Sensitive information held by more than 40 police forces across the UK is stored on Microsoft Azure cloud services despite a previous security assessment warning that the data could be vulnerable to foreign actors and other cyber threats.
The information includes criminal records, victim statements, intelligence, case files, body-worn video, digital evidence and internal police communications. A police document examined by the Guardian found that some of the information was more sensitive than the UK classification of “official”.
The concerns were raised in a 2017 assessment of the risks involved in moving police information to Microsoft's global cloud services. The assessment specifically mentioned the possibility of sensitive information being accessed by “US government insiders” and warned that police data could be processed or stored around the world.
The findings have now raised fresh questions about how securely some of Britain's most sensitive policing information is stored and who could potentially access it.
In 2017, senior police officials examined a series of risks linked to moving police data to Microsoft cloud services, including Azure.
The assessment warned that Microsoft's software could contain weaknesses that might eventually be exploited by criminals and other attackers. It also said police forces could not always be certain where their information or related data was being processed or stored.
Because Microsoft's cloud system operates across a large international network, the assessment said police information could potentially be transmitted or stored outside the UK.
The document also identified a specific concern about possible access by US government insiders.
At the time, police officials proposed several measures to reduce the risks, including keeping systems updated, using security software and applying Microsoft's built-in encryption.
However, experts who later reviewed the assessment told the Guardian that these measures might not fully address the concerns about foreign access.
Since the 2017 assessment, Microsoft cloud services have become widely used across UK policing.
The National Police Chiefs' Council (NPCC) said access to police information stored in the cloud is restricted to people who have a genuine need to see it and is subject to security controls.
Microsoft also says its Azure services can meet specific UK police security requirements. Its published information states that the National Police Information Risk Management Team assessed UK Azure data centres against Police-Assured Secure Facilities requirements.
Microsoft has also said that customer information is not automatically exposed to foreign governments and that it does not provide governments with direct or unrestricted access to customer data.
The company said it had not provided UK government data in response to a US government request.
One of the central issues is the difference between where information is physically stored and who may be able to access the systems supporting it.
Microsoft operates a global cloud network, while technical support can involve employees and contractors working in different countries.
Cloud experts cited by the Guardian questioned whether keeping data in UK data centres alone could fully remove the risks linked to international access.
Microsoft, however, said it has strict controls around employee access and safeguards designed to protect customer information.
The company also says government requests for customer information must go through legal processes and that it takes steps to challenge requests where appropriate.
Microsoft's published government-request information shows that it receives legal requests for data from UK authorities under arrangements including the UK Investigatory Powers Act and other legal procedures.
The issue has also raised wider questions about the relationship between UK data and US technology companies.
US laws, including the CLOUD Act, can create legal questions when US-based technology companies hold data belonging to customers outside America. Legal experts cited by the Guardian argued that contractual promises alone may not completely remove those concerns.
The debate is not limited to policing. The UK government relies heavily on major US technology companies for cloud computing and other digital services.
That wider dependence has led to increasing discussion about data sovereignty — the principle that organisations should retain effective control over where their information is stored and who can access it.
Importantly, the security concerns do not establish that UK police data has been stolen or accessed illegally.
The Guardian reported that there is no firm evidence showing that the sensitive police information stored on Microsoft Azure has been breached as a result of the risks identified in the 2017 assessment.
A former senior policing source told the Guardian that it may not always be possible to know whether a breach has occurred because of limitations in the information available from cloud systems.
The issue is therefore about potential exposure and security risk rather than a confirmed breach.
The NPCC has maintained that police information stored in the cloud is protected by access controls and security measures.
Microsoft has rejected the suggestion that using its cloud services automatically makes customer data insecure or exposes it to foreign governments. The company says it has strong safeguards around access and follows legal requirements when governments request information.
Microsoft also says UK customers can use UK-based data centres and that Azure supports the security requirements of UK law enforcement.
The continuing debate centres on whether those protections provide sufficient safeguards for the most sensitive information held by British police.
For now, there is no confirmed evidence that the concerns identified in the 2017 assessment have resulted in a breach of UK police data. But the disclosure of the old security assessment has renewed questions about Britain's long-term reliance on overseas technology companies to store and manage highly sensitive public-sector information.
Daily Dazzling Dawn understands that the issue is likely to remain part of the wider debate over cybersecurity, cloud computing and the UK's control of sensitive government data.