Security1 publisher2 min readPublished
Police risk owner signed off on US insider access to UK criminal records in 2017
A Guardian investigation surfaced the 2017 assessment for moving UK criminal records and victim statements onto Azure, with US government insiders among the 15 risks its signatory accepted. Five specialists say the risk stands.
The Watch · Security desk

What happened
- A 2017 document signed off by then City of London police commissioner Ian Dyson, who also held the national senior information risk owner title, reviewed 15 risks of moving police data onto Microsoft Azure.
- The data at stake includes criminal records, victim statements, internal emails and material from more than 40 UK police forces, some of it above the standard "official" classification.
- The document names the threat directly: sensitive data shared by or taken from Microsoft by the US government, then released by US government insider attackers.
- The Guardian reports that officers accepted the data would be visible to "US government insiders" and could be "transmitted worldwide", with "the extent of this ... unknown".
- Every UK police force has since put data wholly or partly on Microsoft's cloud, and the UK government spends at least 1.9bn pounds a year on Microsoft software.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction A force relying on the police assurance that data stays in the UK is relying on a guarantee its supplier told Police Scotland it cannot give. Neither party has reconciled the two positions in public.
- exposure With provider-managed encryption as the main control and a compellable US parent above it, the insider entry on the risk register is accepted risk for every tenant holding victim statements and criminal records.
- constraint If the logging in these systems would not show provider-side access, forces cannot answer the breach question either way, and any incident review starts with no evidence to examine.
- decision Michels's point applies outside policing: a buyer with sensitive-jurisdiction data has to test which legal entity can be compelled to hand it over, because EU-style residency assurances address where the data is stored.
Whether that risk entry becomes an actual disclosure depends on US law. Under the CLOUD Act, American authorities can compel a US-based company to produce data it controls even when the data sits outside the United States. In some cases the company can be barred from telling the customer that a demand arrived [11]. Microsoft, Amazon and Google have said they would challenge such requests when possible [12].
The 2017 document proposed three protections: Microsoft's built-in encryption, keeping servers updated, and letting individual police chiefs decide whether to use the service [8]. Specialists interviewed by the Guardian, Microsoft engineers among them, said encryption does not prevent Microsoft employees from accessing the data. They also said it would not necessarily prevent the US government from obtaining it [9].
Dave Michels, a researcher at Queen Mary University of London's Cloud Legal Project, told the Guardian that Microsoft's cloud infrastructure spans over 100 countries. Pieces of a single file can end up stored across several of them, Sweden to Ethiopia [10]. Microsoft has started offering EU customers assurances that data stays within European borders. Michels called the focus on data location somewhat beside the point, because the people who can access the data matter more than the servers holding it [13].
"The risk is obvious, even though the providers of the cloud and the government both have an interest in talking it down," Douwe Korff, professor of international law, told the Guardian [14].
Two statements on the record do not fit together. Police officials told the Guardian the data stays in the UK and that Microsoft cannot share it without permission [15]. Microsoft told Police Scotland in 2023 that data can leave the UK and that it cannot guarantee data sovereignty [16]. That was six years after the assessment was signed [19].
"All the security guys I worked with when this policy came in expected a big breach by now, and we know it will take that to change the police's position," a former senior policing source told the Guardian [17]. The same source said: "The truth is, however, the level of logging and information in the cloud systems would not necessarily tell us if there was a problem. We really don't know if the data has been breached or not" [18].
Security Affairs, summarising the Guardian's findings, wrote that the former officer's statement is not a claim that nothing has happened. It is a claim that the available logs and monitoring might not detect a breach even if one had occurred [20]. No incident is reported.
What to watch
- Whether Microsoft or UK policing reconciles the 2023 Police Scotland statement on data sovereignty with the claim that police data stays in the UK.
- Whether any force publishes an audit of provider-side access to its Azure tenant, or admits its logging cannot produce one.
- Whether the EU Data Boundary style assurances are extended to UK policing workloads, and whether they cover access as well as storage location.