Source · Select Committees · Public Accounts Committee

Recommendation 3

3

Require Department to detail data protection policies, assurance, and changes made after breaches

Conclusion
The Department did not do enough to learn the lessons from previous data breaches. Before the February 2022 data breach, the Department had policies in place to protect against the loss of personal information. After three separate data breaches in autumn 2021 relating to the ARAP, the Department reviewed its data protection policies and guidance, and it worked with the Information Commissioner’s Office (ICO) to make targeted improvements to prevent similar incidents from recurring. Despite this, the Department continued to experience data breaches, including the significant data breach in February 2022. In August 2025, the Department disclosed that there had been 49 separate data breaches to date at the unit handling applications from Afghan citizens to relocate to the UK, seven of which met the threshold for disclosure to the ICO. The Department continues to work to reduce the risk of further data breaches, but it has not given us confidence that sufficient action has yet been taken. recommendation Alongside its Treasury Minute response, the Department should write to the Committee to provide details of: • its policies, processes and guidance to prevent data protection breaches relating to personal information; • how the Department assures itself that these are being followed, including the level of attendance at related mandatory training; and • the changes to policies, processes and guidance the Department has made in response to previous data breaches.
Government Response

A response document is linked to this report, dated 19 January 2026. Response attribution to this conclusion has not been verified. Read the response document ↗