Guardian reveals UK police data stored on Microsoft Azure vulnerable to US access
Official security assessment found sensitive files from 40+ police forces at risk of compromise by US government and foreign actors.
What to know
- More than 40 UK police forces store highly sensitive data—criminal records, victim statements, classified files—on Microsoft Azure, which a 2017 official assessment found vulnerable to US government access and foreign compromise.
- Police claim UK contracts prevent US authorities from viewing the data and that it remains in the UK, but Microsoft disclosed to Police Scotland in 2023 that data "can go outside the UK" and it "cannot guarantee data sovereignty".
- The UK government spends at least £1.9bn on Microsoft software annually, and almost every police force now depends on Azure, despite risks identified nine years ago remaining unresolved.
- Five specialists confirmed the security risks from the original 2017 assessment persist today, raising concerns that potentially "secret" or "top secret" classified information may be vulnerable.
Storing sensitive police data on US-based cloud platforms undermines UK digital sovereignty and puts public safety at risk.
-
“Official assessments showing sensitive UK police data on US cloud platforms is vulnerable to US legal access and foreign compromise exposes our eroded digital sovereignty.”
Fife4Europe · Mastodon ↗
“US government insiders would be able to see the data, and that it could be "transmitted worldwide", with "the extent of this … unknown".”
2017 police decision document, Official UK police record · The Guardian ↗
Ian Dyson Senior UK police officerMicrosoft Cloud service providerUK Police Forces Data custodiansThe Guardian Investigative journalist
How it unfolded 1 development · click the chart to see its coverage articlesposts
-
1
Police and Microsoft respond to vulnerability allegations
When the Guardian approached police, they dismissed the risks, stating that UK contracts with Microsoft prevent US authorities from viewing data without permission and that data remains in the UK. Microsoft responded that it "does not provide any government with direct or unfettered access to customer data" and has not provided UK data in response to US government requests, though it acknowledged responding to US government requests through valid legal processes.
“There's no evidence that this has been properly understood. The data is "some of the most sensitive that exists". You're talking about information that, if it gets into the wrong hands, or if the information is incorrect, [means] people can get hurt or may die.”
— Senior UK policing source, Former senior police officer · source -
J
"As a cloud customer, if you’re relying on a contractual commitment from a cloud provider not to hand over data when forced to under foreign law, that is not worth much more than the piece of paper it’s written on.” The police were warned years ago this would be a security risk. # UKPolicing # Microsoft # Data # DataSecurity Sensitive UK police…
2 more of the top 3 · 5 posts in this stretch
-
I
"SENSITIVE POLICE DATA HELD ON 'VULNERABLE' CLOUD PLATFORM" @AishaDown.bsky.social for @TheGuardian.com Highly sensitive UK police data is held on Microsoft Azure, a cloud platform a Guardian investigation says is vulnerable to compromise by foreign actors. #TheGuardian #TomorrowsPapersToday
-
S
TL;DR: A UK security assessment reveals that sensitive police data stored on Microsoft cloud platforms is at risk of compromise by foreign actors and the US government, including criminal records and internal communications. The findings raise serious concerns about the security of critical information across over 40 UK police forces. https://www…
-
-
background
Guardian investigation reveals police data vulnerability to US access and foreign compromise — The Guardian publishes an exclusive investigation finding that sensitive files from more than 40 UK police forces—including criminal records, victim statements, internal emails, and some files exceeding "official" classification—are stored on Microsoft Azure, which an official UK security assessment deemed vulnerable to compromise by foreign actors and the US government. Five specialists reviewing the Guardian's findings confirmed the risks identified in the 2017 document persist today.
-
background
Microsoft discloses to Police Scotland that data can leave UK — Microsoft provided Police Scotland with a disclosure stating that data "can go outside the UK" and that it "cannot guarantee data sovereignty", contradicting later police statements about data remaining in the UK.
-
background
UK police decide to store sensitive data on Microsoft Azure — In a 2017 meeting chaired by senior officer Ian Dyson, British police stakeholders decided to transfer sensitive data to Microsoft's cloud platform. The decision document examined by the Guardian noted that officers accepted "US government insiders" would be able to see the data and it could be "transmitted worldwide", with "the extent of this … unknown".
Also covered reported alongside — the timeline has no entry for these yet
-
first by Guardian Tech, 5d ago · also Guardian
What people are saying 2 voices from 1 site · best of 5 · verbatim
- Sep 19
-
W
Such a wise decision to base UK police and other official IT procurement on # Microsoft and other US big tech. Has no-one in the upper echelons of the civil service ever heard of # DigitalSovereignty ? https://www. theguardian.com/uk-news/2026/s ep/18/sensitive-uk-police-data-vulnerable-to-compromise-by-us-government-and-foreign-actors
- Sep 18
-
F
Official assessments showing sensitive UK police data on US cloud platforms is vulnerable to US legal access and foreign compromise exposes our eroded digital sovereignty. Relying on foreign tech to store domestic intelligence risks public safety. Why hand over our data? (1/2) 🤔 # FBPE https://www. theguardian.com/uk-news/2026/s…