Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Can Research Data Be Stored in Commercial Cloud Services?

Commercial cloud storage is not automatically prohibited for research data, but neither is every cloud service suitable. The answer depends on the data, provider, configuration, contract, jurisdiction, security controls, and institutional requirements.

312
Research Data in Commercial Cloud Services Guide 312 of 398
01 · The Question

Can You Put Participant Data in Google Drive, OneDrive, Dropbox, AWS, or Another Cloud Service?

Cloud services make research convenient. Files synchronize across devices, collaborators can work remotely, backups may be automated, and large datasets can be processed without maintaining local infrastructure.

Then the research data become sensitive. Perhaps they contain participant names, health information, interview recordings, identifiable photographs, confidential business information, or a key linking study IDs to identities. Suddenly, "just put it in the cloud" sounds considerably less straightforward.

Commercial cloud services can be appropriate for research data, including some personal data, but suitability cannot be determined from the word cloud alone. Researchers need to evaluate the particular service and the particular data.

02 · The Short Answer

Yes, but Only When the Particular Cloud Service Is Appropriate for the Data

In Brief

Research data can often be stored or processed in commercial cloud services when the service is institutionally authorized and provides appropriate contractual, legal, organizational, and technical safeguards for the type of data involved.

A familiar brand, paid subscription, password, or claim that data are encrypted is not enough by itself. Check institutional approval, the provider's role and contract, security controls, data location and transfers, access arrangements, backup and recovery, retention and deletion, and any requirements specific to sensitive or regulated research data.

03 · What You Need to Know

The Real Question Is Not Cloud or No Cloud, but Which Cloud for Which Data

"The cloud" is someone else's computing infrastructure

Cloud computing can provide storage, software, databases, computing capacity, analytics, collaboration tools, and other services over a network. Researchers may encounter software-as-a-service platforms such as online survey or collaboration tools, storage services, and infrastructure platforms that provide virtual machines or large-scale computing resources.

From a data-governance perspective, using a cloud service means another organization may store, transmit, back up, or otherwise process information on infrastructure that the research team does not physically control.

That does not inherently make the arrangement unsafe. Universities themselves routinely use externally hosted infrastructure. It does mean the research organization needs to understand what the provider does and what protections govern the relationship.

Institutionally approved cloud services are different from personal cloud accounts

A university-provided Microsoft 365 account and a researcher's personal consumer OneDrive account may use technology from the same company, yet the governance arrangements can be very different.

Institutional services may be covered by negotiated contracts, data-processing terms, configured security controls, identity management, access logging, retention settings, support arrangements, and institutional risk assessment. A free or personally purchased consumer account may not provide the same contractual or administrative protections.

University College London, for example, advises researchers to evaluate whether a cloud service is suitable and compliant with institutional data protection and information-security policies and directs researchers toward institutionally provided services. Trinity College Dublin similarly advises researchers to use approved, vetted services and to review contracts, privacy terms, security controls, and relevant assessments when considering new technology.

The practical rule is therefore not "Microsoft good, Dropbox bad" or the reverse. The relevant question is which specific service tier, account, configuration, contract, and institutional arrangement you are using.

Start by classifying the research data

A dataset containing published aggregate statistics does not present the same risks as identifiable medical records, raw interview recordings, genetic data, passwords, or a participant reidentification key.

Before choosing storage, determine what the dataset contains and how sensitive it is. Consider whether it contains personal data, legally protected categories, confidential information, intellectual property, contractual restrictions, export-controlled information, or data subject to funder or sector-specific requirements.

The appropriate service should follow the data classification, not the researcher's preferred interface.

Check whether you need all of the data in the cloud

Even when a cloud environment is approved, data minimization still matters. A collaborator may need the pseudonymized analytical dataset without needing names, contact information, consent records, or the reidentification key.

Separating identifiers from research data can reduce exposure. Particularly sensitive files may warrant different storage or access arrangements from the rest of the project.

The provider may be processing personal data on your institution's behalf

Where a cloud provider processes personal data only on the controller's instructions, it may act as a processor under GDPR-style frameworks or as a personal information processor under the Philippine Data Privacy Act framework.

This relationship can trigger contractual requirements. GDPR Article 28, for example, requires specified arrangements between controllers and processors and requires controllers to use processors providing sufficient guarantees for appropriate technical and organizational measures.

Under the Philippine Data Privacy Act implementing rules, a personal information controller remains responsible for personal data under its control or custody, including information outsourced or transferred to a personal information processor or third party, and must use contractual or other reasonable means to provide a comparable level of protection.

This is why identifying the controller and other data roles matters before a cloud provider is introduced.

Security is more than encryption

Encryption at rest and in transit can be important safeguards, but cloud security also depends on identity management, authentication, authorization, account configuration, logging, monitoring, backups, recovery, vulnerability management, administrator privileges, incident response, and user behavior.

A well-secured cloud environment can still be compromised by a researcher who publicly shares a folder link or approves access for the wrong account. Conversely, a local computer sitting under someone's desk is not automatically safer merely because no cloud provider is involved.

Researchers should evaluate the complete security arrangement rather than treating the physical location of the server as a proxy for safety.

Who can access the account matters

Access should correspond to research roles. Shared passwords make it difficult to know who accessed or changed information and can prevent timely revocation when someone leaves the project.

Where supported and institutionally required, individual accounts, strong authentication, appropriate multi-factor authentication, role-based permissions, and access reviews can help reduce unauthorized use.

Cloud collaboration also makes it very easy to grant access. That convenience should not bypass the question of whether a collaborator actually needs access to participant data.

Data location can create legal and contractual issues

Cloud data may be stored, replicated, backed up, or accessed from more than one country. Depending on the provider, service configuration, and applicable law, researchers may have some control over data residency or processing regions.

This can matter when data protection law regulates international transfers, when ethics approvals or participant information specify particular arrangements, or when contracts, funders, governments, or institutions impose geographic restrictions.

Do not assume that selecting a region in a cloud dashboard resolves every international-transfer issue. Support access, subprocessors, backups, disaster recovery, and other processing may also need consideration.

If information may cross national borders, assess the requirements for international research data transfers.

Read the contract, not only the privacy page

Researchers often inspect a provider's public privacy policy and conclude that the service is acceptable. That policy may not describe the contractual terms governing an institutional research account.

Relevant questions can include what the provider may do with uploaded information, whether it acts only on documented instructions, which subprocessors it uses, what security commitments apply, how incidents are reported, how data are returned or deleted, where information is processed, whether audit information is available, and what happens when the contract ends.

These questions are usually better handled through institutional procurement, privacy, legal, information-security, or research IT processes than by an individual researcher clicking "I agree" to consumer terms.

Certifications are useful evidence, not automatic approval

Security certifications and independent assurance reports can provide useful evidence about a provider's controls. Trinity College Dublin, for example, advises researchers assessing technology to look for independent security certification such as ISO 27001 alongside contracts, privacy statements, security controls, and impact assessment.

A certification does not establish that every service from that provider is suitable for every research dataset. Scope, configuration, contractual coverage, data classification, and institutional requirements still matter.

Backup and synchronization are not the same thing

A synchronized cloud folder can replicate accidental deletion, corruption, or unwanted changes across devices. Version history and provider recovery features may help, but researchers should understand what recovery guarantees actually exist.

For important research data, determine whether the institution or provider performs backups, how long versions are retained, whether deleted information can be recovered, and how restoration works. A reassuring cloud icon beside the filename is not a data recovery plan.

Deletion also needs planning

When a project requires information to be deleted, researchers need to understand what deletion means within the service. Data may exist in active storage, synchronized devices, backups, version histories, archives, or other provider systems.

The relevant contractual and technical documentation should explain retention and deletion mechanisms sufficiently for the institution to meet its obligations. Researchers should also avoid keeping unnecessary duplicate copies across multiple cloud services simply because synchronization makes duplication effortless.

04 · A Practical Example

Choosing Cloud Storage for an Interview Study

Hypothetical Example

Recorded interviews containing sensitive personal information

A research team records interviews about employees' experiences of workplace discrimination. The recordings contain names, employer information, voices, and potentially sensitive disclosures. A researcher proposes uploading the files to a personal cloud account because it has 2 TB of available storage.

Classify the data The team recognizes that the raw recordings contain identifiable and potentially sensitive personal information requiring stronger protection than ordinary public research materials.
Check institutional options The university provides an approved research storage service covered by institutional security controls and contractual arrangements. The research team verifies that the service is approved for this data classification.
Restrict access Access is limited to team members who require the raw recordings. Analysts who need only pseudonymized transcripts do not receive the audio files.
Check processing arrangements The team confirms the provider's role, relevant contractual protections, permitted processing locations, authentication requirements, backup arrangements, and incident-reporting process through institutional guidance.
Document the choice The approved storage arrangement is reflected in the research data management and ethics documentation as required.

The important decision was not whether cloud technology is inherently safe. It was whether this particular institutional cloud arrangement was appropriate for these particular files.

05 · What Researchers Often Get Wrong

Common Misconceptions About Research Data in the Cloud

Misconception

Is Cloud Storage Automatically Less Secure Than a Local Computer?

No. Security depends on the systems, configuration, controls, users, and threats involved. An institutionally managed cloud environment may provide stronger controls than an unmanaged personal device. The reverse can also occur when an unsuitable cloud service is used.

Misconception

If a Cloud Service Uses Encryption, Is It Automatically Suitable?

No. Encryption addresses only part of the risk. Access control, contractual terms, data location, subprocessors, authentication, incident response, retention, deletion, configuration, and institutional approval can all matter.

Misconception

Can I Use My Personal Cloud Account if the Same Company Provides the University's Account?

Do not assume so. Consumer and institutional services can differ in contracts, administration, security configuration, support, retention, identity management, and institutional oversight. Follow the service and account type your institution has approved.

Misconception

If the Provider Is a Famous Technology Company, Has Due Diligence Already Been Done?

No. Provider reputation does not determine whether a particular product, subscription, configuration, processing region, or contractual arrangement meets the requirements for your research data.

Misconception

If the Files Are in the Cloud, Is the Provider Now Responsible for Them?

Not entirely. A provider may have processor and security obligations, but the controller retains its own accountability. Outsourcing storage does not transfer away all responsibility for participant data.

Misconception

Does Ethics Approval Automatically Approve Any Cloud Service?

No. Ethics approval may describe or approve a particular data-management arrangement, but institutional privacy, information-security, procurement, contractual, and legal requirements may also apply. Changing the storage arrangement may require additional review.

06 · What This Means for You

Choose the Storage Environment After You Understand the Data

Do not begin with the cloud service you already use and then try to make the research fit it. Begin with the dataset's sensitivity, legal requirements, collaboration needs, retention requirements, and institutional classification, then select an approved environment capable of meeting them.

A simple decision framework

If the data are public or genuinely anonymous
A wider range of cloud environments may be appropriate, subject to research, contractual, integrity, and institutional requirements.
If the data contain personal or confidential information
Use a service approved for the relevant data classification and verify the applicable security, privacy, contractual, and access requirements.
If the data are highly sensitive or specially regulated
Confirm the permitted storage environment with the relevant institutional privacy, security, legal, or research-governance office before uploading anything.
If the proposed service is a personal or free consumer account
Do not assume it is acceptable simply because the provider is reputable or the files are password-protected. Check institutional authorization first.
If the provider may process data internationally
Assess applicable international-transfer and data-residency requirements before use.

Also consider whether the data should be divided. Identifiers, consent records, reidentification keys, raw recordings, and pseudonymized analytical datasets do not necessarily need identical access or storage arrangements.

If researchers will also download cloud-hosted information to laptops or home computers, the cloud assessment is only part of the picture. You must separately determine whether participant data can be stored on those personal computers or devices.

07 · A Quick Checklist

Before Uploading Research Data to a Cloud Service

Verify:
The sensitivity and institutional classification of the research data.
Whether the specific service, subscription, and account type are institutionally approved for that data classification.
Who is the controller and what legal or contractual role the cloud provider performs.
Whether appropriate contracts or data-processing terms are in place through the institution.
Where personal data may be stored, backed up, accessed, or otherwise processed and whether international-transfer requirements apply.
Whether encryption, authentication, access controls, logging, backup, recovery, and incident-response measures are appropriate.
Whether each person with access actually needs the information available to them.
How retention, deletion, account closure, and project completion will be handled.
Whether the proposed storage matches the approved ethics application, data management plan, contracts, participant information, and institutional policies where applicable.
08 · Frequently Asked Questions

Common Questions About Cloud Storage for Research

Can I store research data in Google Drive?

Possibly, but the provider name alone is not enough to answer the question. An institutionally managed Google Workspace environment may have different contractual and security arrangements from a personal Google account. Check whether your specific service and account are approved for the type of research data involved.

Can I use OneDrive for participant data?

Potentially, if the particular institutional OneDrive service is approved for the relevant data classification and the project satisfies applicable security, privacy, access, and governance requirements. Do not assume a personal OneDrive account has the same approval.

Can sensitive research data be stored in the cloud?

Potentially. Some institutional cloud environments are specifically designed or configured for sensitive data. The appropriate answer depends on the sensitivity, applicable regulation, provider and service, configuration, contractual safeguards, processing location, and institutional policy.

Does the cloud provider own research data uploaded to its service?

Do not assume either ownership or non-ownership from the fact that a service is cloud-based. Review the applicable institutional contract and service terms, including provisions concerning intellectual property, permitted provider use, processing instructions, retention, and deletion.

Is encryption enough to make cloud storage compliant?

No. Encryption may be an important safeguard, but compliance and security can also depend on contracts, access controls, authentication, processing purposes, international transfers, retention, incident response, configuration, and other technical and organizational measures.

Can I open cloud-stored research data on my personal laptop?

That is a separate question. Even when cloud storage is approved, downloading, synchronizing, caching, or accessing the data on a personal device may be restricted by institutional policy or require specific security controls.

Does paying for a cloud service make it suitable for research data?

No. Payment does not establish appropriate privacy, security, contractual, or institutional safeguards. A paid consumer service can still be unsuitable for particular research data.

09 · The Bottom Line

Cloud Storage Can Be Appropriate, but the Service Must Fit the Data

The Bottom Line

Research data can often be stored in commercial cloud services, but only when the specific service and configuration provide appropriate safeguards and satisfy the project's legal, ethical, contractual, security, and institutional requirements.

Do not decide from the provider's brand name or from whether the service says "encrypted." Classify the data first, then verify the account, contract, processing locations, access controls, security measures, retention arrangements, and institutional approval before uploading the research files.

10 · Sources and Further Reading

Authoritative Sources on Cloud Storage and Research Data

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes