Skip to content
Amrani Academy

3. Handling information remotely

Approved storage only: no personal accounts, no workarounds

Where you store work information matters as much as how you protect your devices. Remote working creates constant temptations to move data somewhere convenient: your personal email, a private cloud drive, a USB stick, a messaging app. Resist all of them.

Why approved storage exists

Your organisation's approved storage, typically corporate OneDrive, SharePoint, Google Workspace, or similar, is backed up, access controlled, encrypted, and recoverable. If a laptop dies or is stolen, the data survives. If someone leaves, access can be revoked. If there is a legal or data protection question, the organisation can find and account for its information. None of that is true of your personal Dropbox or Gmail.

The classic workarounds, and why they're incidents

Emailing a spreadsheet of client data to your personal address "to work on tonight" moves personal data outside the organisation's control, which can itself be a reportable data protection breach, even with good intentions. The same applies to saving files to a personal cloud account, a home computer's local drive, or an unencrypted USB stick. When you change roles or leave, that stranded data doesn't come back, and nobody knows it exists until it surfaces in the worst possible way.

Shadow IT

Signing up for unapproved apps and services with your work email, free file converters, note-taking tools, AI assistants, survey platforms, is known as shadow IT. Each one becomes an unmanaged copy of company or client data, on terms nobody has reviewed. If an approved tool doesn't meet your need, ask IT for one that does rather than quietly adopting your own.

The simple test

Before you save, send, or upload anything, ask: is this an approved company location? If yes, carry on. If no, or if you're not sure, stop and check. Working remotely should change where you sit, not where the data lives.

Course contents