13
Department had data protection policies but improved systems since February 2022 breach.
Conclusion
As part of its investigation into the February 2022 data breach, the Department provided to the ICO details of its data protection policies, as well as training and guidance for staff on the risks of sharing information by email, that were in place at the time of the incident. The ICO found that, in its view, the Department did have policies and processes in place designed to address the risks of sharing information externally when the data breach took place, and that it had taken steps to implement improved systems and processes since then.29
Government Response
A response document is linked to this report, dated 19 January 2026. Response attribution to this conclusion has not been verified. Read the response document.
Source
Committee
Public Accounts Committee
Inquiry
Afghanistan Response Route (ARR)
Report
54th Report - Afghanistan Response Route
14 Nov 2025
HC 1391
Addressee Bodies
HM Treasury
Timeline
Recommendation age
0.8 yr
Report published
14 Nov 2025