XClose

Advanced Research Computing

Home
Menu

Research Data Environment Decision Tool

Use this page and tool to determine the most appropriate UCL research data environment for your data based on its type, sensitivity and risk.

Where should I store my research data? 

What is the general rule at UCL? 

At UCL, all research data that includes personal data must be stored on UCL-managed or approved secure systems.  In research, most personal data should be treated as sensitive, and the default expectation is that it will be stored and analysed within a Tier 3 Trusted Research Environment.  In some cases, alternative UCL platforms or approved external systems may be appropriate.  However, this should be based on a clear justification, taking into account the sensitivity, identifiability, risk, and any contractual or regulatory requirements associated with the data.
 

Research Data Environment Decision Tool

In most research cases:

  • Personal data → should be treated as sensitive
  • Sensitive, identifiable, or regulated data → should be stored in a Tier 3 Trusted Reserach environment
  • Truly anonymous, low-risk data → can usually be stored in standard UCL systems


Start here:

Use the decision tool below (takes 2–3 minutes) to identify the most appropriate UCL research data environment for your data.

It will guide you through a small number of questions about sensitivity, identifiability, and risk, and provide a recommended approach.

(if accessibility features are not working in this embedded form, please open the form in a separate window using this link: https://forms.cloud.microsoft/e/f9zFgtMu7k)

Microsoft Form Widget Placeholderhttps://forms.cloud.microsoft/Pages/ResponsePage.aspx?id=_oivH5ipW0yTySE...|height=700

If you are unsure, or would like advice, please contact the UCL Information Governance Advisory Service via email at infogov@ucl.ac.uk or here on MyServices

The tool above is indicative only and does not replace a formal classification of research data.  Formal advice and support are available from the Information Governance Advisory Service. 

 

UCL platforms for research data 

Approved platforms for sensitive research data (Tier 3 Trusted Research Environment)

UCL-approved platforms for storing and working with sensitive research data include: 

 

Approved platforms for non-sensitive research data 

Research data that is not sensitive is also expected to be stored on UCL platforms, unless there is a clear and justified reason not to.  Common UCL storage platforms include: 

 

Can I just store my research data on UCL-managed storage? 

No, often this is not enough for research data.  Not all UCL-managed storage provides the same level of security.  Standard services such as OneDrive, SharePoint, or the S: drive are not designed for sensitive research data. In addition, contractual or regulatory requirements may mandate that data is stored in a higher-security location.  Tier 3 Trusted Research Environment are specialised platforms and should be used where higher levels of security are required.  

 

How do I decide if I need something more secure? 

In practice, decisions about where to store research data at UCL are based on a combination of four key factors:

  • Sensitivity (e.g. personal or special category data)
  • Identifiability (can individuals or organisations be identified?)
  • Risk (what would happen if the data were disclosed?)
  • Legal or contractual requirements (e.g. NHS or data sharing agreements)

You should consider all of these together rather than relying on a single factor.

 

What does Personal, Sensitive and Pseudonymised data mean?

  • Personal data:
    • Identifies a person directly or indirectly
    • Must always be protected
    • In research, usually treated as sensitive
  • Special category data:
    • Health, ethnicity, religion, etc.
    • Requires additional legal protections
  • Pseudonymised data:
    • Identifiers replaced with codes
    • Still personal data if re-identification is possible

 

What does “Highly Confidential” data mean at UCL? 

At UCL, research data is typically classified as “Highly Confidential” if it is sensitive, identifiable, could cause harm if disclosed, or is subject to legal or contractual controls.  This typically includes: 

  • Sensitive personal data (e.g. health data, ethnicity, genetics, criminal offence data) 
  • Data that can identify individuals, either directly or indirectly 
  • Pseudonymised data where re-identification is still realistically possible 
  • Data with legal or contractual restrictions (e.g. NHS data) 
  • Most research data that researchers would describe as “sensitive” will be classified as “Highly Confidential.” 

These are the same factors used to determine whether a Tier 3 Trusted Research Environment is required.

 

What is a “Tier 3 environment”? 

A Tier 3 environment (also called a Trusted Research Environment) is a highly secure, controlled workspace for working with highly confidential (sensitive) data. 

It provides stronger safeguards than standard storage, ensuring appropriate information security through access controls and the controlled movement and sharing of data. 

The UCL Tier 3 environments are the UCL Data Safe Haven and the ARC TRE. 

 

When should I use a Tier 3 environment? 

You should use a Tier 3 environment if your data meets one or more of the following: 

  • Includes personal data that is sensitive, identifiable, or could pose a risk if disclosed (in research, personal data should normally be treated as sensitive)
  • Includes special category (sensitive personal) data (e.g. health, ethnicity, genetics, criminal offence data)
  • Is pseudonymised but not truly anonymised (there is a realistic risk of re-identification)
  • Would be likely to cause harm to individuals or organisations if disclosed
  • Is subject to legal, contractual, regulatory, or ethical requirements requiring a secure environment (e.g. NHS data)

In short, if your data is sensitive (i.e. highly confidential), identifiable, persoanl, or tightly regulated, you should use Tier 3. 

 

When can I use standard UCL storage? 

Standard UCL services (e.g. OneDrive, SharePoint) are appropriate when: 

  • Your data is not highly sensitive 
  • Individuals cannot realistically be identified 
  • A breach would have low or moderate impact 
  • None of the Tier 3 criteria apply 

 This is what UCL calls “public” or “confidential” data rather than “highly confidential” data. 

 

What if my data has been anonymised? 

If your data has been properly anonymised, and individuals cannot realistically be identified, you may be able to use a less restrictive environment.  However, “Pseudonymised” data is not the same as anonymous.  If re-identification is still possible, the data should be treated as highly confidential and stored in a Tier 3 environment.  If your data could be linked to other datasets, contains detailed characteristics, or allows individuals to be singled out, it should also be treated as highly confidential and normally stored in a Tier 3 environment.  Err on the side of caution and choose a more secure environment if unsure.  Seek advice from infogov@ucl.ac.uk (we recommend doing this early, especially if your study involves sensitive or regulated data).  You can sometimes move to a lower level later if your data becomes genuinely low risk. 

 

Where can I find more guidance?