ITS and UVa logos for printed output

Box (UVA Box)

UVA Box User Responsibilities & Data Restrictions

Jump to...

What May Be Stored in a UVA Box Account

UVA Box is a storage and collaboration service providing faculty, staff, and students at the University of Virginia the ability to access, store, and share a wide range of University content securely from almost anywhere. It is important, however, that you be a good caretaker of institutional information, only use your UVA Box account for certain kinds of data, and access it via official (not third-party) Box apps.

  Data Permitted in UVA Box Data Prohibited in UVA Box
UVA Box & Official Box Apps (i.e., apps developed by Box, not third parties*)
  • Health information, including HIPAA-protected data
  • Social Security, passport, or financial account numbers
  • Credit card processing (PCI) data
  • Export-controlled research (e.g. ITAR, EAR)
  • Any other highly sensitive data (refer to University policy for examples)

*Third-party apps are likely to pull information out of the secure Box environment and should not be used for institutional data.

Box's Intended Use at UVA

  • UVA Box is intended for University-related activities only. For personal activities, you can get a personal account with Box or with another cloud storage provider.
  • UVA Box is not intended for highly sensitive data.

What May Not Be Stored in a UVA Box Account

Acceptable use of your UVA Box account is limited to files containing only non-sensitive or moderately sensitive data; the storage of files containing institutional data classified as “highly sensitive” is prohibited. This includes personal information that can lead to identity theft if exposed, and health information that reveals an individual’s health condition and/or history of health services use. (Refer to University policy for examples.)

If you need to store highly sensitive data, you must use other, specially configured UVA internal services. Please contact the UVA Information Security Office or Health Information & Technology Office for additional information.

Management of University Data in Box

All federal and state laws, plus the University of Virginia information policies and data protection standards, and’s Terms of Service, apply to your use of UVA Box.

  • Official Information Requests: As with other UVA-provided storage services, you must provide all materials concerning University business to the University, if requested, in accordance with the Freedom of Information Act (FOIA), internal investigations or audits, subpoena, search warrant, or other legal actions.
  • Leaving the University: 
    • Faculty & Staff: You must turn over to your department supervisor/chair all materials concerning University business when your employment relationship with the University has ended. 
    • Graduating Students: Your UVA Box and its contents will be migrated to a free, personal Box account, but anything more than 50GB of data will be "Read Only". 
    • For complete information on managing your data after leaving UVA, see "What happens to my files when I graduate?" and "What happens to my files if I leave my job at UVA or retire?".
  • Data Retention: You must retain all materials concerning University matters in accordance with the University Records retention and disposition schedules on the UVA Records Management Office website.

Use of Apps with University Data in Box

You may only use official Box apps (that is, apps that have been developed by, and store data on, Box). Third-party applications that can sync with Box—for example, Google Apps, Microsoft SkyDrive, etc.—take University data out of the secure UVA Box environment and onto other companies’ application servers.

The UVA contract with Box does not extend to those companies or third-party applications at this time, so their use for institutional data is prohibited.

  Page Updated: Tuesday 2017-12-19 11:55:55 EST