Last reviewed: Next review due:
The core risk: data you upload is data that can be compelled
When you upload a file to a mainstream cloud storage provider, you are handing a copy of that file to a company that can be legally compelled to produce it. In the UK, a production order under PACE or an equipment interference warrant under the IPA 2016 can require a provider to produce your files. US providers can be served US orders under the CLOUD Act, which has a broader reach than UK law in some respects.
This does not mean you should never use cloud storage. For the vast majority of journalism, it poses no practical risk. The issue arises when cloud storage is used for: unpublished investigation notes; source contact details; raw interview recordings; or documents received from sensitive whistleblowers. For this material, the alternatives below significantly reduce your exposure.
Provider risk comparison
US company. CLOUD Act and US legal orders apply. Google can read your files. Large data requests transparency report published annually.
US company. Apple Advanced Data Protection (ADP) provides E2E encryption if enabled — but only in some regions and for some data types. Verify your settings. Standard iCloud is not E2E encrypted.
US company. Dropbox encrypts data in transit and at rest, but holds the encryption keys. Can produce decrypted files under legal order.
Free, open-source client-side encryption. You encrypt before uploading. Provider only sees ciphertext. Works with any provider. You manage the key.
Swiss/EU company. Zero-knowledge encryption. Provider cannot read your files. Designed for regulated industries and privacy-sensitive use. Commercial.
Swiss company, same organisation as ProtonMail. End-to-end encrypted, open-source clients. No access to file contents by provider. Competitive pricing.
Red flags
- Storing unpublished investigation notes or source contact details in Google Drive or iCloud.
- Sharing a Dropbox link with a sensitive source.
- Using a work Microsoft OneDrive account for personal investigation research — your employer can access it.
- iCloud backups of your iPhone enabled without Apple Advanced Data Protection turned on.
- Assuming that a password on a cloud folder makes it inaccessible to the provider.
Cloud storage security checklist
- I do not store unpublished sensitive investigation material in mainstream cloud storage (Google Drive, Dropbox, OneDrive).
- If I use iCloud, I have enabled Apple Advanced Data Protection in my iPhone Settings.
- For sensitive documents, I use Cryptomator to encrypt before uploading to any cloud provider.
- For high-sensitivity material, I use Proton Drive or Tresorit (zero-knowledge providers).
- I do not use work-owned cloud storage for personal investigation research or source communications.
- I have reviewed what my phone automatically syncs to iCloud or Google Photos (including documents, contacts, messages).
Source protection checklist
Cloud storage decisions are part of your source protection posture. Assess your full workflow.
Source Protection ChecklistCommon mistakes
- Assuming cloud storage is secure because it requires a password to log in.
- Not reviewing automatic backup settings — iCloud and Google can sync far more than you realise.
- Using a work cloud account for private investigation research — employers have access.
- Downloading documents from a source into Google Drive without considering the metadata implications.
- Confusing in-transit encryption (standard) with zero-knowledge encryption (rare) — most providers offer the former only.
Related guides
Primary sources
- Cryptomator — client-side cloud encryption (cryptomator.org)
- Proton Drive — zero-knowledge encrypted cloud storage
- Tresorit — end-to-end encrypted cloud storage
- Apple Advanced Data Protection documentation
- Police and Criminal Evidence Act 1984 — production orders (legislation.gov.uk)
- Investigatory Powers Act 2016 (legislation.gov.uk)
Frequently asked questions
Can UK police or courts access my Google Drive or iCloud?
What is Cryptomator and how does it help?
What is a zero-knowledge cloud storage provider?
Does UK GDPR protect journalist data in cloud storage?
Related guides
Primary sources
- Proton Drive — Zero-Knowledge Encrypted Storage— Proton
- Cryptomator — Client-Side Cloud Encryption— Cryptomator Project
- Tresorit — End-to-End Encrypted Cloud Storage— Tresorit
- Police and Criminal Evidence Act 1984— legislation.gov.uk
- Investigatory Powers Act 2016— legislation.gov.uk
- Guide to UK GDPR— Information Commissioner's Office
- Protecting Data in the Cloud— Electronic Frontier Foundation