Universities and schools provide cloud storage to students and staff as a matter of course. Microsoft 365 Education gives students access to OneDrive. Google Workspace for Education provides Google Drive. These tools are deeply embedded in academic life — assignments, research drafts, lecture notes, and group project files flow through them constantly.
Many students also use the same accounts for personal files. It’s convenient. The storage is often large. The apps are already installed. Why not?
The answer involves admin access, data retention after graduation, institutional monitoring policies, and privacy terms that differ substantially from the consumer versions of the same products. Your school’s cloud account is not the same privacy environment as your personal cloud account. Understanding the difference matters for anyone who has used — or is currently using — an educational account for personal storage.
How Educational Cloud Accounts Differ from Consumer Accounts
When you sign up for a personal Google account or personal Microsoft account, you’re an individual customer of a consumer service. Google and Microsoft’s consumer privacy policies govern your data, and the account belongs to you indefinitely.
When a school provisions a Google Workspace for Education or Microsoft 365 Education account for you, the dynamic shifts in important ways:
The school is the customer, not you. Educational cloud accounts are purchased by the institution. The contractual relationship is between Google or Microsoft and the school — not between Google or Microsoft and you as an individual. This means the terms that govern your data are negotiated by and primarily protect the institution.
The school is the account administrator. Every educational Google Workspace or Microsoft 365 deployment has an administrator — typically the school’s IT department or a designated staff member. Administrators have access to capabilities that the account holders themselves do not.
The account is temporary. Student accounts are typically deactivated at graduation or shortly after. Unlike a personal account you might maintain for decades, an educational account has a built-in expiration tied to your enrollment status.
What School Admins Can See in Google Workspace for Education
Google provides educational institutions with administrative capabilities through the Google Admin console. These capabilities include:
Email access: School admins with appropriate permissions can access students’ Google Workspace email — read, search, and export individual accounts. This capability is primarily intended for institutional purposes (legal requests, safety investigations, IT support), but the access exists regardless of purpose.
Drive file access: Admins can access Google Drive files stored in educational accounts. Via Google Vault, institutions can preserve, search, and export files from individual student accounts. Every document you’ve created or stored in your school Google Drive is potentially accessible to the institution’s authorized administrators.
Activity logging: Google Workspace for Education logs user activity — login times, IP addresses, file access events, sharing activity, and application usage. Admins can access these activity reports for any account in the domain.
Device management: If you’ve connected your personal phone or computer to your school Google account through managed device enrollment, the institution may have the ability to see a list of devices connected to the account, and in some managed configurations, to remotely wipe the device.
Audit logs: Every administrative action and many user actions create audit log entries that the institution retains. Even if you delete a file from your school Drive, the deletion event is logged.
Google’s transparency about these capabilities is notable — the Admin SDK documentation makes these access levels explicit. Less noted is that students using these accounts are often not informed about this administrative access in practical terms.
What School Admins Can See in Microsoft 365 Education
Microsoft 365 Education provides similar administrative capabilities through the Microsoft 365 Admin Center and Microsoft Purview (formerly Compliance Center):
Email and Teams content: Institutional admins can access student Exchange Online email, Teams messages, and Teams meeting recordings through compliance tools. Microsoft Purview allows institutions to perform content searches across all communication channels in the tenant.
OneDrive files: Admins can access and recover files stored in OneDrive for Business accounts within the school tenant, including files you believe you’ve deleted.
Audit logs: Microsoft 365’s audit logging captures file access events, sharing events, login events, and significant account actions. These logs are available to institutional administrators.
eDiscovery: Microsoft’s compliance tools include full eDiscovery capabilities — the ability to search, preserve, and export any content in the institution’s Microsoft 365 tenant in response to legal investigations or court orders. This capability extends to student accounts.
Teams call recordings: If you’ve used Microsoft Teams for meetings and those meetings were recorded to the cloud, those recordings reside in institutional cloud storage accessible to admins and covered by the institution’s retention policies.
The FERPA Distinction
In the United States, the Family Educational Rights and Privacy Act (FERPA) protects students’ educational records — including grades, enrollment status, and academic history. FERPA grants students rights to access and correct their educational records and restricts disclosure to third parties without consent.
However, FERPA does not extend to all data in a student’s cloud account. A term paper stored in Google Drive is an educational record only if it has been submitted and graded. A personal journal you kept in OneDrive, or photos from a weekend trip stored in your school account, are not educational records under FERPA.
FERPA also does not restrict the institution’s own access to account data — it governs disclosure to external third parties. Your school can access data in educational accounts without FERPA restriction; it’s external disclosure that FERPA governs.
This means the FERPA protections that students may assume apply to their school accounts are significantly narrower than the actual data that resides there.
What Happens at Graduation or Account Closure
Educational accounts are provisioned for the duration of enrollment. When you graduate, leave, or are otherwise separated from the institution, the account is typically deactivated.
The timeline varies: Some institutions deactivate accounts within days of separation. Others offer a grace period of months. A few universities maintain alumni accounts for years. You typically won’t know the timeline until it’s about to apply to you.
Data deletion is not guaranteed or immediate: When an educational account is deactivated, the institution may retain the account data for compliance, legal, or archival purposes before any eventual deletion. Microsoft’s and Google’s agreements with educational institutions allow institutions to retain data according to their own data retention policies.
Files are gone from your access: From the moment your account is deactivated, you lose access to every file you stored exclusively in that account. If you haven’t exported and saved copies of your work, it may be inaccessible to you even if it’s still technically retained by the institution.
The migration window is rarely communicated clearly: Most graduates discover the loss of their school cloud storage after it’s already happened. A project portfolio built in Google Sites, research notes accumulated across years in Google Docs, or a photo archive backed up to school OneDrive — all of it becomes inaccessible at account closure.
Who Else Has Access
Beyond institutional administrators, educational cloud accounts may be accessible to additional parties:
Law enforcement: Educational institutions receive legal process — subpoenas, court orders, and national security letters — that require them to provide account data to law enforcement. Institutions are generally prohibited from notifying account holders when this occurs under certain legal process types.
Google and Microsoft themselves: As with any cloud service, the platform provider (Google or Microsoft) has access to account data under their technical architecture. Their data handling as processor is governed by their agreements with the institution.
Research and institutional analysis: Some institutions use aggregate anonymized data from institutional accounts for research purposes. The degree to which individual account data is involved varies.
Compromised administrators: An institutional IT administrator’s credentials can be phished or otherwise compromised, creating unauthorized access to the accounts in their domain.
Categories of Files That Especially Don’t Belong There
Given these access dynamics, some file categories are particularly ill-suited to school cloud accounts:
Personal journals and mental health notes: Students often use digital note-taking tools in school accounts for personal writing. Personal journals, mental health reflections, and therapy-adjacent writing have no place in an institutionally-administered account with admin access.
Legal documents: Immigration documents, legal correspondence, financial documents, or family legal materials stored in a school account are accessible to institutional administrators.
Personal photos: A collection of personal photos stored in school OneDrive or school Google Photos (where enabled) is accessible to admins and subject to the institution’s retention and access policies.
Off-topic medical information: Health-related files, appointment records, or personal health tracking that has nothing to do with the academic relationship should not be in an institutionally-controlled account.
Professional side work: If you’re doing freelance work during school, files related to that work — client materials, contracts, invoices — that are stored in your school account are in the institution’s data environment.
A Practical Approach to School Cloud Accounts
Using school cloud accounts for academic work is entirely reasonable. Using them exclusively for all your personal storage is a meaningful privacy risk.
Keep academic and personal storage separate. Use your school account for school work — that’s what it’s for. Maintain a separate personal cloud storage account for everything else.
Export important academic work before graduating. Give yourself a month before graduation to export every file you’ll want to keep. Download complete copies of your coursework, research, and academic writing to personal storage before your access ends.
Don’t rely on school cloud accounts for files with long-term value. Personal projects, creative work, and any file with sentimental or professional value should live in storage you control indefinitely — not in storage that expires when your enrollment does.
Check your school’s account policies. Most universities publish their acceptable use policy and data retention policy. Reading them (even briefly) gives you a concrete picture of what your institution’s administrators can access and how long data is retained.
Use personally-owned storage for sensitive content from day one. The habit of using your school account for everything is easy to fall into. Treating it as a school-use-only tool from the beginning is easier than migrating years of personal files after the fact.
The Broader Pattern
Educational cloud accounts are one example of a pattern worth recognizing: provisioned accounts — cloud storage or email provided by an employer, a school, an internet service provider, or any other institution — are not equivalent to personal accounts in terms of privacy and data ownership.
Every provisioned account is ultimately controlled by the provisioner, not you. The privacy terms that govern it are the institution’s terms with the platform provider, not your terms as an individual. The account can be terminated by the institution at any time for any reason.
Understanding this distinction before accumulating years of personal data in provisioned storage is the best way to avoid the frustrating discovery — at graduation, at job change, or after a disciplinary matter — that your personal files were never really as private as you assumed.
Personal storage that you own, pay for directly, and can carry across your entire adult life is a different thing from storage provided as a benefit by an institution with its own interests, policies, and legal obligations. Both have their place. Only one should hold your most personal files.