THE TELL

Your police file is on Microsoft Azure. Nobody can say exactly where

A 2017 UK police document accepted that data could be "transmitted worldwide" and seen by "US government insiders". Then every force in Britain moved its files there anyway.

If you have ever reported a crime in the UK, given a witness statement, or had your name written into a criminal record, that file is almost certainly sitting on a commercial cloud platform run by an American company. The Guardian has seen an official UK police assessment that judged this setup vulnerable to "compromise" by foreign actors and the US government.

The platform is Microsoft Azure. It runs on datacentres, cables and networking gear spread across more than 100 countries. More than 40 UK police forces keep criminal records, victim statements, internal emails and other sensitive material there. Some of it exceeds the "official" classification — which in Britain means it could be "official sensitive", "secret" or "top secret".

What it means

The decision was made in a meeting in 2017, chaired by Ian Dyson, then police commissioner of the City of London and the senior information risk owner for the whole of Britain — the person whose job was to set the rules for how police handle data. Officers looked at 15 risks. They wrote them down. And then they accepted them. The document says police forces "cannot be certain where their data will be processed or stored", that files "could be transmitted and stored worldwide", and that "the extent of this will be unknown".

It also names the risk out loud: "There is a risk of compromise of sensitive data shared by, or taken from, Microsoft by the US government being released by US government insider attackers."

The fix they chose was Microsoft's own built-in encryption, plus leaving the final call to each individual chief. Several specialists told the Guardian that this is like locking your house and giving the only key to the landlord: Microsoft's internal encryption does not stop Microsoft employees from reading the files, and it would not stop the US government obtaining them either. One Microsoft engineer who reviewed the findings said the data "could be viewed by hundreds of people around the world, some of them not vetted, many of them not directly employed by Microsoft".

A source who held senior roles in UK policing put it plainly: "There's no evidence that this has been properly understood."
Share this

And the official answers do not line up. Police told the Guardian their Microsoft contracts mean US authorities cannot see the data without express permission, and that the data stays in the UK. Microsoft told Police Scotland in 2023 that data "can go outside the UK" and that it "cannot guarantee data sovereignty". Microsoft says it "does not provide any government with direct or unfettered access to customer data" and has not handed over UK data in response to a US request — while noting that, like every US tech company, it responds to US government requests made through valid legal processes. Both things can be true at once. That is the part worth sitting with.

Who it matters to

Anyone in Britain who has ever been a victim, a witness or a suspect — your statement is in there, and nobody can tell you which country the copy lives in. Young people especially: a caution at 19 follows you into job checks at 30, and that record now sits on infrastructure spanning over 100 countries. It also touches anyone whose employer or university has quietly moved everything to the same kind of cloud — up to 60% of UK government IT already runs this way, and the state spends at least £1.9bn a year on Microsoft software alone. The lesson is not about police. It is about what "our data is secure" actually means when the servers belong to someone else.

What's next

Watch whether anyone answers the question the Guardian asked directly: can the US government access this data? The police spokesperson declined to comment on the phrase "US government insiders". Police Scotland is still finalising its move onto the platform, so there is at least one force whose decision is not yet finished. Beyond that, the source names no inquiry, no deadline and no review — so we will not invent one.

One detail to hold on to

The most unsettling line in this story is not about hackers. It is a quote from inside policing: "We really don't know if the data has been breached or not." Not a denial, not a reassurance — an admission that the question itself cannot be answered from the UK side.

Sources: The Guardian, "Sensitive UK police data vulnerable to 'compromise' by US government and foreign actors", 18 September 2026 (Aisha Down).

Why we ran this8/10

Досье британской полиции — записи о судимостях и показания жертв — лежат в облаке американской компании, и внутренний документ 2017 года прямо признаёт: где именно эти файлы хранятся и кто из США может в них заглянуть, никто не знает.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← Loudoun County cut property taxes 30%. I…Next: Gemini guessed the passwords itself. Three… →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X