Share on
Dima Samaro

About the author

Dima Samaro

Executive Director at Skyline International for Human Rights

Dima Samaro, Executive Director at Skyline International for Human Rights (SIHR)
 

On 14 May 2026, the World Food Programme (WFP) discovered that its Gaza self-registration system had been breached by unauthorised actors. The exposed data included names, identity numbers, mobile phone numbers, and location data. Seventeen days passed before a Telegram message informed roughly 600,000 Palestinian households that their information had been compromised. WFP has declined to say how many individuals, as opposed to households, were affected, but given that more than two million people in Gaza had registered on the same platform, the scale of exposure may encompass nearly the entire remaining population of the Strip. In Gaza, a name, a phone number, and a neighborhood are enough to find someone.

There was nothing the people affected could have done with the warning even if it had come sooner. They could not change their identity numbers. They could not move their families to safety. They could not withdraw data they had never truly agreed to give. This is the heart of the matter. The people of Gaza were made to hand over everything about themselves in order to eat, and they were given no say in who would hold it, no way to find out where it would go, and no power to take it back.

What is known is that data of this kind, exposed in the middle of what United Nations (UN) bodies and human rights organisations have repeatedly described as a genocide, puts a population already living under occupation, siege, and bombardment at even greater risk. That is not a privacy problem in the way the term is usually understood. In Gaza, the question of who holds your data and what they do with it is a question of whether you live or die.

Consent that was never consent

Start with the word consent, because the entire system rests on pretending it exists. Consent means something only when refusal is possible. A person who can say no and still feed their children is making a choice. A mother told that food requires her fingerprint, her face, or her family's details has not consented to anything. She has submitted because the alternative is starvation. This is a distinction at the heart of data protection law, and watching it collapse in Gaza is a measure of how far the sector has drifted from its own stated principles.

Nowhere was the coercion more naked than at the Gaza Humanitarian Foundation (GHF), the body Israel set up in early 2025, with American backing, to push aside the United Nations Relief and Works Agency (UNRWA) and the wider UN system that had fed Gaza for decades. GHF made Palestinians pass through facial recognition to receive a box of food. By July 2025 one of its own contractors had told reporters that the cameras at its sites fed footage into control rooms shared with Israeli military personnel, connected, by that same account, to military and security targeting infrastructure. Skyline International for Human Rights documented what this meant for ordinary people, a choice between handing your biometric data to a surveillance apparatus or going hungry. And then there were the bodies. By the time GHF halted its operations in October 2025, nearly 3,000 Palestinians had been killed at or near its sites, according to a The New Humanitarian investigation. People were made to give up their data without choice and then shot as they queued for the food it bought them.

GHF did this in the open, with a camera you could see. The rest of the aid system does it more discreetly, through registration databases and the companies hired to run them. The method is gentler. The absence of a real choice is the same.

The companies behind the data

A fingerprint collected in Gaza is dangerous, rather than simply private, because of who ends up handling it. Aid agencies do not build their own data systems. They hire contractors, and in Gaza those contractors are anything but neutral.

GHF's operations were run by private security firms steeped in the military and intelligence worlds. Safe Reach Solutions is headed by a former chief of Central Intelligence Agency (CIA) covert operations. UG Solutions was founded by a former Green Beret and sells its connections to, in its own words, the United States Department of War and allied militaries and security services. These are not logistics outfits that happen to carry guns. Watching and controlling populations is their trade, and they were handed direct access to the biometric data of starving civilians.

The World Food Programme is a quieter case and a fairer one to the agency because the WFP is a real humanitarian institution, and there is no reason to think it wished anyone harm. The problem is the company it chose to work with. WFP's data systems have for years been tied to Palantir Technologies, a firm born out of intelligence funding, whose software is widely used for predictive policing and which, according to investigations by The Nation and others, has been accused of supplying artificial intelligence (AI) systems used in Israeli targeting in Gaza. The UN Special Rapporteur on the occupied Palestinian territory found reasonable grounds to believe Palantir provided automated predictive targeting technology and real-time battlefield data integration for automated military decision-making in Gaza. Dropsite News reported that the company keeps a permanent desk inside the United States-led Civil-Military Coordination Centre in southern Israel, reportedly tracking aid distribution in real time. Palantir denies any complicity in the targeting of Palestinians and says some of the reporting about it is inaccurate and that parts of its work predate the war.

Accept the denial in full, and the danger does not go away, because this is a problem of secrecy, not of proof. The people who registered with WFP did not hand their data to Palantir. They handed it to the United Nations, an institution they had every reason to trust, and that act dropped their records into a data environment built and run by a company whose other customers are militaries and intelligence services. Nobody has shown the public what keeps civilian aid data separate from that company's military work, or whether anything does. The people whose data it is were never told the question existed. That is what no recourse means in practice. Your most intimate information sits inside a system you cannot see, governed by a contract you will never read, held by a company you did not choose and might have every reason to fear.

What WFP confirmed was exposed, namely names, identity numbers, mobile numbers, and location data, already understates what the platform was built to collect. According to WFP's own annual country reports, the self-registration application also gathered marital status, health information including pregnancies and disabilities, the names and identity numbers of family members, and detailed displacement histories recording every move since October 2023. When civil society organisations raised these concerns publicly, WFP dismissed the risks by stating it was unaware of any misuse or exploitation of the data, a response that raises serious questions given that no risk assessment had apparently been conducted as of 31 May 2026.

We have seen this before

None of this is new, and that is perhaps the most damning thing about it. The humanitarian sector was warned, repeatedly and specifically, and it carried on.

In 2021, Human Rights Watch (HRW) revealed that the United Nations High Commissioner for Refugees (UNHCR) had collected the biometric data of Rohingya refugees in Bangladesh, people who had fled a genocide, and that this data was passed to the Bangladeshi government and on to Myanmar, the very state whose military had tried to wipe them out. Many refugees said they were never told their fingerprints and iris scans could be shared with the country they had escaped. UNHCR disputed the findings and insisted refugees could access aid whether or not they agreed to the sharing. But the essential fact stood. An aid agency had gathered the most sensitive data imaginable from a persecuted people, and that data reached their persecutor. The worst-case scenario that digital rights researchers had warned about for years was no longer hypothetical. It had happened.

It was not a one-off either. In Jordan, research has found that UNHCR's refugee data is fully accessible to the government, which cross-checks it against its counter-terrorism records, and Syrian refugees there have long been required to scan their irises simply to collect their food. The pattern is consistent across very different crises. Vulnerable people are told to register to survive, the risks are never properly explained, and their data feeds into systems and governments they have no power over. Gaza is not a departure from how digital humanitarianism works. It is what happens when that model meets a military bent on surveillance and a population it is actively trying to destroy.

Why this kills

It would be possible to file all of this under bureaucratic failure, were it not for what the data can do once it moves. Israel's war in Gaza has run on data-driven targeting at a scale never seen before. Lavender, first documented by +972 Magazine and Local Call and subsequently analysed by HRW and Al-Haq, reportedly assigned suspicion scores to tens of thousands of Palestinians to build target lists, with known error rates and barely any human check. Gospel reportedly chose buildings to bomb. Where's Daddy reportedly followed people through their phones so strikes could land when they were home with their families.

These systems run on data, and the more of it an actor holds about a population, the more they can do. That is the link that turns a registration form into something far heavier than it looks. A database of names, faces, family structures and locations is exactly what these systems feed on. When that database is gathered by an aid agency but processed through companies tied to military and intelligence work, companies with documented histories of enabling surveillance, supporting occupation infrastructure, or facing credible allegations of human rights violations, the gap between a food queue and a target list shrinks to almost nothing. I am not saying a specific WFP record has been turned into a specific airstrike. I am saying the pathway exists, it is hidden from view, and it lies entirely beyond the control of the people most likely to die because of it. A structure like that should never have been allowed to take shape over a captive population.

This is why consent and recourse are not abstractions for a policy seminar. Elsewhere, a data breach means fraud or embarrassment. In Gaza it can mean a family killed in their home. A population that cannot refuse to hand over its data, cannot see who holds it, and cannot stop it reaching the Israeli military and security apparatus has been stripped of the one protection humanitarian action exists to provide.

What the law demands

International humanitarian law does not treat any of this as discretionary. Under the Fourth Geneva Convention, an occupying power that cannot feed the people under its control must allow and assist relief, under Articles 55 and 59, and must let food and relief pass freely, under Article 23. Relief is a right of the protected population, not a reward for good behaviour. The moment food is made conditional on giving biometric data to the Israeli occupation's surveillance machine, it stops being relief in any sense the Convention recognises and becomes a tool of screening and control, which raises grave questions under the ban on collective punishment in Article 33. The same law is clear that humanitarian relief operations must be impartial and conducted without adverse distinction, never used as a cover for, or a feeder into, the military operations of a party to the conflict. A data pipeline running from a hungry family toward Israeli military analytics is exactly what these rules were written to stop.

The sector cannot pretend it merely watched this happen. Parts of it went along with it. In August 2025, with nearly 3,000 Palestinians already killed near GHF sites, senior aid officials met privately with GHF and, according to a readout obtained by The New Humanitarian, agreed among other things to soften their public criticism of it. In WFP's case, audits had flagged data protection failures as far back as 2017 and 2022, and the breach happened anyway. The warnings were there. The protection was not.

But the surrender was never inevitable, and some chose differently. When Israel moved in early 2026 to demand staff lists from international non-governmental organisations, including the personal details of Palestinian employees, with no promise the data would not be used for military or intelligence ends, dozens of organisations refused, among them Médecins Sans Frontières (MSF), Oxfam, CARE International, the Norwegian Refugee Council and the International Rescue Committee. They knew a list of names in the hands of the Israeli occupation forces can become a list of targets, and they paid the operational price of saying no. That is the bar. The rest of the sector should be held to it.

What has to change

The fixes here are not complicated, and that is the indictment. Their absence is a failure of will, not a gap in knowledge.

People must be able to receive life-saving aid without surrendering biometric or other sensitive data into systems they cannot see. This begins with a principle the sector already claims to hold but routinely ignores, data minimisation, the idea that an agency should collect only what a task strictly requires and keep it only as long as it is needed. Gaza shows the cost of abandoning it.

Every extra data point gathered, every biometric taken when a name would have done, and every record kept long after its purpose has passed becomes a standing liability that can be breached, leaked, or handed to the Israeli military. A registration system that, in a context like Gaza, can cost people their lives when it fails.

Where sensitive data is truly unavoidable, the standards for consent, security, and deletion have to match the danger, and in Gaza the danger is as high as it gets. Aid agencies must stop hiring companies whose core business is military targeting, predictive policing, or mass surveillance to handle the data of the people they are meant to protect, because what a company does for its other clients is the clearest sign of what it can do with the data in its care. And agencies must publish, in full, the vendors and processors in their data chains and release their data protection assessments so that a person being asked to register can know, before they decide, exactly whose hands their information will pass through.

The Palestinians behind those 600,000 households exposed in the WFP breach, possibly the majority of everyone still alive in Gaza, and the many more made to scan their faces for a meal, were owed one simple thing. That becoming visible in order to survive would not make them easier to kill. In Gaza that promise was broken. The least they are owed now is the truth about how their data was taken and where it has gone, and a system that no longer asks Palestinians to choose between their safety and their survival.