When you use OneDrive, you store, organise, and share data through Microsoft’s cloud service. How well that data is protected depends not only on technical security measures, but also on the legal and or­gan­isa­tion­al framework behind the service.

A brief summary of OneDrive security

Microsoft protects OneDrive data with several layers of security. Files are encrypted during transfer using TLS and protected at rest with mul­tilayered en­cryp­tion methods, including AES-256. However, standard OneDrive storage does not provide tra­di­tion­al end-to-end en­cryp­tion where only users control the en­cryp­tion keys.

Ad­di­tion­al features such as two-factor au­then­tic­a­tion and access controls provide further pro­tec­tion. Overall, OneDrive offers a high level of technical security for personal use and many business scenarios.

From a privacy per­spect­ive, OneDrive still requires a closer look. As a U.S.-based provider, Microsoft may be subject to legal access ob­lig­a­tions, including under the CLOUD Act. For busi­nesses in the UK, the key question is whether OneDrive is con­figured to meet internal security policies, industry re­quire­ments, and UK data pro­tec­tion rules such as the UK GDPR. This depends on factors such as account settings, access controls, retention policies, and the type of data being stored.

HiDrive Next Cloud Storage
Your data – available anytime, anywhere
  • Set it up ef­fort­lessly and start saving files straight away
  • Your data is available anywhere and on all devices
  • 100% GDPR compliant in European data centres

What is OneDrive?

With OneDrive, you can store and organise your files in Microsoft’s cloud. The service is available on common Windows systems as well as on macOS, iOS, and Android, and requires a Microsoft account. OneDrive is also included in many Microsoft 365 packages.

You can sync OneDrive files across devices or limit syncing to selected apps and devices. OneDrive also lets you create automatic backups and use sharing features to col­lab­or­ate with others on files.

What en­cryp­tion does OneDrive use?

Detailed in­form­a­tion about Microsoft’s OneDrive security measures is available on the Microsoft support page. It is important to dis­tin­guish between en­cryp­tion in transit and en­cryp­tion at rest.

When data is trans­ferred between your device and Microsoft’s servers, OneDrive uses TLS en­cryp­tion methods. Stored data is also protected at rest. Microsoft uses several methods for this, including drive-level en­cryp­tion, for example with BitLocker, and file-level en­cryp­tion based on AES-256.

This mul­tilayered security ar­chi­tec­ture provides a high level of pro­tec­tion against un­au­thor­ised access and brute-force attacks.

Access rights for data in OneDrive

Similar to Google Drive, OneDrive lets you share files and folders with selected people and define what they can do with them. You can:

  • specify whether re­cip­i­ents can only view content or also edit it.
  • share content with specific email addresses or through generated links.
  • set time limits or ad­di­tion­al re­stric­tions, depending on the account type and admin settings.

You can adjust or revoke existing per­mis­sions at any time, which helps you stay in control of your data.

Microsoft states that Zero Standing Access (ZSA) applies to employee access to customer data. This means Microsoft employees do not have permanent access to stored data. Access is only granted in defined ex­cep­tion­al cases, requires jus­ti­fic­a­tion and approval, and is subject to strict security controls.

For UK users and busi­nesses, gov­ern­ment and cross-border access can also be relevant. As a U.S.-based provider, Microsoft may have to comply with valid legal requests from U.S. au­thor­it­ies, including requests under the CLOUD Act. Companies should therefore consider not only technical access controls, but also legal access risks, UK GDPR re­quire­ments, and internal com­pli­ance policies when using OneDrive.

OneDrive and the CLOUD Act

The U.S. CLOUD Act was passed in 2018 and gives U.S. au­thor­it­ies a legal basis for re­quest­ing data from U.S.-based tech­no­logy providers. Companies such as Microsoft may be required to provide data in response to valid gov­ern­ment requests, even if that data is stored on servers outside the United States.

For UK busi­nesses, this means OneDrive should be assessed not only from a technical security per­spect­ive, but also from a legal and com­pli­ance per­spect­ive. Key questions include what type of data is stored, which Microsoft 365 package and con­trac­tu­al terms apply, how UK GDPR re­quire­ments are met, and whether ad­di­tion­al safe­guards are needed. These may include stricter access controls, retention policies, sens­it­iv­ity labels, en­cryp­tion options, and internal rules for handling con­fid­en­tial or regulated data.

How secure is OneDrive against cy­ber­at­tacks?

In general, Microsoft offers solid and reliable security for cloud storage, much like Google and Apple. This is es­pe­cially true if you use OneDrive for personal files or to back up data that is not business-critical. OneDrive includes several security measures against cy­ber­at­tacks and un­au­thor­ised access:

  • strong password pro­tec­tion for user accounts
  • two-factor au­then­tic­a­tion (MFA) for ad­di­tion­al account security
  • TLS en­cryp­tion during data transfer
  • mul­tilay­er en­cryp­tion for stored data, including AES-256
  • con­trolled access processes based on the Zero Standing Access principle
  • network isolation, firewalls and physical data centre security
  • malware scanning for uploaded files in Microsoft 365 en­vir­on­ments
  • ransom­ware detection and recovery features, depending on the package
  • version history and file recovery
  • Personal Vault for es­pe­cially sensitive files in personal accounts
  • granular sharing options for files and folders, such as access re­stric­tions for links
  • no­ti­fic­a­tions for sus­pi­cious sign-in attempts
  • account recovery using stored security in­form­a­tion
  • access logging and mon­it­or­ing, es­pe­cially in business en­vir­on­ments

Where are OneDrive servers located?

Where OneDrive data is stored and processed depends on the specific usage scenario and Microsoft service being used. Microsoft operates data centers worldwide, including in the U.S., Europe, and Asia.

For many European customers, Microsoft completed the EU Data Boundary in February 2025 after it was launched in 2023. This allows certain customer and personal data from core cloud services to be stored and processed within the EU and EFTA regions. While this mainly affects EU customers, UK busi­nesses should still review where their data is stored, which Microsoft services are being used, and whether in­ter­na­tion­al data transfers may occur in specific support, dia­gnost­ic, or legal access scenarios.

Tip

If the location of your data is es­pe­cially important, it is worth choosing cloud providers with clearly defined regional server locations and trans­par­ent data handling practices. Services with European data centres and clearly doc­u­mented privacy measures can help or­gan­isa­tions meet UK GDPR and internal com­pli­ance re­quire­ments more easily while reducing risks related to in­ter­na­tion­al data transfers.

Is OneDrive compliant with UK GDPR and EU data pro­tec­tion rules?

If you do business in the UK or EU, you must comply with ap­plic­able data pro­tec­tion reg­u­la­tions when storing and pro­cessing customer data. Whether OneDrive can be used in a compliant way depends on the specific setup and use case. Microsoft provides a range of con­trac­tu­al and technical found­a­tions for OneDrive and Microsoft 365, including a Data Pro­tec­tion Addendum, Standard Con­trac­tu­al Clauses, and detailed security and com­pli­ance in­form­a­tion.

At the same time, OneDrive remains relevant from a data pro­tec­tion per­spect­ive because it is provided by a U.S. company. Under certain con­di­tions, Microsoft may have to respond to lawful requests from gov­ern­ment au­thor­it­ies. Busi­nesses therefore need to consider not only technical security, but also the legal im­plic­a­tions of potential third-country access.

Microsoft has improved its data pro­cessing practices in recent years. With the EU Data Boundary, data from many European business customers is generally processed within the EU and EFTA. However, actual data pro­cessing still depends on the specific service, con­fig­ur­a­tion, and usage scenario.

For compliant use, companies should implement suitable technical and or­gan­isa­tion­al measures. These include a data pro­cessing agreement, clearly defined access rights, multi-factor au­then­tic­a­tion, and trans­par­ent in­form­a­tion for data subjects.

Is OneDrive secure for business and com­pli­ance?

Busi­nesses need to assess OneDrive carefully from a data pro­tec­tion and com­pli­ance per­spect­ive. Microsoft provides security and com­pli­ance features as well as con­trac­tu­al documents such as the Data Pro­tec­tion Addendum and Standard Con­trac­tu­al Clauses. However, each company remains re­spons­ible for ensuring that OneDrive is used in line with UK GDPR and, where ap­plic­able, EU GDPR re­quire­ments.

Because Microsoft is a U.S. provider, legal access ob­lig­a­tions such as the CLOUD Act also need to be con­sidered. Under certain con­di­tions, au­thor­it­ies may be able to request access to data. This risk should be included in the company’s data pro­tec­tion as­sess­ment. Companies should therefore review the current con­trac­tu­al terms, technical safe­guards, and data flows before using OneDrive for personal or sensitive data.

Companies using OneDrive should pay par­tic­u­lar attention to the following points:

  • a data pro­cessing agreement or Microsoft Data Pro­tec­tion Addendum
  • a clear legal basis for pro­cessing personal data
  • trans­par­ent in­form­a­tion in the privacy policy about the type, scope, and purpose of data pro­cessing
  • review of third-country data transfers and the safe­guards used
  • technical and or­gan­isa­tion­al measures such as multi-factor au­then­tic­a­tion and access controls

Under UK GDPR and, where ap­plic­able, EU GDPR, companies must conclude a data pro­cessing agreement with Microsoft if they store personal data in OneDrive for business purposes. This agreement should define:

  • which personal data Microsoft receives
  • why the data is shared with Microsoft
  • how long Microsoft stores the data
  • which rights, ob­lig­a­tions, and liability limits apply

To use OneDrive in line with GDPR re­quire­ments, companies should:

  • assess risks related to third-country data transfers, for example through a Transfer Impact As­sess­ment
  • review Microsoft’s current con­trac­tu­al and com­pli­ance doc­u­ment­a­tion
  • define internal rules for data clas­si­fic­a­tion and access
  • implement logging, mon­it­or­ing, and au­thor­isa­tion concepts

What are some al­tern­at­ives to OneDrive?

If you still have questions about Microsoft’s privacy measures and wonder how secure OneDrive is for your specific use case, it is worth comparing different cloud providers. This helps you assess the features, security levels, and privacy options offered by available OneDrive al­tern­at­ives.

European cloud providers, including providers based in Germany, are popular al­tern­at­ives to OneDrive. They often offer clearer data residency options and can make it easier to meet European data pro­tec­tion re­quire­ments if you do business there. Providers with strong privacy standards and GDPR-compliant server locations include IONOS HiDrive and Se­cure­Cloud, among others.

Reviewer

Go to Main Menu