Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Can Research Data Be Stored on USB Drives or Portable Media?

USB drives and portable media can create significant risks because they are easy to copy, lose, steal, or connect to unauthorized systems. When their use is necessary and permitted, encryption and strict handling controls are particularly important.

314
Research Data on USB Drives Guide 314 of 398
01 · The Question

Can You Put Research Data on a USB Drive?

You need to move a dataset from one computer to another. Uploading it is inconvenient, the internet connection is unreliable, or the destination system is deliberately isolated from the network. A USB drive seems like the obvious solution.

It is small, fast, inexpensive, and works almost everywhere. Those same qualities are also its weakness.

A USB drive containing participant data can be copied in seconds, forgotten in a computer, dropped in a taxi, left in a conference room, stolen with a bag, or connected to an infected machine. Portable media may therefore be permitted for some research uses, but it requires deliberate controls and may be prohibited for certain data or institutions.

02 · The Short Answer

Use Portable Media Only When It Is Permitted and Necessary

In Brief

Research data may sometimes be stored or transferred on USB drives or other portable media, but only when institutional policy permits it and appropriate safeguards, particularly encryption and controlled handling, are applied to the data involved.

Because removable media are easy to lose, steal, duplicate, and connect to unauthorized systems, researchers should first consider whether an approved network transfer, managed cloud service, secure repository, or other controlled method can achieve the same purpose with less risk.

03 · What You Need to Know

Portability Is Both the Advantage and the Risk

USB drives are not inherently prohibited everywhere

There is no universal rule stating that research data can never be stored on removable media. Institutional requirements differ, and particular research environments may use encrypted portable media for legitimate operational reasons.

However, removable media deserve particular caution because physical possession of the device can provide direct access to whatever is stored on it unless effective safeguards prevent that access.

The UK Information Commissioner's Office notes that removable media such as USB devices and SD cards are easily lost or misplaced and can also introduce malware and other cybersecurity risks. It recommends considering more appropriate methods of transporting or storing personal information before using removable media.

Ask whether you need portable media at all

Before configuring an encrypted USB drive, ask why the data need to be on one.

If the purpose is simply to send a dataset to a collaborator, an approved secure transfer service may provide better access control, logging, revocation, and confirmation of receipt. If the purpose is backup, an institutionally managed backup system may be more reliable. If the purpose is working from home, secure remote access may avoid creating another portable copy.

Portable media can still be justified where connectivity is unavailable, a secure offline workflow is required, instruments generate data locally, or approved systems require physical transfer. The important point is that convenience alone should not automatically determine the transfer method.

Encryption is especially important for removable media

Encryption protects information by making it unreadable without the necessary password, key, or other authentication. If an encrypted USB drive is lost, the physical device can still disappear, but the person who finds it may be unable to read the protected files.

The Philippine National Privacy Commission's data-security guidance specifically identifies portable media such as USB flash drives and disks as devices that should be encrypted when they store, collect, or transfer personal data.

For Philippine government agencies, NPC Circular 16-01 is more specific: an agency using portable media such as disks or USB drives to store or transfer personal data must ensure that the data are encrypted. The Circular also states that, where possible, manual transfer through removable physical media should not be allowed and provides additional requirements when such transfer is unavoidable or necessary.

ICO guidance similarly states that personal information stored on removable media is at risk of unauthorized access without encryption and recommends encryption where there is a business need to use USB storage.

Password protection and encryption are not always the same

A USB drive advertised as "password protected" may implement different technical protections depending on the product. Researchers should verify that the mechanism provides encryption meeting institutional requirements rather than assuming that any password prompt is sufficient.

Encryption may be applied to the entire device or to individual files. ICO guidance notes that whole-device encryption is generally more robust and enforceable, although file-level encryption may also be appropriate in some circumstances.

The appropriate method should follow institutional policy and technical guidance rather than being improvised by the individual researcher.

The encryption key needs protection too

An encrypted file offers little practical protection if its password is written on the USB drive, stored in a text file beside the encrypted archive, or sent together with the device through the same channel.

Keys and passwords should be handled according to institutional security requirements. Where a password needs to be communicated to an authorized recipient, using a separate approved communication channel can reduce the risk that the encrypted data and its means of access are compromised together.

Do not copy more data than the task requires

If a collaborator needs 15 variables from 500 participants, that does not necessarily justify copying the entire research database, contact list, consent records, and reidentification key onto a USB drive.

Apply data minimization before the transfer. Create the smallest dataset that properly serves the authorized purpose and remove direct identifiers when they are not required.

This reduces the consequences if the device is lost and also makes it easier to explain why each piece of information was transferred.

Portable media can introduce malware into research systems

The risk is not only that information leaves the USB drive. Malicious software can enter a research computer through removable media.

A device used across personal computers, laboratory instruments, conference computers, public terminals, and institutional systems can become a bridge between otherwise separate environments. Institutions may therefore restrict which USB devices can connect to managed computers or require organization-issued media.

Researchers should follow institutional requirements concerning approved devices, malware scanning, autorun settings, and connection to protected systems.

Physical handling still matters when the data are encrypted

Encryption reduces unauthorized access risk, but a lost drive still represents loss of institutional property or research information and may affect availability. If the USB contains the only copy of raw field data, encryption will not recreate the study after the device disappears.

Portable media should therefore be physically controlled, inventoried where required, transported appropriately, and never treated as the sole authoritative copy of important research data unless a specifically designed workflow requires it and appropriate recovery arrangements exist.

Do not use a USB drive as an informal permanent archive

Flash media can fail, become corrupted, be misplaced, or become technologically obsolete. A USB drive forgotten in a drawer is not a research preservation strategy.

Long-term research retention should normally use an approved repository, archive, institutional storage system, or another environment designed for preservation and governed access.

If portable media are used temporarily for collection or transfer, establish when the information will be moved to the authoritative storage location and when the portable copy should be securely removed.

Deleting a file may not securely erase the underlying data

Ordinary deletion generally removes the operating system's reference to a file rather than guaranteeing that the underlying information cannot be recovered. Secure disposal of electronic media can therefore require specialized procedures.

The Philippine Data Privacy Act implementing rules require policies and procedures governing the transfer, removal, disposal, and reuse of electronic media to ensure appropriate protection of personal data.

When a USB drive is no longer needed, follow institutional sanitization or destruction procedures appropriate to the media and data rather than simply deleting the folder and giving the device to someone else.

A lost encrypted USB drive can still be an incident

Researchers sometimes assume that encryption means there is nothing to report if a device disappears. Encryption can materially change the risk assessment, but the loss should still be reported through the appropriate institutional process.

The responsible organization needs to determine what information was present, whether encryption was correctly implemented, whether the key may also have been compromised, whether another copy exists, and whether the event meets applicable breach-notification criteria.

If a device containing research data disappears, treat it as a potential loss or accidental disclosure of research data rather than making the final assessment yourself.

Watch Out

Never use an unencrypted USB drive for personal research data merely because the transfer will take only a few minutes. A short transfer can create a long-lived breach if the device is lost, copied, or left behind.

04 · A Practical Example

Moving Field Research Data Without Internet Access

Hypothetical Example

An offline field site

A research team collects participant survey data at a remote field site where reliable internet access is unavailable. The collection laptop must periodically transfer data to an encrypted institutional laptop that will be transported back to the university.

Confirm necessity The team documents that secure network transfer is not reasonably available and that removable media are permitted by institutional policy for this workflow.
Use approved media An institution-approved encrypted USB device is used rather than a researcher's personal promotional flash drive.
Minimize the transfer Only the required research files are copied. Unnecessary identifiers and unrelated files are not transferred.
Control the device The USB remains under the custody of an authorized team member and is not connected to unrelated or public computers.
Verify and remove After the files are transferred to the approved institutional environment and their integrity is verified, the portable copy is handled according to the project's approved deletion or reuse procedure.

Here the USB drive serves a genuine operational purpose. The goal is not to prohibit portable media reflexively but to prevent convenience from becoming an unmanaged data-transfer system.

05 · What Researchers Often Get Wrong

Common Mistakes With USB Drives and Research Data

Misconception

If the USB Never Leaves My Pocket, Is Encryption Unnecessary?

No. Portable media are easily lost, stolen, forgotten, or accidentally exchanged. Appropriate encryption protects the information when physical control fails.

Misconception

Is a Password-Protected ZIP File Always Enough?

Not necessarily. Encryption methods vary considerably. Use the encryption method and tools approved by your institution for the sensitivity of the data rather than assuming that any password-protected archive meets the required standard.

Misconception

Can I Use Any USB Drive if I Delete the Data Immediately Afterwards?

No. The information is exposed during the period it exists on the device, and ordinary deletion may not securely erase the underlying data. Device authorization, encryption, handling, and secure disposal requirements still matter.

Misconception

Is a USB Drive a Good Backup?

It can form part of a deliberately designed backup system in some contexts, but an ad hoc USB copy is usually a poor substitute for managed backup. Portable media can be lost, damaged, corrupted, or forgotten and may create unmanaged duplicate personal data.

Misconception

If the USB Is Encrypted, Can I Ignore It When It Goes Missing?

No. Report the loss promptly. The responsible institution should assess whether encryption was effective, what information was involved, whether availability was affected, and whether the incident triggers further action.

06 · What This Means for You

Use Portable Media as a Controlled Exception, Not an Invisible Convenience

Before using a USB drive, identify the purpose it serves and determine whether a more controlled transfer or storage method is reasonably available.

A simple decision framework

If an approved secure network or managed transfer method can reasonably do the job
Prefer that method when institutional policy or risk assessment supports it.
If removable media are necessary and permitted
Use institutionally approved encrypted media and follow required handling procedures.
If only part of the dataset is needed
Transfer only those records and variables required for the authorized purpose.
If the device will move between people or institutions
Document authorized recipients and use appropriate physical and cryptographic controls for the transfer.
If the USB is lost, stolen, or cannot be accounted for
Report the incident immediately through the appropriate institutional process.

Where the purpose is simply to send a file to another researcher, portable media are not your only option. Depending on institutional arrangements, a managed transfer service or approved cloud environment may provide better control. The same principle applies before deciding whether research data should be sent by email.

07 · A Quick Checklist

Before Copying Research Data to Portable Media

Check:
Whether institutional policy permits removable media for the type of research data involved.
Whether portable media are actually necessary or an approved secure transfer method can be used instead.
The USB drive or other medium is institutionally approved where required.
The device or research files are encrypted using an approved method appropriate to the data.
Passwords or cryptographic keys are protected separately from the portable media.
Only the minimum records, variables, and identifiers required for the purpose are copied.
The device will remain physically controlled and will not be connected to unauthorized or untrusted computers.
An authoritative copy or appropriate backup exists so loss of the device does not destroy irreplaceable research data.
There is an approved procedure for removing, sanitizing, reusing, or destroying the portable media when it is no longer required.
08 · Frequently Asked Questions

Common Questions About Research Data on USB Drives

Can I put participant data on a USB drive?

Possibly, if institutional policy permits it and appropriate safeguards are applied. Personal data on portable media should generally be encrypted, and some organizations or data classifications may prohibit removable-media use entirely.

Does a USB drive containing research data need encryption?

Encryption is strongly supported by authoritative data-security guidance for removable media containing personal information. Philippine government agencies are specifically required by NPC Circular 16-01 to ensure that personal data stored or transferred on portable media are encrypted.

Can I use my own USB drive?

Only if your institution permits it. Some organizations require institution-issued or specifically approved encrypted media because personally owned devices are harder to configure, inventory, control, and securely dispose of.

Can I mail or courier an encrypted USB drive to a collaborator?

Potentially, but the transfer should be authorized and assessed for the data involved. Appropriate encryption, physical tracking, recipient verification, separate handling of access credentials, and any required data-transfer arrangements should be considered.

What should I do if I lose an encrypted USB drive?

Report the loss immediately through your institution's incident process. Encryption may reduce the likelihood of unauthorized access, but the institution still needs to assess the data, encryption, key security, availability, and applicable breach requirements.

Can I delete the files and reuse the USB drive?

Possibly, but ordinary file deletion may not constitute secure sanitization. Follow your institution's approved procedure for securely erasing, reusing, or destroying media that have contained personal or confidential research data.

Are external hard drives treated like USB flash drives?

Many of the same considerations apply because both are portable storage media. Encryption, physical control, access, backup, transport, sanitization, and institutional authorization should be assessed according to the data and device involved.

09 · The Bottom Line

A USB Drive Should Be a Deliberate Data-Control Decision

The Bottom Line

Research data can sometimes be stored or transferred on USB drives and other portable media, but their use should be authorized, necessary, appropriately encrypted, physically controlled, and limited to the data required for the task.

Before copying the files, ask whether a more controlled method can accomplish the same purpose. If portable media are genuinely needed, plan the entire lifecycle of that copy, including encryption, transport, access, incident reporting, removal, and secure disposal.

10 · Sources and Further Reading

Authoritative Sources on Portable Media and Data Security

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes