Microsoft is refusing to tell Police Scotland where and how the law enforcement data being uploaded to its cloud servers will be processed on the grounds of “commercial confidentiality.”
The revelation comes from a Freedom of Information request released by the Scottish police Authority (SPA) and first reported on by Computer Weekly, showing that Microsoft is refusing requests by the SPA and Police Scotland to release information on its international data flows when handing sensitive law enforcement data.
The requests come as Scottish police authorities are moving their data to the cloud, opting for Microsoft Office 365 in their digital infrastructure implementation.
If the SPA cannot confirm this information from Microsoft, however, then it will be unable to comply with the Data Protection Act 2018 (DPA) which has specific requirements concerning law enforcement data and the limitations of transferring this data outside the UK.
When asked specifically to see transfer risk assessments for the countries used by Microsoft where there is no data adequacy agreement with the UK, Microsoft “declined to provide the assessments,” the SPA said in their data protection impact assessment (DPIA).
Microsoft has also informed the SPA that it is unable to confirm the sovereignty of law enforcement data that is stored and processed by its 0365 service.
The SPA says that Microsoft previously agreed to make changes to its data processing protocol when it came to the Digital Evidence Sharing Capability (DESC) of Police Scotland which uses Microsoft Azure, these amendments remain unclear. And, Microsoft said that while it could offer “some level of assurance” for this project, it would fall short of other stipulations in the DPA.
Further, though it could make changes to that system, Microsoft said that “O365 operates in a completely different manner and there is currently no way to guarantee data sovereignty.”
Microsoft has not provided the SPA with assurances transfers to countries with data adequacy agreements, nor has it provided International Data Transfer Agreements.
Besides these major data protection issues, the DPIA identified any other issues when it came to Microsoft, including that the firm holds all the encryption keys for the data, meaning that Microsoft could access the data or hand it over to the US if required to by the government. The firm is also not allowing the UK to vet any Microsoft staff who may be accessing the data outside of the UK.
Police Scotland has been contacted for comment.
Recommended reading
- ICO Publishes Draft Guidance on Biometric Data Use in the UK
- ICO Issues Guidance on Facial Recognition Technology
- Google Changes AI Policy to Work on Weapons and Surveillance
- UK Police Use of Facial Recognition Found to be ‘Unethical’
It seems that Police Scotland has been seeking clarification from Microsoft regarding its data transfer practices and if these are legal for months, other FOI responses seen by Computer Weekly show.
Police Scotland has been requesting information on international data transfers since October 2024, finding that Microsoft’s response was inadequate.
Hyberscale cloud services are used throughout the UK by law enforcement, and the correspondence between Police Scotland and Microsoft highlight how difficult it is to maintain transparency in the operations of these tech giants when it comes to sensitive data.
In the correspondence released in an FOI request, Microsoft did say that its M365 cloud services “is not designed to process special categories of personal data on a large scale,” which brings into question why it was adopted by Police in the first place.





