A Guardian investigation has found that vast stores of sensitive British police records sit on Microsoft Azure infrastructure that an official UK security assessment judged vulnerable to compromise by foreign intelligence services and the US government. The material includes criminal histories, victim statements, internal correspondence and other restricted files held by more than 40 forces across the country, some of it graded above the standard “official” tier.

The 2017 decision that locked in the risk

In 2017, a meeting chaired by Ian Dyson, then commissioner of the City of London police and the senior information risk owner for all UK policing, weighed 15 specific risks of migrating law-enforcement data onto Microsoft’s global cloud. The summary document, signed off by Dyson, recorded that participants accepted “US government insiders” would be able to view the data and that it could be “transmitted worldwide”, with the full extent of that distribution unknown. The decision followed the Cabinet Office’s 2013 “cloud first” mandate, which pressed departments onto commercial US platforms unless they cleared burdensome exemption hurdles.

Nearly every force now dependent

Today almost every UK police force runs on Azure, and the government spends at least £1.9bn a year on Microsoft licences. Five specialists who reviewed the Guardian’s findings said the risks identified in 2017 remain unaddressed. A source with senior policing experience said there is “no evidence that this has been properly understood”, describing the data as “some of the most sensitive that exists” and warning that exposure or corruption of it could put lives at risk.

Police assurances contradict Microsoft’s own disclosures

When questioned, police representatives said contractual terms prevent US authorities from accessing the data without express permission and that the information stays in the UK. Microsoft’s own 2023 disclosure to Police Scotland told a different story: the company stated that data “can go outside the UK” and that it “cannot guarantee data sovereignty”. Microsoft added that it does not give any government “direct or unfettered access” and has not handed over UK police data in response to a US request, though it complies with valid US legal process like any US-based provider.

What happens next

The gap between the police’s public assurances and the vendor’s contractual reality remains unresolved. With the “cloud first” policy still in force and no public plan to reclassify or relocate the most sensitive datasets, the 2017 risk register effectively stands as current operating doctrine.