
Open Rights Group
UK civil society organisation campaigning for digital rights, privacy, and tech accountability.
Last refreshed: 19 April 2026 · Appears in 2 active topics
What did the Open Rights Group say about UK cloud lock-in and national security?
Timeline for Open Rights Group
Mentioned in: Midlands fund writes its first cheques
UK Startups and InnovationMentioned in: Onwurah: DSIT has no coherent strategy
European Tech SovereigntyMentioned in: Kendall names seven infrastructure bets for £500m Sovereign AI Unit
European Tech SovereigntyPublished Tech Giants and Giant Slayers report warning US-tech dependency is a national security risk
European Tech Sovereignty: ORG brands UK tech dependency a riskBackground
The Open Rights Group published 'Tech Giants and Giant Slayers' on 15 April 2026, branding Britain's decade of US tech dependency a national security vulnerability and citing a Competition and Markets Authority estimate that the UK wastes £500m a year on cloud services due to lock-in and switching barriers . The report flagged the US CLOUD Act as a mechanism that can compel US-headquartered providers to disclose UK data without UK consent, and cited Microsoft's documented shutdown of email services for individuals hit by ICC-related US sanctions as concrete precedent.
Founded in 2005, the Open Rights Group is Britain's leading civil society organisation on digital rights. It campaigns on mass surveillance, online censorship, biometric data use, and data protection, operating as a counterweight to both government overreach and corporate data extraction. Its Patrons and supporters include academics, lawyers, and technologists; it is funded by individual donors and small grants rather than corporate sponsorship.
The April 2026 report represents a significant broadening of ORG's framing: from privacy rights to national security risk. By citing the CMA cloud lock-in figure alongside CLOUD Act exposure and Palantir contract expansion, ORG is making the case that cloud dependency is not merely a commercial or regulatory problem but a structural security one .