Where Should My Research Data Be Stored During The Project?
What Makes a Good Storage Location
Not all storage locations provide the same level of protection, security or accessibility.
A storage solution that works well for one project may be unsuitable for another. For example, a single researcher working with publicly available data may have different requirements from a research team handling sensitive personal information.
When deciding where to store research data during the project, it can be useful to consider several characteristics of the storage location.
| Characteristic | Why is it important? |
| Backup and recovery | Hardware can fail, files can be deleted accidentally and data can become corrupted. A good storage location should provide backup mechanisms or be compatible with the project's backup strategy so that data can be recovered if something goes wrong. |
| Security | Research data may be targeted by malware, ransomware or other cyberattacks. A good storage solution should provide appropriate technical protections to reduce the risk of unauthorised access, theft or loss of data. |
| Access control | Researchers should be able to control who can view, modify or delete data. In collaborative projects, not all team members may need access to all datasets, particularly when sensitive information is involved. |
| Accessibility and collaboration | Researchers need to be able to access the data when required. Some projects may require data to remain on secure institutional systems and only be accessible on-site, while others may benefit from cloud-based access using authenticated accounts. In collaborative projects, it is also important to consider how researchers will share and work on the same files. |
| Capacity and performance | Research projects can generate large amounts of data. It is worth considering whether the storage location can accommodate both current and future data volumes, and whether it provides sufficient performance for the types of data being used. |
| Institutional support and sustainability | Many institutions provide approved storage services for research data. These often include technical support, guidance, access management and compliance with institutional policies. It is also worth considering what happens if a researcher changes institution, loses access to an account or leaves the project. |
A good storage location is one that matches the needs of the project while allowing researchers to store, access and manage their data effectively.
Common Storage Options
Researchers may use a wide range of storage solutions simultaneously during a project. For example, data may be collected on a laptop, synchronised to institutional storage and shared through a cloud-based platform.
The "best" storage location depends on the project. Sensitive personal data may require secure institutional storage, while an international collaboration may benefit from a cloud-based solution that allows controlled access across institutions.
Each option has advantages and limitations, and the most appropriate choice will depend on the nature of the data, the level of collaboration required and any legal or institutional requirements.
| Storage option | Advantages | Limitations |
|---|---|---|
| Local devices | Convenient and immediately accessible. No internet connection required. | Vulnerable to hardware failure, loss or theft. Collaboration can be difficult. |
| Encrypted external USB drives | Portable and useful for transporting data between locations or systems. Encryption can provide additional protection for sensitive data. | Vulnerable to loss or damage. Should not be considered the only copy of the data. |
| Institutional storage | Typically supported by institutional IT services and may include backup, security and access management. | Access may be limited to institutional members and available capacity may be restricted. |
| Shared network drives | Facilitate collaboration within a research group or institution. Centralised storage can reduce duplicate copies. | May be difficult to access remotely or from partner institutions. |
| Cloud storage services | Accessible from multiple locations and devices. Often support collaboration and file synchronisation. | Security, data protection, storage limits and service terms should be considered carefully. |
| Specialised research platforms | May provide features such as structured data management, metadata capture, version history or integration with research workflows. | May require training and may not be suitable for all types of research data. |
Tip: Researchers should always check whether their institution, funder or project has specific requirements regarding where research data may be stored.
Other Places Where Data May Reside
Research data are not always created directly in their main storage location. During collection, processing or transfer, data may temporarily reside on a variety of devices and systems that also need to be considered when planning storage.
| Storage location | Typical use | Considerations |
| Email attachments | Sharing datasets between collaborators | Multiple copies can quickly proliferate, making it difficult to identify the most recent version. Email should generally not be used as a primary storage location for research data. Additional security and confidentiality concerns may arise when sharing sensitive data by email. |
| Mobile devices (e.g. phones, tablets) | Surveys, field observations, photographs, audio recordings and data collection applications | Data should be transferred regularly to the project's main storage location. Personal devices may create security and ownership concerns. |
| Scientific instruments and laboratory equipment | Microscopes, scanners, sequencers, imaging systems, sensors and analytical instruments | Data may remain temporarily on the instrument computer. Researchers should verify how long files are retained and who is responsible for transferring them. |
| Memory cards (SD, microSD, CF cards) | Cameras, drones, audio recorders and field equipment | Easy to lose or damage. Files should be transferred and backed up as soon as practical. |
| Non-encrypted external drives | Temporary storage or transport of non-personal and non-sensitive data | Vulnerable to loss, damage or corruption. Should not be considered a long-term storage solution or the only copy of the data. |
| High-Performance Computing (HPC) systems | Large-scale computational analyses and simulations | Often intended for active processing rather than long-term storage. Data may be deleted automatically after a defined period. |
| Electronic Laboratory Notebooks (ELN) | Recording experimental procedures, observations and research data | May provide structured data capture, version history and controlled access, but storage capacity and export options vary between systems. |
| Data collection platforms | Online surveys, mobile data collection tools and specialised research software | Make sure you understand where the data are stored, who controls access and how data will be exported and preserved. |
Many of these locations should be viewed as temporary stages in the data lifecycle rather than the final destination of the data. When planning storage, it is important to consider not only where data will be stored during the project, but also how they will move between devices, systems and collaborators.
Important: remember that storage media do not last forever. Hard drives, solid-state drives (SSDs), USB drives and memory cards all deteriorate over time and can fail without warning. Even when a device is not actively being used, components may degrade, leading to data corruption or data loss. For this reason, removable media such as external drives, USB sticks and memory cards should generally be considered temporary storage locations rather than long-term preservation solutions. Important research data should be transferred to managed storage systems and included in a regular backup strategy.
Storage for Collaborative Projects
When research data are used by multiple people, storage decisions become more complex. Researchers need to consider not only where data will be stored, but also how collaborators will access and manage them throughout the project.
Avoid Multiple Independent Copies
Where possible, collaborators should work from a shared storage location rather than maintaining separate copies of the same files. This reduces confusion and helps ensure that everyone is working with the same data.
As discussed in the previous guide, clear versioning practices help prevent confusion when multiple researchers contribute to the same data. This aligns with common recommendations for collaborative data management, which emphasise explicit version tracking and controlled update processes.
Define Access Permissions
Access permissions should be defined according to the needs of the project, particularly when sensitive or confidential data are involved.
Not everyone involved in a project necessarily requires access to all data. Some collaborators may only need to view data, while others may need permission to modify or delete files.
Defining permissions from the beginning of a project can help reduce both security risks and accidental modifications.
Consider External Collaborators
Collaborative projects often involve researchers from different institutions, countries or organisations.
Before selecting a storage solution, consider whether all collaborators will be able to access the data easily and whether any institutional, legal or contractual requirements may affect where the data can be stored.
A storage solution that works well for one institution may not be suitable for a multi-institutional project.
Storing Sensitive Data
Not all research data can be stored in the same way.
Some projects involve data that could cause harm if accessed by unauthorised individuals. Examples may include personal data, health information, commercially sensitive information, confidential research data or data subject to legal, ethical or contractual restrictions.
For these types of data, storage decisions often involve additional requirements beyond those discussed previously.
Follow Institutional Requirements
Many institutions have specific policies or approved storage solutions for sensitive research data. In some cases, certain storage locations or services may not be permitted for particular types of data.
Before collecting or storing sensitive data, researchers should check whether institutional, legal, ethical or funder requirements apply to their project. It may also be helpful to consult relevant support services within the institution, such as a Data Protection Officer (DPO), Chief Information Security Officer (CISO), information security team, research office or research data support service.
Restrict Access
Access should be limited to people who genuinely need it for their work on the project.
This may involve assigning different permission levels, restricting access to specific project members or storing sensitive datasets separately from other project materials.
Consider Encryption
Encryption provides an additional layer of protection by making data unreadable to unauthorised individuals. Depending on the institutions, encryption may be applied by default to storage devices, files or data transfers between systems.
Be Aware of Where Data Are Stored
When using cloud services, survey platforms or other online systems, it is important to understand where the data are stored and which organisations have access to them.
This may be particularly important when working with personal or confidential information.
Find more detailed information in our dedicated guide on sensitive data.
Storage Is Not Backup
A common misconception is that storing data somewhere automatically means they are protected against loss.
In reality, storage and backup are not the same thing.
For example, a file stored on a laptop, an external hard drive, a shared network drive or a cloud service may still be lost if the device fails, the file is deleted accidentally, the account becomes inaccessible or the data become corrupted.
A storage location answers the question:
Where is my data?
A backup answers a different question:
How can I recover my data if something goes wrong?
| Situation | Storage? | Backup? |
|---|---|---|
| A dataset stored on a laptop | ✓ | ✗ |
| A dataset stored on a USB drive | ✓ | ✗ |
| A dataset stored on a cloud service | ✓ | Not necessarily |
| A dataset stored in multiple independent copies that can be used to recover lost data | ✓ | ✓ |
A good storage solution should include backup mechanisms, but researchers should not assume that this is always the case. It is important to understand whether backups are provided automatically, how often they occur and how data can be recovered if needed.
One commonly used principle is the 3-2-1 rule, which recommends keeping at least three copies of data, stored on two different types of media, with at least one copy stored in a separate location.
These additional copies are intended for recovery in the event of data loss and should not be treated as active working copies of the data.
Key Takeaways
- A good storage location should be reliable, secure, accessible and appropriate for the needs of the project.
- Research data may be stored in many locations during a project, including computers, institutional systems, cloud services, scientific instruments and data collection platforms.
- Storage media such as hard drives, USB drives and memory cards can fail or deteriorate over time and should not be relied upon as the only copy of the data.
- Collaborative projects benefit from shared storage locations, clearly defined access permissions and agreed working practices.
- Sensitive data may require additional safeguards, such as restricted access, encryption and the use of approved storage solutions.
- Storage and backup are not the same thing. A storage location answers where the data are, while a backup helps recover them if something goes wrong.
- The 3-2-1 rule is a commonly used principle for reducing the risk of data loss, but backup copies should not be treated as active working copies of the data.
Author: Jonathan England
Created: August 2026