Skip to content

Leadership1 publisher3 min readPublished

Britain's police signed off the Azure sovereignty risk in 2017

More than 40 UK police forces hold sensitive data on Microsoft Azure, and according to a Guardian investigation the 2017 assessment that cleared the move already recorded that US government insiders would be able to see it.

The Board Room · Leadership desk

Illustration accompanying Britain's police signed off the Azure sovereignty risk in 2017

What happened

  • A Guardian investigation found sensitive police data on Microsoft cloud platforms that an official UK security assessment deemed vulnerable to compromise by foreign actors and the US government.
  • The material includes criminal records, victim statements and internal emails held by more than 40 police forces across the UK.
  • Microsoft told Police Scotland in a 2023 disclosure that data can go outside the UK and that it cannot guarantee data sovereignty.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • contradiction The police account and Microsoft's own disclosure cannot both describe the operative control, so any buyer resting sovereignty on contract language is choosing between them without having tested either.
  • exposure Because the accountable information risk owner signed the acceptance, a force arguing contractual sovereignty today is contradicted by its own signed assessment.
  • constraint Near-universal dependence on one platform limits this quarter's remedy to classification and placement, since substitution cannot be procured inside a budget year.
  • precedent Every department that migrated under cloud first inherits the same unresolved question about where its data is processed, whatever its contract says.

The 2017 summary is a record of accepted risk. Officers put in writing that "US government insiders" would be able to see the data, and that it could be "transmitted worldwide", with "the extent of this ... unknown" [6]. Ian Dyson chaired the meeting at which 15 risks were weighed, and he signed the document off [14]. He was commissioner of the City of London police at the time, and also the senior information risk owner for all of Britain, the officer whose job was to set the norms for how British police handled their data [15].

The assurance the police later gave the Guardian is hard to square with that record. They said Britain's contracts with Microsoft meant US authorities could not view data without express permission, and that the data held on Microsoft remained in the UK [11]. Microsoft told Police Scotland in 2023 that data "can go outside the UK" and that it "cannot guarantee data sovereignty" [12]. Six years separate the officers' acceptance of worldwide transmission from the vendor's statement that it cannot promise otherwise [19].

Microsoft said it "does not provide any government with direct or unfettered access to customer data", said it had not provided UK data in response to a US government request, and said that like all US-based tech companies it responded to such requests made through valid legal processes [13]. Those answers go to whether a handover has happened. The 2017 assessment recorded that "Police forces cannot be certain where their data will be processed or stored" [18], and that Microsoft's software "carries vulnerabilities which will be exploited by cybercriminals and other threat actors in due course" [17]. Five specialists who reviewed the Guardian's findings said the risks in that document persist today [7].

Procurement policy is why a documented risk became the default. The Cabinet Office introduced "cloud first" in 2013, a government-wide push to move almost all departments onto commercial public cloud, and departments that resisted had to jump through burdensome administrative hoops [16]. Four years later the police moved their most sensitive material [5]. Almost every UK force now depends on Azure, and the UK government spends at least £1.9bn on Microsoft software each year [8]. The platform runs on datacentres, networking gear and fibre spanning more than 100 countries [4].

Nothing in this record forces a migration this quarter, and at that level of annual software spend an exit is a programme measured in years [8]. The live decision is narrower: which datasets sit where, and whether the contractual guarantee the police described is written into a control someone has tested. Some files exceed the "official" classification, according to a police document seen by the Guardian, which on the Guardian's account raises the possibility the material could be classed "secret" or "top secret" [3].

"There's no evidence that this has been properly understood," said one source who has held senior roles in UK policing, who described the data as "some of the most sensitive that exists" [9]. He added that if such information gets into the wrong hands, or if it is incorrect, people can get hurt or may die [10].

What to watch

  • Whether any force publishes an updated risk assessment naming the controls that changed since Dyson signed the 2017 summary.
  • Whether Microsoft's UK contract terms are restated to match what police told the Guardian about data staying in the UK.
  • Whether the Cabinet Office revisits cloud first for material above the official classification.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories