skip to content

IT Help and Support

University Information Services
 

This guidance for Microsoft OneDrive for Business ("OneDrive") is to help you understand what data can be stored within this public cloud service, and what classifications of data OneDrive can hold on the basis of the current University Guidance on Data Security Classification.

Similar guidance may apply to other devices you use to store this data and appropriate protections may be necessary on those devices. You should seek out and become familiar with such guidance. It is assumed here that you are already familiar with that guidance.

We have also taken into account the current UK Government Classification system in order to provide additional information and assurance for you to ascertain what data will be appropriate for storage within this Public Cloud Service. Both sets of Classification and Guidance are being provided because of the broad usefulness of the current UK Government Guidelines, which are in use throughout the UK public sector and which have established and considered application in the use of Public Cloud Services.

It is important to note, in all levels of security classification, the principal factor in good data management is the 'need to know’ principle (Information is only shared to people who need to know the information).

University data security classifications and guidelines

The University Guidance defines the following classifications.

  • Level 0: Unclassified or public information Unclassified or public information is the largest class containing the majority of information.
  • Level 1: Cambridge Only This covers information that is only available to students and staff within the Cambridge domain. It includes memoranda, minutes of meetings (not otherwise marked), and site-licensed software.
  • Level 2: Confidential information This covers certain minutes of meetings, general personal information, financial information, or other information designated as confidential but that may be dealt with by any staff with delegated responsibility from the recipient (i.e. it is not, in a strict sense, information 'for your eyes only').
  • Level 3: Personal and strictly confidential information This covers documents that contain highly sensitive information or personal details that are for the eyes of the recipient only where delegated authority is not appropriate.

Application to OneDrive

The Microsoft EES Agreement includes Terms and Conditions that are compliant with UK/EU Data Protection Law and the University Statutes and Ordinances. Microsoft provide EU Model clauses in agreements, hold ISO 27001 and ISO 27018 certifications and operate their data centres within the European Economic Area. The Services offered are integrated with authentication processes entirely within the control of the University of Cambridge.

Staff should note that specific contractual obligations applying to aspects of their work may supersede this guidance and those obligations should be treated as exceptions. Staff should ensure they are aware of any contractual obligations and treat those as having precedence; if in doubt, staff should seek guidance from local Data Protection Officers.

Hence the current policy on the use of OneDrive is:

Subject only to the exclusions below, data under Data Classification Levels 0, 1 and 2 above CAN be stored in OneDrive.

Data excluded from the above includes:

  • data classified as Level 3 above
  • patient identifiable data (including other identifiable data which is subject to the Clinical School’s mandatory data security policy which can be found at http://www.medschl.cam.ac.uk/research/information-governance/)
  • data that is subject to a specific contractual agreement that specifies a particular storage method (that is not OneDrive)
  • data that is subject to a specific contractual agreement that prohibits storage in a public cloud service.

Such data MUST NOT be stored in OneDrive.

Incident reporting

Any breach (loss of data, unauthorised access, 'over-sharing' or any other security incident) must be reported to:

Further information

For further information on classification of data or if you are unsure if your data may fall into an excluded category please contact: .

UIS Service Desk

Phone padded  Service status line: (01223 7)67999
Website  Sign up for SMS/email status alerts
Website  Read major IT incident reports

UIS bITe-size bulletin

A regular newsletter aimed at the University's IT community, highlighting service and project news from UIS.

Sign up >

Latest news

New email address policy: an update from the Chair of the Information Services Committee

5 May 2022

This update from Professor Andy Neely was sent directly to Cambridge staff by email on Thursday 5 May 2022. Dear all, As Chair of the University’s Information Services Committee, I wrote to you in December 2021 with news about a new University policy on the allocation and management of email addresses. This relates to all...

We’re thinking creatively as part of Learning at Work Week – are you?

4 May 2022

Join us and start thinking creatively to enhance your work and problem-solving skills as part of the national campaign, Learning at Work Week from 16 to 20 May.

Wireless access point rental charge increases for 1 August 2022

3 May 2022

We’ve published details of the University Wireless Service’s access point rental charge increases, which will come into effect on 1 August 2022. We hope this helps institutions that rent access points from us to adjust their budget projections accordingly. Worldwide silicon chip shortages and growth in logistical costs...