Data Storage
Data storage is the recording of digital information onto a medium so it can be kept, protected, and retrieved for later use. It ranges from physical devices such as magnetic tape and optical discs to cloud-based systems where data is held on servers in off-site locations. In practice, storage combines the hardware and software that record, organize, and safeguard information.
Data storage refers to the hardware and software used to record, organize, and protect digital information on a storage medium so it can be retrieved and used later. Implementations span physical media (for example, magnetic tape and optical discs), on-premises storage systems, and cloud storage, in which digital data is stored on servers in off-site locations. From a governance and protection standpoint, storage is the layer where retention, access, and integrity controls are applied; it is distinct from the classification of data held (for example, whether that data constitutes personal data) and does not by itself determine lawful basis, retention obligations, or applicable jurisdiction. This entry describes the concept of storage generally and does not cover cross-border transfer mechanics, statutory retention periods, encryption or pseudonymization treatment, or the security controls that may be layered on top of stored data; those are addressed as separate topics, and note that storing data in encrypted or tokenized form does not on its own render it non-personal.
Why it matters
Data storage is the layer at which most retention, access, and integrity controls are actually applied, which makes it central to both information governance and data protection. Where and how information is held shapes whether an organization can locate, retrieve, and demonstrate control over the data it holds. Because storage is distinct from the classification of the data itself, an organization can store personal data, special category data, and non-personal operational data on the same systems, and it remains the organization's responsibility to know which is which. Governance frameworks generally expect accountability to be demonstrable, so the ability to show how stored data is organized and safeguarded matters more than a stated intention to protect it.
A common expert-level error is to assume that storing data in encrypted or tokenized form removes it from the scope of data protection obligations. It generally does not; encryption and tokenization are protective measures layered on top of storage, but they do not on their own render data non-personal. Storage decisions therefore do not by themselves determine lawful basis, statutory retention obligations, or applicable jurisdiction, all of which are governed separately. Treating storage as a compliance answer rather than a foundational infrastructure layer risks overlooking the separate legal and policy work that data protection typically requires.
Because storage spans physical media, on-premises systems, and cloud services held on servers in off-site locations, the practical questions it raises differ by deployment model. This entry describes storage as a concept and does not cover cross-border transfer mechanics, retention periods, or the specific security controls that may be applied; those are addressed as separate topics and should not be inferred from storage arrangements alone.
Who it's relevant to
Inside Data Storage
Common questions
Answers to the questions practitioners most commonly ask about Data Storage.