The UK government is under pressure to explain why it has not fully implemented all recommendations from a 2023 review into 11 major public sector data breaches, including the exposure of Afghans who worked with British forces and victims of child sexual abuse. The review, triggered by a leak of personal data of about 10,000 Police Service of Northern Ireland officers, was published on Thursday after a 22-month delay.
The Cabinet Office review identified three common themes among the breaches: lack of controls over ad hoc downloads of sensitive data, release of information via wrong recipient emails, and hidden personal data in spreadsheets. Chi Onwurah, chair of the science, innovation and technology committee, welcomed the publication but criticised the delay, noting that only 12 of 14 recommendations have been implemented.
Onwurah questioned why the government kept the review secret for so long, even after the Afghan data breach became public. She stated: 'For the government to fulfil its ambitions of using tech to boost the economy and transform our public sector, it needs the public to trust that it can keep their data secure.'
Information Commissioner John Edwards urged the government to go 'further and faster' in improving data security practices. In a letter to Cabinet Office minister Pat McFadden, he called for full implementation of the review's recommendations as a matter of urgency.
A government spokesperson said the review was completed under the previous administration and that the current government has strengthened security guidance, updated training, and announced plans to upgrade digital infrastructure. However, it remains unclear which two recommendations have not yet been implemented.