH-designated and discipline-specific repositories first, and points investigators to the NSTC’s Desirable Characteristics of Data Repositories framework for evaluating a generalist alternative when no discipline-specific option exists. Figshare meets most of those characteristics (persistent identifiers, metadata, free access, security) but is weaker on curation, which is worth naming explicitly in a DMP rather than assuming acceptance.

Related CASRAI resources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →