Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Can Researchers Store Participant Data on Personal Computers or Devices?

Storing participant data on a personal computer or device is not automatically acceptable simply because the researcher owns and controls it. Whether it is permitted depends on institutional policy, the sensitivity of the data, and the safeguards applied to the device.

313
Participant Data on Personal Devices Guide 313 of 398
01 · The Question

Can You Download Participant Data to Your Own Laptop?

You collect research data using an approved institutional system, then download the spreadsheet to your laptop so you can analyze it at home. Perhaps the computer is personally owned. Perhaps it is the same laptop you use for teaching, browsing, personal email, family photographs, and everything else.

Is that acceptable because you are the researcher and the computer never leaves your possession?

Not necessarily. A personal device can introduce risks involving theft, loss, malware, unauthorized household access, insecure backups, synchronization to personal cloud accounts, outdated software, and inadequate encryption. Whether participant data may be stored or accessed on such a device depends on the applicable institutional, ethical, contractual, security, and legal requirements.

02 · The Short Answer

Personal Devices May Be Permitted, but Only Under Appropriate Controls

In Brief

Researchers should store participant data on personal computers, laptops, phones, or tablets only when their institution permits it and the device satisfies the security requirements appropriate to the sensitivity of the data.

For some projects, institutional policy may prohibit local storage entirely or require an institution-managed device. Where personal devices are permitted, encryption, access control, updates, malware protection, secure backup, appropriate accounts, and procedures for loss or theft may be necessary.

03 · What You Need to Know

Owning the Computer Does Not Make It an Approved Research Environment

Personal ownership and institutional authorization are different questions

A researcher may have exclusive physical possession of a laptop while the institution remains responsible for personal data processed through the research. The fact that the computer belongs to you therefore does not establish that you are free to store institutional research data on it.

Organizations may impose bring-your-own-device, or BYOD, policies specifying whether personally owned devices may access or store institutional information and what safeguards are required.

The Philippine National Privacy Commission has advised that personal devices may be used where provision of organization-owned ICT resources is impractical, but such use should be governed by the organization's BYOD policy. Its work-from-home guidance also recommends using organization-authorized software and avoiding external services and software for organizational files unless authorized.

The first question is therefore not "Is my laptop secure?" It is "Am I authorized to use this laptop for these data?"

Accessing data and storing a local copy are not necessarily the same thing

A researcher might access an institutional virtual desktop or secure web application from a personal computer without downloading participant data to that computer. In another arrangement, opening a synchronized folder may automatically create local copies.

These situations create different risks. Remote access can sometimes keep data within institutionally controlled infrastructure, while downloading or synchronizing files creates another copy that must be protected, managed, retained, and eventually deleted appropriately.

Before accessing research data remotely, determine whether the system creates temporary files, offline copies, browser downloads, synchronized folders, cached information, or backups on the local device.

The sensitivity of the data changes what protection is appropriate

A public dataset presents a different risk from identifiable interview recordings, medical information, detailed psychological assessments, financial information, or a file linking participant names to study IDs.

The Philippine Data Privacy Act requires reasonable and appropriate organizational, physical, and technical measures to protect personal information against accidental or unlawful destruction, alteration, disclosure, and other unlawful processing. The appropriate level of security takes account of factors including the nature of the information and risks presented by the processing.

This risk-based approach means there is no sensible universal statement that every personal device is safe or every personal device is unsafe. The safeguards need to fit the information and the processing.

Encryption matters particularly for portable devices

Laptops, smartphones, and tablets can be lost or stolen. Encryption can substantially reduce the likelihood that possession of the physical device immediately gives someone access to the personal data stored on it.

The National Privacy Commission's data-security guidance includes encryption of personal information stored on laptops and other portable devices among relevant safeguards. For government agencies, NPC Circular 16-01 specifically requires full-disk encryption when laptops are used to store personal data.

UK Information Commissioner's Office guidance likewise recommends storage encryption for devices including PCs, laptops, smartphones, tablets, and removable media.

Encryption does not eliminate every risk. If a laptop is unlocked when stolen, malware captures credentials, files are synchronized elsewhere, or an authorized user sends the data to the wrong person, encryption at rest may offer little protection against that particular event.

A login password is not the same as full-disk encryption

A computer password controls access through the normal login process. Full-disk encryption protects information stored on the disk by making it unreadable without the necessary authentication or cryptographic key.

Researchers should not assume that setting a Windows or macOS password automatically establishes that all locally stored research data are encrypted in the manner required by institutional policy. Verify the actual device configuration.

Updates and malware protection matter

A personal computer used for research can be exposed to malicious websites, email attachments, unauthorized software, browser extensions, outdated applications, and other threats unrelated to the research itself.

NPC security guidance identifies current operating-system security patches, firewall protection, malware protection, and regularly updated security software among measures relevant to systems containing personal information.

A device that no longer receives security updates may therefore be inappropriate for sensitive participant data even if it still runs your statistical software perfectly well. Statistical significance, alas, does not patch an operating system.

Other people should not inherit your research access

A personally owned computer may be shared with family members, colleagues, students, or other users. Participant information should not become accessible simply because another person knows the device password or uses the same account.

Appropriate arrangements may include individual user accounts, strong authentication, automatic screen locking, restricted administrator privileges, and access controls appropriate to the project and institutional requirements.

The broader principle is that access should be limited to people who actually require the information. That remains true even when everyone with physical access to the computer is someone you trust personally.

Automatic synchronization can create copies you did not intend

A researcher downloads a participant spreadsheet to the desktop. The desktop automatically synchronizes with a personal cloud service. The laptop also backs up to another consumer service. Suddenly the dataset exists in several places even though the researcher believes there is only one local copy.

Before storing participant data locally, check operating-system backup settings, cloud synchronization, photo or document backup applications, browser download locations, messaging applications, and other services that may automatically copy files.

If cloud storage is involved, separately verify whether that cloud environment is appropriate for the research data.

Local copies create retention and deletion responsibilities

Suppose the master research dataset is correctly deleted or anonymized at the end of the retention period, but a researcher's laptop still contains an old export in the Downloads folder. The project has not necessarily eliminated the identifiable copy.

Research teams should know where local copies are permitted, how they are tracked, when they should be removed, and whether copies may remain in backups or synchronized folders.

This is one reason data minimization applies to copies as well as variables. The fact that another copy can be created does not mean another copy is needed.

Phones and tablets require the same basic analysis

Researchers increasingly use smartphones and tablets for fieldwork, recording, photography, survey collection, messaging, and document access. These devices can contain substantial quantities of participant information.

Appropriate safeguards may include device encryption, strong authentication, remote-lock or remote-wipe capability where institutionally supported, timely software updates, controlled applications, secure transfer to approved storage, and deletion from the device when local retention is no longer necessary.

Researchers should also consider what happens to files created by camera, audio, messaging, or survey applications. A recording may be automatically uploaded to a personal account unless synchronization settings have been configured appropriately.

Government research in the Philippines may face specific off-site requirements

The Philippine Data Privacy Act contains particular requirements for sensitive personal information maintained by government agencies. Section 23 addresses off-site access and transportation of such information and requires approval under specified circumstances, along with encryption requirements.

NPC Circular 16-01 provides additional security requirements for government agencies, including state colleges and universities. Researchers working within those organizations should therefore check the rules applicable to their institution rather than assuming that general BYOD practice is sufficient.

Check Before Downloading

If the data are sensitive, regulated, contractually restricted, or institutionally classified, do not download them to a personal device merely because remote work is convenient. Verify the permitted storage and access arrangement first.

04 · A Practical Example

Working From Home With Participant Interview Data

Hypothetical Example

A researcher wants to analyze transcripts on a home laptop

A university researcher has pseudonymized interview transcripts stored in an approved institutional research environment. The researcher wants to download them to a personally owned laptop because the qualitative analysis software is installed there.

Check authorization The researcher first checks whether institutional policy permits the relevant class of research data to be stored on personally owned devices.
Check the device Where BYOD use is permitted, the researcher verifies required encryption, supported operating-system updates, malware protection, authentication, screen locking, and other institutional security controls.
Check synchronization The researcher confirms that the folder will not automatically upload the transcripts to an unapproved personal cloud account or backup service.
Minimize the copy Only the pseudonymized transcripts required for analysis are downloaded. The participant identity key remains in the approved institutional environment.
Remove the copy When local processing is no longer required, the researcher follows institutional procedures for deleting the authorized local copy rather than leaving it indefinitely on the laptop.

If the institution instead prohibits local storage for that data classification, installing stronger antivirus software does not override the prohibition. The researcher needs an approved alternative, such as remote access to institutional infrastructure or an institution-managed device.

05 · What Researchers Often Get Wrong

Common Misconceptions About Personal Devices and Research Data

Misconception

If I Am the Only Person Who Uses My Laptop, Is It Automatically Safe?

No. Unauthorized access can result from theft, malware, account compromise, insecure synchronization, outdated software, or other technical and physical risks even when no one else normally uses the computer.

Misconception

Does a Login Password Mean My Research Files Are Encrypted?

Not necessarily. Login authentication and storage encryption are different controls. Verify whether appropriate disk or file encryption is actually enabled and meets institutional requirements.

Misconception

If the Data Are Pseudonymized, Can I Store Them Anywhere?

No. Pseudonymized data can remain personal data when individuals can be reidentified using additional information. Pseudonymization can reduce risk, but it does not automatically remove security or governance requirements.

Misconception

If Ethics Approved the Study, Did It Approve My Personal Laptop?

Not necessarily. Ethics approval does not override institutional information-security, privacy, data-management, contractual, or BYOD requirements. Use the storage and device arrangements actually authorized for the project.

Misconception

Can I Keep an Extra Copy at Home as a Backup?

Only if that backup arrangement is authorized and appropriately protected. Unmanaged duplicate copies can make access, retention, breach response, and deletion harder rather than making the project safer.

06 · What This Means for You

Treat the Device as Part of the Research Data Environment

When participant information reaches a laptop, phone, tablet, or desktop, that device becomes part of the project's security environment. Its configuration therefore matters just as much as the research repository from which the file came.

A simple decision framework

If institutional policy prohibits local or personal-device storage
Keep the data in the approved environment and use an authorized access method.
If personal devices are permitted
Meet the required BYOD, encryption, authentication, software, update, access, backup, and incident-response controls.
If you only need remote access
Consider whether an approved remote or virtual environment can avoid creating a local participant-data copy.
If only part of the dataset is required
Use the minimum necessary information and keep identifiers or other unnecessary sensitive fields out of the local copy.
If the device is lost, stolen, compromised, or accessed by an unauthorized person
Follow the institutional incident procedure immediately rather than waiting to determine independently whether harm occurred.

The same principle applies to researchers who move data onto portable storage. A USB drive introduces a different set of risks, so removable media should be assessed separately.

07 · A Quick Checklist

Before Putting Participant Data on a Personal Device

Verify:
Your institution permits the relevant research data to be accessed or stored on personally owned devices.
The device meets required encryption and authentication standards.
The operating system and authorized security software remain supported and appropriately updated.
Other users of the device cannot access the participant data.
Files will not automatically synchronize to an unapproved personal cloud, backup, or application.
Only the personal data actually required for the local task are copied to the device.
You know how and when authorized local copies must be deleted or returned to institutional storage.
You know whom to contact immediately if the device is lost, stolen, compromised, or accessed without authorization.
08 · Frequently Asked Questions

Common Questions About Personal Devices and Participant Data

Can I store participant data on my personal laptop?

Possibly, but only if your institution permits it for the relevant data and the device meets required safeguards. Sensitive or regulated data may require an institution-managed environment instead.

Can I work on research data from home?

Often yes, but remote work does not remove privacy and security requirements. Use the institutionally approved device, remote-access method, storage environment, and safeguards for the data involved.

Is full-disk encryption enough?

No. Encryption is important, particularly for portable devices, but security can also require appropriate authentication, updates, malware protection, access controls, secure transfer, backup arrangements, and incident procedures.

Can I store pseudonymized data on a personal device?

Only if the applicable institutional and security requirements permit it. Pseudonymized information may still constitute personal data, although separating identifiers can substantially reduce risk.

Can I use my phone to record research interviews?

Only where the device and recording application are approved for that purpose. Check encryption, automatic cloud uploads, app permissions, access controls, transfer procedures, and how recordings will be removed from the phone afterward.

What should I do if my laptop containing participant data is stolen?

Report it immediately through your institution's privacy or information-security incident process. Do not delay reporting while trying to decide whether encryption means the incident is harmless; the responsible organization needs to assess the event.

09 · The Bottom Line

Your Personal Laptop Is Still Part of the Research Security System

The Bottom Line

Participant data should be stored on a personal computer or device only when that use is institutionally permitted and the device provides safeguards appropriate to the data and research context.

Before downloading anything, check authorization, encryption, access, updates, synchronization, backup, retention, and incident procedures. If the institution provides a secure way to work without creating a local copy, that may remove several risks before they need to be managed.

10 · Sources and Further Reading

Authoritative Sources on Personal Devices and Data Security

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes