June 23rd, 2024

Microsoft admits no guarantee of sovereignty for UK policing data

Microsoft admits inability to guarantee UK policing data sovereignty on its public cloud, potentially breaching UK data protection laws. Concerns persist despite company's efforts to address issues, impacting all UK government users.

Read original articleLink Icon
Microsoft admits no guarantee of sovereignty for UK policing data

Microsoft has admitted to Scottish policing bodies that it cannot ensure the sovereignty of UK policing data stored on its public cloud infrastructure, despite previous claims. The company acknowledged that data uploaded to the Police Scotland IT system may be processed overseas, not necessarily in the UK as required by law. This revelation raises concerns about compliance with UK data protection regulations. Microsoft's acknowledgment of international data transfers affects all UK government users facing similar limitations on data offshoring. The disclosure has prompted experts to highlight the breach of UK law by using such technology. The issue extends beyond policing, impacting other public sector data hosting requirements. Microsoft stated it has not altered its Azure services' operation and has worked with Police Scotland to ensure compliance with data protection laws. The concerns about data sovereignty and processing outside the UK have been ongoing, with Microsoft making commitments to address these issues. Despite these commitments, questions remain about ensuring compliance with UK regulations regarding data processing and storage locations.

Link Icon 5 comments
By @stuaxo - 4 months
Does this effect the switch from Google to Microsoft

https://www.civilserviceworld.com/news/article/cabinet-offic...

By @Havoc - 4 months
Sounds like they were asked for pretty broad guarantees. Not sure there is anything of substance here. Note the “any service”:

> “The sovereignty measures committed to by Microsoft do NOT extend to support of any services – this will always be likely to result in international transfers

By @ricktdotorg - 4 months
this data sovereignty issue is almost certainly going to come up with the UK NHS / Palantir Federated Data Platform[0] which is going to be using Microsoft and AWS cloud services.

[0] https://blog.palantir.com/palantir-and-the-nhs-dd1362982fa9

By @retox - 4 months