Microsoft has acknowledged it cannot guarantee that UK policing data hosted on its M365 and Azure platforms will remain within British borders, revealing that international data transfers are inherent to its cloud infrastructure. This disclosure challenges the long-held assumption by government departments that physical UK data centers ensure true data sovereignty. Consequently, law enforcement and other public bodies may have been operating under the mistaken belief that their sensitive information was legally protected from cross-border processing, raising serious questions about compliance with strict data protection regulations designed for national security and privacy. The revelation casts doubt on the efficacy of the UK government’s cloud-first policy, which has driven widespread adoption of Microsoft services across central government since 2017. Critics argue that this strategy was implemented on blind trust, with procurement decisions often made by technical staff focused on cost rather than regulatory implications. The fact that data sovereignty was not clearly defined or enforced suggests a systemic failure in due diligence, where the promise of localized hosting was misinterpreted as a guarantee against offshore processing, potentially leaving vast amounts of public sector data exposed to foreign jurisdictions. This situation is critically relevant to open data and digital governance because it highlights the fragility of public trust in proprietary cloud providers. If the fundamental premises of data residency and sovereignty are unreliable, then any open data initiatives relying on these platforms must rigorously verify data locations and legal protections. It underscores the urgent need for transparent, verifiable standards in public procurement to ensure that digital infrastructure serves public interest rather than corporate convenience, preventing future misallocation of resources and ensuring that open data remains truly under public control.
Source: computerweekly.comPublished on 2024-06-26