Microsoft cloud platform exposes UK police data to US government access risks

Microsoft cloud platform exposes UK police data to US government access risks

A Guardian investigation found that data from more than 40 police forces sits on Microsoft infrastructure despite longstanding concerns over foreign access and data sovereignty.

Sensitive data from more than 40 UK police forces is stored on Microsoft Azure despite an internal security assessment warning that the information could be vulnerable to foreign access, according to a Guardian investigation.

The files include criminal records, victim statements, internal emails and other sensitive police information. Some data exceeds the UK government’s standard official classification, raising the possibility that certain files could fall under higher security classifications.

The concerns date back to a 2017 police assessment conducted before forces moved significant amounts of data onto Microsoft’s cloud infrastructure. The document warned that police could not be certain where their data would be processed or stored and said information could potentially be transmitted globally through Microsoft’s infrastructure.

Advertisement

The assessment also identified a potential risk involving US government insiders gaining access to sensitive information held by Microsoft. Five specialists who reviewed the findings for the Guardian said the underlying risks remain relevant today.

Almost every UK police force now relies on Microsoft Azure to some degree, according to the report. The Guardian said the data stored on the platform includes intelligence, body worn video, digital evidence and case files.

The National Police Chiefs’ Council disputed suggestions that police data was inadequately protected. It said UK policing generally requires the use of UK only data centers and does not expect information to be shared with the US government without permission from the UK government.

Microsoft also rejected the suggestion that using its cloud services automatically exposes information to foreign governments. The company said it does not provide governments with direct or unrestricted access to customer data and said it has never provided UK government data in response to a request from US or other foreign authorities.

Microsoft separately says its UK Azure data centers have undergone security assessments designed for law enforcement customers and comply with Police Assured Secure Facilities requirements.

The dispute highlights broader concerns around data sovereignty as UK public institutions become increasingly dependent on cloud infrastructure operated by US technology companies. The Guardian reported that as much as 60% of UK government IT infrastructure is hosted on cloud platforms, while police forces have increasingly relied on Azure since migrations began in 2017.

There is no evidence cited in the investigation showing that the police data has actually been compromised. A former senior policing source told the Guardian, however, that existing monitoring may not be sufficient to establish with certainty whether unauthorized access has occurred.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Microsoft cloud platform exposes UK police data to US government access risks
Microsoft cloud platform exposes UK police data to US government access risks

A Guardian investigation found that data from more than 40 police forces sits on Microsoft infrastructure despite longstanding concerns over foreign access and data sovereignty.

Share

Add us on Google

Sensitive data from more than 40 UK police forces is stored on Microsoft Azure despite an internal security assessment warning that the information could be vulnerable to foreign access, according to a Guardian investigation.

The files include criminal records, victim statements, internal emails and other sensitive police information. Some data exceeds the UK government’s standard official classification, raising the possibility that certain files could fall under higher security classifications.

The concerns date back to a 2017 police assessment conducted before forces moved significant amounts of data onto Microsoft’s cloud infrastructure. The document warned that police could not be certain where their data would be processed or stored and said information could potentially be transmitted globally through Microsoft’s infrastructure.

Advertisement

The assessment also identified a potential risk involving US government insiders gaining access to sensitive information held by Microsoft. Five specialists who reviewed the findings for the Guardian said the underlying risks remain relevant today.

Almost every UK police force now relies on Microsoft Azure to some degree, according to the report. The Guardian said the data stored on the platform includes intelligence, body worn video, digital evidence and case files.

The National Police Chiefs’ Council disputed suggestions that police data was inadequately protected. It said UK policing generally requires the use of UK only data centers and does not expect information to be shared with the US government without permission from the UK government.

Microsoft also rejected the suggestion that using its cloud services automatically exposes information to foreign governments. The company said it does not provide governments with direct or unrestricted access to customer data and said it has never provided UK government data in response to a request from US or other foreign authorities.

Microsoft separately says its UK Azure data centers have undergone security assessments designed for law enforcement customers and comply with Police Assured Secure Facilities requirements.

The dispute highlights broader concerns around data sovereignty as UK public institutions become increasingly dependent on cloud infrastructure operated by US technology companies. The Guardian reported that as much as 60% of UK government IT infrastructure is hosted on cloud platforms, while police forces have increasingly relied on Azure since migrations began in 2017.

There is no evidence cited in the investigation showing that the police data has actually been compromised. A former senior policing source told the Guardian, however, that existing monitoring may not be sufficient to establish with certainty whether unauthorized access has occurred.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.