Information Security ยท Teachers College
Research Data Storage Options
A guide to TC-approved storage platforms for research data, organized by data sensitivity level so you can quickly find the right option for your project.
Choosing the right storage platform for your research data is one of the most important security decisions you will make for your project. The right choice depends on what kind of data you are working with. Use this page to identify approved options based on your data's sensitivity level, and contact the TCIT Information Security team if you are unsure which applies to your situation.
Public
Data appropriate for public release. Examples: published datasets, public-facing content, open research data.
Internal
Non-public TC information not intended for public release. Examples: unpublished drafts, aggregate operational data, internal communications.
Confidential
Sensitive data whose unauthorized disclosure could harm individuals or TC. Examples: de-identified human subjects data, unpublished research, donor records.
Restricted
Highly sensitive data governed by law or regulation. Examples: HIPAA-covered health data, FERPA student records, CUI, federally controlled research data.
The table below shows which storage platforms are approved for each data classification level. Approved means the platform is cleared for that data type. Requestable means access is available but must be requested. Contact InfoSec means additional review is required before use.
| Data Level | TC Google Drive (Standard - included with TC account) |
TC Google Drive (HIPAA Account) |
TC Dropbox (HIPAA compliant) |
Secure Research File Server |
|---|---|---|---|---|
| Public | Approved Standard TC Google account. No additional setup required. | Approved HIPAA account also works for public data. | Approved Subject to license availability. | Approved Contact InfoSec to discuss suitability for your project. |
| Internal | Approved Use your TC Google account with appropriate sharing restrictions. Do not use personal Google accounts. | Approved | Requestable Limited licenses available. Contact InfoSec to request access. | Approved Good option for large datasets or projects requiring controlled access. |
| Confidential | Contact InfoSec Standard Google Drive may be appropriate depending on data type and access controls. Confirm with InfoSec before use. | Approved Requestable. Recommended for confidential research data requiring enhanced controls. | Requestable HIPAA-compliant. Limited licenses. Contact InfoSec to request and confirm suitability. | Approved Recommended for large or sensitive datasets requiring granular access control. |
| Restricted | Not Approved Standard Google Drive is not approved for HIPAA, FERPA, CUI, or other restricted data. | Contact InfoSec May be appropriate for some restricted data types. InfoSec and sponsor review required before use. | Contact InfoSec HIPAA-compliant. May be appropriate for some restricted data. InfoSec review and sponsor approval required. | Contact InfoSec Often the best option for restricted data. Contact InfoSec to discuss configuration and access controls for your specific requirements. |
TC Google Drive (Standard)
Available to all TC faculty, staff, and students as part of TC's Google Workspace agreement. Appropriate for Public and Internal research data with proper sharing restrictions applied. Do not use a personal Google account for research data.
Get help with Google Drive โTC Google Drive (HIPAA Account)
A specially configured Google Workspace account with enhanced security controls, suitable for Confidential research data and some Restricted data types. Must be requested through InfoSec. Not included with a standard TC Google account.
Request a HIPAA Google account โTC Dropbox (HIPAA Compliant)
TC's enterprise Dropbox environment is HIPAA compliant and appropriate for Confidential and some Restricted research data. Licenses are limited - contact InfoSec to check availability and confirm suitability for your data type before requesting access.
Request Dropbox access โSecure Research File Server
TC's secure research file server environment provides dedicated, access-controlled storage for research projects with large datasets or heightened security requirements. Particularly well-suited for projects with significant data volumes, sensitive data classifications, or sponsor-mandated security controls. Contact InfoSec to discuss whether this option is right for your project.
Contact InfoSec to discuss โ- Your IRB protocol must accurately describe where your data will be stored. If you change storage platforms mid-project, update your protocol and notify InfoSec.
- Some federal sponsors (NIH, NSF, DoD, DoE) specify storage requirements in their award documents. Contact InfoSec to confirm your chosen platform meets any sponsor-specific requirements.
- External collaborators and research affiliates can access TC storage platforms through the affiliate provisioning process. See the Affiliate Request Form for details.
- At the end of your project, data must be securely deleted or archived per your Data Security Plan. Standard deletion is not sufficient for Confidential or Restricted data. See the End-of-Study Data Checklist for guidance.
Not sure which storage option is right for you?
TCIT Information Security ยท 212-678-3300, Opt. 2