More than 40 police forces across the United Kingdom have stored highly sensitive data on Microsoft’s Azure cloud platform, raising concerns about potential vulnerabilities and access by foreign actors, including the US government. The data involved includes criminal records, victim statements, internal communications, body-worn video footage, and other law enforcement materials, some of which have been classified beyond "official" levels, potentially reaching "secret" or "top secret."

In 2017, a senior policing official, Ian Dyson—then Commissioner of the City of London Police and the senior information risk owner (SIRO) for UK policing—oversaw an assessment of risks associated with migrating police data to Microsoft’s cloud services. The review identified at least 15 risks, notably highlighting vulnerabilities to cyberattacks and the inability to guarantee the exact locations where data would be stored or processed due to the global and distributed nature of Microsoft’s cloud infrastructure.

The assessment specifically warned of the threat posed by “US government insiders,” stating that sensitive information hosted on Microsoft’s platform could potentially be accessed or released by personnel within the US government. The hyper-scale and international distribution of Azure’s data centers mean police data and metadata could be transmitted and held worldwide, with the extent of this distribution unclear. This raised concerns that the data was insufficiently protected in an environment attractive to attackers.

Officials proposed mitigations, including prompt patching of servers, antivirus protections, and enabling Microsoft’s native encryption. However, cybersecurity experts and engineers familiar with the platform have questioned the effectiveness of these measures. Native encryption does not prevent Microsoft employees, or by extension US government agencies, from accessing the data. Some engineers involved in supporting Microsoft’s cloud infrastructure reportedly have the ability to view data from across the globe, including sensitive police information, often without stringent vetting.

Despite the identified risks, UK police forces have broadly adopted Microsoft Azure since 2017, with some, such as Police Scotland, still in the process of full implementation. The National Police Chiefs’ Council stated that access to cloud data is restricted to authorized personnel and subject to strict controls, emphasizing contractual terms with Microsoft that reportedly prevent data sharing with the US government without explicit UK government consent. Nonetheless, the Council acknowledged terminology shifts and did not directly address concerns about potential US government access.

Microsoft has denied that its cloud services inherently compromise data security or expose customer information to foreign governments, asserting that it has never provided UK government data in response to any such requests. The company emphasized that any legal demands would be evaluated against UK law and contractual obligations. However, legal experts note that US legislation, such as the Cloud Act, permits US authorities to access data held by US cloud providers worldwide without requiring warrants or notifying customers, creating a potential legal avenue for extraterritorial data access.

Individuals with experience in UK policing and data security have expressed concerns that the full scope of data exposure remains unknown. Some believe that a significant breach may have already occurred or is likely, but current monitoring and logging systems may not detect or confirm such incidents. Although senior leaders reportedly remain confident in Microsoft’s assurances, experts stress that the risks involved in relying heavily on a US-based cloud provider for sensitive law enforcement data warrant closer scrutiny and stronger safeguards.