Jessica Entwistle
September 21 2026
The Guardian reports that an official UK security assessment found that vast troves of highly sensitive police data stored on Microsoft cloud platforms are vulnerable to potential compromise by foreign actors and the US government. The files, held by more than 40 UK police forces, include criminal records, victim statements, internal emails and other sensitive information. The security assessment raised concerns about data sovereignty, the legal framework governing access to data stored on US-controlled cloud infrastructure, and the risk of unauthorised access by hostile actors or foreign governments under laws such as the US CLOUD Act, which allows US authorities to compel disclosure of data held by US companies regardless of where it is stored.
This story highlights the tension between cloud adoption and data sovereignty for UK public sector organisations and businesses handling sensitive information. Many UK organisations use Microsoft Azure, AWS or Google Cloud for operational efficiency, cost and scalability. However, the legal and jurisdictional risks associated with storing sensitive data on platforms subject to foreign government access requests are often underestimated or not fully understood at board level. For UK businesses in regulated sectors such as legal, healthcare, finance or those working with government contracts, understanding where data is stored, who has legal access to it and what protections are in place is a governance and compliance issue, not just a technical one. The risk is not only from hostile actors exploiting technical vulnerabilities, but also from lawful access requests under foreign legal frameworks that may conflict with UK data protection obligations or client confidentiality requirements. This creates potential legal, reputational and operational risks that need to be understood and managed at senior level.
For many organisations, this is a reminder to review where sensitive data is stored, whether cloud service agreements include adequate data residency and sovereignty protections, and whether risk assessments account for the legal frameworks governing foreign government access to cloud-hosted data. Consider whether your organisation's data classification, cloud architecture and vendor contracts reflect the sensitivity of the information you hold. Review whether sensitive data is stored in UK or EU regions, whether encryption keys are managed independently of the cloud provider, and whether your organisation has visibility into how data may be accessed under foreign legal frameworks. Consider whether your board and senior leadership understand the data sovereignty risks associated with your cloud strategy, and whether governance processes ensure that these risks are reviewed regularly as part of procurement, contract renewal and risk management activities.
Source: The Guardian