A Guardian investigation published on 18 September 2026 reports that vast quantities of highly sensitive UK police data — criminal records, victim statements and internal emails from more than 40 police forces — are held on Microsoft Azure, and that an official UK security assessment found the arrangement vulnerable to “compromise” by foreign actors and by the US government. Some of the material is reported to exceed “official” classification, potentially falling into “secret” or “top secret” territory. Five independent specialists who reviewed the findings told the paper the risks persist today.
The detail that makes this more than a public–sector procurement story is the date on the paperwork. The decision to place sensitive police data on Microsoft’s platform followed a 2017 meeting chaired by Ian Dyson, then City of London Police Commissioner and the UK’s senior information risk owner. The risk assessment produced around that decision did not miss the exposure. It recorded it. It accepted that “US government insiders” could see the data, that the data could be “transmitted worldwide” with the extent “unknown”, and that “police forces cannot be certain where their data will be processed or stored”. This is not a story about a risk nobody spotted. It is a story about a risk that was written down, signed off, and then inherited by everyone who came afterwards — which is a pattern any UK business that has ever accepted a supplier risk on a one–page form will recognise.
What the investigation reports
The core finding is one of scale combined with classification. More than 40 police forces hold material on Azure that includes criminal records, victim statements and internal correspondence. An official UK security assessment is reported to have concluded that this storage arrangement was vulnerable to compromise by foreign actors and by the US government, and that some of the files involved go beyond the “official” tier of the government classification scheme — potentially into “secret” or “top secret”. Those are not adjacent categories. They carry materially different handling requirements, and the gap between how data is classified and where it actually sits is the substance of the concern.
The 2017 documentation is the part that will be studied longest. The assessment accompanying the decision recorded that Microsoft’s software “carries vulnerabilities which will be exploited by cybercriminals and other threat actors in due course” — a statement that is simultaneously unremarkable, since it is true of all software, and striking in a document justifying the placement of national policing data. It also recorded that “police forces cannot be certain where their data will be processed or stored”. That sentence is the whole sovereignty question stated plainly, nine years before it became a headline.
Both sides of the argument as it now stands are on the record, and they do not entirely reconcile. Police told the Guardian that their contracts with Microsoft mean US authorities cannot view data without express permission, and that data stored on Microsoft remains in the UK. Against that, Microsoft is reported to have told Police Scotland in 2023 that data “can go outside the UK” and that it “cannot guarantee data sovereignty”. Microsoft, for its part, said it “does not provide any government with direct or unfettered access to customer data” and that it had not provided UK data in response to a US government request — while confirming that, like all US–based technology companies, it responds to US government requests made through valid legal processes.
That last sentence is the one to read twice, because it is not a contradiction and it is not an evasion. It is an accurate description of the position every US–headquartered provider occupies. A company can hold a genuine commitment not to grant unfettered access, can have received no relevant request, and can still be subject to a legal regime in which a valid, lawful demand must be answered. A contractual promise from a supplier and a statutory obligation on that supplier are different instruments, and where they conflict, the contract is not the one that prevails.
Nothing in this story suggests Azure has been breached, that Microsoft has behaved improperly, or that a technical control has failed. That is precisely why it matters for UK organisations. The exposure described is a legal and jurisdictional one: a US–incorporated company can be compelled, through valid legal process, to respond to demands from its home government regardless of where the data physically sits or what a UK customer contract says. Encryption at rest, UK data residency commitments and an excellent security posture do not address that question, because it is not a security question. The uncomfortable implication for any business is that a supplier assessment can be entirely clean on every technical control and still leave a material exposure unexamined — because no standard questionnaire asks “under whose law does our provider ultimately operate, and what can it be required to do?”
Nine years from a signed–off risk to a front page
The chronology matters more than usual here, because the central claim of the reporting is not that something went wrong but that nothing changed. Each step below is individually defensible; the sequence is what produces the position.
Read as a whole, this is a governance failure rather than a security one, and the distinction is not academic. Security failures are addressed with controls. Governance failures of this shape — a risk formally accepted at a moment when the dependency was small, never re–examined as the dependency grew — are addressed only by someone deliberately reopening a decision that is nobody’s current responsibility. That is a much harder thing to make happen, in a police force or in a forty–person business.
What “sovereignty” actually buys you, by deployment model
The word sovereignty is used loosely enough to be nearly useless in supplier conversations, so it helps to be concrete about what different arrangements give you. The chart below is an indicative planning model — not measured data — ranking how much genuine control an organisation retains over where its data goes and who can compel access to it.
Two observations follow from that ordering, and both cut against the instinctive response to a story like this. The first is that pinning a UK region — the control most organisations reach for — moves you far less than people assume. Data residency addresses where bytes sit. It does not address who can be compelled to produce them, which is a function of where the provider is incorporated, not where the disk is. The 2017 assessment’s observation that forces “cannot be certain where their data will be processed or stored” and Microsoft’s reported 2023 statement that data “can go outside the UK” both point at the same gap between residency as a setting and residency as a guarantee.
The second is that the top of the chart is not a recommendation. Holding your own keys and running your own infrastructure genuinely does maximise jurisdictional control, and for the overwhelming majority of UK SMEs it would be a poor trade — worse availability, worse patching, worse physical security, worse recovery, and a far higher chance of an ordinary breach caused by ordinary neglect. The realistic answer for most organisations is not to leave the hyperscalers. It is to know which of their data would actually matter if a jurisdictional risk crystallised, and to treat that subset differently from everything else.
The finding that makes this current rather than historical
A story built on a 2017 document invites an obvious defence: that was nine years ago, the platform has moved on, the controls are better, the contracts are tighter. The Guardian put its findings to five independent specialists, and the answer came back without division.
Unanimity among five reviewers is not proof, and specialists asked to comment on a security question are not a random sample of opinion. But it is a meaningful signal on the specific point at issue, which is narrow: not whether Azure is well–engineered, but whether the particular exposure documented in 2017 has since been closed. The reason it has not, on this reading, is structural rather than technical. The risk derives from the legal status of a US–incorporated provider, and no amount of engineering investment changes a company’s jurisdiction of incorporation.
It is worth being scrupulous about what is and is not alleged, because stories in this area attract more heat than they generate light. There is no reported breach. There is no allegation that Microsoft has acted improperly, and the company’s stated position — no direct or unfettered government access, no UK data provided in response to a US government request — is a substantive one. Equally, the confirmation that it responds to valid legal process is not a caveat that can be waved away, because it describes the precise mechanism the 2017 assessment was worried about. Both things are true at once, and an organisation making decisions here has to hold both.
The £1.9bn annual spend figure is what converts this from a debate into a constraint. At that level of dependency across government, the practical options available to any single department, force or agency are narrow. That is the real lesson for a business reading this: the moment to evaluate a jurisdictional risk is before the dependency is load–bearing, because afterwards the assessment becomes a formality conducted in the knowledge that no other answer is affordable.
Where UK SMEs carry the same exposure without knowing it
It is easy to read this as a policing story with no read–across to a fifty–person business. The read–across is direct, because the underlying mechanism — a supplier risk accepted once, never revisited as the dependency grew — is close to universal. The rows below reflect where that typically sits in an SME estate.
The first row is the one that unlocks the rest. Most organisations cannot answer, in any structured way, which of their data would genuinely matter if a provider were lawfully compelled to produce it. For a marketing agency the honest answer may be “almost none of it”, and that is a perfectly good answer — it converts an anxiety into a documented position. For a law firm holding privileged client material, a healthcare provider holding special category data, a defence subcontractor, or an accountant holding client tax affairs, the answer is different and the question deserves real work. The failure is not choosing a hyperscaler. The failure is never having distinguished between the two cases.
The fifth row is the one most often missed and the cheapest to fix. Organisations that have thought carefully about production data frequently hold their backups with the same provider, in the same jurisdiction, under the same contract — which means the backup inherits every characteristic of the primary, including the ones the organisation is worried about. Backup is the natural place to introduce jurisdictional diversity, because it is the workload least sensitive to latency and least entangled with day–to–day operations. A UK–held, independently keyed backup copy is a modest cost that addresses several risks simultaneously, sovereignty among them.
What a serious answer costs
The bands below are indicative planning figures for UK businesses, covering a structured data sovereignty and supplier–risk review and the remediation that usually follows — not quotes. The variable that moves them most is regulatory exposure, not headcount.
| Business profile | Typical scope | Indicative cost | What you get for it |
|---|---|---|---|
| Small business, low–sensitivity data, 1 – 25 staff | Data inventory by category, provider and region confirmation, sub–processor review, a short documented risk position | £900 – £3,000 | A written, defensible answer to “where is our data and who could be made to hand it over?” — most likely concluding that current arrangements are appropriate |
| Professional services firm holding client–confidential material | Classification of client data, privilege and confidentiality mapping, contract and DPA review, customer–managed key assessment, UK–held backup copy | £3,000 – £12,000 | Confidence that professional obligations to clients are matched by the technical arrangements holding their information |
| SME handling special category or regulated data | Full data mapping, transfer risk assessment, encryption and key management design, segregation of the sensitive subset, ICO–ready documentation | £12,000 – £40,000 | The sensitive minority of your data treated differently from the bulk, rather than one policy applied uniformly to everything |
| Supplier to government, defence or critical national infrastructure | Classification alignment to the government scheme, sovereign or UK–incorporated hosting for the in–scope subset, supply chain assurance evidence, periodic reassessment cycle | £25,000 – £90,000 | An assurance position that survives a customer’s security questionnaire and a re–tender, with evidence rather than assertions |
| Any organisation, ongoing | A named owner for supplier risk, a scheduled annual reassessment, and a trigger to re–examine when a dependency materially grows | £0 – £4,000 a year | The one control that would have changed the story in this article: someone whose job it is to reopen an accepted risk when the context changes |
The last row is deliberately priced at close to nothing, because it is close to nothing. What failed here, on the reporting’s own account, was not analysis — the 2017 analysis was clear–eyed to the point of bluntness. What failed was the absence of any mechanism to revisit an accepted risk as the dependency scaled from a decision into an institution. Every organisation reading this has at least one such risk on file: signed off when it was small, never looked at since.
Two ways to hold a supplier risk
Reactive posture
What most UK organisations have today
- Cloud provider chosen years ago for sound reasons, with the risk position written once and never reopened
- All data treated identically, so the genuinely sensitive minority gets the same handling as the routine bulk
- Data residency believed to be guaranteed because a region was selected in a console
- Contractual assurances from the supplier treated as answering a question that is actually about jurisdiction
- Backups held with the same provider, in the same jurisdiction, under the same contract as production
- Sub–processor lists unread, so onward transfers are unknown rather than consciously accepted
- Nobody owns supplier risk, so nothing triggers a review when the dependency grows tenfold
Proactive posture
Where a virtual CIO engagement takes you
- A data inventory by category, with an explicit judgement on which subset would matter if a provider were compelled to disclose
- Sensitive material handled differently — segregated, separately keyed, or hosted under UK jurisdiction — while the bulk stays where it is efficient
- Residency confirmed in the contract and the data processing agreement, not inferred from a setting
- The jurisdictional question asked and answered in writing: under whose law does this provider operate, and what can it be required to do?
- Backups deliberately diversified, so the recovery copy does not inherit every characteristic of the primary
- Sub–processors reviewed at onboarding and on change, with onward transfers accepted knowingly
- A named owner and a scheduled reassessment, plus a trigger when a dependency materially grows
The gap between those columns is judgement rather than spending. Most of the right–hand column is analysis and documentation, and the expensive–sounding items — segregation, separate keying, UK–jurisdiction hosting — only apply to the subset of data that the analysis identifies, which in most businesses is a small fraction of the total. The organisations that get this wrong are rarely the ones that chose badly. They are the ones that never distinguished between their sensitive data and their ordinary data, and therefore had to apply one posture to everything, which in practice means applying the cheaper one.
Take a sheet of paper and list your data categories — client files, employee records, financial data, product information, correspondence, backups, whatever fits your business. Against each one write three things. Where does it live (which provider, which region, and is that confirmed in the contract or merely selected in a console)? Who could be made to produce it (under whose law is the provider incorporated, and what does the contract actually say about government requests)? And would it matter — concretely, if this category were disclosed to a foreign government under valid legal process, what would the consequence be for your clients, your obligations and your business? For most categories in most businesses the honest answer to the third column is “very little”, and writing that down is a legitimate and valuable outcome. The exercise earns its keep on the one or two rows where the answer is not “very little”, because those rows are the ones deserving a different arrangement — and until you have done this, they are being handled exactly like everything else.
What this means for Cyber Essentials, the ICO and your own assurance
It is worth being clear that Cyber Essentials does not address this. The scheme covers technical controls — boundary firewalls, secure configuration, access control, malware protection, patch management — and does so well. It does not ask under whose jurisdiction your cloud provider operates, because that is not a technical control question. An organisation can hold Cyber Essentials Plus, maintain an excellent security posture, and carry an entirely unexamined jurisdictional exposure. That is not a criticism of the scheme; it is a reminder that certification demonstrates conformance to a defined scope, and reading it as a general statement that data is safe is a category error.
The UK GDPR position is more directly engaged, and this is where most SMEs have a concrete obligation rather than a philosophical concern. International transfers of personal data require a lawful basis and, in practice, a transfer risk assessment considering the legal regime in the destination country — including the powers of public authorities to access data. An organisation relying on a provider that has stated it “cannot guarantee data sovereignty”, as Microsoft is reported to have told Police Scotland in 2023, has a factual input it ought to be reflecting in that assessment. The point is not that using a US provider is unlawful; very large numbers of compliant UK organisations do it every day. The point is that the assessment is supposed to be genuine, and a great many are copied from a template that never engaged with the question.
The governance lesson sits at board level and translates directly to a virtual CIO conversation. What this story describes is a risk accepted by one person, in one meeting, in one year, on behalf of an institution that then grew its dependency for nine years without anyone revisiting the decision. That is not a policing pathology. It is what happens by default in every organisation, because accepted risks leave the agenda the moment they are accepted, and nothing in a normal management cycle brings them back. The control that fixes it is unglamorous: a register of accepted risks, a named owner for each, an annual review date, and a rule that a material change in the scale of a dependency triggers reassessment regardless of the calendar.
Finally, the resilience dimension deserves a mention, because sovereignty and continuity point in the same direction. An organisation whose production systems, backups and identity provider all sit with a single supplier has concentrated more than one kind of risk in one place. Introducing jurisdictional diversity into the backup copy happens to address the sovereignty concern, the supplier–failure concern and the account–compromise concern simultaneously. It is rarely the cheapest option considered in isolation and frequently the best value once all three are counted.
The story at a glance
| Item | Detail |
|---|---|
| The report | A Guardian investigation published 18 September 2026 |
| What is held | Criminal records, victim statements and internal emails from more than 40 UK police forces, stored on Microsoft Azure |
| The official finding | A UK security assessment found the arrangement vulnerable to “compromise” by foreign actors and the US government |
| Classification concern | Some files reportedly exceed “official” classification and could be classed as “secret” or “top secret” |
| Origin of the decision | A 2017 meeting chaired by Ian Dyson, then City of London Police Commissioner and the UK’s senior information risk owner |
| What the 2017 assessment accepted | That “US government insiders” could see the data, and that it could be “transmitted worldwide” with the extent “unknown” |
| What it said about the platform | Microsoft’s software “carries vulnerabilities which will be exploited by cybercriminals and other threat actors in due course” |
| What it said about location | “Police forces cannot be certain where their data will be processed or stored” |
| Expert view | Five independent specialists who reviewed the findings said the risks identified in 2017 persist today |
| Scale of dependency | Almost every UK police force now depends on Azure; UK government spends at least £1.9bn a year on Microsoft software |
| Police position | Contracts mean US authorities cannot view data without express permission, and data stored on Microsoft remains in the UK |
| Microsoft to Police Scotland, 2023 | Data “can go outside the UK” and the company “cannot guarantee data sovereignty” |
| Microsoft’s statement | It “does not provide any government with direct or unfettered access to customer data” and had not provided UK data in response to a US government request, but confirmed it responds to US government requests made through valid legal processes |
| Policy background | The Cabinet Office’s “cloud first” policy, introduced in 2013, pushed departments towards commercial public cloud, often US–based |
| What is not alleged | No breach of Azure, no improper conduct by Microsoft, and no failure of a technical control — the exposure described is legal and jurisdictional |
| Free first step for a business | List your data categories and record, for each: where it lives, who could be compelled to produce it, and whether disclosure would actually matter |
This story connects to several we have covered recently, and the thread running through them is the same: dependencies that were reasonable when they were small, and were never re–examined once they became structural. The Gemini autonomous hacking research and the NCSC’s adversary simulation work is the closest parallel in spirit — a capability assessment made at one moment in time, overtaken by how fast the underlying platform moved. The PSTN switch–off with months left to run is the same governance failure in physical infrastructure: a decision deferred until the options narrowed to one. The BT email password reset flood showed what happens to an organisation with no real escalation route into a very large supplier, which is a question worth asking before a dependency becomes load–bearing rather than after. LINX’s LON2 fabric passing 1Tbps makes the concentration argument in the network layer — a second path is only worth having if it does not share a failure mode with the first, which applies as neatly to a backup copy as to a circuit. And the new digital ID rules for alcohol sales show the opposite approach in a new system: a certified register, a published standard, and an assertion in place of a data transfer.
Do you know which of your data would actually matter?
Cloudswitched works with UK businesses on Azure and cloud infrastructure — including the part that comes before the architecture: establishing which data you hold, where it genuinely sits, what your contracts and data processing agreements actually say, and which small subset deserves different handling from the rest. For most organisations the outcome is a documented position confirming that current arrangements are appropriate. The value is in having asked, and in knowing which rows were the exceptions.
Talk to us about Azure Cloud ServicesFrequently asked questions
Accepted risks do not expire on their own
The failure described in this story was not analysis — the 2017 assessment was strikingly clear about what it was accepting. The failure was that nothing ever brought that decision back to the table as the dependency grew. Cloudswitched provides virtual CIO and cloud infrastructure services to UK businesses: data mapping and classification, contract and data processing agreement review, jurisdictionally diverse backup, and a supplier risk register with named owners and review dates, so that the decisions you made when you were smaller get revisited while you still have options.
Talk to us about Azure Cloud Services


