01 · The Question
Can You Put Research Data on a USB Drive?
You need to move a dataset from one computer to another. Uploading it is inconvenient, the internet connection is unreliable, or the destination system is deliberately isolated from the network. A USB drive seems like the obvious solution.
It is small, fast, inexpensive, and works almost everywhere. Those same qualities are also its weakness.
A USB drive containing participant data can be copied in seconds, forgotten in a computer, dropped in a taxi, left in a conference room, stolen with a bag, or connected to an infected machine. Portable media may therefore be permitted for some research uses, but it requires deliberate controls and may be prohibited for certain data or institutions.
03 · What You Need to Know
Portability Is Both the Advantage and the Risk
USB drives are not inherently prohibited everywhere
There is no universal rule stating that research data can never be stored on removable media. Institutional requirements differ, and particular research environments may use encrypted portable media for legitimate operational reasons.
However, removable media deserve particular caution because physical possession of the device can provide direct access to whatever is stored on it unless effective safeguards prevent that access.
The UK Information Commissioner's Office notes that removable media such as USB devices and SD cards are easily lost or misplaced and can also introduce malware and other cybersecurity risks. It recommends considering more appropriate methods of transporting or storing personal information before using removable media.
Ask whether you need portable media at all
Before configuring an encrypted USB drive, ask why the data need to be on one.
If the purpose is simply to send a dataset to a collaborator, an approved secure transfer service may provide better access control, logging, revocation, and confirmation of receipt. If the purpose is backup, an institutionally managed backup system may be more reliable. If the purpose is working from home, secure remote access may avoid creating another portable copy.
Portable media can still be justified where connectivity is unavailable, a secure offline workflow is required, instruments generate data locally, or approved systems require physical transfer. The important point is that convenience alone should not automatically determine the transfer method.
Encryption is especially important for removable media
Encryption protects information by making it unreadable without the necessary password, key, or other authentication. If an encrypted USB drive is lost, the physical device can still disappear, but the person who finds it may be unable to read the protected files.
The Philippine National Privacy Commission's data-security guidance specifically identifies portable media such as USB flash drives and disks as devices that should be encrypted when they store, collect, or transfer personal data.
For Philippine government agencies, NPC Circular 16-01 is more specific: an agency using portable media such as disks or USB drives to store or transfer personal data must ensure that the data are encrypted. The Circular also states that, where possible, manual transfer through removable physical media should not be allowed and provides additional requirements when such transfer is unavoidable or necessary.
ICO guidance similarly states that personal information stored on removable media is at risk of unauthorized access without encryption and recommends encryption where there is a business need to use USB storage.
Password protection and encryption are not always the same
A USB drive advertised as "password protected" may implement different technical protections depending on the product. Researchers should verify that the mechanism provides encryption meeting institutional requirements rather than assuming that any password prompt is sufficient.
Encryption may be applied to the entire device or to individual files. ICO guidance notes that whole-device encryption is generally more robust and enforceable, although file-level encryption may also be appropriate in some circumstances.
The appropriate method should follow institutional policy and technical guidance rather than being improvised by the individual researcher.
The encryption key needs protection too
An encrypted file offers little practical protection if its password is written on the USB drive, stored in a text file beside the encrypted archive, or sent together with the device through the same channel.
Keys and passwords should be handled according to institutional security requirements. Where a password needs to be communicated to an authorized recipient, using a separate approved communication channel can reduce the risk that the encrypted data and its means of access are compromised together.
Do not copy more data than the task requires
If a collaborator needs 15 variables from 500 participants, that does not necessarily justify copying the entire research database, contact list, consent records, and reidentification key onto a USB drive.
Apply data minimization before the transfer. Create the smallest dataset that properly serves the authorized purpose and remove direct identifiers when they are not required.
This reduces the consequences if the device is lost and also makes it easier to explain why each piece of information was transferred.
Portable media can introduce malware into research systems
The risk is not only that information leaves the USB drive. Malicious software can enter a research computer through removable media.
A device used across personal computers, laboratory instruments, conference computers, public terminals, and institutional systems can become a bridge between otherwise separate environments. Institutions may therefore restrict which USB devices can connect to managed computers or require organization-issued media.
Researchers should follow institutional requirements concerning approved devices, malware scanning, autorun settings, and connection to protected systems.
Physical handling still matters when the data are encrypted
Encryption reduces unauthorized access risk, but a lost drive still represents loss of institutional property or research information and may affect availability. If the USB contains the only copy of raw field data, encryption will not recreate the study after the device disappears.
Portable media should therefore be physically controlled, inventoried where required, transported appropriately, and never treated as the sole authoritative copy of important research data unless a specifically designed workflow requires it and appropriate recovery arrangements exist.
Do not use a USB drive as an informal permanent archive
Flash media can fail, become corrupted, be misplaced, or become technologically obsolete. A USB drive forgotten in a drawer is not a research preservation strategy.
Long-term research retention should normally use an approved repository, archive, institutional storage system, or another environment designed for preservation and governed access.
If portable media are used temporarily for collection or transfer, establish when the information will be moved to the authoritative storage location and when the portable copy should be securely removed.
Deleting a file may not securely erase the underlying data
Ordinary deletion generally removes the operating system's reference to a file rather than guaranteeing that the underlying information cannot be recovered. Secure disposal of electronic media can therefore require specialized procedures.
The Philippine Data Privacy Act implementing rules require policies and procedures governing the transfer, removal, disposal, and reuse of electronic media to ensure appropriate protection of personal data.
When a USB drive is no longer needed, follow institutional sanitization or destruction procedures appropriate to the media and data rather than simply deleting the folder and giving the device to someone else.
A lost encrypted USB drive can still be an incident
Researchers sometimes assume that encryption means there is nothing to report if a device disappears. Encryption can materially change the risk assessment, but the loss should still be reported through the appropriate institutional process.
The responsible organization needs to determine what information was present, whether encryption was correctly implemented, whether the key may also have been compromised, whether another copy exists, and whether the event meets applicable breach-notification criteria.
If a device containing research data disappears, treat it as a potential loss or accidental disclosure of research data rather than making the final assessment yourself.
Watch Out
Never use an unencrypted USB drive for personal research data merely because the transfer will take only a few minutes. A short transfer can create a long-lived breach if the device is lost, copied, or left behind.