Afghan data breach was foreseeable, MoD used secrecy as a shield
Published: 30/07/2026
| Uk Parliament
A parliamentary inquiry by the House of Commons Defence Committee has concluded that a Ministry of Defence (MoD) personal data breach in 2022, exposing the identities of thousands of Afghan relocation applicants fleeing the Taliban, was a "foreseeable systemic failure" rather than an isolated error.
In a comprehensive report, the committee revealed that the MoD lacked the necessary expertise to manage the Afghan Relocation and Assistance Policy (ARAP) at scale, relying on inappropriate tools, weak operating procedures, insufficient training, and an inadequate culture of data protection complaints handling and accountability.
In his evidence to the committee, former Defence Secretary Sir Ben Wallace explained that operating procedures were ignored and that secondary checks would have been unlikely to catch the hidden Excel data due to a lack of basic training and adherence to guidance. The admission is in direct contrast to the MoD's written evidence that the breach occurred "while officials were following agreed processes." The committee found this to be a "stark admission of continuing cultural failure," given that it is "relatively straightforward" to ensure no Excel files contain hidden data, and that "central government guidance on how to protect against this known concern was well publicised at the time of the data breach."
Despite acknowledging the pressure following the fall of Kabul in 2021, the committee noted this did not justify the continuation of systemic weaknesses into 2022, especially after earlier data incidents had already exposed serious risks. Furthermore, the committee also concluded that the MoD used secrecy as a shield against public accountability, leaving affected Afghans without essential information and support.
Training announcement: Freevacy provides comprehensive training for new and existing practitioners on the changes introduced by the DUA Act to the UK General Data Protection Regulation (GDPR), the Data Protection Act 2018 (DPA18), and the Privacy and Electronic Communications Regulations 2003 (PEC-Regulations). Our courses are always up to date and provide a forum for learning and discussing how to ensure your data protection processes remain compliant. Find out more.
What is this page?
You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.
The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.