Report Details Systemic Failures in UK Afghan Relocation Scheme and Data Breach Response
A comprehensive report by the House of Commons Defence Committee has concluded that Afghans who collaborated with UK forces were improperly denied relocation, leading to prolonged exposure to danger, delays, and uncertainty. The report identifies a significant data breach within the Ministry of Defence (MOD) as a “foreseeable systemic failure,” which it asserts contributed to a broader breakdown of governance, accountability, and public trust.
These findings are detailed in the committee’s report, titled Shifting heaven and earth? The Afghan data breach and resettlement schemes, published on July 30, five years after the fall of Kabul and approximately a year after public acknowledgment of the data breach incident.
The data breach, which occurred in February 2022, involved an MOD staff member transmitting a spreadsheet containing sensitive information outside secure government channels. Initially believed to affect around 150 applicants to the Afghan Relocations and Assistance Policy (ARAP), further investigation revealed that the spreadsheet contained detailed personal information pertaining to more than 18,500 applications. The breach remained undetected until August 2023, when a portion of the dataset surfaced in a public Facebook group. Following this discovery, the government managed its response under an unprecedented superinjunction, a legal order that effectively prohibited public reporting of both the breach and the subsequent governmental actions for nearly two years.
The Defence Committee’s report unequivocally states that the data breach was preventable. Its formal conclusion asserts: “The breach was not simply an individual mistake, but a foreseeable systemic failure. It arose from the combination of inappropriate tools, weak operating procedures, insufficient training, poor organisational continuity, and an inadequate culture of data protection and accountability. The pressures of the fall of Kabul in 2021 help to explain how these weaknesses developed; they do not excuse their continuation into 2022. The MOD handled sensitive immigration casework using tools and controls not appropriate for a life-endangering dataset at any scale.” This statement highlights a fundamental flaw in the MOD’s operational framework for handling such critical data.
The report further traces the origins of the MOD’s involvement in the ARAP scheme. Sir Ben Wallace, who established the policy during his tenure as Defence Secretary, informed the committee that he intentionally separated eligibility decisions from the Home Office. He stated, “ARAP was for our people who had helped us and saved lives… The Home Office was always very keen to blur the two, and I did not want to blur the two.” Wallace conceded that this decision necessitated the MOD essentially “to design and make immigration databases from scratch.” David Williams, the Permanent Secretary at the time of the scheme’s inception, described the initial system to the committee as “essentially a combination of the ad hoc use of spreadsheets on SharePoint sites,” underscoring the improvised nature of the data management infrastructure.
A notable discrepancy emerged during the inquiry regarding the cause of the breach. Sir Ben Wallace contended that the breach could only have occurred if established operating procedures were disregarded, adding that “someone definitely did not do their job.” In contrast, the MOD’s written evidence stated that the breach took place “while officials were following agreed processes.” The committee characterized this divergence as a clear indication of a persistent cultural failure within the department regarding data protection and adherence to protocols.
Accountability and Secrecy Concerns
Regarding accountability, the committee observed that no individual appeared to have been held personally responsible for the data breach. Its conclusion on this matter frames the episode as a significant failure of governance: “Describing the breach as a systemic failure does not mean that responsibility lay nowhere. Institutional accountability requires clear lines of responsibility. Where a department takes on unfamiliar responsibilities involving life-endangering data, clear senior ownership of risk, assurance and data protection becomes more important. The evidence suggests that this ownership was inadequate before the breach; the injunction then made ordinary political accountability for the response largely impossible for nearly two years.”
The report also critiques the government’s protracted reliance on legal secrecy, specifically the superinjunction. It found that this measure displaced conventional public, parliamentary, and audit scrutiny, allowing major decisions impacting thousands of Afghan individuals and significant public funds to be made without transparency. Furthermore, the government reportedly failed to maintain adequate oversight of the direct financial ramifications arising from its response to the breach.
Tan Dhesi MP, the committee chair, commented in a press release accompanying the report: “This inquiry began with a data breach, but became about the real lives affected by delay, secrecy and flawed decision-making. The government must now explain how it will protect eligible Afghans who cannot safely, lawfully or affordably reach a third country for UK entry-clearance checks. Otherwise, the latest ‘self-move’ policy risks excluding people the UK has promised to help, including some who should have been brought here years ago.” This highlights the ongoing concern for the safety and rightful relocation of those who assisted UK forces.
Dhesi further articulated broader concerns, stating: “The broader picture is deeply troubling. The Ministry of Defence should stick to defence – it should never have been left to run immigration casework schemes. Secrecy has been too easily used as a shield against proper accountability in areas far removed from sensitive operations. The government needs to be more open to scrutiny and challenge, including where Special Forces are involved, and must account for administrative failures that have affected lives, damaged trust, and carried significant cost to the British taxpayer.” His comments advocate for a clearer delineation of departmental responsibilities and enhanced transparency in government operations.
Committee Recommendations
Among its key recommendations, the Defence Committee calls for the implementation of enforceable minimum standards for data handling and demands renewed clarity on senior accountability within government. Specifically, it recommends: “Government should mandate and enforce minimum standards for skills, process, tools, controls, independent assurance and testing for datasets where compromise could plausibly risk life. The MOD should also explain who held senior official responsibility for data-protection risk in ARAP before the February 2022 breach, whether any disciplinary, performance-management or other accountability processes followed, and how individual senior accountability is now assigned in comparable high-risk operations. The government should also review how ministerial accountability can be preserved where major decisions are taken under legal secrecy and cannot be scrutinised by Parliament or the public until after the responsible ministers may have left office.”
The government is expected to provide a response within two months of the report’s publication. The committee has requested that the government publish a single action plan detailing lessons learned from both the data breach and the resettlement response. This plan should include “each action assigned a named owner, timetable for completion, intended outcome and means of reporting progress,” with progress reports mandated every six months.
The overarching conclusion of the report reiterates the human impact of these administrative failings: “But the central lesson of this episode is that a foreseeable MOD data failure became a wider failure of governance. A breach that should have been prevented was followed by a response shaped by prolonged secrecy, weak accountability, fragmented delivery and inadequate challenge. The consequences were operational, financial and constitutional, but also, first and foremost, human. High-risk, secret, rapidly scaled operations require stronger systems, clearer ownership, earlier external challenge and firmer accountability from the outset.”
Why This Matters
The findings of the House of Commons Defence Committee report bear significant implications across several critical domains, from national security and human rights to government transparency and public trust. At its core, this report highlights the profound human cost incurred when administrative failures intersect with sensitive humanitarian and security operations. Thousands of Afghans who risked their lives to support UK forces have been left in precarious situations, facing ongoing danger and uncertainty due to bureaucratic shortcomings, including a major data breach that exposed their identities and personal details. For these individuals, the failures mean a prolonged wait for promised safety and a betrayal of trust by a nation they served.
Beyond the immediate human impact, the report raises fundamental questions about the competence and accountability of government departments, particularly when operating outside their primary remit. The MOD, a department primarily focused on defence, was tasked with running a complex immigration scheme, for which it was ill-equipped. The committee’s description of the data breach as a “foreseeable systemic failure” underscores a worrying lack of appropriate tools, training, and a robust data protection culture within a department handling life-endangering information. This points to a broader risk of systemic vulnerability across government operations if departments are not adequately prepared and resourced for unforeseen responsibilities, potentially jeopardizing national security and the safety of individuals involved in future critical operations.
Furthermore, the extensive use of an unprecedented superinjunction to manage the aftermath of the breach is a significant concern for democratic accountability and transparency. By preventing public and parliamentary scrutiny for nearly two years, critical decisions affecting thousands of people and substantial public funds were made behind closed doors. This practice undermines the principles of open government and the ability of Parliament to hold ministers and officials to account, especially when sensitive operations or national security matters are invoked. The report’s call for a review of how ministerial accountability can be preserved under legal secrecy is crucial for ensuring that such measures do not become a shield against legitimate oversight.
Finally, the handling of the ARAP scheme and the subsequent data breach has implications for the UK’s international reputation and its ability to secure cooperation in future conflicts. When a nation fails to adequately protect those who assist its military efforts, it sends a chilling message to potential local partners globally. This erosion of trust can severely hamper future foreign policy objectives, making it more difficult to recruit and rely on local allies in complex geopolitical environments. The report serves as a critical reminder that administrative integrity, robust data protection, and unwavering accountability are not merely bureaucratic niceties but essential pillars for effective governance, national security, and upholding ethical responsibilities on the global stage.

