UK Police Data on Microsoft Azure Vulnerable to US Access
A Guardian investigation reveals sensitive UK police data stored on Microsoft Azure may be accessible to the US government despite UK data sovereignty claims.
A Guardian investigation has revealed that highly sensitive UK police data, including victim statements and criminal records, is stored on Microsoft Azure cloud platforms and remains vulnerable to compromise by foreign actors and the US government.
Microsoft Corporation provides the infrastructure used by nearly every UK police force following a 2013 cloud first policy introduced by the Cabinet Office. A 2017 security assessment signed by Ian Dyson, then the senior information risk owner for British police, warned that US government insiders could access the data and that the global infrastructure could transmit information worldwide.
While the National Police Chiefs' Council and Microsoft claim that strict controls keep the data within the UK, Microsoft previously disclosed to Police Scotland that it cannot guarantee data sovereignty. Legal experts highlight that the US Cloud Act allows US authorities to access data held by US companies regardless of physical storage location, potentially overriding any contractual commitments made to the UK government.