Source · Select Committees · Public Accounts Committee

Recommendation 2

2

Require assurance that new casework system prevents recurrence of Afghan resettlement data breaches

Conclusion
The Department did not have appropriate systems and controls in place at the time of the February 2022 breach to manage personal data in a high-risk environment. The Department did not use a caseworking system designed to hold and process high volumes of sensitive personal information relating to the government’s Afghan resettlement schemes until May 2022, when it introduced the Defence Afghan Casework System. Instead, the Department relied on Excel spreadsheets stored in a Sharepoint site, which was neither appropriate nor adequate for handling thousands of lines of personal data. The Department was still managing its data in this way when it launched the ARAP in April 2021, amidst a rapidly deteriorating security situation in Afghanistan. The manner in which the Department was storing and accessing this data contributed to the February 2022 data breach. This is because the individual who sent the email inadvertently shared data on 18,700 people without knowing it was included in 3 the spreadsheet. They thought they were sharing only information relating to 150 people, for a legitimate purpose to gather information about applicants’ eligibility. recommendation The Department should provide confirmation to the Committee that it is now managing all Afghan resettlement schemes through its new caseworking system and provide us with assurance that this would prevent a recurrence of the February 2022 breach or similar.
Government Response

A response document is linked to this report, dated 19 January 2026. Response attribution to this conclusion has not been verified. Read the response document ↗