Microsoft cloud platform exposes UK police data to US government access risks

13 hours ago 22

Sensitive UK police data, including information about victims, witnesses, and active operations, sits on Microsoft cloud infrastructure that an official security assessment found vulnerable to foreign government access. That includes the US government, which can compel disclosure under its own laws regardless of where the data physically resides.

The scope of exposure

Microsoft’s hyperscale cloud architecture routes data through a sprawling global network. Reports from investigations and Freedom of Information disclosures between 2024 and 2026 indicate that UK policing data could potentially be accessed from 105 countries via various subprocessors.

Microsoft itself has acknowledged it cannot guarantee data sovereignty for M365. The company also said it cannot operationalize case-by-case consent for international data transfers under Part 3 of the Data Protection Act 2018, which governs how law enforcement agencies handle personal data.

When asked for detailed risk assessments covering data transfers to non-adequate jurisdictions, Microsoft cited commercial confidentiality.

Concerns have been raised that encryption keys held by Microsoft and its partners could enable compelled disclosures under US laws, particularly the CLOUD Act. That 2018 US law allows American authorities to demand data from US-based tech companies regardless of where the data is physically stored.

Compliance gaps across UK police forces

As of December 2020, multiple UK police forces were found processing data on M365 without completing the required Data Protection Impact Assessments.

Police Scotland received specific warnings about its Digital Evidence Sharing Capability (DESC) system, which was piloted in 2023. The assessment concluded that DESC’s use of Azure would not meet legal requirements due to sovereignty concerns and CLOUD Act risks. The Scottish Biometrics Commissioner has called for regulatory investigation into whether current practices comply with Part 3 of the Data Protection Act 2018.

The Scottish Police Authority has echoed these concerns, noting that Microsoft’s inability to provide binding guarantees about data localization creates an untenable compliance position for agencies handling some of the most sensitive personal information in the country.

Why sovereign cloud alternatives matter now

The UK government is currently working through the Data Use and Access Bill, which aims to address some of the regulatory gaps that allow this situation to persist.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article