Police Scotland has been served with an information notice from the Scottish Biometrics commissioner, requiring them to prove their cloud-based digital evidence system is compliant with data protection rules for law enforcement.
Currently, the Digital Evidence Sharing Capability service is being piloted in Scotland, under contract to Axion, the body-worn camera and video provider, and hosted by Microsoft Azure for their cloud system.
Watchdogs, however, have voiced their concerns regarding the use of cloud in policing, saying the new service is not capable of complying with current data laws.
The Data Protection Impact Assessment by the Scottish Police Authority did identify several risks with the use of Microsoft Azure which may put its use by the police force in jeopardy of being illegal.
Firstly, Microsoft is using standard rather than specific contracts with the police, without any specific stipulations on data protection or accessing of certain data. Further, Axon cannot comply with the data sovereignty clauses found in legislation.
Concerningly, under the Cloud Act, all cloud data stored by Microsoft is accessible by the US government as Microsoft is a US corporation. Adding onto this is the notably softer data protections found in the US that UK citizens may have their data subject to if requested by the US government.
The information request was sent on 22 April, and Police Scotland will have until June to reply.
Br. Brian Plastow of the Scottish Biometrics Commissioner wrote the letter, with the main concerns surrounding the processing of biometric data by cloud providers.
The letter asked for clarification on if any biometric data had been exchanged by Police Scotland, if this exchange was compliant with data protection laws, and what country this data was hosted by.
Further, the letter asked if any discussions had occurred with the Information Commissioner’s Office (ICO) regarding international transfers and data sovereignty and if these were at all resolved.
Plastow details recommendations to ensure data sovereignty, mainly by hosting a cloud platform entirely in the UK so the data is not subject to any other governments.
Recommended
- DIGIT Leader | Generative AI: Fad or Fundamental?
- Edinburgh Napier to Help Make the UK a Leader in Cryptography
- Geospatial Commission Launches Earth Observation Data Pilot
Previously, the ICO had been working with the SPA to configure how the cloud system would work under data laws – they found that any technical support from the US via the Cloud Act would indeed constitute an international data transfer that would not be compliant under current regulations.
They previously had concerns with similar uses of cloud infrastructure in Police forces across England and Wales to process citizens’ data.





