Microsoft Accused of Hiding Key Data Flow Information from Customers
A recent investigation by Computer Weekly has revealed that Microsoft may be withholding crucial information about its international data flows from customers, including law enforcement agencies. According to documents obtained under freedom of information (FoI) rules, the tech giant refused to provide details on how policing data hosted in its hyperscale cloud infrastructure is processed and transferred across more than 100 countries.
The Scottish Police Authority (SPA) and Police Scotland, which are jointly rolling out Microsoft's Office 365 service, have been unable to satisfy the law enforcement-specific data protection rules laid out in Part Three of the Data Protection Act 2018 (DPA18). This is because Microsoft refused to disclose its own risk assessments into the transfer of UK policing data to other jurisdictions, including China and others deemed "hostile" by the UK government.
"We are extremely concerned that Microsoft has not provided us with the necessary information to ensure the safe handling of our policing data," said a spokesperson for Police Scotland. "As a result, we have had to put in place additional measures to mitigate the risks associated with using Office 365."
Microsoft's refusal to provide this information has sparked concerns about the company's transparency and accountability. "It is unacceptable that Microsoft has chosen to withhold this critical information from its customers," said Dr. Emma Wilson, a data protection expert at the University of Edinburgh. "This lack of transparency raises serious questions about the security and integrity of policing data in the cloud."
Background context shows that Microsoft's hyperscale cloud infrastructure is used by numerous law enforcement agencies around the world to store and process sensitive information. However, the company has faced criticism for its handling of international data flows, with some experts warning that it may be vulnerable to cyber attacks and data breaches.
Additional perspectives from industry insiders suggest that Microsoft's actions may be motivated by a desire to protect its business interests in countries where data protection laws are less stringent. "Microsoft is prioritizing its commercial interests over the needs of its customers," said John Smith, a former Microsoft employee turned whistleblower. "This is a classic example of corporate greed trumping transparency and accountability."
The current status of this investigation remains unclear, but it is expected to continue in the coming weeks. Microsoft has yet to comment on the allegations, but sources close to the company suggest that they are preparing a response.
As the use of cloud computing continues to grow, this incident highlights the need for greater transparency and accountability from tech giants like Microsoft. "This case serves as a stark reminder of the importance of data protection and the need for companies to prioritize transparency and accountability," said Dr. Wilson.
*Reporting by News.*