Get a quote

Afghanistan Relocations and Assistance Applicants Data Breach: Hard Lessons Learned

24 August 2026

Emma Young, Senior Consultant DPO, Rep services and AI

Blog

Data Protection

GDPR

Privacy

What a recent Defence Committee report says about the 2022 Afghan data breach – and what it asks of the rest of us.

ARAP (the Afghan Relocations and Assistance Policy) was the UK scheme that brought Afghan citizens who had worked with British forces to safety after the Taliban returned to power in August 2021. Its applicants were interpreters, drivers, security staff, embassy workers and their families, many of whom were still living in Afghanistan in hiding when they applied.

The data ARAP processed wasn’t sensitive on first look – it included names, contact details, family members, case notes and links to UK personnel. However,  the context meant it was highly sensitive.

In February 2022, a member of MOD (Ministry of Defence) personnel sent an Excel file to a trusted third party outside government. They were trying to confirm employment details for ARAP applicants and believed it contained around 150 records. In fact, it contained detailed personal information relating to more than 18,500 applications, sitting in hidden rows invisible to anyone opening the file normally. Nobody inside the department noticed. The breach surfaced eighteen months later, in August 2023, when part of the dataset appeared in a Facebook group.

What followed – an unprecedented superinjunction lasting nearly two years, a secret relocation route and costs the NAO (National Audit Office) could not verify – has been well covered.

On 30 July, the House of Commons Defence Committee published Shifting heaven and earth? The Afghan data breach and resettlement schemes, which has shed more light on how the breach occurred and how it could have been prevented.

The Committee’s verdict

The breach was not simply an individual mistake but a “foreseeable systemic failure”: unsuitable tools, weak operating procedures, insufficient training, poor organisational continuity, and an inadequate culture of data protection and accountability. The Committee accepts that the fall of Kabul explains how those weaknesses formed. It does not accept that it excuses their survival into 2022, months after the emergency phase had ended.

Five points worth taking back to your own organisation

1. The risk was documented long before it materialised.
The ICO (Information Commissioner’s Office) had published guidance on accidental disclosure through hidden spreadsheet content since at least 2015. Government Digital Service guidance from June 2021 required checks for hidden tabs, columns and rows before sharing files. The MOD had issued its own guidance on the same point. None of this was obscure. Yet the person sending the file didn’t know that spreadsheets can carry hidden data at all, let alone how to check.

A key takeaway for every organisation is to understand where data is provided in Excel sheets and create a process which mitigates the risk. The process could include information to be provided only as a PDF or CSV file or sent via a secure transfer link which expires.

 

2. The risk register held the pieces but never assembled them.
This is the one I have taken back to my own registers. Classified risk entries the Committee reviewed showed that the department had recognised the risk of individual personal data loss and had separately recognised spreadsheets as a data quality problem. What no entry recorded was the combination: a mass loss event arising from spreadsheet use. The catastrophic version of the risk was never written down, so it was never assessed and so it was never treated.

Where does your register carry two entries that are only dangerous together?

 

3. Remediation after the first incident was too narrow.
In September 2021, an ARAP contact email exposed 245 applicants in the cc field. After an investigation, similar incidents were found internally in which 265 applicants were affected. A written ministerial statement that November reported that significant remedial action had been taken. The ICO fined the department £350,000 for that incident and related breaches in December 2023.

Months after the ministerial statement was the far more serious February 2022 breach. The MOD’s argument is that the two incidents were different in kind, so the earlier fixes were never designed to prevent the later one. The Committee treats that as precisely the problem. Closing an incident is not the same as closing the class of risk it belongs to. Eighteen further personal data incidents were reported in the same team between February 2022 and November 2023, and seven of those were high enough risk that they were reported to the ICO.

What is clear, then, is that there was insufficient visibility at a senior level to notice and fix a repeated pattern of breaches to actually take action despite the Deputy DPO raising this as a risk.

 

4. A second pair of eyes would not have saved them.
When asked about the discrepancy between someone not doing their job and officials following agreed processes, the department told the Committee it was unlikely the hidden data would have been found even if a second check had been carried out. Sign-off controls only work when the checker knows what they are checking for. That is a training gap dressed as a process one. It’s important when identifying risk mitigations that these are tested and reviewed periodically to make sure they’re effective.

 

5. Notification is a safeguarding exercise, not just a legal obligation.
The MOD’s notification was tested, issued in English, Dari and Pashto, and reached an estimated 96% of those affected. It still did not tell people which of their details had been exposed, whether family members were included or what to actually do. The helpline operated in English only, could not verify identity and could not tell callers whether they were affected. Of the 231 survey respondents who had been notified, 38% found the security advice useful.

Article 34 UK GDPR (General Data Protection Regulation) asks for clear, plain language describing the nature of the breach and the steps being taken. Reaching people is not the same as informing them in a way that they can take action to protect themselves.

The ARAP breach is an extreme example but that doesn’t mean individuals aren’t at risk in the event of a breach in your own organisation. Possible consequences of a data breach include domestic abuse, stalking and identity theft. You may not know what the data subject’s particular vulnerabilities are but that doesn’t mean they aren’t there. Make sure they have enough information to take appropriate action.

Accountability and what happens next

No individual has been held personally accountable and the ICO has declined to undertake an investigation or take enforcement action despite the deaths of at least 49 people, something which raised eyebrows in the compliance community, but a position which has been defended by the then Information Commissioner, John Edwards.

The then Permanent Secretary accepted that ultimate responsibility for data security sat with him and said the breach was a factor, though not the main one, in his decision to step down.

The Committee recommends mandatory minimum standards for skills, process, tools, controls, independent assurance and testing wherever the compromise of a dataset could plausibly risk life. It has also asked the department to name who held senior responsibility for data protection risk in ARAP before February 2022 and to say whether any accountability process followed. The government has two months to respond and has been asked to produce a single action plan with named owners, timetables and six-monthly progress reporting.

The uncomfortable part and what you should take from it

This was not only a security failure. Earlier breaches had already shown what was possible and no one owned the risk closely enough to act on the warning. Nothing here required sophistication to go wrong: a spreadsheet doing a job it was never built for, a team under sustained pressure, high turnover, guidance that existed but was never taught and a risk register that never asked what would happen if the whole file walks out of the door.

That last one is where most organisations I work with have their own version of the gap. A comprehensive information asset register tells you what you hold, how sensitive it is, and what it costs you if that data is lost, altered or exposed. Without it, your risk register is describing a system nobody has fully mapped.

The difference between your organisation and the MOD is not capability. It is scale, sensitivity and luck. You can measure the first two. The third has never been a control.

 

Data protection, delivered by experts
Our privacy team is made up of qualified data protection professionals with extensive practical data protection compliance experience.

We understand the law and how to translate it into organisational reality in a way that is both compliant and aligned to your goals and priorities.