UNHCR is one of the most data-intensive humanitarian organisations in the world. Its operations across more than 130 countries depend on the accurate collection, management, and sharing of data about some of the world’s most vulnerable people. The shift to cloud-based infrastructure, formalised under the Digital Transformation Strategy 2022–2026, marks the most significant change to UNHCR’s information architecture in the agency’s history. It offers real operational gains — but it also introduces risks that are qualitatively different from those of legacy systems, and that go to the heart of UNHCR’s principles of neutrality, impartiality, and the protection of persons of concern.

This paper examines how UNHCR stores and uses data in the cloud, who accesses it, at what frequency, and for what purposes; the advantages of cloud migration; and the significant disadvantages and risks that commercial cloud infrastructure poses for a humanitarian organisation whose data subjects cannot consent to, and may be endangered by, the misuse of their information. It concludes with a recommendation for a dedicated UN sovereign cloud infrastructure as the only arrangement consistent with the organisation’s mandate.

Data storage before cloud transformation

For most of its history, UNHCR managed data through on-premises systems that were neither designed for the scale of modern humanitarian operations nor for the cross-border, multi-stakeholder environment in which UNHCR now functions.

Beneficiary data — legacy conditions

Beneficiary data — registration records, biometric profiles, refugee status determination (RSD) case files, needs assessments, and protection documentation — was held in a patchwork of local databases, physical files, and standalone digital systems. The ProGres casework database, which by December 2021 held live records for over 12.3 million registered individuals, was hosted in centralised on-premises environments. The result was fragmentation: data was not consistently available across operations, and field offices often maintained local shadow copies on individual hard drives.

A 2019 evaluation found that personal data was routinely transferred via unencrypted email and shared through commercial platforms such as WhatsApp and Dropbox — practices fundamentally incompatible with UNHCR’s own data protection obligations. Security standards were inconsistent across operations. In emergencies, the inability to rapidly provision systems or share verified data across borders was operationally acute.

Operational and administrative data — legacy conditions

Financial, supply chain, human resources, and programme data were managed through MSRP (Management System for the Renewal Programme), introduced in 2004. By 2020, MSRP had become structurally inadequate: it was not mobile-enabled, could not support simultaneous data access across multiple geographies, and could not keep pace with a doubling of country-level budget management — from USD 282 million to USD 618 million in financial terms between 2019 and 2020 alone. Reporting was slow, fragmented across disconnected platforms, and required manual reconciliation. The system could not provide the real-time financial visibility that a global operation managing over USD 4 billion annually required.

UNHCR data in the cloud — types, users, and frequency of use

Beneficiary data

Beneficiary data constitutes UNHCR’s most sensitive and voluminous category. It includes:

Users include UNHCR protection officers, registration staff, information management officers, implementing partners, host government authorities (where data-sharing agreements exist), and — through the Microdata Library and the World Bank–UNHCR Joint Data Centre — external researchers and the public.

Frequency of use is high and operationally critical. Registration data informs every protection decision, assistance distribution, and resettlement referral. By 2021, over 9.7 million individuals had been biometrically enrolled across 80 countries. Between 2016 and 2020, UNHCR disbursed over USD 3 billion in cash assistance to more than 25 million people across 100 countries, with biometric authentication underpinning the integrity of distributions.

Operational and administrative data

Operational data encompasses financial budgets and expenditure, supply chain and logistics records, human resources and payroll data, programme plans and results frameworks, partner project agreements, and donor relationship management. Users include country representatives, regional bureau directors, finance and supply chain staff, programme managers, and senior leadership. Use is continuous — budget decisions, procurement approvals, and reporting cycles run year-round across 130+ countries.

The Business Transformation Programme, initiated in 2020, moved these systems to SaaS cloud platforms: an ERP for financial management, Compass for results-based management, PROMS for partner project management, and Synergy for relationship management. The 2023 ServiceNow deployment for Ukrainian refugees in Hungary and Poland — enabling multi-channel case intake and aggregated interaction data — illustrates the operational potential of cloud-enabled service delivery.

Advantages of cloud storage for UNHCR

The case for cloud migration is strongest for operational and administrative data, and real but qualified for beneficiary data. The principal advantages:

Why commercial cloud is inappropriate for UNHCR’s core data

Despite the operational advantages above, the use of commercial hyperscale cloud infrastructure — dominated by Amazon Web Services (AWS), Microsoft Azure, and Google Cloud — for UNHCR’s most sensitive data raises risks that go beyond technical considerations and strike at the institutional foundations of humanitarian action.

Vendor lock-in and loss of control

UNHCR’s migration to US-headquartered hyperscalers creates structural dependency through proprietary APIs, managed services, and data formats that raise switching costs beyond viable thresholds. There is a documented lock-in threshold — the point at which the cost of moving data, modifying applications, and reskilling employees exceeds the savings that cloud services originally promised. UNHCR, with constrained budgets and a workforce trained on incumbent platforms, is particularly exposed. The agency’s own Digital Transformation Strategy acknowledges the need to avoid “threats to continuity-of-access” and prioritise open technical standards — a commitment that sits in tension with deepening dependency on proprietary hyperscale ecosystems.

Military entanglement and dual-use infrastructure

Confirmed investigative reporting in 2025 established that all three major hyperscalers — AWS, Azure, and Google Cloud — are operationally entangled with military and intelligence activities in ways that directly compromise their claim to neutrality.

Unit 8200 of the Israeli Defence Forces stored 8,000 TB of military surveillance data on Microsoft Azure. Israel’s Military Intelligence Directorate used AWS for mass surveillance, including for AI-assisted targeting analysis linked to decisions in Gaza. The CIA has held cloud contracts with AWS since 2013, extended in 2020 to Microsoft, Google, Oracle, and IBM. The US Department of Defense’s Joint Warfighting Cloud Capability (JWCC) contract, worth up to USD 9 billion, distributes classified military workloads — including battlefield communications and AI-driven intelligence analysis — across these same commercial platforms.

A single AWS availability zone in Northern Virginia may simultaneously process classified Pentagon data, serve commercial applications, and host humanitarian data.

Iran’s 2026 declaration of AWS, Azure, and Google data centres as military targets makes the risk concrete: refugee data now sits, structurally, in potential conflict infrastructure.

Compelled disclosure and the US CLOUD Act

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act, 2018) permits US federal agencies to compel US-headquartered cloud providers to disclose data regardless of where it is physically stored, without notifying the data subject or the organisation. Data residency outside the United States provides no legal protection: the CLOUD Act establishes that data access follows corporate control, not geographic location. Non-disclosure orders may further prevent providers from alerting UNHCR that access has been sought.

For UNHCR, this means that biometric data, protection status, nationality, and location of refugees held on AWS or Azure infrastructure can, in principle, be accessed by US law enforcement or intelligence agencies without UNHCR’s knowledge. In politically sensitive operational contexts — where persons of concern may face persecution from state actors — this is not a theoretical risk. It is a direct threat to the principle of non-refoulement.

The Handbook on Data Protection in Humanitarian Action addresses this directly: humanitarian organisations must account for such legislation when selecting technology, and the risk is compounded by non-disclosure obligations that “undermine transparency and trust and complicate incident response timelines.” UNHCR’s UN privileges and immunities may offer partial protection in principle, but this remains an unresolved and contingent safeguard.

Service politicisation — the ICC precedent

Perhaps the most instructive precedent for UNHCR is not a hypothetical but a documented event. In February 2025, the Trump administration imposed sanctions on ICC officials, including Chief Prosecutor Karim Khan, over the court’s investigation of Israeli officials for alleged war crimes in Gaza. Following the sanctions, Khan’s Microsoft Outlook email account — his primary official communications platform — was suspended. Dutch press reporting, confirmed by technology activist and former Dutch intelligence regulator Bert Hubert, indicated that Microsoft told the ICC it was required to deny Khan access to its services as a result of the sanctions, and that failure to do so would result in Microsoft terminating email services for the entire organisation.

Microsoft President Brad Smith publicly denied the company had “stopped or suspended” services to the ICC as an institution. However, the ICC subsequently migrated from Microsoft Office to openDesk, an open-source platform developed under a German government digital sovereignty initiative — a de facto acknowledgement that the dependency had become untenable. In June 2025, Microsoft admitted under oath in a French court that it could not guarantee digital sovereignty if the US government demanded access under the CLOUD Act.

The lesson for UNHCR is direct. UNHCR’s operations routinely involve investigations, protection monitoring, and documentation of human rights violations that may be contested by member states or powerful political actors. Its platforms, if hosted on US commercial infrastructure, are susceptible to exactly the same pressure that was applied to the ICC. A US government that can sanction an ICC prosecutor and threaten to disable institutional email services can apply equivalent leverage to any organisation operating on the same infrastructure. Unlike the ICC, which could migrate its productivity suite, UNHCR’s cloud-hosted systems include the registration and biometric records of millions of refugees. The consequences of suspension or compelled access in those systems are measured in protection failures, not inconvenience.

Business continuity and operational reliability

The operational record of hyperscale cloud providers is incompatible with the reliability demands of humanitarian operations. Between August 2024 and August 2025, AWS, Azure, and Google Cloud recorded more than 100 service outages. The AWS outage of October 2025 lasted 15 hours and paralysed 3,500+ organisations across 60 countries. Azure incidents average 14.6 hours of downtime per incident. In July 2025, an Outlook outage lasting 19 hours disrupted millions of users.

For UNHCR, a 15-hour system outage during an active refugee registration drive, a cash assistance distribution, or an emergency evacuation is not an operational inconvenience — it is a protection failure with potentially life-threatening consequences. The root cause of these outages is systemic: insufficient change-management discipline and pre-deployment validation. Recurrence is not a contingency to be planned for; it is a certainty.

The connectivity constraints of UNHCR’s operational environment compound this risk. Cloud-dependent systems fail when internet access fails — precisely the condition that prevails in the remote, conflict-affected, or under-resourced settings where UNHCR operates. The 2019 evaluation specifically recommended investing in tools capable of functioning in both online and offline modes, a requirement that commercial SaaS platforms do not inherently meet.

The case for a UN sovereign cloud infrastructure

The risks documented above are not incidental to the choice of cloud vendor; they are structural features of commercial cloud infrastructure that reflect the commercial, legal, and geopolitical environment in which those providers operate. They cannot be resolved by more demanding contractual terms, data residency clauses, or encryption protocols, though all of these reduce exposure at the margins.

The fundamental issue is that commercial cloud providers are subject to the laws, political pressures, and economic interests of the states in which they are incorporated. UNHCR’s mandate requires it to act independently of political influence. These two conditions are in structural tension that contractual arrangements cannot fully resolve.

Precedents and analogues

The ICC’s migration to openDesk following the Khan email suspension demonstrates that international legal institutions have concluded that dependency on US commercial infrastructure is inconsistent with operational independence. NATO’s November 2025 decision to deploy Google Distributed Cloud in an air-gapped configuration — Google software on NATO-operated hardware, physically disconnected from Google’s network — reflects the same logic: use the software capability, own the infrastructure.

The European Commission’s EUR 180 million sovereign cloud tender (2025) and the growing body of EU digital sovereignty legislation (the Data Act, NIS2, DORA) signal that dependence on US hyperscalers for sensitive institutional data is becoming untenable even for civilian public-sector bodies. For an organisation whose data subjects are stateless, displaced, and potentially persecuted, the standard must be higher.

A proposed UN cloud model

UNHCR should advocate within the UN system for the establishment of a dedicated UN sovereign cloud infrastructure, operated under the auspices of the UN Secretariat or a purpose-built UN agency, with the following characteristics:

The financial case for a shared UN cloud is strengthened by the cost premium already imposed by commercial sovereign cloud options: BCG analysis (2025) estimates a 10–30% premium over standard public cloud for compliance-grade sovereign services. Amortised across the UN system, a UN-operated infrastructure would provide comparable or superior governance at manageable cost, while eliminating the structural vulnerabilities that commercial dependency creates.

Transition pathway

In the immediate term, UNHCR should:

Conclusion

Cloud migration is appropriate for UNHCR, but not uniformly so. For operational and administrative data, the benefits are clear and the risks manageable with sound governance. For beneficiary data — the most sensitive category, held on behalf of people who have no alternative but to entrust their information to the agency — commercial cloud infrastructure is structurally incompatible with UNHCR’s mandate.

The evidence is no longer theoretical. Commercial cloud platforms are demonstrably entangled in military operations, subject to compelled disclosure under US law, susceptible to service denial under political pressure, and operationally unreliable at the scale that humanitarian operations require. The ICC precedent makes clear that this is not a risk to be managed through better contracts — it is a structural condition of commercial cloud that only structural alternatives can address.

UNHCR holds data on some of the world’s most vulnerable people. The infrastructure that holds that data should be held to the same standard of neutrality, impartiality, and independence as the organisation itself.

Commercial hyperscale cloud, as currently constituted, cannot meet that standard. A UN sovereign cloud can, and should.

This document was drafted with the assistance of Claude (Anthropic), an AI language model, drawing on source materials, prior research, and referenced published sources provided or identified during the research process. All content has been reviewed by the author, who takes responsibility for the accuracy of facts, the framing of arguments, and the conclusions reached.