16 Accepted

Department identified 49 data breaches, attributing many to common email errors.

Conclusion
We asked the Department about the reported 49 data breaches, which included seven which met the threshold for reporting to the ICO, and whether there were ongoing investigations relating to these. The Department said that five incidents related to the use in emails of the ‘to’ field instead of the ‘bcc’ field; one related to an incorrect link to an online portal; and one was the February 2022 data breach.37 We also asked the Department whether there were any further incidents which were not in the public domain. The Department told us that there are no further incidents which would meet the threshold for notification to the ICO, but that it is a feature of running a complex and large organisation that there will be accidental data breaches.38 In correspondence received after our evidence session the Department provided details of the 49 breaches, including clarifying that some of the incidents had been combined such that the seven incidents which met the threshold for reporting to ICO were being shown as five incidents on its list.39 34 Q 2 35 Q 3 36 Letter from Ministry of Defence, 7 October 2025 37 Qq 22–23 38 Qq 64–65 39 Letter from Ministry of Defence, 7 October 2025 12 Enabling effective scrutiny of the Afghanistan Response Route The Department’s approach to notifying Parliament
Government Response Summary
The government commissioned an independent MOD-wide Data Protection Review in 2023, finalized in 2024 with recommendations, and will provide a report on mandatory data protection training completion in its first six-monthly update.
Government Response
Accepted
HM Government Accepted
3.1 The government agrees with the Committee’s recommendation. Recommendation implemented 3.2 In 2023, the department’s Executive Committee commissioned an independent, MOD-wide Data Protection Review in response to several high-profile and sensitive data protection incidents within the department and across government. This included the discovery of the February 2022 incident. Neil McIvor, the Chief Data Officer at the Department for Education, was appointed to lead this comprehensive review. 3.3 The resulting report, finalised in 2024, included a number of recommendations aimed at strengthening data protection practices across MOD. Requested details relating to the department’s data protection policies and processes are covered in the department’s response to the Committee set out in the letter dated 7 October 2025 which includes an update on how the recommendations in the McIvor Review have been implemented. 3.4 In addition to the McIvor Review, the department will provide a report showing the percentage of staff who have completed the mandatory data protection and information governance training within the first six-monthly update to the Committee referenced at recommendation 1.
Addressee Bodies
HM Treasury
Timeline
Recommendation age 0.7 yr
Report published 14 Nov 2025