Skip to main content

File encryption

You can encrypt files that you want to be accessible only to yourself or to a limited group of people. Encrypt files at least when confidentiality of the data so requires. Files containing data classified as category 1R, such as special categories of personal data, must always be stored in encrypted form.

A method suitable for encrypting all types of files is to use appropriate encryption program, for which instructions are provided below.

In Microsoft Office applications, you can assign a sensitivity level to a document, but this does not result in the file being encrypted when saved; encryption must be done with a separate program.

Choosing an encryption program

There are three alternative programs from which you can choose the one that suits your needs. All the programs provide strong protection that is sufficient for storing all types of data, including special categories of personal data or other kinds of 1R class data. You can find the programs in the Software Center on a TUNI Windows computer. If you cannot find the program in a TUNI Mac or Linux computer, contact IT Helpdesk. The programs are free of charge and free of usage limitations, and users of their own home computers or people outside our higher education community can install them from public sources.

Choose a suitable program for your needs by evaluating the advantages and disadvantages of the following alternative programs.

Program and link to instructionsAdvantagesDisadvantagesSuitable use cases
VeraCryptEncrypted files can be edited easily.Only one person can use the vault at a time.
You must define the vault size when creating it, and you cannot increase it later.
Fits most needs.
When you may also need to store Office documents.
Backups.
CryptomatorEncrypted files can be edited easily.
Multiple users can open the vault at the same time.
The vault size grows dynamically as you add files.
Does not work well with Microsoft Office applications; see details in the intranet news.
Storing very large files in a vault located on a group folder (S drive) or personal storage (P drive) is very slow.
When no need for Office documents.
When no need to store large files (videos) on the S drive.
When you need simultaneous access by multiple users.
7-ZipFast and easy to use.
Widely used, so the recipient can easily open the archive.
Encrypted files can not be edited easily.Sending by email.
Backups.

Additional instructions

Handling encrypted files

When you handle (i.e. view and edit) files encrypted with an encryption program, always open the files directly from the virtual drive created by the encryption program and save any outputs generated during processing directly to that virtual drive. Do not copy (extract) files from the virtual drive elsewhere for processing, as this easily leaves an unencrypted copy behind unintentionally. 

However, working as described above may prove far too slow or otherwise cumbersome, for example when a Cryptomator vault is stored in a shared folder (S: drive) and contains very large files. In such a situation, you can proceed as follows. However, the working method explained below contains significantly more risks than the method explained in the previous paragraph. That is why you should try first to work according to the working method explained in the previous paragraph.

  1. Create a new VeraCrypt volume on your computer’s hard drive in a folder that is not synchronised anywhere else, such as OneDrive. On a Windows computer, Downloads is a suitable folder. Create a volume large enough to hold all the files you expect to work with during a single working day.
  2. Repeat all the steps 3-10 every working day.
  3. Open the VeraCrypt volume on your computer, creating for example drive D:.
  4. Open the Cryptomator vault or VeraCrypt volume on the S: drive, creating for example drive E:.
  5. Copy the files you plan to work with today from E: to D:.
  6. Open files from D: and edit them as needed. Save any modified files and any new files you create to D:. Close all applications you used for editing.
  7. Copy all files from D: to E:.
  8. Check that you can open the files on E: and they seem OK.
  9. Delete all files from D:. This ensures that you do not keep unnecessary duplicate copies of the files that could make it difficult to keep track of where the most recent version is stored.
  10. Lock all vaults and volumes (as you would normally do at the end of each working day).

You can continue to use the volume you created in step 1 on subsequent working days. As its purpose is only to serve as temporary storage during the working day, it is advisable to keep it empty between working days for clarity.

In case a file becomes corrupted or is lost during file processing, make backup copies of the vault or volume on the S: drive from time to time to another storage location, such as P: or the Downloads folder on your Windows computer. Add the current date to the end of the backup name.

Sharing encrypted files

To share encrypted files within Tampere Universities, create the vault or volume on the S drive and grant the user right to everyone who needs the files. Users can then open the vault or volume from the S drive with the encryption software and work with the files. Please note the shared-use limitations described in the table above.

Unfortunately, sharing encrypted files with partners outside Tampere Universities is more complicated. For instructions, see the page Sharing files with partners (under construction).

Encrypting to a USB drive or memory stick

  • If you want to store data classified as 1R, such as sensitive personal data, on a standard USB drive or memory stick, you must first encrypt the USB drive at the file system level. On a Windows computer, this means encrypting it with BitLocker; instructions are provided below. For Mac computers, see the corresponding instructions on Apple’s website. Only after this may you store data on the USB drive, encrypted with one of the encryption tools mentioned above. Note that on Windows, a USB drive encrypted at the file system level works only on Windows computers. The same applies to Mac computers.
  • You can also request from IT Helpdesk a USB drive that automatically encrypts its contents and works with all operating systems. Data classified as 1R, such as sensitive personal data, must still be encrypted with an encryption program even when stored on such a drive.
  • If the drive needs to be delivered to another person, provide the password or code required to open the drive separately from the password used in the encryption program, for example one via text message and the other via encrypted email. Inform the recipient from where to install the encryption program you used, or store on the drive the installation files or a portable version of the encryption program for all required operating systems.

Transferring encrypted data

You can transfer data classified as 1R, such as sensitive personal data, securely by packaging and encrypting it into a single file using VeraCrypt or 7-Zip and sending the file via the Funet FileSender service. Use a long password, at least 20 characters. Send the password used for encryption by text message to the recipient’s personal phone number. In this way, you can send files outside our higher education community or transfer them between systems, such as from Windows to Mac or vice versa.

 

IT Helpdesk
0294 520 500
it-helpdesk [at] tuni.fi (it-helpdesk[at]tuni[dot]fi)
helpdesk.tuni.fi

Published: 2.6.2026
Updated: 7.9.2026