Research Data Storage Options

Information Security ยท Teachers College

Research Data Storage Options

A guide to TC-approved storage platforms for research data, organized by data sensitivity level so you can quickly find the right option for your project.

Choosing the right storage platform for your research data is one of the most important security decisions you will make for your project. The right choice depends on what kind of data you are working with. Use this page to identify approved options based on your data's sensitivity level, and contact the TCIT Information Security team if you are unsure which applies to your situation.

Not sure how to classify your data? Check the data classification key below, review TC's Data Classification Policy, or schedule a consultation with InfoSec. When in doubt, treat data as the most sensitive category that could apply.
Data Classification Key

Public

Data appropriate for public release. Examples: published datasets, public-facing content, open research data.

Internal

Non-public TC information not intended for public release. Examples: unpublished drafts, aggregate operational data, internal communications.

Confidential

Sensitive data whose unauthorized disclosure could harm individuals or TC. Examples: de-identified human subjects data, unpublished research, donor records.

Restricted

Highly sensitive data governed by law or regulation. Examples: HIPAA-covered health data, FERPA student records, CUI, federally controlled research data.

Storage Options by Data Classification

The table below shows which storage platforms are approved for each data classification level. Approved means the platform is cleared for that data type. Requestable means access is available but must be requested. Contact InfoSec means additional review is required before use.

Data Level TC Google Drive
(Standard - included with TC account)
TC Google Drive
(HIPAA Account)
TC Dropbox
(HIPAA compliant)
Secure Research
File Server
Public Approved Standard TC Google account. No additional setup required. Approved HIPAA account also works for public data. Approved Subject to license availability. Approved Contact InfoSec to discuss suitability for your project.
Internal Approved Use your TC Google account with appropriate sharing restrictions. Do not use personal Google accounts. Approved Requestable Limited licenses available. Contact InfoSec to request access. Approved Good option for large datasets or projects requiring controlled access.
Confidential Contact InfoSec Standard Google Drive may be appropriate depending on data type and access controls. Confirm with InfoSec before use. Approved Requestable. Recommended for confidential research data requiring enhanced controls. Requestable HIPAA-compliant. Limited licenses. Contact InfoSec to request and confirm suitability. Approved Recommended for large or sensitive datasets requiring granular access control.
Restricted Not Approved Standard Google Drive is not approved for HIPAA, FERPA, CUI, or other restricted data. Contact InfoSec May be appropriate for some restricted data types. InfoSec and sponsor review required before use. Contact InfoSec HIPAA-compliant. May be appropriate for some restricted data. InfoSec review and sponsor approval required. Contact InfoSec Often the best option for restricted data. Contact InfoSec to discuss configuration and access controls for your specific requirements.
About Each Storage Option
๐Ÿ“ Included with TC account

TC Google Drive (Standard)

Available to all TC faculty, staff, and students as part of TC's Google Workspace agreement. Appropriate for Public and Internal research data with proper sharing restrictions applied. Do not use a personal Google account for research data.

Get help with Google Drive โ†’
๐Ÿ”’ Requestable

TC Google Drive (HIPAA Account)

A specially configured Google Workspace account with enhanced security controls, suitable for Confidential research data and some Restricted data types. Must be requested through InfoSec. Not included with a standard TC Google account.

Request a HIPAA Google account โ†’
๐Ÿ“ฆ Requestable - limited licenses

TC Dropbox (HIPAA Compliant)

TC's enterprise Dropbox environment is HIPAA compliant and appropriate for Confidential and some Restricted research data. Licenses are limited - contact InfoSec to check availability and confirm suitability for your data type before requesting access.

Request Dropbox access โ†’
๐Ÿ–ฅ๏ธ Contact InfoSec to set up

Secure Research File Server

TC's secure research file server environment provides dedicated, access-controlled storage for research projects with large datasets or heightened security requirements. Particularly well-suited for projects with significant data volumes, sensitive data classifications, or sponsor-mandated security controls. Contact InfoSec to discuss whether this option is right for your project.

Contact InfoSec to discuss โ†’
Important Reminders
Never use these for research data: Personal Google accounts, personal Dropbox, personal email, iCloud, or any consumer storage service not listed on TC's Applications Approved for Research list. Using unapproved storage can violate your IRB protocol, your grant agreement, and TC policy.
Related Resources

Not sure which storage option is right for you?

TCIT Information Security ยท 212-678-3300, Opt. 2

Schedule a consultation
Back to skip to quick links