Skip to main content
Category: Data Lifecycle and Disposal

Data Storage

Also known as: Data Storage Systems, Digital Storage
Simply put

Data storage is the recording of digital information onto a medium so it can be kept, protected, and retrieved for later use. It ranges from physical devices such as magnetic tape and optical discs to cloud-based systems where data is held on servers in off-site locations. In practice, storage combines the hardware and software that record, organize, and safeguard information.

Formal definition

Data storage refers to the hardware and software used to record, organize, and protect digital information on a storage medium so it can be retrieved and used later. Implementations span physical media (for example, magnetic tape and optical discs), on-premises storage systems, and cloud storage, in which digital data is stored on servers in off-site locations. From a governance and protection standpoint, storage is the layer where retention, access, and integrity controls are applied; it is distinct from the classification of data held (for example, whether that data constitutes personal data) and does not by itself determine lawful basis, retention obligations, or applicable jurisdiction. This entry describes the concept of storage generally and does not cover cross-border transfer mechanics, statutory retention periods, encryption or pseudonymization treatment, or the security controls that may be layered on top of stored data; those are addressed as separate topics, and note that storing data in encrypted or tokenized form does not on its own render it non-personal.

Why it matters

Data storage is the layer at which most retention, access, and integrity controls are actually applied, which makes it central to both information governance and data protection. Where and how information is held shapes whether an organization can locate, retrieve, and demonstrate control over the data it holds. Because storage is distinct from the classification of the data itself, an organization can store personal data, special category data, and non-personal operational data on the same systems, and it remains the organization's responsibility to know which is which. Governance frameworks generally expect accountability to be demonstrable, so the ability to show how stored data is organized and safeguarded matters more than a stated intention to protect it.

A common expert-level error is to assume that storing data in encrypted or tokenized form removes it from the scope of data protection obligations. It generally does not; encryption and tokenization are protective measures layered on top of storage, but they do not on their own render data non-personal. Storage decisions therefore do not by themselves determine lawful basis, statutory retention obligations, or applicable jurisdiction, all of which are governed separately. Treating storage as a compliance answer rather than a foundational infrastructure layer risks overlooking the separate legal and policy work that data protection typically requires.

Because storage spans physical media, on-premises systems, and cloud services held on servers in off-site locations, the practical questions it raises differ by deployment model. This entry describes storage as a concept and does not cover cross-border transfer mechanics, retention periods, or the specific security controls that may be applied; those are addressed as separate topics and should not be inferred from storage arrangements alone.

Who it's relevant to

Information Governance Leads
Storage is the infrastructure layer where ownership, retention, and access policies are operationalized. Governance leads need to map what is held across physical, on-premises, and cloud storage so that policy can be applied consistently and accountability can be demonstrated with evidence rather than stated intent.
Data Protection Officers and Privacy Professionals
DPOs and privacy professionals should recognize that storage does not by itself determine lawful basis, retention obligations, or applicable jurisdiction, and that storing data in encrypted or tokenized form does not make it non-personal. Storage arrangements inform, but do not resolve, these separate data protection questions.
Security and Infrastructure Teams
These teams design and maintain the hardware and software that record, organize, and protect stored data, and they typically apply integrity and access controls at this layer. Their work overlaps with governance but remains distinct: securing stored data is separate from classifying it or determining its retention and legal treatment.
Compliance Officers
Compliance officers rely on an accurate understanding of where data resides across storage systems to assess obligations. Because this entry does not address cross-border transfer mechanics, statutory retention periods, or specific security controls, those areas must be evaluated separately rather than inferred from the choice of storage medium or provider.

Inside Data Storage

Storage Location and Media
The physical or logical location where data resides, such as on-premises servers, cloud object storage, databases, backups, or removable media. The location can affect which jurisdiction's rules apply and, where data crosses borders, may implicate transfer mechanics that are out of scope for this entry.
Storage Limitation Principle
Under the EU GDPR and UK GDPR, personal data should generally be kept in a form permitting identification of individuals for no longer than is necessary for the purposes for which it is processed. This principle links storage to defined retention periods, though the specific retention rules and schedules are addressed separately.
Security Controls at Rest
Information security measures applied to stored data, such as encryption at rest, access controls, and integrity protections, addressing confidentiality, integrity, and availability. Note that applying encryption or tokenization to stored data does not, on its own, render that data non-personal.
Governance Metadata
Data governance elements associated with stored data, including ownership, stewardship assignments, data catalogs, and lineage. These are governance concerns distinct from security controls, though the two overlap where access policy is enforced technically.
Controller and Processor Responsibilities
Where a data controller determines purposes and means of storage, it bears primary accountability for lawful storage and retention; a data processor typically stores data only on documented instructions from the controller. Accountability generally requires demonstrable evidence of these arrangements, not merely stated intent.
Pseudonymized and Anonymized Data in Storage
Stored pseudonymized data remains personal data because re-identification is reversible, and remains in scope for data protection regimes. Genuinely anonymized data, where identification is irreversible, is generally out of scope for most regulation. The distinction turns on reversibility, not on the storage method used.

Common questions

Answers to the questions practitioners most commonly ask about Data Storage.

Does encrypting stored data mean it is no longer personal data and therefore out of scope for data protection obligations?
No. Encryption of data at rest is a security control that reduces the risk of unauthorized access, but it does not render the underlying data non-personal. Where the controller or a related party retains the ability to reverse the encryption, the data generally remains personal data and stays within the scope of applicable regimes such as the EU GDPR or UK GDPR. Encryption is best understood as a safeguard supporting confidentiality and integrity, not as a mechanism that removes accountability, lawful basis, or data subject rights obligations.
Is deciding how and where data is stored purely an information security responsibility rather than a governance one?
No. Storage decisions sit at the intersection of information security and data governance and should not be collapsed into one discipline. Information security addresses the confidentiality, integrity, and availability controls applied to stored data, while data governance covers ownership, stewardship, classification, lineage, and the policies that determine what may be stored, by whom, and under what conditions. Both perspectives typically apply, and accountability under governance frameworks generally requires demonstrable evidence of these decisions rather than stated intent alone.
How should storage locations be documented in a way that supports accountability?
Storage locations, systems, and the parties responsible for them should generally be recorded in a manner that can be evidenced on request. Under the EU GDPR and UK GDPR, records of processing activities may reference storage arrangements, though a records of processing obligation is not the same as a data inventory tool and neither is a substitute for the other. Documentation should be maintained by the accountable role, kept current, and support the demonstration of governance decisions rather than merely asserting that controls exist. This entry does not address cross-border transfer mechanics associated with storage locations.
What is the relationship between storage and retention?
Storage concerns where and how data is held, while retention concerns how long it may be kept and when it must be deleted or otherwise disposed of. These are distinct but related considerations, and storage design typically needs to support retention outcomes such as timely deletion. The specific retention periods, lawful bases for continued storage, and deletion mechanics are out of scope for this entry and depend on jurisdiction, purpose, and implementation.
Who bears responsibility for stored data when a processor holds it on behalf of a controller?
Where a processor stores data on behalf of a controller, the controller generally remains accountable for determining the purposes and means of processing, including decisions that shape storage, while the processor typically acts on the controller's documented instructions and bears obligations relating to the security and handling of the data it stores. The precise allocation of obligations is usually set out in the arrangement between the parties. This entry does not address the full contractual requirements or the differences in treatment across regimes such as the CCPA and CPRA or HIPAA.
Do pseudonymized records stored separately from their re-identification keys still count as stored personal data?
Generally, yes. Pseudonymization is reversible, and where a re-identification key exists and can be linked back to individuals, the pseudonymized data typically remains personal data even if the key is stored separately. Separating the key is a recognized safeguard that can reduce risk, but it does not achieve the irreversibility associated with anonymization. Storage arrangements should therefore treat such records as personal data unless a defensible assessment establishes that re-identification is no longer reasonably possible.

Common misconceptions

Encrypting or tokenizing stored data removes it from data protection obligations.
Encryption and tokenization are security controls that reduce risk, but stored data that can still be linked back to individuals remains personal data. These techniques do not make data non-personal or place it outside the scope of applicable regimes such as the EU or UK GDPR.
The storage limitation principle sets a fixed, universal retention period.
The storage limitation principle under the EU GDPR and UK GDPR requires that data not be kept longer than necessary for its purpose, but it does not prescribe a single duration. Appropriate retention depends on purpose, context, and other legal obligations, and specific retention rules are handled separately from the storage concept itself.
Where data is stored is purely a security and infrastructure decision.
Storage decisions involve both information security controls and data governance concerns such as ownership, stewardship, and lineage. Storage location may also affect which jurisdiction applies and, where data moves across borders, may raise transfer considerations that are out of scope here.

Best practices

Define and document retention periods tied to specific processing purposes so that stored personal data is not kept longer than necessary, consistent with the storage limitation principle in the EU and UK GDPR.
Apply security controls such as encryption at rest and access restrictions, while recognizing that these controls do not remove data from the scope of data protection obligations.
Maintain governance metadata for stored data, including assigned ownership, stewardship, and lineage, keeping these governance functions distinct from but coordinated with security controls.
Record whether the organization stores data as a controller or a processor, and hold demonstrable evidence of the corresponding responsibilities and instructions rather than relying on stated intent.
Track whether stored data is pseudonymized or genuinely anonymized, treating pseudonymized data as still in scope and confirming irreversibility before treating any data as anonymized.
Where storage locations span jurisdictions or cross borders, escalate to assess applicable law and transfer mechanics, which fall outside the scope of the storage concept alone.