Back to News

Sensitive UK Police Data on Microsoft Azure Flagged as Vulnerable - What It Means for Data Sovereignty

Sensitive UK Police Data on Microsoft Azure Flagged as Vulnerable - What It Means for Data Sovereignty

A Guardian investigation published on 18 September 2026 reports that vast quantities of highly sensitive UK police data — criminal records, victim statements and internal emails from more than 40 police forces — are held on Microsoft Azure, and that an official UK security assessment found the arrangement vulnerable to “compromise” by foreign actors and by the US government. Some of the material is reported to exceed “official” classification, potentially falling into “secret” or “top secret” territory. Five independent specialists who reviewed the findings told the paper the risks persist today.

The detail that makes this more than a public–sector procurement story is the date on the paperwork. The decision to place sensitive police data on Microsoft’s platform followed a 2017 meeting chaired by Ian Dyson, then City of London Police Commissioner and the UK’s senior information risk owner. The risk assessment produced around that decision did not miss the exposure. It recorded it. It accepted that “US government insiders” could see the data, that the data could be “transmitted worldwide” with the extent “unknown”, and that “police forces cannot be certain where their data will be processed or stored”. This is not a story about a risk nobody spotted. It is a story about a risk that was written down, signed off, and then inherited by everyone who came afterwards — which is a pattern any UK business that has ever accepted a supplier risk on a one–page form will recognise.

40+
UK police forces whose data — criminal records, victim statements and internal emails — is reported to be held on Microsoft Azure
£1.9bn
Minimum annual UK government spend on Microsoft software, the scale that makes this a strategic dependency rather than a procurement choice
2017
Year of the meeting and risk assessment that accepted the exposure in writing — including that data could be “transmitted worldwide” with the extent “unknown”
5 of 5
Independent specialists who reviewed the Guardian’s findings and concluded that the risks identified in 2017 persist today

What the investigation reports

The core finding is one of scale combined with classification. More than 40 police forces hold material on Azure that includes criminal records, victim statements and internal correspondence. An official UK security assessment is reported to have concluded that this storage arrangement was vulnerable to compromise by foreign actors and by the US government, and that some of the files involved go beyond the “official” tier of the government classification scheme — potentially into “secret” or “top secret”. Those are not adjacent categories. They carry materially different handling requirements, and the gap between how data is classified and where it actually sits is the substance of the concern.

The 2017 documentation is the part that will be studied longest. The assessment accompanying the decision recorded that Microsoft’s software “carries vulnerabilities which will be exploited by cybercriminals and other threat actors in due course” — a statement that is simultaneously unremarkable, since it is true of all software, and striking in a document justifying the placement of national policing data. It also recorded that “police forces cannot be certain where their data will be processed or stored”. That sentence is the whole sovereignty question stated plainly, nine years before it became a headline.

Both sides of the argument as it now stands are on the record, and they do not entirely reconcile. Police told the Guardian that their contracts with Microsoft mean US authorities cannot view data without express permission, and that data stored on Microsoft remains in the UK. Against that, Microsoft is reported to have told Police Scotland in 2023 that data “can go outside the UK” and that it “cannot guarantee data sovereignty”. Microsoft, for its part, said it “does not provide any government with direct or unfettered access to customer data” and that it had not provided UK data in response to a US government request — while confirming that, like all US–based technology companies, it responds to US government requests made through valid legal processes.

That last sentence is the one to read twice, because it is not a contradiction and it is not an evasion. It is an accurate description of the position every US–headquartered provider occupies. A company can hold a genuine commitment not to grant unfettered access, can have received no relevant request, and can still be subject to a legal regime in which a valid, lawful demand must be answered. A contractual promise from a supplier and a statutory obligation on that supplier are different instruments, and where they conflict, the contract is not the one that prevails.

The risk here is jurisdictional, not technical — and that changes what “secure” means

Nothing in this story suggests Azure has been breached, that Microsoft has behaved improperly, or that a technical control has failed. That is precisely why it matters for UK organisations. The exposure described is a legal and jurisdictional one: a US–incorporated company can be compelled, through valid legal process, to respond to demands from its home government regardless of where the data physically sits or what a UK customer contract says. Encryption at rest, UK data residency commitments and an excellent security posture do not address that question, because it is not a security question. The uncomfortable implication for any business is that a supplier assessment can be entirely clean on every technical control and still leave a material exposure unexamined — because no standard questionnaire asks “under whose law does our provider ultimately operate, and what can it be required to do?”

Nine years from a signed–off risk to a front page

The chronology matters more than usual here, because the central claim of the reporting is not that something went wrong but that nothing changed. Each step below is individually defensible; the sequence is what produces the position.

2013 — the Cabinet Office introduces “cloud first”
Government policy pushes departments to migrate data to commercial public cloud platforms, frequently US–based, with what the reporting characterises as burdensome administrative hoops for those that resisted. The policy was a reasonable answer to a real problem — ageing, expensive, poorly secured public sector infrastructure. Its second–order effect was to make the path of least resistance run through a small number of very large American companies.
2017 — the meeting and the decision
British police decide to move sensitive data onto Microsoft’s platform following a meeting chaired by Ian Dyson, then City of London Police Commissioner and the UK’s senior information risk owner. The accompanying risk assessment accepts that “US government insiders” could see the data and that it could be “transmitted worldwide” with the extent “unknown”.
2017 — what the assessment says about the platform
The same assessment states that Microsoft’s software “carries vulnerabilities which will be exploited by cybercriminals and other threat actors in due course”, and that “police forces cannot be certain where their data will be processed or stored”. The exposure is therefore not discovered later by journalists. It is documented at the point of decision, and accepted.
2017 – 2026 — the dependency deepens
Adoption spreads until almost every UK police force depends on Microsoft Azure, and UK government spending on Microsoft software reaches at least £1.9bn a year. This is the phase in which a risk accepted once becomes structural: each additional force, system and integration raises the cost of revisiting the decision, until revisiting it is no longer a realistic option for any single organisation acting alone.
2023 — Microsoft’s statement to Police Scotland
Microsoft tells Police Scotland that data “can go outside the UK” and that it “cannot guarantee data sovereignty”. This sits awkwardly beside the position police elsewhere have given — that contracts mean US authorities cannot view data without express permission and that data stored on Microsoft remains in the UK. Both statements may be accurate about different things; the difficulty is that customers have been relying on the more reassuring one.
18 September 2026 — the Guardian publishes
The investigation sets out the scale of police data held on Azure across more than 40 forces, and reports that an official UK security assessment found the arrangement vulnerable to compromise by foreign actors and the US government, with some files exceeding “official” classification and potentially classifiable as “secret” or “top secret”.
18 September 2026 — the responses
Police point to contractual protections and UK data residency. Microsoft says it “does not provide any government with direct or unfettered access to customer data” and has not provided UK data in response to a US government request, while confirming that, like all US–based technology companies, it responds to US government requests made through valid legal processes. Five independent specialists who reviewed the findings say the 2017 risks persist.
20 September 2026 — where it stands
No technical failure has been alleged and no breach has been reported. What is in dispute is whether contractual assurances can answer a jurisdictional question, and whether a risk acceptance recorded in 2017 by one officer, in one meeting, should still be governing the handling of national policing data nine years and several hundred thousand records later.

Read as a whole, this is a governance failure rather than a security one, and the distinction is not academic. Security failures are addressed with controls. Governance failures of this shape — a risk formally accepted at a moment when the dependency was small, never re–examined as the dependency grew — are addressed only by someone deliberately reopening a decision that is nobody’s current responsibility. That is a much harder thing to make happen, in a police force or in a forty–person business.

What “sovereignty” actually buys you, by deployment model

The word sovereignty is used loosely enough to be nearly useless in supplier conversations, so it helps to be concrete about what different arrangements give you. The chart below is an indicative planning model — not measured data — ranking how much genuine control an organisation retains over where its data goes and who can compel access to it.

US hyperscaler, default region settings
12%
US hyperscaler, UK region pinned
29%
US hyperscaler plus customer–managed keys
44%
US hyperscaler’s UK or EU sovereign cloud offering
57%
UK–incorporated cloud provider
74%
On–premises or UK colocation
87%
Encrypted with keys held solely by you
94%

Two observations follow from that ordering, and both cut against the instinctive response to a story like this. The first is that pinning a UK region — the control most organisations reach for — moves you far less than people assume. Data residency addresses where bytes sit. It does not address who can be compelled to produce them, which is a function of where the provider is incorporated, not where the disk is. The 2017 assessment’s observation that forces “cannot be certain where their data will be processed or stored” and Microsoft’s reported 2023 statement that data “can go outside the UK” both point at the same gap between residency as a setting and residency as a guarantee.

The second is that the top of the chart is not a recommendation. Holding your own keys and running your own infrastructure genuinely does maximise jurisdictional control, and for the overwhelming majority of UK SMEs it would be a poor trade — worse availability, worse patching, worse physical security, worse recovery, and a far higher chance of an ordinary breach caused by ordinary neglect. The realistic answer for most organisations is not to leave the hyperscalers. It is to know which of their data would actually matter if a jurisdictional risk crystallised, and to treat that subset differently from everything else.

The finding that makes this current rather than historical

A story built on a 2017 document invites an obvious defence: that was nine years ago, the platform has moved on, the controls are better, the contracts are tighter. The Guardian put its findings to five independent specialists, and the answer came back without division.

5/5
All five independent specialists who reviewed the Guardian’s findings concluded that the risks identified in the 2017 assessment persist today — a unanimous verdict on the question of whether the passage of time has resolved the exposure

Unanimity among five reviewers is not proof, and specialists asked to comment on a security question are not a random sample of opinion. But it is a meaningful signal on the specific point at issue, which is narrow: not whether Azure is well–engineered, but whether the particular exposure documented in 2017 has since been closed. The reason it has not, on this reading, is structural rather than technical. The risk derives from the legal status of a US–incorporated provider, and no amount of engineering investment changes a company’s jurisdiction of incorporation.

It is worth being scrupulous about what is and is not alleged, because stories in this area attract more heat than they generate light. There is no reported breach. There is no allegation that Microsoft has acted improperly, and the company’s stated position — no direct or unfettered government access, no UK data provided in response to a US government request — is a substantive one. Equally, the confirmation that it responds to valid legal process is not a caveat that can be waved away, because it describes the precise mechanism the 2017 assessment was worried about. Both things are true at once, and an organisation making decisions here has to hold both.

The £1.9bn annual spend figure is what converts this from a debate into a constraint. At that level of dependency across government, the practical options available to any single department, force or agency are narrow. That is the real lesson for a business reading this: the moment to evaluate a jurisdictional risk is before the dependency is load–bearing, because afterwards the assessment becomes a formality conducted in the knowledge that no other answer is affordable.

Where UK SMEs carry the same exposure without knowing it

It is easy to read this as a policing story with no read–across to a fifty–person business. The read–across is direct, because the underlying mechanism — a supplier risk accepted once, never revisited as the dependency grew — is close to universal. The rows below reflect where that typically sits in an SME estate.

Data sovereignty and supplier–risk gaps in a typical UK SME
No record of which data categories would actually matter if a provider were compelled to disclose High
Supplier risk accepted at onboarding years ago and never re–examined as usage grew High
Data residency assumed from a region setting rather than confirmed in the contract High
Client confidentiality or professional privilege obligations not mapped to where that data sits High
Backups held with the same provider as production, inheriting identical jurisdictional exposure Mid
Encryption keys managed by the provider by default, with no customer–managed option evaluated Mid
Sub–processor lists never reviewed, so onward transfers are unknown rather than accepted Mid
No named owner for supplier risk, so no one is due to revisit any of the above Low

The first row is the one that unlocks the rest. Most organisations cannot answer, in any structured way, which of their data would genuinely matter if a provider were lawfully compelled to produce it. For a marketing agency the honest answer may be “almost none of it”, and that is a perfectly good answer — it converts an anxiety into a documented position. For a law firm holding privileged client material, a healthcare provider holding special category data, a defence subcontractor, or an accountant holding client tax affairs, the answer is different and the question deserves real work. The failure is not choosing a hyperscaler. The failure is never having distinguished between the two cases.

The fifth row is the one most often missed and the cheapest to fix. Organisations that have thought carefully about production data frequently hold their backups with the same provider, in the same jurisdiction, under the same contract — which means the backup inherits every characteristic of the primary, including the ones the organisation is worried about. Backup is the natural place to introduce jurisdictional diversity, because it is the workload least sensitive to latency and least entangled with day–to–day operations. A UK–held, independently keyed backup copy is a modest cost that addresses several risks simultaneously, sovereignty among them.

What a serious answer costs

The bands below are indicative planning figures for UK businesses, covering a structured data sovereignty and supplier–risk review and the remediation that usually follows — not quotes. The variable that moves them most is regulatory exposure, not headcount.

Business profile Typical scope Indicative cost What you get for it
Small business, low–sensitivity data, 1 – 25 staff Data inventory by category, provider and region confirmation, sub–processor review, a short documented risk position £900 – £3,000 A written, defensible answer to “where is our data and who could be made to hand it over?” — most likely concluding that current arrangements are appropriate
Professional services firm holding client–confidential material Classification of client data, privilege and confidentiality mapping, contract and DPA review, customer–managed key assessment, UK–held backup copy £3,000 – £12,000 Confidence that professional obligations to clients are matched by the technical arrangements holding their information
SME handling special category or regulated data Full data mapping, transfer risk assessment, encryption and key management design, segregation of the sensitive subset, ICO–ready documentation £12,000 – £40,000 The sensitive minority of your data treated differently from the bulk, rather than one policy applied uniformly to everything
Supplier to government, defence or critical national infrastructure Classification alignment to the government scheme, sovereign or UK–incorporated hosting for the in–scope subset, supply chain assurance evidence, periodic reassessment cycle £25,000 – £90,000 An assurance position that survives a customer’s security questionnaire and a re–tender, with evidence rather than assertions
Any organisation, ongoing A named owner for supplier risk, a scheduled annual reassessment, and a trigger to re–examine when a dependency materially grows £0 – £4,000 a year The one control that would have changed the story in this article: someone whose job it is to reopen an accepted risk when the context changes

The last row is deliberately priced at close to nothing, because it is close to nothing. What failed here, on the reporting’s own account, was not analysis — the 2017 analysis was clear–eyed to the point of bluntness. What failed was the absence of any mechanism to revisit an accepted risk as the dependency scaled from a decision into an institution. Every organisation reading this has at least one such risk on file: signed off when it was small, never looked at since.

Two ways to hold a supplier risk

Reactive posture

What most UK organisations have today

  • Cloud provider chosen years ago for sound reasons, with the risk position written once and never reopened
  • All data treated identically, so the genuinely sensitive minority gets the same handling as the routine bulk
  • Data residency believed to be guaranteed because a region was selected in a console
  • Contractual assurances from the supplier treated as answering a question that is actually about jurisdiction
  • Backups held with the same provider, in the same jurisdiction, under the same contract as production
  • Sub–processor lists unread, so onward transfers are unknown rather than consciously accepted
  • Nobody owns supplier risk, so nothing triggers a review when the dependency grows tenfold

Proactive posture

Where a virtual CIO engagement takes you

  • A data inventory by category, with an explicit judgement on which subset would matter if a provider were compelled to disclose
  • Sensitive material handled differently — segregated, separately keyed, or hosted under UK jurisdiction — while the bulk stays where it is efficient
  • Residency confirmed in the contract and the data processing agreement, not inferred from a setting
  • The jurisdictional question asked and answered in writing: under whose law does this provider operate, and what can it be required to do?
  • Backups deliberately diversified, so the recovery copy does not inherit every characteristic of the primary
  • Sub–processors reviewed at onboarding and on change, with onward transfers accepted knowingly
  • A named owner and a scheduled reassessment, plus a trigger when a dependency materially grows

The gap between those columns is judgement rather than spending. Most of the right–hand column is analysis and documentation, and the expensive–sounding items — segregation, separate keying, UK–jurisdiction hosting — only apply to the subset of data that the analysis identifies, which in most businesses is a small fraction of the total. The organisations that get this wrong are rarely the ones that chose badly. They are the ones that never distinguished between their sensitive data and their ordinary data, and therefore had to apply one posture to everything, which in practice means applying the cheaper one.

33
Indicative data sovereignty readiness, out of 100, for a typical UK SME that has adopted a major cloud platform, is satisfied with its technical security, and has never documented which of its data would matter if the provider were lawfully compelled to disclose it
The three–column exercise that turns anxiety into a position

Take a sheet of paper and list your data categories — client files, employee records, financial data, product information, correspondence, backups, whatever fits your business. Against each one write three things. Where does it live (which provider, which region, and is that confirmed in the contract or merely selected in a console)? Who could be made to produce it (under whose law is the provider incorporated, and what does the contract actually say about government requests)? And would it matter — concretely, if this category were disclosed to a foreign government under valid legal process, what would the consequence be for your clients, your obligations and your business? For most categories in most businesses the honest answer to the third column is “very little”, and writing that down is a legitimate and valuable outcome. The exercise earns its keep on the one or two rows where the answer is not “very little”, because those rows are the ones deserving a different arrangement — and until you have done this, they are being handled exactly like everything else.

What this means for Cyber Essentials, the ICO and your own assurance

It is worth being clear that Cyber Essentials does not address this. The scheme covers technical controls — boundary firewalls, secure configuration, access control, malware protection, patch management — and does so well. It does not ask under whose jurisdiction your cloud provider operates, because that is not a technical control question. An organisation can hold Cyber Essentials Plus, maintain an excellent security posture, and carry an entirely unexamined jurisdictional exposure. That is not a criticism of the scheme; it is a reminder that certification demonstrates conformance to a defined scope, and reading it as a general statement that data is safe is a category error.

The UK GDPR position is more directly engaged, and this is where most SMEs have a concrete obligation rather than a philosophical concern. International transfers of personal data require a lawful basis and, in practice, a transfer risk assessment considering the legal regime in the destination country — including the powers of public authorities to access data. An organisation relying on a provider that has stated it “cannot guarantee data sovereignty”, as Microsoft is reported to have told Police Scotland in 2023, has a factual input it ought to be reflecting in that assessment. The point is not that using a US provider is unlawful; very large numbers of compliant UK organisations do it every day. The point is that the assessment is supposed to be genuine, and a great many are copied from a template that never engaged with the question.

The governance lesson sits at board level and translates directly to a virtual CIO conversation. What this story describes is a risk accepted by one person, in one meeting, in one year, on behalf of an institution that then grew its dependency for nine years without anyone revisiting the decision. That is not a policing pathology. It is what happens by default in every organisation, because accepted risks leave the agenda the moment they are accepted, and nothing in a normal management cycle brings them back. The control that fixes it is unglamorous: a register of accepted risks, a named owner for each, an annual review date, and a rule that a material change in the scale of a dependency triggers reassessment regardless of the calendar.

Finally, the resilience dimension deserves a mention, because sovereignty and continuity point in the same direction. An organisation whose production systems, backups and identity provider all sit with a single supplier has concentrated more than one kind of risk in one place. Introducing jurisdictional diversity into the backup copy happens to address the sovereignty concern, the supplier–failure concern and the account–compromise concern simultaneously. It is rarely the cheapest option considered in isolation and frequently the best value once all three are counted.

The story at a glance

Item Detail
The report A Guardian investigation published 18 September 2026
What is held Criminal records, victim statements and internal emails from more than 40 UK police forces, stored on Microsoft Azure
The official finding A UK security assessment found the arrangement vulnerable to “compromise” by foreign actors and the US government
Classification concern Some files reportedly exceed “official” classification and could be classed as “secret” or “top secret”
Origin of the decision A 2017 meeting chaired by Ian Dyson, then City of London Police Commissioner and the UK’s senior information risk owner
What the 2017 assessment accepted That “US government insiders” could see the data, and that it could be “transmitted worldwide” with the extent “unknown”
What it said about the platform Microsoft’s software “carries vulnerabilities which will be exploited by cybercriminals and other threat actors in due course”
What it said about location “Police forces cannot be certain where their data will be processed or stored”
Expert view Five independent specialists who reviewed the findings said the risks identified in 2017 persist today
Scale of dependency Almost every UK police force now depends on Azure; UK government spends at least £1.9bn a year on Microsoft software
Police position Contracts mean US authorities cannot view data without express permission, and data stored on Microsoft remains in the UK
Microsoft to Police Scotland, 2023 Data “can go outside the UK” and the company “cannot guarantee data sovereignty”
Microsoft’s statement It “does not provide any government with direct or unfettered access to customer data” and had not provided UK data in response to a US government request, but confirmed it responds to US government requests made through valid legal processes
Policy background The Cabinet Office’s “cloud first” policy, introduced in 2013, pushed departments towards commercial public cloud, often US–based
What is not alleged No breach of Azure, no improper conduct by Microsoft, and no failure of a technical control — the exposure described is legal and jurisdictional
Free first step for a business List your data categories and record, for each: where it lives, who could be compelled to produce it, and whether disclosure would actually matter

This story connects to several we have covered recently, and the thread running through them is the same: dependencies that were reasonable when they were small, and were never re–examined once they became structural. The Gemini autonomous hacking research and the NCSC’s adversary simulation work is the closest parallel in spirit — a capability assessment made at one moment in time, overtaken by how fast the underlying platform moved. The PSTN switch–off with months left to run is the same governance failure in physical infrastructure: a decision deferred until the options narrowed to one. The BT email password reset flood showed what happens to an organisation with no real escalation route into a very large supplier, which is a question worth asking before a dependency becomes load–bearing rather than after. LINX’s LON2 fabric passing 1Tbps makes the concentration argument in the network layer — a second path is only worth having if it does not share a failure mode with the first, which applies as neatly to a backup copy as to a circuit. And the new digital ID rules for alcohol sales show the opposite approach in a new system: a certified register, a published standard, and an assertion in place of a data transfer.

Do you know which of your data would actually matter?

Cloudswitched works with UK businesses on Azure and cloud infrastructure — including the part that comes before the architecture: establishing which data you hold, where it genuinely sits, what your contracts and data processing agreements actually say, and which small subset deserves different handling from the rest. For most organisations the outcome is a documented position confirming that current arrangements are appropriate. The value is in having asked, and in knowing which rows were the exceptions.

Talk to us about Azure Cloud Services

Frequently asked questions

Has Microsoft Azure been hacked?
No. Nothing in this reporting alleges a breach of Azure, a failure of a technical control, or improper conduct by Microsoft. That is genuinely important to understand, because it determines what a sensible response looks like. The exposure described is legal and jurisdictional: a US–incorporated company can be required, through valid legal process, to respond to demands from its home government, and that is a property of where the company is incorporated rather than of how well its platform is engineered. Microsoft has stated that it does not provide any government with direct or unfettered access to customer data and that it had not provided UK data in response to a US government request. Both of those statements can be true while the underlying jurisdictional question remains open.
Should we move our business off Azure or AWS?
For the overwhelming majority of UK SMEs, no — and a story like this is a poor basis for that decision. The hyperscalers deliver availability, patching, physical security and recovery capability that almost no small organisation can match in–house, and leaving for a less capable arrangement usually trades a remote jurisdictional risk for a far more probable ordinary one. The proportionate response is narrower and more useful: identify which of your data would genuinely matter if it were disclosed to a foreign government under valid legal process, and consider whether that subset — which is typically small — warrants different handling. For most businesses the review concludes that current arrangements are appropriate, and documenting that conclusion is itself worth doing.
We selected a UK region. Isn’t our data sovereign?
Region selection and sovereignty are different things, and conflating them is the single most common error in this area. Choosing a UK region addresses where the bytes physically sit. It does not address who can be lawfully compelled to produce them, which follows from where the provider is incorporated. The 2017 police assessment made this point in plain terms — that forces “cannot be certain where their data will be processed or stored” — and Microsoft is reported to have told Police Scotland in 2023 that data “can go outside the UK” and that it “cannot guarantee data sovereignty”. If residency matters to you, it needs to be a contractual commitment with defined scope, not an assumption derived from a dropdown in a console.
Does Cyber Essentials cover any of this?
No, and it is not intended to. Cyber Essentials covers technical controls — firewalls, secure configuration, access control, malware protection and patch management — and it covers them well. It does not ask under whose jurisdiction your cloud provider operates, because that is not a technical control. An organisation can hold Cyber Essentials Plus, run a genuinely strong security posture, and carry an entirely unexamined jurisdictional exposure at the same time. This is worth saying because certification is often read as a general assurance that data is safe. It demonstrates conformance to a defined scope, and sovereignty sits outside that scope. Both things are worth having; neither substitutes for the other.
What are our actual UK GDPR obligations here?
International transfers of personal data require a lawful transfer mechanism and, in practice, a transfer risk assessment that considers the legal regime in the destination country — including the powers of public authorities there to access data. That assessment is supposed to be a genuine analysis rather than a template exercise, and a provider statement that it “cannot guarantee data sovereignty” is a relevant factual input to it. None of this makes using a US–headquartered provider unlawful; very large numbers of fully compliant UK organisations do so every day. It does mean that if your assessment was copied from a precedent and has never engaged with the jurisdictional question, it is not currently doing the job it exists to do.
What is the practical difference between a contractual promise and a legal obligation?
A contract binds a supplier to you. A statute binds the supplier to a government. When the two conflict, the contract is not the instrument that prevails — and a supplier complying with a valid legal demand in its home jurisdiction is not breaching your agreement in any meaningful sense, because no commercial contract can lawfully promise to defeat a statutory obligation. That is why Microsoft’s two statements sit together without contradiction: it can genuinely not provide direct or unfettered access, and can genuinely respond to requests made through valid legal processes. For a customer, the practical implication is that assurance about government access has to come from an analysis of the applicable legal regime, not from a clause.
Our backups are with the same provider as production. Does that matter?
It matters for several reasons at once, of which sovereignty is only one. A backup held with the same provider, in the same jurisdiction, under the same contract and reachable from the same administrative accounts inherits every characteristic of the primary — including supplier failure, account compromise and any jurisdictional exposure you are concerned about. Backup is also the easiest workload to diversify, because it is insensitive to latency and barely entangled with daily operations. A UK–held, independently keyed backup copy is a comparatively modest cost that addresses the sovereignty question, the supplier–concentration question and the account–compromise question in a single step, which is why it is usually the first thing we recommend looking at.
Is this really relevant to a small business, or is it a government problem?
The specific facts are a government problem; the mechanism is universal. What the reporting describes is a supplier risk that was identified accurately, accepted formally when the dependency was small, and then never revisited across nine years in which that dependency grew into something structural. Every organisation has risks in that shape. The small–business version is a cloud platform adopted in 2019 for a handful of users that now holds every client file the firm possesses, assessed once at onboarding by someone who has since left. Whether your conclusion today is the same as it was then is a question worth asking deliberately, and nothing in a normal management cycle will ask it for you.
What is a sovereign cloud offering, and is it worth it?
Broadly, it is a deployment model in which a provider commits to keeping data, and often operational access, within a defined geography and under defined controls — sometimes with local partners or separate legal structures intended to limit the reach of foreign jurisdiction. These offerings genuinely narrow the exposure and they are not a complete answer, because the parent company’s incorporation does not change. They also cost more and offer fewer services than the mainstream platform. The sensible approach is to size the decision to the data: applying a sovereign offering to your entire estate is usually poor value, whereas applying it to the specific subset your review flags as genuinely sensitive can be an efficient and proportionate answer.
What is the single most useful thing to do this week?
Write down your data categories and, for each one, three things: where it actually lives, who could be lawfully compelled to produce it, and whether disclosure would genuinely matter. That is an afternoon’s work and it requires no budget. For most categories in most businesses the honest answer to the third question is “very little”, and recording that converts a vague unease into a documented position you can point to. The exercise pays for itself on the one or two rows where the answer is different, because those are the rows that deserve a different arrangement — and until the list exists, they are being handled identically to everything else, which is exactly the failure this story describes.

Accepted risks do not expire on their own

The failure described in this story was not analysis — the 2017 assessment was strikingly clear about what it was accepting. The failure was that nothing ever brought that decision back to the table as the dependency grew. Cloudswitched provides virtual CIO and cloud infrastructure services to UK businesses: data mapping and classification, contract and data processing agreement review, jurisdictionally diverse backup, and a supplier risk register with named owners and review dates, so that the decisions you made when you were smaller get revisited while you still have options.

Talk to us about Azure Cloud Services
Tags:AzureCloud BackupCyber EssentialsVirtual CIO
CloudSwitched

London-based managed IT services provider offering support, cloud solutions and cybersecurity for SMEs.

CloudSwitched Service

Azure Cloud Services

Cloud servers, migration and ongoing Azure management for UK businesses

Learn More

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

20
  • Microsoft 365 Copilot

Measuring Microsoft 365 Copilot ROI: A UK Business Guide to Proving the Licence Cost Is Worth It in 2026

20 Sep, 2026

Copilot ROI measurement is the conversation that arrives about ten months after the licences do. The rollout went well enough, people say they like it, and...

Read more
19
  • Penetration Testing

What Happens During a Penetration Test: A UK Business Guide to the Process Start to Finish in 2026

19 Sep, 2026

The penetration test process is opaque to most of the people who commission it. A UK business signs off a quote, agrees some dates, and then waits. Somewhere...

Read more
18
  • Cloud Backup

Backup Retention Policy: A UK Business Guide to How Long You Should Actually Keep Your Data in 2026

18 Sep, 2026

A backup retention policy is the answer to a question most UK businesses have never actually been asked: how far back do you need to be able to go? In the...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.