How secure is encrypted data if the key is stored in the cloud?

A report published by Forbes in January 2026 provides the first public evidence that Microsoft has handed over BitLocker recovery keys to the FBI. This was made technically possible by the default configuration of modern Windows versions, which automatically upload recovery keys to the Microsoft cloud. For companies in the DACH region, this results in an immediate need for review: key ownership as a core element of technical safeguards under Article 32 GDPR must be reassessed. The case illustrates that cloud-bound encryption solutions without independent key management do not provide sufficient protection.
Background
BitLocker is Microsoft’s native full-disk encryption mechanism for Windows drives and is enabled by default on modern devices. According to reports by Forbes, TechCrunch, and Tom’s Hardware, Microsoft provided the FBI with BitLocker recovery keys for three seized laptops in the spring of 2025 as part of a law enforcement request. Microsoft confirmed to Forbes that it receives an average of around 20 such requests per year.

The technical core of the issue is that Windows 11 requires a Microsoft account by default during setup, which means BitLocker keys are automatically linked to the user’s online identity and stored in the Microsoft cloud. In the Home edition, this cloud storage is effectively mandatory. Even in Enterprise and Education editions, cloud storage may be active depending on Group Policy configuration and is promoted by Microsoft as the recommended approach.

By comparison, Apple stores FileVault keys via iCloud Keychain using end-to-end encryption, meaning Apple itself has no access and therefore cannot hand over keys even under legal compulsion. Microsoft, by contrast, has structural access to these keys and provides them when legally required.

Legal and Data Protection Assessment
Article 32 GDPR requires controllers to implement appropriate technical measures to secure personal data, including, explicitly, encryption. The decisive factor, however, is not merely the use of encryption, but who holds the key ownership.

If BitLocker keys are stored in the Microsoft cloud, the factual control over the encrypted data no longer lies exclusively with the organization. As a result, the protective effect of encryption against third parties – including U.S. authorities based on the CLOUD Act – is limited. This directly affects the assessment of technical safeguards under Article 32 GDPR, the execution of Transfer Impact Assessments (TIA) when using Microsoft cloud products in the context of international data transfers, and the records of processing activities as well as the outcome of the Data Protection Impact Assessment (DPIA) under Article 35 GDPR.

In addition, it must be considered that the U.S. CLOUD Act enables U.S. authorities, under certain conditions, to access data managed by U.S. companies – regardless of where the data is stored. As a U.S.-based corporation, Microsoft is also subject to this jurisdiction.

Risk Assessment for Organizations
The risk is multidimensional:
  • Government access: U.S. law enforcement authorities (and, in the future, potentially other law enforcement agencies with corresponding mutual legal assistance frameworks) may access device data via Microsoft without needing to technically break encryption.
  • Data breach risk: Compromises of Microsoft cloud infrastructure (historically documented on multiple occasions) could expose recovery keys to third parties.
  • Compliance risk: Organizations that have documented BitLocker as their sole security measure under Article 32 GDPR, without independently controlling key management, risk an incomplete security controls framework.
  • Reputational risk: In the event of a data protection incident involving cloud-stored keys, organizations may face difficult-to-explain gaps in their security concept.

Companies are particularly exposed if they use Windows Home editions, operate devices without dedicated Group Policy configuration, rely on managed device environments with default settings, or list BitLocker in their DPIA or technical and organizational measures (TOM) catalogue as an effective security measure without documenting the key storage location.

Recommendations for Action
  • Inventory: Check whether BitLocker keys are stored in Microsoft cloud accounts and on which devices this applies. This can be verified via the Microsoft account portal as well as through Active Directory / Azure AD.
  • Establish key ownership: Configure BitLocker via Group Policy so that keys are stored exclusively locally (on-premises Active Directory or an internal key management system). If necessary, delete keys already stored in the cloud.
  • Update TOM documentation: Add the specific key storage location and access controls to your records of technical and organizational measures.
  • Review TIA: If Microsoft cloud services are in use, verify whether the existing Transfer Impact Assessment adequately addresses the issue of cloud-stored encryption keys and the implications of the CLOUD Act.
  • Evaluate alternative encryption solutions: For highly sensitive areas, it is recommended to assess solutions with a proven zero-knowledge architecture or fully independent key management.
Need for consulting?
GfDDE – Gesellschaft für Datenschutz und Datensicherheit – in Europa GmbH supports you in the assessment of cloud-bound encryption solutions in the GDPR context – practical and professionally grounded.
Sources
Forbes / Thomas Brewster (22 January 2026): Microsoft Gave FBI Keys To Unlock BitLocker Encrypted Data

TechCrunch (23 January 2026): Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects’ laptops

Tom’s Hardware (24 January 2026): Microsoft gave customers’ BitLocker encryption keys to the FBI

TechRepublic (26 January 2026): Microsoft Shared BitLocker Keys With FBI, Raising Privacy Fears

Schneier on Security (3 February 2026): Microsoft is Giving the FBI BitLocker Keys

More news

Phishing via a legitimate Microsoft address: Power BI abuse and GDPR obligations for companies

Since January 2026, a sophisticated phishing campaign has been active in which attackers send deceptive emails using the legitimate Microsoft sender address no-reply-powerbi@microsoft.com . This is technically possible due to a legitimate feature of Microsoft Power BI: when creating a dashboard, any external email address can be added as a subscriber, and the content of the automatically sent notification can be freely configured.

Read more…