A UK government department plans to consolidate file shares and archives onto object storage. A local authority evaluates a hosted backup service. A supplier bids for a public sector contract that involves storing citizen data. Each of them needs to understand how the Government Security Classifications Policy applies to data storage, and what that means for where data lives, who can access it and how it is protected.
This article explains the UK classification tiers, how they apply to storage, the National Cyber Security Centre (NCSC) cloud security principles that guide cloud and hosted services and practical storage design choices for public sector organizations and their suppliers. It is part of our data sovereignty series; see also sovereign cloud architecture.
The Government Security Classifications Policy, most recently updated by the Cabinet Office in 2023 and 2024, defines three classification levels:
The vast majority of government data is OFFICIAL. SECRET and TOP SECRET information is handled in specialized, accredited environments with their own infrastructure and processes, outside the scope of general commercial storage.
OFFICIAL is designed to be handled with good commercial security practice, which is why many departments use commercial cloud and hosted services for OFFICIAL workloads. For storage, the expectation is not exotic technology but well-implemented controls:
OFFICIAL-SENSITIVE information calls for stronger need-to-know controls, which in storage terms means tighter access policies, separate buckets or accounts, additional logging and sometimes restrictions on where data may be stored or who may administer it.
For cloud and hosted services, the NCSC publishes 14 cloud security principles that public sector buyers use to assess services. They cover data in transit protection, asset protection and resilience, separation between customers, governance, operational security, personnel security, secure development, supply chain security, secure user management, identity and authentication, external interface protection, secure service administration, audit information for users and secure use of the service. Storage contributes directly to many of them:
| NCSC principle | Storage implications |
|---|---|
| Data in transit protection | TLS for all access and replication traffic |
| Asset protection and resilience | Data location, encryption at rest, erasure coding, multi-site, secure deletion |
| Separation between customers | Per-tenant accounts, policies and encryption |
| Operational security | Patching, vulnerability management, monitoring |
| Personnel security | Vetted administrators, separation of duties |
| Supply chain security | Assurance over storage vendor and support access |
| Secure service administration | Hardened management interfaces, role-based admin |
| Audit information | Logs available to customers for their own monitoring |
UK government guidance takes a risk-based view of data location for OFFICIAL information rather than imposing a blanket requirement to keep data in the UK. In practice, many departments, local authorities, health bodies and police forces prefer or require UK hosting for some workloads, for reasons including legal jurisdiction, public confidence and operational control. UK GDPR and the Data Protection Act 2018 also apply to personal data, including rules on international transfers. Storage that can be deployed entirely within UK data centers gives buyers the most flexibility.
Make sure storage management interfaces are reachable only from trusted networks, administrators are vetted and actions are logged. Avoid platforms that require management through services hosted outside your chosen jurisdiction.
Use separate buckets, accounts or even separate clusters for OFFICIAL-SENSITIVE data, with tighter access policies and monitoring.
Encrypt data at rest and in transit, with keys managed in systems you control.
Public sector organizations are frequent ransomware targets. Use immutable copies with compliance-mode object lock, separate credentials and tested recovery.
Agree how storage vendor support accesses systems, with remote access disabled by default and supervised when used.
Ensure the storage platform supports verifiable deletion and that drives are sanitized or destroyed at end of life according to policy.
Departments consolidating file shares, archives and backups often move to object storage for scale and cost. Most of this data is OFFICIAL, with pockets of OFFICIAL-SENSITIVE information such as personnel or policy material that need separate handling.
Councils hold social care, housing and planning records, much of it personal data. Ransomware resilience and UK GDPR compliance are usually the top priorities, together with affordable long-term retention for records schedules.
NHS organizations and suppliers follow health-specific frameworks alongside the classification policy, including data security and protection requirements for health and care data. Imaging archives, records and backups are common storage workloads.
Police forces store large volumes of digital evidence, body-worn camera footage and case files, with strict access logging and retention rules. Storage must support evidential integrity and clear audit trails.
Public sector organizations must also follow records management obligations, including retention schedules and transfer of records of historical value to archives. Storage should support retention policies, legal holds and defensible deletion, with evidence of what was deleted and when. Object storage lifecycle rules and object lock help enforce these schedules consistently across large volumes of records.
Many public sector organizations run their own assurance processes before a system goes live, reviewing risks, controls and supplier evidence. Storage teams can help by providing architecture documentation, configuration evidence for encryption and access control, logging arrangements, recovery test results and details of vendor support and update processes. Having this material ready shortens approvals and makes later audits easier.
Suppliers storing government data must demonstrate controls appropriate to the classification and contract. That often includes recognized certifications, alignment with the NCSC principles, staff vetting and clear statements about data location. Choosing storage that runs on infrastructure the supplier controls simplifies these assurances.
Scality RING and ARTESCA are software-defined object storage platforms that run entirely on infrastructure chosen by the organization or its supplier, with no mandatory dependence on external cloud services. They can be deployed across multiple UK sites, support S3 access with compliance-mode object lock, encryption, multi-tenancy, role-based administration and audit logging. That makes them suitable foundations for public sector storage at OFFICIAL, including stricter configurations for OFFICIAL-SENSITIVE data, alongside the organization's own policies and accreditation processes.
Run regular recovery tests, review administrator access quarterly and confirm that logs reach your security monitoring. Small, routine checks catch drift long before an audit or an incident does.
UK government security classifications put most public sector data at OFFICIAL, where good commercial security, well implemented, is the expectation. For storage, that means strong access control, encryption, logging, resilience, secure disposal and supplier assurance, guided by the NCSC cloud security principles. OFFICIAL-SENSITIVE data needs tighter controls, and many organizations also prefer UK hosting. Storage that runs fully under your control in UK data centers makes meeting those expectations simpler.
OFFICIAL, SECRET and TOP SECRET, with OFFICIAL-SENSITIVE used as a marking for particularly sensitive OFFICIAL information.
Yes. OFFICIAL is designed to be handled with good commercial security, and many organizations use cloud and hosted services that meet the NCSC cloud security principles.
Guidance takes a risk-based approach for OFFICIAL data, but many organizations prefer or require UK hosting. UK GDPR rules apply to personal data transfers.
Fourteen principles covering areas such as data protection in transit, asset protection, customer separation, personnel security, supply chain and audit information.
With tighter need-to-know access controls, separation from other data, additional logging and, where required, location or administration restrictions.