03 · What You Need to Know
The Real Question Is Not Cloud or No Cloud, but Which Cloud for Which Data
"The cloud" is someone else's computing infrastructure
Cloud computing can provide storage, software, databases, computing capacity, analytics, collaboration tools, and other services over a network. Researchers may encounter software-as-a-service platforms such as online survey or collaboration tools, storage services, and infrastructure platforms that provide virtual machines or large-scale computing resources.
From a data-governance perspective, using a cloud service means another organization may store, transmit, back up, or otherwise process information on infrastructure that the research team does not physically control.
That does not inherently make the arrangement unsafe. Universities themselves routinely use externally hosted infrastructure. It does mean the research organization needs to understand what the provider does and what protections govern the relationship.
Institutionally approved cloud services are different from personal cloud accounts
A university-provided Microsoft 365 account and a researcher's personal consumer OneDrive account may use technology from the same company, yet the governance arrangements can be very different.
Institutional services may be covered by negotiated contracts, data-processing terms, configured security controls, identity management, access logging, retention settings, support arrangements, and institutional risk assessment. A free or personally purchased consumer account may not provide the same contractual or administrative protections.
University College London, for example, advises researchers to evaluate whether a cloud service is suitable and compliant with institutional data protection and information-security policies and directs researchers toward institutionally provided services. Trinity College Dublin similarly advises researchers to use approved, vetted services and to review contracts, privacy terms, security controls, and relevant assessments when considering new technology.
The practical rule is therefore not "Microsoft good, Dropbox bad" or the reverse. The relevant question is which specific service tier, account, configuration, contract, and institutional arrangement you are using.
Start by classifying the research data
A dataset containing published aggregate statistics does not present the same risks as identifiable medical records, raw interview recordings, genetic data, passwords, or a participant reidentification key.
Before choosing storage, determine what the dataset contains and how sensitive it is. Consider whether it contains personal data, legally protected categories, confidential information, intellectual property, contractual restrictions, export-controlled information, or data subject to funder or sector-specific requirements.
The appropriate service should follow the data classification, not the researcher's preferred interface.
Check whether you need all of the data in the cloud
Even when a cloud environment is approved, data minimization still matters. A collaborator may need the pseudonymized analytical dataset without needing names, contact information, consent records, or the reidentification key.
Separating identifiers from research data can reduce exposure. Particularly sensitive files may warrant different storage or access arrangements from the rest of the project.
The provider may be processing personal data on your institution's behalf
Where a cloud provider processes personal data only on the controller's instructions, it may act as a processor under GDPR-style frameworks or as a personal information processor under the Philippine Data Privacy Act framework.
This relationship can trigger contractual requirements. GDPR Article 28, for example, requires specified arrangements between controllers and processors and requires controllers to use processors providing sufficient guarantees for appropriate technical and organizational measures.
Under the Philippine Data Privacy Act implementing rules, a personal information controller remains responsible for personal data under its control or custody, including information outsourced or transferred to a personal information processor or third party, and must use contractual or other reasonable means to provide a comparable level of protection.
This is why identifying the controller and other data roles matters before a cloud provider is introduced.
Security is more than encryption
Encryption at rest and in transit can be important safeguards, but cloud security also depends on identity management, authentication, authorization, account configuration, logging, monitoring, backups, recovery, vulnerability management, administrator privileges, incident response, and user behavior.
A well-secured cloud environment can still be compromised by a researcher who publicly shares a folder link or approves access for the wrong account. Conversely, a local computer sitting under someone's desk is not automatically safer merely because no cloud provider is involved.
Researchers should evaluate the complete security arrangement rather than treating the physical location of the server as a proxy for safety.
Who can access the account matters
Access should correspond to research roles. Shared passwords make it difficult to know who accessed or changed information and can prevent timely revocation when someone leaves the project.
Where supported and institutionally required, individual accounts, strong authentication, appropriate multi-factor authentication, role-based permissions, and access reviews can help reduce unauthorized use.
Cloud collaboration also makes it very easy to grant access. That convenience should not bypass the question of whether a collaborator actually needs access to participant data.
Data location can create legal and contractual issues
Cloud data may be stored, replicated, backed up, or accessed from more than one country. Depending on the provider, service configuration, and applicable law, researchers may have some control over data residency or processing regions.
This can matter when data protection law regulates international transfers, when ethics approvals or participant information specify particular arrangements, or when contracts, funders, governments, or institutions impose geographic restrictions.
Do not assume that selecting a region in a cloud dashboard resolves every international-transfer issue. Support access, subprocessors, backups, disaster recovery, and other processing may also need consideration.
If information may cross national borders, assess the requirements for international research data transfers.
Read the contract, not only the privacy page
Researchers often inspect a provider's public privacy policy and conclude that the service is acceptable. That policy may not describe the contractual terms governing an institutional research account.
Relevant questions can include what the provider may do with uploaded information, whether it acts only on documented instructions, which subprocessors it uses, what security commitments apply, how incidents are reported, how data are returned or deleted, where information is processed, whether audit information is available, and what happens when the contract ends.
These questions are usually better handled through institutional procurement, privacy, legal, information-security, or research IT processes than by an individual researcher clicking "I agree" to consumer terms.
Certifications are useful evidence, not automatic approval
Security certifications and independent assurance reports can provide useful evidence about a provider's controls. Trinity College Dublin, for example, advises researchers assessing technology to look for independent security certification such as ISO 27001 alongside contracts, privacy statements, security controls, and impact assessment.
A certification does not establish that every service from that provider is suitable for every research dataset. Scope, configuration, contractual coverage, data classification, and institutional requirements still matter.
Backup and synchronization are not the same thing
A synchronized cloud folder can replicate accidental deletion, corruption, or unwanted changes across devices. Version history and provider recovery features may help, but researchers should understand what recovery guarantees actually exist.
For important research data, determine whether the institution or provider performs backups, how long versions are retained, whether deleted information can be recovered, and how restoration works. A reassuring cloud icon beside the filename is not a data recovery plan.
Deletion also needs planning
When a project requires information to be deleted, researchers need to understand what deletion means within the service. Data may exist in active storage, synchronized devices, backups, version histories, archives, or other provider systems.
The relevant contractual and technical documentation should explain retention and deletion mechanisms sufficiently for the institution to meet its obligations. Researchers should also avoid keeping unnecessary duplicate copies across multiple cloud services simply because synchronization makes duplication effortless.