UK Ministry of Defense – €400,000 Fine (United Kingdom, 2023)

€400,000Information Commissioner's Office13 December 2023United Kingdom
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The UK Ministry of Defense was fined EUR 400,000 for accidentally revealing the email addresses of Afghan nationals eligible for evacuation. This incident is serious because it could have endangered lives if the Taliban had accessed that information. It serves as a reminder for organizations to protect personal data carefully.

What happened

The Ministry of Defense disclosed personal data by sending an email without hiding recipients' addresses.

Who was affected

Afghan nationals who were eligible for evacuation to the UK after the Taliban takeover.

What the authority found

The Information Commissioner's Office determined that the Ministry of Defense failed to protect personal data, leading to the fine.

Why this matters

This ruling emphasizes the need for strict data protection practices, especially when handling sensitive information. Organizations must ensure that personal data is adequately secured to prevent similar breaches.

Source verified 6 March 2026
articles corrected
national law identified
amount discrepancy
Full Legal Summary
Detailed

The UK DPA has fined the Ministry of Defense EUR 400,000 for disclosing personal data of individuals who were to be relocated to the UK after the Taliban took control of Afghanistan in 2021. The Ministry of Defense had sent an email to a distribution list of Afghan nationals who were eligible for evacuation without hiding the e-mail adresses and thus revealing the personal e-mail addresses and personal data of the recipients to the other e-mail recipients. The ICO stated that if the data had fallen into the hands of the Taliban, it could have led to a threat to lives.

Related Enforcement Actions (0)

No other enforcement actions found for UK Ministry of Defense in UK

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

13 December 2023

Authority

Information Commissioner's Office

Fine Amount

€400,000

Enforcement Tracker ID

ETid-2170

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. UK Ministry of Defense - United Kingdom (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: