skip to content

IT Help and Support

University Information Services
 

This guidance for Microsoft OneDrive for Business ("OneDrive") is to help you understand what data can be stored within this public cloud service, and what classifications of data OneDrive can hold on the basis of the current University Guidance on Data Security Classification.

Similar guidance may apply to other devices you use to store this data and appropriate protections may be necessary on those devices. You should seek out and become familiar with such guidance. It is assumed here that you are already familiar with that guidance.

We have also taken into account the current UK Government Classification system in order to provide additional information and assurance for you to ascertain what data will be appropriate for storage within this Public Cloud Service. Both sets of Classification and Guidance are being provided because of the broad usefulness of the current UK Government Guidelines, which are in use throughout the UK public sector and which have established and considered application in the use of Public Cloud Services.

It is important to note, in all levels of security classification, the principal factor in good data management is the 'need to know’ principle (Information is only shared to people who need to know the information).

University data security classifications and guidelines

The University Guidance defines the following classifications.

  • Level 0: Unclassified or public information Unclassified or public information is the largest class containing the majority of information.
  • Level 1: Cambridge Only This covers information that is only available to students and staff within the Cambridge domain. It includes memoranda, minutes of meetings (not otherwise marked), and site-licensed software.
  • Level 2: Confidential information This covers certain minutes of meetings, general personal information, financial information, or other information designated as confidential but that may be dealt with by any staff with delegated responsibility from the recipient (i.e. it is not, in a strict sense, information 'for your eyes only').
  • Level 3: Personal and strictly confidential information This covers documents that contain highly sensitive information or personal details that are for the eyes of the recipient only where delegated authority is not appropriate.

Application to OneDrive

The Microsoft EES Agreement includes Terms and Conditions that are compliant with UK/EU Data Protection Law and the University Statutes and Ordinances. Microsoft provide EU Model clauses in agreements, hold ISO 27001 and ISO 27018 certifications and operate their data centres within the European Economic Area. The Services offered are integrated with authentication processes entirely within the control of the University of Cambridge.

Staff should note that specific contractual obligations applying to aspects of their work may supersede this guidance and those obligations should be treated as exceptions. Staff should ensure they are aware of any contractual obligations and treat those as having precedence; if in doubt, staff should seek guidance from local Data Protection Officers.

Hence the current policy on the use of OneDrive is:

Subject only to the exclusions below, data under Data Classification Levels 0, 1 and 2 above CAN be stored in OneDrive.

Data excluded from the above includes:

  • data classified as Level 3 above
  • patient identifiable data (including other identifiable data which is subject to the Clinical School’s mandatory data security policy which can be found at http://www.medschl.cam.ac.uk/research/information-governance/)
  • data that is subject to a specific contractual agreement that specifies a particular storage method (that is not OneDrive)
  • data that is subject to a specific contractual agreement that prohibits storage in a public cloud service.

Such data MUST NOT be stored in OneDrive.

Incident reporting

Any breach (loss of data, unauthorised access, 'over-sharing' or any other security incident) must be reported to:

Further information

For further information on classification of data or if you are unsure if your data may fall into an excluded category please contact: .

UIS Service Desk

Phone padded  Service status line: (01223 7)67999
Website  Sign up for SMS/email status alerts
Website  Read major IT incident reports

UIS bITe-size bulletin

A regular newsletter aimed at the University's IT community, highlighting service and project news from UIS.

Sign up >

Latest news

New University Card Management System launches 15 September

18 August 2022

UIS will launch the new University Card Management System in September. We’re aiming for Thursday 15 September, however, this will be dependent on progress with printing the new student cards. The system will be down for a day. We will confirm the date nearer the time. Once the new system is live, Card Reps will be using...

MCS Linux service deprecated

17 August 2022

We have deprecated the MCS Linux service because of technical and resource constraints. At its peak, MCS Linux accounted for only 2% of MCS machines deployed, and use of this service has declined steadily in recent years. Unfortunately, we have had to remove the Linux part of the service because of unforeseen technical...

New cloud research platform service from UIS

15 August 2022

Amazon Web Services (AWS) and RONIN available via UIS UIS is pleased to announce that access to Amazon Web Services (AWS) and RONIN are now available through a new University-provided cloud research platform service. If you would like to join the increasing number of Cloud users and to save around 11% on list prices for...