15
Accepted
Department implemented significant data protection improvements following multiple previous breaches.
Conclusion
We asked the Department about its response to a data breach which occurred in September 2021 relating to the ARAP scheme.31 The Department told us that it had engaged with the ICO in the autumn of 2021 follow multiple data breaches.32 The Department disclosed three data breaches which occurred in September and October 2021 in its 2021–22 Annual Report and Accounts.33 The Department said that its response was specific to the nature of those data breaches. This included requiring a second person to check emails which were sent outside the Department’s IT systems, and a system alert if the sender tried to email more than a certain 27 Information Commissioner’s Office, Record of ICO [Information Commissioner’s Office] involvement in the data breach announced by the MoD [Ministry of Defence] on 15 July 2025, para 16cii4a, July 2025 28 Letter from Ministry of Defence, 7 October 2025 29 C&AG’s Report, para 12 30 C&AG’s Report, para 16 31 Q 2 32 Q 9 33 Ministry of Defence, Annual Report and Accounts 2021–22, page 68, July 2022 11 number of addressees.34 The Department said that, once it discovered the February 2022 data breach, it carried out a much more fundamental review of its data protection and information handling policies, training and systems.35 In correspondence received after our evidence session the Department said that, since 2023, it had implemented further software improvements, alongside reviewing its processes and polices. In addition, it noted that that all staff are mandated to undertake various data and e-learning courses that offer awareness of good data management practices, and that it has produced bespoke training and educational materials to assist staff in putting their learning into practice.36
Government Response Summary
The government commissioned an independent MOD-wide Data Protection Review in 2023, finalized in 2024 with recommendations, and will provide a report on mandatory data protection training completion in its first six-monthly update.
Government Response
Accepted
Government Response
Accepted
HM Government
Accepted
3.1 The government agrees with the Committee’s recommendation. Recommendation implemented 3.2 In 2023, the department’s Executive Committee commissioned an independent, MOD-wide Data Protection Review in response to several high-profile and sensitive data protection incidents within the department and across government. This included the discovery of the February 2022 incident. Neil McIvor, the Chief Data Officer at the Department for Education, was appointed to lead this comprehensive review. 3.3 The resulting report, finalised in 2024, included a number of recommendations aimed at strengthening data protection practices across MOD. Requested details relating to the department’s data protection policies and processes are covered in the department’s response to the Committee set out in the letter dated 7 October 2025 which includes an update on how the recommendations in the McIvor Review have been implemented. 3.4 In addition to the McIvor Review, the department will provide a report showing the percentage of staff who have completed the mandatory data protection and information governance training within the first six-monthly update to the Committee referenced at recommendation 1.
Source
Committee
Public Accounts Committee
Inquiry
Afghanistan Response Route (ARR)
Report
54th Report - Afghanistan Response Route
14 Nov 2025
HC 1391
Addressee Bodies
HM Treasury
Timeline
Recommendation age
0.7 yr
Report published
14 Nov 2025