Skip to main content
Category: Systems and Technology

Cloud Storage

Also known as: cloud data storage, online storage
Simply put

Cloud storage is a way of saving data on remote servers managed by a third-party provider, where it can be accessed over the internet rather than on local computers or physical hard drives. Organizations store data with the provider and retrieve it online as needed. This differs from keeping files on equipment physically located within the organization.

Formal definition

Cloud storage is a model of computer data storage in which data is held on remote servers, typically managed as a service by a third-party provider, and stored in logical pools accessible to users over a network such as the public internet. It is often offered as a managed service capable of holding variable amounts of data, including unstructured data, with retrieval on demand. The evidence available describes cloud storage as a general computing service and does not address its recordkeeping implications; whether data held in cloud storage constitutes an authoritative record, and how retention, disposition, integrity, and jurisdictional obligations apply, depends on organizational policy, contractual arrangements, and applicable legal and regulatory requirements that fall outside the scope of these sources.

Why it matters

Cloud storage has become a common location for the data and files that organizations create and manage, which raises important considerations for records professionals. When information that may constitute a record is held on remote servers managed by a third-party provider rather than on equipment physically located within the organization, questions arise about who controls the data, how its integrity is maintained, and how it can be reliably retrieved over time. The evidence available describes cloud storage as a general computing service and does not itself address these recordkeeping implications, so professionals should treat storage location as one factor among several rather than as a determinant of records status.

Whether data held in cloud storage constitutes an authoritative record, and how retention, disposition, integrity, and jurisdictional obligations apply to it, typically depends on organizational policy, contractual arrangements with the provider, and applicable legal and regulatory requirements. Because a provider manages the underlying servers as a service, the organization's ability to demonstrate authenticity and to control retention and disposition may rest heavily on the terms of the service agreement. These arrangements vary, and requirements differ across jurisdictions and sectors, so organizations often need to assess cloud storage against their own recordkeeping and compliance frameworks rather than assuming default arrangements will meet those obligations.

The distinction between storing data and managing records is significant here. Cloud storage, as described in the available sources, is a mechanism for holding and retrieving data on demand; it does not by itself provide the classification, retention scheduling, disposition controls, or evidential safeguards that recordkeeping typically requires. Organizations relying on cloud storage for information that has record value should consider how those recordkeeping functions are provided, whether by the storage service, by additional systems, or by organizational process.

Who it's relevant to

Records Managers
Records managers need to consider whether data held in cloud storage constitutes an authoritative record and how classification, retention, and disposition controls apply when data resides on servers managed by a third-party provider. Because cloud storage as described is a general storage service rather than a recordkeeping system, records managers often need to assess how recordkeeping functions are provided alongside or on top of it.
Information Governance Officers
Information governance officers assess cloud storage within the broader accountability framework spanning policy, risk, privacy, and security. Their interest extends to how contractual arrangements with the provider, organizational policy, and applicable legal and regulatory requirements shape the organization's control over data held remotely.
Compliance and Legal Leads
Compliance and legal leads are concerned with how retention, disposition, integrity, and jurisdictional obligations apply to data stored with a third-party provider. Because these requirements typically depend on jurisdiction, sector, and the terms of the service agreement, legal review of provider arrangements is often warranted.
IT and Infrastructure Teams
IT and infrastructure teams implement and manage cloud storage as a service, handling how data is stored in logical pools and retrieved on demand over the network. They often work with records and governance functions to ensure that storage arrangements support the organization's recordkeeping and compliance requirements.

Inside Cloud Storage

Off-premises storage infrastructure
Cloud storage typically refers to the provision of data storage capacity by a third-party provider, accessed over a network, rather than on infrastructure the organization directly owns and operates. In a recordkeeping context, records held in cloud storage remain subject to the same lifecycle controls as records held on-premises.
Shared responsibility arrangement
Responsibility for the security, availability, and configuration of cloud storage is often divided between the provider and the customer. The precise division depends on the service model and contractual terms, and the recordkeeping accountability for records generally remains with the organization even where operational custody rests with the provider.
Service and deployment models
Cloud storage is commonly offered under varying service arrangements and deployment models, such as public, private, or hybrid configurations. The chosen model can affect where data physically resides, who can access it, and how retention and disposition controls can be applied.
Data location and residency considerations
Because cloud storage may hold data across multiple facilities or jurisdictions, the physical or legal location of stored records can be relevant. Requirements relating to data residency, cross-border transfer, and jurisdictional obligations depend on jurisdiction, sector, and organizational policy.
Contractual and service terms
The relationship with a cloud storage provider is typically governed by contracts and service-level terms covering matters such as availability, security, access, retrieval, and the return or deletion of data. These terms are central to determining whether recordkeeping obligations can be met.
Records lifecycle controls in a cloud setting
Records placed in cloud storage still require controls for capture, classification, retention, and disposition. Cloud storage is a storage mechanism and does not by itself constitute a recordkeeping system, so the properties that make something an authoritative record, such as authenticity, reliability, integrity, and usability, must still be maintained.

Common questions

Answers to the questions practitioners most commonly ask about Cloud Storage.

Does storing records in the cloud mean the records are automatically managed or preserved?
No. Cloud storage typically refers to the hosting of digital content on infrastructure operated by a third-party provider, and it should not be equated with records management. Storage provides capacity and availability, but it does not by itself apply classification, retention, disposition controls, or the metadata needed to sustain authenticity, reliability, integrity, and usability over time. Records-management functionality generally must be configured or layered on top of storage through additional systems, policies, and controls, depending on organizational requirements.
Does moving records to the cloud transfer responsibility for compliance and recordkeeping to the provider?
Not typically. Under most cloud arrangements, the provider is responsible for aspects of the underlying infrastructure, while the organization generally retains accountability for how records are classified, retained, disposed of, and protected. This division is often described as a shared responsibility model, though the precise allocation depends on the service type and contractual terms. Legal, regulatory, and privacy obligations commonly remain with the organization that owns the records, and these obligations vary by jurisdiction and sector.
How can retention and disposition be enforced for records held in cloud storage?
Enforcement typically requires that retention rules and disposition actions be governed by policy and, where possible, applied through system controls rather than left to manual practice. This may involve integrating cloud storage with recordkeeping functionality that supports classification, retention scheduling, and defensible disposition, which may include destruction, transfer, or permanent preservation. Organizations often need to confirm that a provider can genuinely execute and evidence disposition, since apparent deletion at the application level does not necessarily correspond to removal across all copies and backups. The available mechanisms depend on the platform and organizational configuration.
What should organizations consider about data location and jurisdiction when using cloud storage for records?
The physical or logical location where records are stored can carry legal and regulatory significance, because obligations relating to privacy, access, and cross-border transfer differ across jurisdictions. Organizations often need to establish where data resides, where it may be replicated, and which legal regimes may apply as a result. Because requirements depend on jurisdiction and sector, it is generally advisable to clarify these matters through contractual terms and to seek appropriate legal or compliance advice rather than assuming any single regime applies.
How can the authenticity and integrity of records be maintained in cloud storage?
Maintaining the properties that make content an authoritative record, such as authenticity, reliability, integrity, and usability, generally requires controls beyond the act of storage. This often includes capturing and preserving metadata, applying access and change controls, maintaining audit trails, and ensuring that records remain usable as formats and systems evolve. In cloud environments, organizations typically need assurance that these controls operate as expected and can be evidenced, and the specific measures available depend on the platform and how it is configured.
What issues around access, continuity, and exit should be addressed before adopting cloud storage for records?
Organizations often consider how records will remain accessible over their required retention period, including in the event of service disruption, provider change, or contract termination. Relevant considerations may include the ability to retrieve records and their associated metadata in usable formats, arrangements for continuity and business resumption, and clear exit provisions. Because records may need to be retained well beyond the life of any single contract or provider relationship, these matters are typically addressed through policy and contractual terms, with the appropriate arrangements depending on organizational requirements and applicable obligations.

Common misconceptions

Storing records in the cloud transfers records management responsibility to the provider.
Under a shared responsibility arrangement, the provider often handles operational custody of the infrastructure, but accountability for the records themselves typically remains with the organization. The division of responsibility depends on the service model and contract, and does not usually relieve the organization of its recordkeeping and compliance obligations.
Cloud storage is itself a records management system.
Cloud storage is primarily a storage mechanism. It does not inherently provide the classification, retention scheduling, disposition, and control capabilities needed to manage records as evidence across their lifecycle. Those functions must be provided by additional systems, configuration, or governance regardless of where the data is held.
Data location does not matter once records are in the cloud.
The physical or legal location of stored data can be significant. Requirements relating to data residency, cross-border transfer, access, and jurisdictional obligations vary across jurisdictions and sectors, so where records reside may affect how obligations are met.

Best practices

Clarify the shared responsibility arrangement in writing, documenting which controls the provider operates and which the organization retains, so that recordkeeping accountability is not lost at the boundary.
Ensure lifecycle controls for capture, classification, retention, and disposition are applied to records in cloud storage, recognizing that the storage mechanism alone does not deliver these functions.
Confirm how the properties that make something an authoritative record, such as authenticity, reliability, integrity, and usability, will be maintained while records are held with a third-party provider.
Review data location and residency implications against applicable jurisdictional and sector requirements before placing records in the cloud, and revisit this as arrangements change.
Negotiate and review contractual and service terms covering access, retrieval, security, and the return or deletion of data at the end of the relationship, and verify they support your retention and disposition obligations.
Evaluate the service and deployment model against organizational policy and risk tolerance, since the model chosen can affect where data resides and how controls can be applied.