As long as you need to live in the UK, you're at their mercy.
If only there was a bigger power that looked a bit more after people's privacy and could stop local governments from doing this...
"7.14 Section 217(8) provides that obligations may be imposed on, and technical capability notices given to, CSPs located outside the UK and may require things to be done or not done outside the UK. Where a notice is to be given to a person outside the UK, the notice may (in addition to electronic or other means of service) be given to the CSP:
-- By delivering it to the person’s principal office within the UK or, if the person does not have an office in the UK, to any place in the UK where the person carries on business or conducts activities; or
-- At an address in the UK specified by the person."
https://www.gov.uk/government/uploads/system/uploads/attachm... -- page 59
For example, I am part owner of a Canadian company that sells an online service. If we hire US employees (developers), then we must collect sales tax and pay income tax for sales originating within the governing municipality.
Obviously, I am talking about US tax law, and your question is of a different nature, so the best thing to do is to contact a lawyer who has expertise in that area. I only offer my experience as evidence that the location of employees can impact the legal responsibilities of a foreign business.
I also don't think it's a safe assumption in any jurisdiction nowadays that the person who gets served with a notice will be an executive. It seems quite plausible to me that a front-line engineer could get served with a notice, and not even be allowed to tell an executive. Thus, even if your employees in the UK don't appear to have been coerced, this appearance could be deceiving.
There may be some limited countermeasures to this sort of thing, like regular audits of system configurations, etc. performed by a different group of people, and who will thus cry murder if they find any anomalies. This should work because the second group of people will not be the target of a notice, and thus not bound by its secrecy provisions. Possibly this group could do their auditing remotely, from outside the UK. Of course the in-UK group could, under coercion, rootkit the system to hide these changes, probably by being told to install government-issued software. Hmm...