Written evidence submitted by Open Rights Group (GDA0016)
1 Founded in 2005, Open Rights Group is a UK-based digital rights organisation working to protect individuals’ rights to privacy and free speech online.
2 With this submission, we want to draw the Public Accounts Committee’s attention to the role that data protection law and oversight plays in removing obstacles to the adoption of data analytics in public service delivery, including for the detection and prevention of fraud and error. We focus, in particular, to the recent debacle that saw the HMRC cutting Child Benefits to up to 24 thousands recipients on the basis of flawed data.[1]
3 As this submission shows, gross negligence and failure to comply with baseline data protection standards resulted in widespread harm and frustration. Notwithstanding the responsibility that HMRC have for this specific incident, we wish to draw attention toward the behaviour of the Information Commissioner’s Office, the data protection watchdog which is tasked to oversee and enforce such standards. Their failure to intervene both before and after the child benefits debacle occurred shows that HMRC non-compliance fits into a broader institutional failure, where the ICO is failing to use its enforcement powers to educate and ensure that public organisations comply with their obligations under UK data protection law.
4 Episodes such as this have the potential to significantly undermine public perception toward important initiatives such a fraud detection and prevention in the welfare system. As data analytics and new technologies become more widely adopted and deployed by the public sector, compliance with data protection law has never been as important to retain public trust and social acceptance. Without addressing the ICO failures and its root causes, the HMRC child benefits debacle is bound to become the first of many failures that will make it incrementally more difficult to justify the use of data analytics tools to the British public.
5 The Select Committee for Science, Innovation and Technology has been conducting an inquiry into the Afghan data breach, where the inaction of the ICO has been recognised as an “institutional failure”.[2] As a result, a group of 70+ among civil society, academics and data protection experts have called for the opening of a full inquiry into the performance of the ICO.[3] We urge the Public Account Committee to recognise that the ICO collapse of regulatory enforcement constitutes a significant barrier to the adoption of data analytics on error and fraud, and to support the scrutiny of the SIT Committee into this important issue. We further substantiate our argument below.
6 In 2023, HM Revenue and Customs (HMRC) signed a “Data Usage Agreement: customer left UK data share pilot” with the Home Office. The scheme consists in matching data between a randomised sample of recipients of Child Benefit allowances and data concerning passenger entry and exit in the UK. The purpose of this data processing was “to establish those customers who have left the UK without return within a specific period”.[4] The agreement also states that a Data Protection Impact Assessment (DPIA) has been completed by HMRC and Home Office to go alongside this Data Usage Agreement.
7 Flaws in the data matching scheme have been exposed by the press since. Parents in Northern Ireland who went oversea with their autistic children had their child benefits unjustly withdrawn after returning via Dublin airport.[5] More mistakes have emerged—such as in the case of a mother who was denied onboarding due to her child’s epileptic seizure, and later stripped of her child benefits based on passenger list’s data[6]—leading HMRC to pause and review their decision to suspend roughly 24 thousands benefits payments.[7] Further, it was reported that HMRC had previously run a trial where this system was found to be defective in 46% of the cases.[8]
8 Open Rights Group also heard from journalists who have been working on this case that “new figures show that the Child Benefit crackdown was wrong in at least 63% of cases”, and that “Only 4% of cases have so far been found to have been incorrectly claiming Child Benefit, either in error or fraudulently”. Further, we have been told that “Around 15,000 families flagged as potentially fraudulent, and had their benefits stopped, were in fact genuine”.
9 For the purposes of UK data protection law, the facts described above are sufficient to establish that the HMRC breached the UK GDPR. In particular:
9.1 Article 5(1)a of the UK GDPR establishes an obligation to process data fairly. As the facts reported above show, individuals will appear in passenger lists of flights that they never actually onboarded—for instance, because they missed the flight. Individuals may also enter or re-enter the UK in ways that are not recorded by the Home Office’s data—for instance, because they travelled through the Common Travel Area between the UK and Ireland. As the Home Office has stated to the press, “Any travel history provided should be interpreted as an intention to travel and not as proof of travel”.[9] Establishing that and individual has left the UK, and thus withdrawing their benefits, at face value and on the basis of incomplete border and passenger’s data is manifestly unreasonable and irrational.
9.2 Article 5(1)d of the UK GDPR establishes an obligation to ensure the accuracy of the data being processed. This includes taking steps “to ensure that personal data that are inaccurate [...] are erased or rectified without delay”. As the press has revealed, border data was never cross-checked and, indeed, it resulted in people seeing their benefits withdrawn for a flight they never took, or because of a trip oversea they made in the past and before their child was even born, or even as they had been paying taxes in the UK for the last 30 years. Thus, HMRC has manifestly failed to take steps to ensure the accuracy of the residency status of individuals whose child benefit was withdrawn.
9.3 Article 35 of the UK GDPR establishes a duty to carry out a Data Protection Impact Assessment (DPIA) if this “is likely to result in a high risk to the rights and freedoms of natural persons”. This includes identifying risks, measures to address them before they materialise, as well as seeking the views of the individuals affected or their representatives before data processing commences. While the HMRC-Home Office Data Usage Agreement states that such an assessment was conducted, reports that a trial of this data matching scheme would led to wrong results in 46% of the cases demonstrate a clear failure to identify and address the risks that emerged from that trial. Instead, HMRC even removed important cross-reference checks with PAYE data, thus removing rather than stepping up measures to prevent harm.
10 This failure has gathered significant media attention; in turn, Member of Parliaments have responded timely and firmly. For instance, the chair of the Treasury Committee heavily criticised HMRC “‘Cavalier’ approach to Child Benefit checks”.[10] Public trust, however, is easily lost and hard to regain. Whereas Parliament’s interest toward this incident is to be praised, intervening after a failure has occurred and resulted in harm will not prevent these incidents from happening again, and does not represent a long-term strategy to address societal concerns around the use of these technologies.
11 UK data protection law does not only establish obligations for organisations such as HMRC. It does also establish the Information Commissioner’s Office (ICO). The ICO is an independent regulator tasked with oversight and enforcement of data protection rules, and with corresponding powers to investigate breaches and bring organisations into compliance. These two aspects are closely interlinked: by monitoring compliance with data protection and ensuring that non-compliant behaviour is punished and remedied, the ICO is meant to educate and promote compliance with the law, thus reducing the likelihood of incidents such as this to happen.
12 Notwithstanding HMRC negligence and responsibilities, the ICO is the watchdog that should have intervened to bring HMRC into compliance and prevent the child benefits debacle from occurring. A spokesperson, however, has stated that HMRC has “continuously” engaged with the ICO which sits on the Digital Economy Act Governance Board and is “aware of any agreements regarding this exercise”. Following the incident, the ICO has stated that they “are in contact with HMRC regarding the issues raised”.[11]
13 Based on the facts reported above, the ICO ought to be aware of the unlawful nature of HMRC data matching exercise, but decided not to intervene. Likewise, there is nothing to suggest the ICO may have opened a formal investigation about this incident, despite evidence of data protection infringements being now in the public domain and, indeed, reported by the media. It is rather extraordinary that the ICO is burying its head on the sand while media and Members of Parliament—who, unlike the ICO, lack statutory powers to compel HMRC to address these data protection infringements—are forced to step in and fill this regulatory void.
14 The ICO inaction before the HMRC data matching failure is, unfortunately, not an isolated case. The Select Committee for Science, Innovation and Technology has been investigating the ICO decision not to open a formal investigation against the Ministry of Defence following the Afghan data breach. In the words of the chair of the SIT committee, this “paint a clear picture of institutional failure”,[12] where the responsibility of the ICO cannot be ignored. A group of 70+ among data protection experts, academics and civil society organisations have written an open letter, exposing the collapse in the ICO regulatory enforcement and, indeed, any kind of regulatory activities.[13]
15 This state of affairs is untenable. The use of data analytics or artificial intelligence technologies to combat fraud requires the adoption, as well as the effective oversight and enforcement, of high data protection standards. As the HMRC debacle has shown, if those standards lack harm will inevitably occur. The lack of effectiveness of the ICO, thus, constitutes a major barrier to the adoption of data analytics and AI tools for combating fraud in the welfare system. If the institutional failure underpinning the ICO current performance remains unaddressed, more incidents like the HMRC data matching one will emerge, the British public will suffer more harm, and the use of these technologies will become politically and socially contested. Ex-post scrutiny and interventions by the press and MPs are no substitute for continual oversight and monitoring over data protection practices in the public sector, which the ICO ought to be providing.
16 In our open letter, Open Rights Group and another 70+ data protection experts have called for a public inquiry into the regulatory performance of the Information Commissioner’s Office. In her response, Chi Onwurah MP has confirmed that the SIT Committee will look into what can be done to improve “both government and the ICO’s practices”.
17 Open Rights Group urges the Public Account Committee:
17.1 To recognise that the ICO collapse of regulatory enforcement constitutes a significant barrier to the adoption of data analytics on error and fraud
17.2 To support the scrutiny of the SIT Committee into this important issue
17.3 To stress the importance of raising data protection standards across the public sector and to, to this end, to support the opening of an inquiry into the ICO.
December 2025
[1]The Guardian, HMRC cuts child benefit for 23,500 families based on incomplete travel data, at: https://www.theguardian.com/society/2025/oct/28/hmrc-cuts-child-benefit-for-35000-families-based-on-incomplete-travel-data
[2]Dame Chi Onwurah MP, Subject: Information Commissioner’s performance – a call for an inquiry, at: https://committees.parliament.uk/publications/50560/documents/275905/default/
[3]Open Rights Group, 70+ organisations and experts demand action over failing ICO, at: https://www.openrightsgroup.org/press-releases/70-organisations-and-experts-demand-action-over-failing-ico/
[4]GOV.UK, Data Usage Agreement: customer left UK data share pilot, at: https://www.gov.uk/government/publications/customer-left-uk-data-share-pilot-2023/data-usage-agreement-customer-left-uk-data-share-pilot
[5]The Guardian, NI parents caught in UK crackdown lose child benefit after travelling via Dublin, at: https://www.theguardian.com/uk-news/2025/oct/26/ni-parents-caught-in-uk-crackdown-lose-child-benefit-after-travelling-via-dublin
[6]The Guardian, Woman turned away from UK-Italy flight due to ill child has benefit stopped, at: https://www.theguardian.com/society/2025/oct/31/woman-flight-italy-did-not-board-child-benefits-stopped
[7]The Guardian, HMRC pauses child benefit crackdown after 23,500 families caught up in data error, at: https://www.theguardian.com/society/2025/oct/29/hmrc-pauses-child-benefit-crackdown-after-23500-families-caught-up-in-data-error
[8]The Guardian, Home Office data in HMRC benefit fraud trial wrong in 46% of cases, at: https://www.theguardian.com/society/2025/nov/09/hmrc-trial-child-benefit-crackdown
[9]The Guardian, HMRC likely to have breached privacy laws in stopping child benefit – experts, at: https://www.theguardian.com/politics/2025/nov/01/hmrc-likely-to-have-breached-privacy-laws-in-stopping-child-benefit-experts
[10]UK Parliament – Treasury Committee, ‘Cavalier’ approach to Child Benefit checks criticised by Treasury Committee Chair, at: https://committees.parliament.uk/committee/158/treasury-committee/news/210486/cavalier-approach-to-child-benefit-checks-criticised-by-treasury-committee-chair/
[11]The Guardian, HMRC likely to have breached privacy laws in stopping child benefit – experts, at: https://www.theguardian.com/politics/2025/nov/01/hmrc-likely-to-have-breached-privacy-laws-in-stopping-child-benefit-experts
[12]Dame Chi Onwurah MP, Subject: Information Commissioner’s performance – a call for an inquiry, at: https://committees.parliament.uk/publications/50560/documents/275905/default/
[13]Open Rights Group, 70+ organisations and experts demand action over failing ICO, at: https://www.openrightsgroup.org/press-releases/70-organisations-and-experts-demand-action-over-failing-ico/