Microsoft told Police Scotland in 2023 it ‘cannot guarantee data sovereignty’
The 2017 assessment was produced after a meeting Dyson chaired in his then-role as City of London police commissioner, in which stakeholders weighed 15 risks the UK would face if police forces transferred their data to Microsoft’s global cloud. The meeting considered both the police’s use of Microsoft software, such as Office 365, and the reliance on the Azure cloud that underpins those services. Dyson was also senior information risk owner (SIRO) for all of Britain, the post responsible for setting norms on how police could safely handle data.
The decision to migrate police data to commercial cloud platforms stemmed from a “cloud first” policy introduced by the Cabinet Office in 2013, which pushed nearly all government departments to move their data to commercial cloud offerings. Up to 60% of UK government IT infrastructure is now hosted on cloud platforms. Britain’s intelligence data is hosted on Amazon’s cloud services, as is its customs data. The Ministry of Defence uses Azure. The UK government spends billions annually on three US tech companies — Amazon, Google and Microsoft — including at least £1.9bn on Microsoft software each year.
Police data held on the platform now includes criminal records, victim statements, internal emails, body-worn video, digital evidence and case files from more than 40 UK police forces, according to a former senior policing source who spoke to the Guardian. Some files exceed “official” classification under UK government rules, raising the possibility they could be classed as “secret” or “top secret.” “A significant volume” of the data exceeded that classification, the assessment said.
The assessment specifically warned that Microsoft’s software “carries vulnerabilities which will be exploited by cybercriminals and other threat actors in due course.” It added that “police forces cannot be certain where their data will be processed or stored” and identified “a risk of compromise of sensitive data shared by, or taken from, Microsoft by the US government being released by US government insider attackers.” The document concluded that the arrangement “places sensitive data, inadequately protected in an environment which then becomes a significantly more attractive target for attackers.”
Five specialists who reviewed the Guardian’s findings told the paper the risks identified in 2017 persist today. Almost every UK police force now depends on Microsoft Azure, and some forces, including Police Scotland, are still finalising their adoption of the technology. Some forces began migrating their data to the cloud in 2017.
“There’s no evidence that this has been properly understood,” the former senior policing source told the Guardian. The data is “some of the most sensitive that exists,” the source added. “You’re talking about information that, if it gets into the wrong hands, or if the information is incorrect, [means] people can get hurt or may die.”
When the Guardian approached the National Police Chiefs’ Council about the document, the council said “UK policing as standard requires the use of UK-only datacentres” but acknowledged that “on occasion” Microsoft employees could access the data “to provide support.” The NPCC added that access was limited to those with a genuine need and was subject to strict controls. Asked about potential US government access, a police spokesperson said they could not comment on the phrase “US government insiders,” because “terminology … changes continuously” and the document was “outdated.” “In line with the contract signed with Microsoft, we do not expect any sharing with the US government without the express permission of the UK government,” the spokesperson added.
Microsoft told the Guardian that “the suggestion that use of Microsoft cloud services means customer data is inherently insecure or automatically exposed to foreign governments is inaccurate.” The company said it “does not provide any government with direct or unfettered access to customer data” and that it had “never provided UK government data in response to any US or global authority request.” It added that, like all US-based tech companies, it responded to US government requests only through valid legal processes and that it had “strong guardrails” around data access by engineers. In a follow-up, the company added that it was bound by its “contractual commitments” and that “if UK law prohibits us from turning over data to another government, that is a binding law that would govern our response to any hypothetical demand.”
But those assurances appear to be at odds with Microsoft’s own earlier disclosures. In a 2023 disclosure to Police Scotland, the company said data “can go outside the UK” and that it “cannot guarantee data sovereignty,” the Guardian reported.
Two legal experts and several Microsoft engineers who spoke anonymously to the paper said those assertions did not reflect the actual risks. A Microsoft engineer who reviewed the Guardian’s findings said the information “could be viewed by hundreds of people around the world, some of them not vetted, many of them not directly employed by Microsoft.”
Dave Michels, a researcher with the Cloud Legal Project at Queen Mary University of London, said Microsoft’s cloud was “a global network of datacentres” with facilities on every continent, and that data stored on it could be split across multiple countries, from Sweden to Ethiopia. In recent years, Michels said, Microsoft had begun offering clients in Europe greater assurances about where their data was stored, including assuring some customers that their data would remain within EU borders. But the focus on data location was “a bit of a red herring,” he said, because thousands of engineers from more than 100 countries maintain Microsoft’s systems, including subcontractors in countries potentially hostile to the UK such as Israel, Egypt, China and Kazakhstan. “You’ve seen the list of their sub-processors of people who have access to customer data,” Michels said. “It’s a long list.” Some engineers could access UK police data directly as part of customer support, while many more could see key features of what the data included. “As a cloud customer, if you’re relying on a contractual commitment from a cloud provider not to hand over data when forced to under foreign law, that is not worth much more than the piece of paper it’s written on,” Michels added.
Douwe Korff, a professor of international law at London Metropolitan University, said the police statement that “we do not expect any sharing [of our data] with the US government” was “typical lawyers’ wriggling.” “The risk is obvious, even though the providers of the cloud and the government both have an interest in talking it down,” Korff said. US law, including the Cloud Act, allows US authorities to access any data held by US cloud companies, including data held abroad, without a warrant, and to require the companies not to disclose such access to cloud customers. Microsoft, Amazon and Google have said they would fight such requests, but “there is nothing that is legally binding” preventing them from sharing data if US authorities demanded it, Korff said.
The 2017 assessment had proposed mitigations including prompt server patching, keeping servers up to date and installing antivirus software, as well as applying Microsoft’s “out-of-the-box” native encryption. It left the final decision about using Microsoft up to individual police chiefs. Several specialists interviewed by the Guardian, including cloud computing specialists and Microsoft engineers, said those mitigations were inadequate because Microsoft’s internal encryption does not prevent its employees from accessing UK police data, nor would it stop the US government from obtaining the files.
Mark Butcher, a cloud expert who acts as a strategic adviser across government, said government security departments are “painfully aware of all the risks” but that senior leaders had relied on Microsoft’s reassurances. “The way that most senior leaders talk about it is: ‘Well, we’ve been reassured by Microsoft that it would never happen,’” Butcher said. The Guardian spoke to six people who have closely followed the country’s data storage arrangements over the past decade. Several of them said that senior leaders did not view dependence on US tech companies as a concern, and trusted them not to give data to US authorities.
“We really don’t know if the data has been breached or not,” the former senior policing source told the Guardian. “The truth is, however, the level of logging and information in the cloud systems would not necessarily tell us if there was a problem.” The source added: “All the security guys I worked with when this policy came in expected a big breach by now, and we know it will take that to change the police’s position.”