securityaffairs.com 21 Sept 2026, 07:28 UTC

UK Police Azure Move Raises Fresh Fears Over US Data Access

UK Police Azure Move Raises Fresh Fears Over US Data Access

A 2017 UK assessment warned that moving police data to Microsoft Azure could expose sensitive information to foreign access and software vulnerabilities. The document, signed off by then City of London Police Commissioner Ian Dyson in his role as the country’s senior information risk owner, covered 15 risks involving criminal records, victim statements, internal emails and data from more than 40 forces.

Some information was reportedly above the standard “official” classification, potentially reaching “secret” or “top secret”. One identified threat was “US government insiders” accessing or releasing data.

The Guardian reported that five specialists who reviewed the assessment believe the concerns remain relevant. All UK police forces now use Microsoft’s cloud wholly or partly, while the government spends at least £1.9bn a year on Microsoft software. Proposed safeguards included encryption, keeping systems updated and allowing individual chief officers to decide whether to use Azure. However, experts said Microsoft personnel could still access encrypted data and that encryption would not necessarily prevent US government access.

The report also highlights uncertainty over data location and legal jurisdiction. Microsoft’s infrastructure spans more than 100 countries, and the US CLOUD Act can require US-based companies to provide data they control even when it is stored overseas. Police officials told the Guardian that data remains in the UK and cannot be shared without permission, while Microsoft reportedly told Police Scotland in 2023 that data could leave the UK and that sovereignty could not be guaranteed.

A former policing source also questioned whether existing cloud logs could reliably reveal a breach. No confirmed breach is reported; the concern is that one might not be detected.

View full article

Article by CyberSIXT