Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Guardian Investigation: UK Police Data on Microsoft Azure Flagged as Vulnerable to US and Foreign Access

A Decision Made in 2017, Risks Still Unresolved
More than 40 UK police forces are storing highly sensitive data, including criminal records, victim statements, internal emails, and files that may exceed standard "official" security classification, on Microsoft's Azure cloud platform, according to a Guardian investigation published this week.
An official UK security assessment reviewed by the Guardian found the setup vulnerable to "compromise" by hostile hackers and foreign governments, including the US government itself.
The roots of this go back to a 2017 meeting chaired by senior police officer Ian Dyson, where officials weighed 15 risks tied to moving police data onto Azure. A record of that meeting, examined by the Guardian, shows officers explicitly accepted that "US government insiders" could see the data and that it could be "transmitted worldwide," with officials admitting "the extent of this... unknown."
Five security specialists who reviewed the Guardian's findings said those same risks persist today, nearly a decade later. Almost every UK police force now runs on Azure. The UK government spends at least £1.9 billion a year on Microsoft software, according to the Guardian.
One source who has held senior roles in UK policing did not mince words: "There's no evidence that this has been properly understood." He called the data "some of the most sensitive that exists," warning that if it fell into the wrong hands, or turned out to be wrong, "people can get hurt or may die."
Police Say One Thing, Microsoft's Own Disclosure Says Another
When the Guardian pressed police about whether this data was actually secure, forces pointed to their Microsoft contracts, saying US authorities could not view the data without express permission and that everything stayed in the UK.
That's a reasonable-sounding answer. Microsoft told Police Scotland something different in 2023. In a disclosure to that force, Microsoft stated plainly that data "can go outside the UK" and that it "cannot guarantee data sovereignty."
Microsoft, for its part, told the Guardian it "does not provide any government with direct or unfettered access to customer data" and said it had not turned over UK police data in response to any US government request. The company added that, like every US-based tech firm, it does respond to US government requests made through valid legal processes.
The relevant legal process is the CLOUD Act, a 2018 US law that lets American authorities compel US-based companies to hand over data regardless of where it's physically stored, according to Crypto Briefing. Encryption keys held by Microsoft and its subprocessors could theoretically enable compelled disclosure under that law, per the same reporting.
Sovereignty on Paper, Not in Practice
Crypto Briefing's reporting, drawing on Freedom of Information disclosures from 2024 through 2026, found UK policing data could potentially route through 105 countries via Microsoft's subprocessor network. Microsoft reportedly declined to provide detailed risk assessments covering transfers to non-adequate jurisdictions, citing commercial confidentiality.
The compliance record is messy too. As of December 2020, multiple UK police forces were processing data on Microsoft 365 without completing the Data Protection Impact Assessments required for that kind of sensitive information, according to Crypto Briefing.
Police Scotland's Digital Evidence Sharing Capability system, piloted in 2023, drew a specific warning. An assessment concluded its use of Azure would not meet legal requirements because of sovereignty concerns and CLOUD Act exposure. The Scottish Biometrics Commissioner has since called for a regulatory investigation into whether current practices comply with Part 3 of the Data Protection Act 2018. The Scottish Police Authority has echoed the concern, saying Microsoft's inability to offer binding data-localization guarantees puts agencies in what it calls an untenable compliance position.
The Defense Worth Taking Seriously
There's a real argument here worth stating plainly. Contractual restrictions on access aren't nothing, and "can theoretically be reached" isn't the same as "has been reached." Microsoft says it hasn't handed over this specific police data to US authorities. No UK police force has been shown to have had data breached or improperly disclosed as a direct result of this architecture. The CLOUD Act itself is a legitimate US law enforcement tool, not a backdoor built for spying, and it requires legal process, not a standing tap.
But a legal requirement to hand data over when compelled is still a legal requirement. The UK's own 2017 risk assessment and Microsoft's 2023 statement to Police Scotland both concede that sovereignty and worldwide transmission are live possibilities, not hypotheticals invented by critics.
What Happens Next
The UK's Data (Use and Access) Act 2025, which received Royal Assent in June 2025, aimed to close some of the regulatory gaps that allowed this arrangement to continue, according to Crypto Briefing. Whether that legislation forces UK policing onto sovereign infrastructure, or simply papers over the same contractual assurances that already contradict Microsoft's own disclosures, remains an open question. No UK regulator has yet announced a formal investigation into whether current Azure-based police data storage violates Part 3 of the Data Protection Act, despite the Scottish Biometrics Commissioner's call for one.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.