Recommendations & Conclusions
14 items
2
Conclusion
54th Report - Afghanistan Response Route
Accepted
The Department did not have appropriate systems and controls in place at the time of the February 2022 breach to manage personal data in a high-risk environment. The Department did not use a caseworking system designed to hold and process high volumes of sensitive personal information relating to the government’s …
Read more
The Department did not have appropriate systems and controls in place at the time of the February 2022 breach to manage personal data in a high-risk environment. The Department did not use a caseworking system designed to hold and process high volumes of sensitive personal information relating to the government’s Afghan resettlement schemes until May 2022, when it introduced the Defence Afghan Casework System. Instead, the Department relied on Excel spreadsheets stored in a Sharepoint site, which was neither appropriate nor adequate for handling thousands of lines of personal data. The Department was still managing its data in this way when it launched the ARAP in April 2021, amidst a rapidly deteriorating security situation in Afghanistan. The manner in which the Department was storing and accessing this data contributed to the February 2022 data breach. This is because the individual who sent the email inadvertently shared data on 18,700 people without knowing it was included in 3 the spreadsheet. They thought they were sharing only information relating to 150 people, for a legitimate purpose to gather information about applicants’ eligibility. recommendation The Department should provide confirmation to the Committee that it is now managing all Afghan resettlement schemes through its new caseworking system and provide us with assurance that this would prevent a recurrence of the February 2022 breach or similar.
Show less
Government response AI summary
The government confirmed the Defence Afghan Relocations Assistance Policy Casework System (DACS) was implemented in May 2022, addressing vulnerabilities with stricter controls, audit logs, and secure data sharing protocols, and undergoes regular maintenance to prevent future data breaches.
Read full response →
HM Treasury
3
Conclusion
54th Report - Afghanistan Response Route
Accepted
The Department did not do enough to learn the lessons from previous data breaches. Before the February 2022 data breach, the Department had policies in place to protect against the loss of personal information. After three separate data breaches in autumn 2021 relating to the ARAP, the Department reviewed its …
Read more
The Department did not do enough to learn the lessons from previous data breaches. Before the February 2022 data breach, the Department had policies in place to protect against the loss of personal information. After three separate data breaches in autumn 2021 relating to the ARAP, the Department reviewed its data protection policies and guidance, and it worked with the Information Commissioner’s Office (ICO) to make targeted improvements to prevent similar incidents from recurring. Despite this, the Department continued to experience data breaches, including the significant data breach in February 2022. In August 2025, the Department disclosed that there had been 49 separate data breaches to date at the unit handling applications from Afghan citizens to relocate to the UK, seven of which met the threshold for disclosure to the ICO. The Department continues to work to reduce the risk of further data breaches, but it has not given us confidence that sufficient action has yet been taken. recommendation Alongside its Treasury Minute response, the Department should write to the Committee to provide details of: • its policies, processes and guidance to prevent data protection breaches relating to personal information; • how the Department assures itself that these are being followed, including the level of attendance at related mandatory training; and • the changes to policies, processes and guidance the Department has made in response to previous data breaches.
Show less
Government response AI summary
The government commissioned an independent MOD-wide Data Protection Review (McIvor Review) in 2023, the recommendations of which were implemented and detailed in a 7 October 2025 letter, and committed to providing a report on mandatory data protection training completion in a future update.
Read full response →
HM Treasury
1
Conclusion
54th Report - Afghanistan Response Route
Accepted
On the basis of a report by the Comptroller and Auditor General (C&AG), we took evidence from the Ministry of Defence (the Department) on the circumstances surrounding the February 2022 data breach and the Department’s subsequent response, including setting up the Afghanistan Response Route (ARR) to relocate affected individuals.1 Since …
Read more
On the basis of a report by the Comptroller and Auditor General (C&AG), we took evidence from the Ministry of Defence (the Department) on the circumstances surrounding the February 2022 data breach and the Department’s subsequent response, including setting up the Afghanistan Response Route (ARR) to relocate affected individuals.1 Since our session on 8 September we have received a letter, dated 7 October 2025, containing detailed information about all the data breaches between 2021 and October 2025 which should be read in conjunction with this report.2
Show less
Government response AI summary
The government agreed to the conclusion, stating it will signpost to Home Office's quarterly immigration statistics on GOV.UK for Afghan Resettlement Programme data and provide broader updates on MOD's ARR relocation and resettlement activity where possible.
Read full response →
HM Treasury
11
Conclusion
54th Report - Afghanistan Response Route
Accepted
We asked the Department to outline how the February 2022 data breach had occurred. The Department told us that the systems it used to manage case work for the ARAP scheme—a Sharepoint site and Excel spreadsheets—were not appropriate for handling many thousands of lines of personal data.22 The Department said …
Read more
We asked the Department to outline how the February 2022 data breach had occurred. The Department told us that the systems it used to manage case work for the ARAP scheme—a Sharepoint site and Excel spreadsheets—were not appropriate for handling many thousands of lines of personal data.22 The Department said that the context for this was that it built up the ARAP scheme at pace throughout 2021 as it became clear that the situation in Afghanistan was deteriorating rapidly.23 The Department also told us that the individual who sent the email which caused the data breach had asked for data on 150 individuals, but that the underlying data was hidden and that they emailed the data out, not knowing the underlying database was there.24 In correspondence received after our evidence session, the Department stated that the February 2022 incident was a result of a one-off action, rather than reflecting a wider culture of non-compliance, but that it was facilitated by the lack of appropriate systems to prevent or mitigate the error.25
Show less
Government response AI summary
The Defence Afghan Relocations Assistance Policy (ARAP) Casework System (DACS) was introduced in May 2022 which addressed many of the vulnerabilities, including stricter access controls, audit logs, and protocols to limit data sharing outside secure systems and new software introduced in January 2025 enhances their …
Read full response →
HM Treasury
12
Conclusion
54th Report - Afghanistan Response Route
Accepted
The Department told us that it has since implemented a new system which has embedded controls to allow the Department to protect information more effectively, and that this meant that it is no longer using embedded or hidden data in spreadsheets.26 The Department 20 C&AG’s Report, para 11 21 C&AG’s …
Read more
The Department told us that it has since implemented a new system which has embedded controls to allow the Department to protect information more effectively, and that this meant that it is no longer using embedded or hidden data in spreadsheets.26 The Department 20 C&AG’s Report, para 11 21 C&AG’s Report, para 12 22 Qq 1, 10 23 Q 1 24 Q 13 25 Letter from Ministry of Defence, 7 October 2025 26 Q 10 10 introduced its new casework management system, known as the Defence Afghan Casework System (DACS), in May 2022, after the February 2022 data breach occurred but before it was discovered.27 In correspondence received after our evidence session, the Department said that the DACS includes stricter access controls and audit logs, and prevents the sharing of data outside secure systems without appropriate protocols being adhered to.28 Learning lessons from previous data breaches
Show less
Government response AI summary
The government states that it implemented the Defence Afghan Relocations Assistance Policy (ARAP) Casework System (DACS) in May 2022, which addressed vulnerabilities such as stricter access controls and audit logs.
Read full response →
HM Treasury
14
Conclusion
54th Report - Afghanistan Response Route
Accepted
In August 2025, the Department reported that there had been 49 separate data breaches between 2021 and 2025 at the unit handling applications from Afghan citizens to relocate to the UK. Of these, the Department assessed that seven met the threshold for notification to the ICO, including the February 2022 …
Read more
In August 2025, the Department reported that there had been 49 separate data breaches between 2021 and 2025 at the unit handling applications from Afghan citizens to relocate to the UK. Of these, the Department assessed that seven met the threshold for notification to the ICO, including the February 2022 data breach. The Department told the NAO that it had handled all breaches in line with the ICO’s policies and processes.30
Show less
Government response AI summary
The government commissioned an independent MOD-wide Data Protection Review in 2023, finalized in 2024 with recommendations, and will provide a report on mandatory data protection training completion in its first six-monthly update.
Read full response →
HM Treasury
15
Conclusion
54th Report - Afghanistan Response Route
Accepted
We asked the Department about its response to a data breach which occurred in September 2021 relating to the ARAP scheme.31 The Department told us that it had engaged with the ICO in the autumn of 2021 follow multiple data breaches.32 The Department disclosed three data breaches which occurred in …
Read more
We asked the Department about its response to a data breach which occurred in September 2021 relating to the ARAP scheme.31 The Department told us that it had engaged with the ICO in the autumn of 2021 follow multiple data breaches.32 The Department disclosed three data breaches which occurred in September and October 2021 in its 2021–22 Annual Report and Accounts.33 The Department said that its response was specific to the nature of those data breaches. This included requiring a second person to check emails which were sent outside the Department’s IT systems, and a system alert if the sender tried to email more than a certain 27 Information Commissioner’s Office, Record of ICO [Information Commissioner’s Office] involvement in the data breach announced by the MoD [Ministry of Defence] on 15 July 2025, para 16cii4a, July 2025 28 Letter from Ministry of Defence, 7 October 2025 29 C&AG’s Report, para 12 30 C&AG’s Report, para 16 31 Q 2 32 Q 9 33 Ministry of Defence, Annual Report and Accounts 2021–22, page 68, July 2022 11 number of addressees.34 The Department said that, once it discovered the February 2022 data breach, it carried out a much more fundamental review of its data protection and information handling policies, training and systems.35 In correspondence received after our evidence session the Department said that, since 2023, it had implemented further software improvements, alongside reviewing its processes and polices. In addition, it noted that that all staff are mandated to undertake various data and e-learning courses that offer awareness of good data management practices, and that it has produced bespoke training and educational materials to assist staff in putting their learning into practice.36
Show less
Government response AI summary
The government commissioned an independent MOD-wide Data Protection Review in 2023, finalized in 2024 with recommendations, and will provide a report on mandatory data protection training completion in its first six-monthly update.
Read full response →
HM Treasury
16
Conclusion
54th Report - Afghanistan Response Route
Accepted
We asked the Department about the reported 49 data breaches, which included seven which met the threshold for reporting to the ICO, and whether there were ongoing investigations relating to these. The Department said that five incidents related to the use in emails of the ‘to’ field instead of the …
Read more
We asked the Department about the reported 49 data breaches, which included seven which met the threshold for reporting to the ICO, and whether there were ongoing investigations relating to these. The Department said that five incidents related to the use in emails of the ‘to’ field instead of the ‘bcc’ field; one related to an incorrect link to an online portal; and one was the February 2022 data breach.37 We also asked the Department whether there were any further incidents which were not in the public domain. The Department told us that there are no further incidents which would meet the threshold for notification to the ICO, but that it is a feature of running a complex and large organisation that there will be accidental data breaches.38 In correspondence received after our evidence session the Department provided details of the 49 breaches, including clarifying that some of the incidents had been combined such that the seven incidents which met the threshold for reporting to ICO were being shown as five incidents on its list.39 34 Q 2 35 Q 3 36 Letter from Ministry of Defence, 7 October 2025 37 Qq 22–23 38 Qq 64–65 39 Letter from Ministry of Defence, 7 October 2025 12 Enabling effective scrutiny of the Afghanistan Response Route The Department’s approach to notifying Parliament
Show less
Government response AI summary
The government commissioned an independent MOD-wide Data Protection Review in 2023, finalized in 2024 with recommendations, and will provide a report on mandatory data protection training completion in its first six-monthly update.
Read full response →
HM Treasury
17
Conclusion
54th Report - Afghanistan Response Route
Accepted
The Department first became aware of the data breach on 14 August 2023, 18 months after it occurred, when personal details of 10 individuals from the dataset were posted online on Facebook.40 Following its discovery of the data breach, on 25 August 2023 the MoD decided to apply to the …
Read more
The Department first became aware of the data breach on 14 August 2023, 18 months after it occurred, when personal details of 10 individuals from the dataset were posted online on Facebook.40 Following its discovery of the data breach, on 25 August 2023 the MoD decided to apply to the High Court for an injunction to prevent the data loss becoming public. Although the MoD did not originally apply for a ‘super-injunction’, on 1 September 2023 the High Court granted this form of legal ruling, which prevented disclosure of both the data breach and the existence of the injunction itself.41 The Department told us that in the two-week period between it becoming aware of the breach and the super-injunction being put in place, it was learning about the scope of the breach and the likely consequences. It was not at the forefront of officials’ minds that it was appropriate to notify the Public Accounts Committee (PAC).42
Show less
Government response AI summary
The government agrees to work with the Committee to ensure timely information sharing, committing to new guidance from the Treasury Officer of Accounts by Spring 2026 on super-injunctions and C&AG communication, and a Dear Accounting Officer letter to be incorporated into Managing Public Money.
Read full response →
HM Treasury
18
Conclusion
54th Report - Afghanistan Response Route
Accepted
The High Court and the Court of Appeal upheld the super-injunction in several subsequent private hearings and judgments between 2023 and 2025.43 The Department said that in September 2023, it expected that an injunction might be in place for at most, a few months.44 The issue could have been raised …
Read more
The High Court and the Court of Appeal upheld the super-injunction in several subsequent private hearings and judgments between 2023 and 2025.43 The Department said that in September 2023, it expected that an injunction might be in place for at most, a few months.44 The issue could have been raised in Parliament while the super-injunction was in place, but was not publicly disclosed in the House of Commons.45 The Department said that Ministers made a judgment around balancing the risk to life and supporting the injunction by limiting those in the circle of knowledge to those who had an absolute need to know. Ministers decided to ‘read in’ 40 C&AG’s Report, para 10 41 C&AG’s Report, para 17 42 Q 28 43 C&AG’s Report, para 18 44 Q 31 45 C&AG’s Report, para 18 13 the Speaker, his Lords equivalent and the shadow Defence Secretary.46 We asked about the Department’s consideration of whether to read in the Chair of PAC and the Comptroller and Auditor General (C&AG). The Department said it had conversations with Ministers about reading in the Chairs of a small number of Select Committees, but in the end, the ministerial decision was not to do so.47
Show less
Government response AI summary
The government agrees to work with the Committee to ensure timely information sharing, committing to new guidance from the Treasury Officer of Accounts by Spring 2026 on super-injunctions and C&AG communication, and a Dear Accounting Officer letter to be incorporated into Managing Public Money.
Read full response →
HM Treasury
19
Conclusion
54th Report - Afghanistan Response Route
Accepted
The data breach was also not reported in the MoD’s Annual Report and Accounts for 2023–24. The Comptroller & Auditor General, who is an officer of the House of Commons, is responsible for the audit of these accounts, which is carried out by his staff at the National Audit Office …
Read more
The data breach was also not reported in the MoD’s Annual Report and Accounts for 2023–24. The Comptroller & Auditor General, who is an officer of the House of Commons, is responsible for the audit of these accounts, which is carried out by his staff at the National Audit Office (NAO).48 The Department said it was accounting for all of the spend on the ARR in the way that it was accounting for the public Afghan relocations and assistance policy spend. It took the judgment that it would not ‘read in’ the C&AG at that point.49 The Permanent Secretary commented that, “In the 2023–24 accounts, my sense was that, at that point, there was nothing material that the Comptroller and Auditor General needed to know about, but it may well be that the Comptroller and Auditor General will come to a different view as we finalise the accounts for 2024–25”.50 In correspondence received after our evidence session the Permanent Secretary stated that he took the decision not to inform the C&AG in the knowledge of the Ministerial position on reading in Parliamentarians and because he judged it would extend the circle of knowledge without offering an opportunity for meaningful scrutiny while the super-injunction was in place.51
Show less
Government response AI summary
The government agrees to work with the Committee to ensure timely information sharing, committing to new guidance from the Treasury Officer of Accounts by Spring 2026 on super-injunctions and C&AG communication, and a Dear Accounting Officer letter to be incorporated into Managing Public Money.
Read full response →
HM Treasury
20
Conclusion
54th Report - Afghanistan Response Route
Accepted
The C&AG told us that the first he knew about the data breach was when it became publicly known in July 2025. His audit director had been briefed at the time of auditing the 2023–24 accounts, that there was a secret matter that could not be shared, and it meant …
Read more
The C&AG told us that the first he knew about the data breach was when it became publicly known in July 2025. His audit director had been briefed at the time of auditing the 2023–24 accounts, that there was a secret matter that could not be shared, and it meant there was a data breach that had not been included in the governance statement in the accounts. There was no briefing of the NAO by the Department about the operational consequences of this, the number of people affected, or the likely cost.52 The audit director was told that they could not tell anybody at the NAO about the detail that they had been briefed with.53 46 Q 32 47 Q 36 48 C&AG’s Report, para 18 49 Q 32 50 Q 40 51 Letter from Ministry of Defence, 7 October 2025 52 Q 33 53 Q 35 14
Show less
Government response AI summary
The government agrees to work with the Committee to ensure timely information sharing, committing to new guidance from the Treasury Officer of Accounts by Spring 2026 on super-injunctions and C&AG communication, and a Dear Accounting Officer letter to be incorporated into Managing Public Money.
Read full response →
HM Treasury
21
Conclusion
54th Report - Afghanistan Response Route
Accepted
The C&AG highlighted to us the crucial importance to the audit opinion of being able to assess whether there was adequate provision in the accounts to cover the full costs of resettlement schemes.54 We challenged the Permanent Secretary about the decision not to make the C&AG aware of the data …
Read more
The C&AG highlighted to us the crucial importance to the audit opinion of being able to assess whether there was adequate provision in the accounts to cover the full costs of resettlement schemes.54 We challenged the Permanent Secretary about the decision not to make the C&AG aware of the data breach and its impact, and whether he had ever raised that issue with Ministers. The Permanent Secretary told us that, from an accounting officer perspective, the period in question had been “deeply uncomfortable”. He noted that the Department’s advice to Ministers had focused on the Defence Select Committee and the Intelligence Security Committee, but recalled some conversations around the role of the NAO and the C&AG. He stressed his personal responsibility, albeit in the context of ministerial decisions on the tightness of briefing of Parliament, for the handling of the relationship in question.55
Show less
Government response AI summary
The government agrees to work with the Committee to ensure timely information sharing, committing to new guidance from the Treasury Officer of Accounts by Spring 2026 on super-injunctions and C&AG communication, and a Dear Accounting Officer letter to be incorporated into Managing Public Money.
Read full response →
HM Treasury
22
Conclusion
54th Report - Afghanistan Response Route
Accepted
The Department and the C&AG have discussed whether they might develop a protocol for use in similar circumstances in future. The Department told us that a super-injunction was so unprecedented it was hard to think of circumstances in which it was likely to see one again.56 It also said that, …
Read more
The Department and the C&AG have discussed whether they might develop a protocol for use in similar circumstances in future. The Department told us that a super-injunction was so unprecedented it was hard to think of circumstances in which it was likely to see one again.56 It also said that, with hindsight, it was not sustainable to have kept the C&AG at arm’s length for a period of two years.57 In correspondence received after our evidence session, the Department said that developing a protocol between the Treasury Officer of Accounts, the C&AG and Accounting Officers should a future super-injunction be used would provide clarity for how this should be managed.58 Meanwhile, there are other matters to do with the Department that are not getting any Parliamentary scrutiny. The Department told us that a proposal for a Parliamentary oversight committee looking at more sensitive aspects of defence work, particularly defence and the nuclear enterprise, was being considered at the highest level within government.59 In the opinion of the PAC, this matter is moving far too slowly. Accounting for the costs of the Afghanistan Response Route
Show less
Government response AI summary
The department will continue to work with the Committee and The Treasury will issue guidance on principles and practicalities of sharing information in the event of a super-injunction. Target implementation date: Spring 2026
Read full response →
HM Treasury