UK Police Data on Microsoft Azure Found Vulnerable to US and Foreign Access

Sensitive UK police data stored on Microsoft Azure was judged vulnerable to access by foreign actors and the US government in an official UK security assessment, according to an investigation published on 18 September 2026.
More than 40 police forces across the UK keep criminal records, victim statements, internal emails and other sensitive information on Microsoft cloud platforms, the investigation found. A police document seen by reporters noted some files sit above "official" classification, the routine level for government work, raising the possibility that "secret" or "top secret" material is held in the same environment. The Guardian
The platform at issue is Microsoft Azure. For readers new to the term, hyperscale public cloud means renting computing space in Microsoft's vast global network of data centres, rather than holding data on police-owned servers. British police decided at a 2017 meeting to place some of their most sensitive data on Microsoft's platform after weighing the trade-offs of that move.
That 2017 meeting was chaired by senior police officer Ian Dyson and examined 15 risks of transferring UK police data to Microsoft's global cloud. Officers accepted that "US government insiders" would be able to see the data and that it could be "transmitted worldwide" with "the extent of this ... unknown". The risks and decisions were set out in a summary document seen by The Guardian and signed off by Dyson. That paper forms the basis for the current assessment of leftover risk, including lawful access from outside the UK and compromise by third parties.
Dependence has grown since. Almost every UK police force now depends on Microsoft Azure, and the UK government spends at least £1.9bn on Microsoft software each year. Microsoft said in a 2023 disclosure to Police Scotland that data "can go outside the UK" and that it "cannot guarantee data sovereignty", meaning the ability to keep data under UK law and control. Microsoft separately stated it "does not provide any government with direct or unfettered access to customer data" and that it had not provided UK data in response to a US government request.
Separate recent disclosures describe incidents around large cloud estates. Cyber firm Wiz said it found a sweeping flaw that could have led to mass exposure of Microsoft cloud customers, according to reporting from July 2026. Reuters Thomson Reuters detected a cybersecurity incident involving access by an unauthorized party, and said its investigation found some court records were affected, including names and personal information. On 3 August 2026, The Hacker News confirmed that the PNLD breach-notice page referenced assets hosted on Microsoft's content.powerapps.com domain. The Hacker News
The broader context here is the tension between policing needs for confidentiality and integrity and the way public cloud works across jurisdictions and shared systems. Important variables are data residency, meaning where data physically sits, key control, personnel access, logging visibility, and the legal routes by which a foreign authority can compel production. Acceptance of insider access and worldwide transmission in 2017 suggests those variables were understood then as remaining risks rather than fully solvable problems.
Looking at what this means for oversight, three questions carry weight. First, how classification policy maps to cloud placement, given material above "official" level. Second, whether contractual promises on sovereignty can limit platform behaviour once data leaves national infrastructure. Third, how exit costs and interoperability shape future buying, when almost every force operates on the same stack. The answers will determine whether any remedy is technical, contractual, or architectural.


