UK Police Data at Risk: Security Assessment Raises Alarms
The Guardian reveals how sensitive UK police data on Microsoft’s cloud is vulnerable to foreign government access, raising serious security concerns

Image credit: Photo by Ann H on Pexels
Key Developments
A recent exclusive report by The Guardian has unveiled alarming findings regarding the security of sensitive police data stored on Microsoft cloud platforms. An official UK security assessment revealed that vast troves of highly sensitive police files, including criminal records and victim statements, are vulnerable to potential compromise by foreign actors and the US government. This urgent matter involves data associated with over 40 police forces across the UK, prompting an immediate re-evaluation of the country's reliance on cloud storage solutions.
Background
In a meeting held in 2017, British police decided to migrate some of their most sensitive data to Microsoft's Azure cloud platform. However, this decision came with grave concerns. Officers acknowledged that 'US government insiders' could access the data, and that its transmission could occur on a global scale with the complete extent of exposure remaining unknown. As indicated by several specialists who reviewed the evidence presented by The Guardian, these risks are still very much in play as nearly every UK police force now uses Microsoft's services.
The UK government has invested significantly in Microsoft software, spending approximately £1.9 billion each year, raising questions about the risk versus reward of such dependency. A senior source, previously involved in the UK's policing, voiced serious concerns, stating, "You're talking about information that, if it gets into the wrong hands, or if the information is incorrect, [means] people can get hurt or may die."
Implications of the Data Vulnerability
The sensitive nature of the police data is evident in the assessments of its classification. Some files exceed the 'official' classification, suggesting they may hold the statuses of either 'official sensitive', 'secret', or 'top secret'. This highlights the pressing need for stringent security measures. Yet, police representatives have claimed that contractual agreements with Microsoft prevent unauthorized access by US authorities. However, these statements appear to contradict Microsoft's own disclosures, which acknowledged that data stored on its cloud can leave the UK and that it cannot guarantee data sovereignty.
Experts, including cloud computing specialists, have expressed concern that the mitigations proposed by police to counter these risks might be insufficient. Microsoft's internal encryption does not adequately prevent unauthorized access by its employees or others who might maintain the systems, including many possibly based in nations with opposing interests to the UK. Professor Douwe Korff of London Metropolitan University called into question the police's claims of security, remarking that any reassurances lack substantive guarantees.
Current Risks and Industry Insights
The National Police Chief’s Council (NPCC) has stated that access to cloud data is restricted to individuals with a legitimate need, governed under strict controls. Yet, according to a Microsoft engineer, the reality is that numerous personnel worldwide could view sensitive information. The assessment from 2017 exhaustively outlined risks inherent in transferring police data to a cloud model, identifying Microsoft's software vulnerabilities and potential unauthorized data processing.
Further compounding the issue is the realization that US law, through legislation like the Cloud Act, allows American authorities to access data held by US companies, irrespective of its location. This reality raises immediate questions about the robustness of contractual assurances being made by technology companies regarding data protection.
Conclusion
The implications of this situation are significant. With the UK government heavily investing in cloud services provided by US companies, the findings from The Guardian's investigation serve as a critical wake-up call. As police forces across the country continue to migrate their sensitive data to cloud platforms, the question remains: can the UK ensure the integrity and security of its law enforcement data in an increasingly complex global digital environment? This ongoing situation will require vigilant oversight and potentially a significant policy overhaul to protect sensitive public data against external vulnerabilities.
Source links
Comments
No approved comments yet.



