• Home
  • Services
    • Services for Organisations
    • Services for Individuals
    • Training
  • Fee Structure
    • Fee Structure for Organisations
    • Fee Structure for Individuals
  • News & Insights
  • Join Us
  • Contact
  • Home
  • Services for Organisations
  • Services for Individuals
  • Training
  • Fee Structure for Organisations
  • Fee Structure for Individuals
  • News & Insights
  • Join Us
  • Contact
 
 
 
 
 
 
 
 
 
 
 
 
 

Ministry of Defence

 

Afghan Relocation Data Breach

 

Back to News
Contact Us
 
 
 

On the 15 July 2025, an injunction preventing the details of an enormous data breach becoming public was lifted at the High Court. As a result, it is now understood that in February 2022 a serious breach of personal data occurred, which put thousands of lives at risk. 

 

The incident, which has caused serious risk to lives was a simple case of an email being sent outside of authorised government systems. The email attached a spreadsheet which contained personal details of almost 19,000 Afghans who had applied to move to the UK. The information included names, contact details and family links for people at risk of Taliban reprisals.

 

This simple error has had a dramatic effect on thousands of people. Approximately 4,500 people have been resettled under a special scheme in an effort to try to protect them, and the cost of doing so is likely to cost the UK up to £850 million.

 

What can organisations learn from this incident?

 

  1. Control spreadsheet sprawl
    Complex operations often rely on spreadsheets. When those files hold personal data, particularly sensitive data, version control and secure collaboration platforms are essential. Emailing copies should be the exception, never routine practice, and if these have to be shared ensure encryption tools are used.

  2. Implement proportionate access restrictions
    Staff should only access the information they genuinely need. Role-based permissions and regular audits reduce the volume of data exposed if a mistake occurs.

  3. Embed staff training and testing
    Human error was at the heart of this breach. Training that goes beyond legal theory to practical scenarios, refresher sessions and simulated phishing all raise day-to-day awareness.

  4. Prepare an incident-response plan
    Having a rehearsed plan, including swift internal escalation, access to professional advice, risk assessments, notification, and timely communication to affected individuals (where necessary) limits risk and builds trust.

  5. Budget for remediation
    The projected £400–450 million additional cost of supporting those still in Afghanistan highlights how expensive remedial measures can become once data is in the public domain. Prevention is invariably cheaper than cure.

 

 

KPDP Consultancy helps businesses to avoid costly mistakes

 

KPDP Consultancy provides independent legal data protection advice and support, GDPR compliance reviews, DSAR handling and tailored staff training for organisations across the UK. Our team applies practical, proportionate solutions that align with business objectives while meeting the stringent expectations of UK data protection law.

 

By learning from high-profile incidents and embedding robust governance, organisations can reduce their risks, protect individuals’ rights and safeguard their own reputations.

 

Contact us now for a free quote. 

 

 

 

This article is for general information only. It does not constitute legal advice and should not be relied upon as such. If you require further information regarding its content, please contact us at info@kpdpconsultancy.co.uk. Law as of July 2025.

 

KPDP Consultancy does not provide legal advice. KPDP Consultancy is a Consultant Practice of Nexa Law Limited, and DR Solicitors Limited. All legal work is strictly conducted only via Nexa Law Limited, or DR Solicitors Limited.

Nexa Law Limited is a limited company registered in England & Wales, under number 10209198 and registered at Unit 14a Maes Y Clawdd, Maesbury Road, Oswestry, Shropshire SY10 8NN. Nexa Law Limited is authorised and regulated by the Solicitors Regulation Authority under SRA number 633024.

DR Solicitors Limited is a limited company registered in England & Wales, under number 06122637 and registered at 7400 Daresbury Park, Daresbury, Warrington, England, WA4 4BS. DR Solicitors Limited is authorised and regulated by the Solicitors Regulation Authority under SRA number 522996.

Cookie Notice

Digital Privacy Notice

Copyright © 2025 KPDP Consultancy. All Rights Reserved. Website designed by FirstFound

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept AllRead MoreReject All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
SAVE & ACCEPT

Get in Touch

Have a question about data protection? Fill in your details below and we will get back to you. 




    [honeypot winnie]