Ministry of Defence
Afghan Relocation Data Breach
On the 15 July 2025, an injunction preventing the details of an enormous data breach becoming public was lifted at the High Court. As a result, it is now understood that in February 2022 a serious breach of personal data occurred, which put thousands of lives at risk.
The incident, which has caused serious risk to lives was a simple case of an email being sent outside of authorised government systems. The email attached a spreadsheet which contained personal details of almost 19,000 Afghans who had applied to move to the UK. The information included names, contact details and family links for people at risk of Taliban reprisals.
This simple error has had a dramatic effect on thousands of people. Approximately 4,500 people have been resettled under a special scheme in an effort to try to protect them, and the cost of doing so is likely to cost the UK up to £850 million.
What can organisations learn from this incident?
- Control spreadsheet sprawl
Complex operations often rely on spreadsheets. When those files hold personal data, particularly sensitive data, version control and secure collaboration platforms are essential. Emailing copies should be the exception, never routine practice, and if these have to be shared ensure encryption tools are used. - Implement proportionate access restrictions
Staff should only access the information they genuinely need. Role-based permissions and regular audits reduce the volume of data exposed if a mistake occurs. - Embed staff training and testing
Human error was at the heart of this breach. Training that goes beyond legal theory to practical scenarios, refresher sessions and simulated phishing all raise day-to-day awareness. - Prepare an incident-response plan
Having a rehearsed plan, including swift internal escalation, access to professional advice, risk assessments, notification, and timely communication to affected individuals (where necessary) limits risk and builds trust. - Budget for remediation
The projected £400–450 million additional cost of supporting those still in Afghanistan highlights how expensive remedial measures can become once data is in the public domain. Prevention is invariably cheaper than cure.
KPDP Consultancy helps businesses to avoid costly mistakes
KPDP Consultancy provides independent legal data protection advice and support, GDPR compliance reviews, DSAR handling and tailored staff training for organisations across the UK. Our team applies practical, proportionate solutions that align with business objectives while meeting the stringent expectations of UK data protection law.
By learning from high-profile incidents and embedding robust governance, organisations can reduce their risks, protect individuals’ rights and safeguard their own reputations.
Contact us now for a free quote.
This article is for general information only. It does not constitute legal advice and should not be relied upon as such. If you require further information regarding its content, please contact us at info@kpdpconsultancy.co.uk. Law as of July 2025.
