Man city would still be the "controller" of the data in question even if it was hosted by a third party, so therefore would be liable for any breaches, this is why companies need to do Data Privacy Impact assessments under DPA2018 where the data stored could hold special category data. (ie. medical information) Under the DPA the controller of the data must make sure the data is secure and safe, this also extends to people that process the data on the controllers behalf. This is why companies have password policies where users must change their password every x days/weeks/months so even if a password was breached unknowingly, it would be changed at some point.