11
Accepted
February 2022 data breach caused by inappropriate systems and hidden data.
Conclusion
We asked the Department to outline how the February 2022 data breach had occurred. The Department told us that the systems it used to manage case work for the ARAP scheme—a Sharepoint site and Excel spreadsheets—were not appropriate for handling many thousands of lines of personal data.22 The Department said that the context for this was that it built up the ARAP scheme at pace throughout 2021 as it became clear that the situation in Afghanistan was deteriorating rapidly.23 The Department also told us that the individual who sent the email which caused the data breach had asked for data on 150 individuals, but that the underlying data was hidden and that they emailed the data out, not knowing the underlying database was there.24 In correspondence received after our evidence session, the Department stated that the February 2022 incident was a result of a one-off action, rather than reflecting a wider culture of non-compliance, but that it was facilitated by the lack of appropriate systems to prevent or mitigate the error.25
Government Response Summary
The Defence Afghan Relocations Assistance Policy (ARAP) Casework System (DACS) was introduced in May 2022 which addressed many of the vulnerabilities, including stricter access controls, audit logs, and protocols to limit data sharing outside secure systems and new software introduced in January 2025 enhances their ability to securely share data.
Government Response
Accepted
Government Response
Accepted
HM Government
Accepted
2.2 The Defence Afghan Relocations Assistance Policy (ARAP) Casework System (DACS) was introduced in May 2022. It is used for ARAP and Afghan Response Route eligibility case- working. DARR have recently included a limited number of ACRS details into DACS to assist with cross-government resettlement work however the majority of ACRS data is managed on Home Office systems. 2.3 The introduction of DACS addressed many of the vulnerabilities, including stricter access controls, audit logs, and protocols to limit data sharing outside secure systems. DACS undergoes maintenance and improvements on a regular basis to mitigate against the risk of a future data incident. 2.4 While sharing personal data with trusted third parties outside of central Government remains crucial in verifying applications, the completion of data sharing agreements and data protection impact assessments enables the department to manage the associated risks. There are numerous data sharing agreements in place to facilitate this and in January 2025, the department introduced new software that enhances our ability to securely share data with partners for the purposes of administering the ARP. 2.5 The department continues to enhance technical controls that seek to address the likely causes of a data incident as part of its cyber security programme. Through these technical improvements, the department is equipped with the right tools to minimise the risk of a recurrence of the February 2022 data incident or similar.
Source
Committee
Public Accounts Committee
Inquiry
Afghanistan Response Route (ARR)
Report
54th Report - Afghanistan Response Route
14 Nov 2025
HC 1391
Addressee Bodies
HM Treasury
Timeline
Recommendation age
0.5 yr
Report published
14 Nov 2025