Our website uses cookies! You can disable them by changing your browser settings but if you carry on using the site we'll assume you don't mind! Read our privacy policy for more details.

The dark data supply chain

Surveillance and data-sharing at the UK border

Illustration by Naomi Gennery @nn.aa.ii

Dotted along the quaint, picturesque English coastline, in between small towns, sit a row of surveillance towers. They’re spread between Hastings and Ramsgate, metal structures jutting out awkwardly alongside walking trails and quiet cliffsides. Each is equipped with radar and camera technology, scanning the English Channel to “detect, identify, and track objects of interest.”

What should be publicly accessible land is, at various points, fenced off to protect technology that claims to help ‘protect’ the UK from the perceived threat of immigration.

Developed by US defence tech company Anduril Industries, the Sentry towers are part of a suite of technologies – physical infrastructure and remote data processing – that contribute to growing militarisation at the UK border, according to researcher Samuel Storey. Anduril, working at the intersection of defence and AI, says that more than a tenth of its team is made up of military veterans who “use their defense experience to ensure [their] products meet the needs of the warfighter.” 

But, why, today, do we need a ‘warfighter’ at the British border? The business of borders is a prominent one in the technology industry: a ballooning industry, lobbying interests and the weaponisation of personal data have all converged to produce the modern defence tech sector. Anduril’s founder has, perhaps unsurprisingly, expressed his support for Israel.

Technology, both in its physical manifestation and the data that drives it, is not apolitical. Political and philosophical underpinnings drive how technology is employed, who funds it, who administers it, and who is handed the reins to manage it, be that a government department itself, or an external contractor. Having reported at the intersection of technology, policy, and community, I have seen firsthand the outsized influence that the technology industry has on regulation, lobbying, and people. 

The Anduril towers – like the digital identification proposal and the likely growing influence of algorithmic decision-making in refugee and asylum-seeking cases – are a technological manifestation of policy decisions that facilitate the UK’s hostile environment.  

Our data isn’t ours 

The technology-laden, surveilled border has been tried and tested before: at the US-Mexico border, in Palestine, and at the Greece-Turkey border. Physical surveillance towers in the Arizona desert, which have received humongous investment from the Trump administration, have forced migrants to take riskier routes into the US in order to avoid their image being captured. In Palestine, Israeli surveillance along the borders of Gaza and the West Bank has long experimented with technology, and since Oct. 7, 2023, has used a combination of surveillance technologies and AI-assisted weaponry to target civilians. 

The visible technology infrastructure, and the “invisible” data that it collects, enter a complex, largely obscured system – a ‘data supply chain’ that is almost impossible to trace. The people whose information gets embroiled in that system become dehumanised data points, subject to analysis, tracking and probing. Government accountability and transparency become warped as private, profit-driven and commercial interests skew priorities. 

What began as Sam’s research project during a Master’s degree has become part of an ongoing initiative at the Migrants’ Rights Network (MRN) to investigate technology, AI and datafication at the UK border. Sam has, for the last couple of years, been trying to understand what types of information the Anduril towers collect, where that information flows to, and how it might be contributing to administrative decision-making in government. 

I caught up with Sam to learn more about how he has traced the path of the data collected by Anduril’s towers, and what he’s uncovered about what the government is – and perhaps more interestingly, is not – willing to share publicly.

Following the data 

Through the Freedom of Information Act (FOIA), Sam tells me that he has attempted to find out whether the information collected by the Anduril towers has been used to prosecute anybody under sections 24 and 25 of the Immigration Act 1971. The former criminalises so-called “illegal entry,” and the latter anybody that assists an illegal entry. 

It’s ever-important to remember that, in the UK, refugees have always had the right to seek asylum as per international law. Guidance on what constitutes irregular or unlawful entry or arrival into the UK specifically mentions arrival by small boat.

“The reason I focused on the Anduril towers themselves was because there were only a handful of articles about them, and even then, the scope of their use was not necessarily known,” Sam tells me. “At that time, we were only aware of three towers. And so it’s from that I tried to discern exactly how many towers there were, what they were being used for and how they were being used.” 

Oxford University’s Migration Observatory found that roughly “41,000 people were detected crossing the English Channel in small boats in 2025” and 24 people died trying to cross the Channel last year. 

These are people escaping challenging and often dangerous circumstances that we are turning our backs on at the British border. Thousands of people are having their personally identifiable information collected by technology at the border, with no understanding of where that information goes, where it is stored, and who has access to it. An already vulnerable population is made even more vulnerable, their rights to their own personal information stripped. 

Using FOIs to piece together an opaque system 

Between June 2022 and June 2025, the Home Office had a contract with Anduril valued at over £16 million. Only towards the end of the contract were details published online. The contract was then extended until June 2026, bringing its total value up to £21 million

Sam has since checked whether the towers are still in operation, and, along with finding them squarely where they were before, has also found that as of June 2026, there is a public tender notice out for further maritime intelligence, surveillance and reconnaissance work, valued at nearly £120 million. The notice specifically seeks a technology provider that can track and identify small boats using a network of new and existing sensors. 

The towers are part of a system of surveillance aircraft, marine patrol boats and drones, one of which was the subject of a CNN investigation in 2023. According to the journalists’ analysis of the drone’s flight path, it would have flown over the area where a distress call had been made by a small boat. The Home Office, however, “did not answer CNN’s questions as to why its response took so long to save lives given the extensive AI technology in its arsenal.”    

To date, many of the Freedom of Information (FOI) requests that Sam has made to piece together how surveillance and information flows from the Anduril towers to the public sector have been partially successful, unsuccessful, or completely denied. Sam has also had to make nine complaints to the Information Commissioner’s Office (ICO) about various delays and inadequacies in public sector departments’ responses. 

A consistent reason Sam has received for this partial or incomplete delivery of information is that it would not be in the national interest, specifically from a security perspective, to make this information public. He has also been told that the commercial interests of the companies involved would be at stake should the information he has requested be shared. Here we see a key tension that exists when private technology influences bleed into the public service: how can we separate competitive business interests from the public good? In that tug-of-war, do the technology companies have an outsized influence?

The FOIs have gone not just to the Home Office, but to the Ministry of Defence, the Courts and Tribunals Service, the Marine and Coastguard Agency (MCA), the Crown Prosecution Service (CPS), and various other bodies. This alone shows the complicated web of government bodies involved in policing migrants and refugees at the British border. It also perhaps gives us a small indication of where the data collected by the Anduril towers might travel to. 

An opaque FOI process 

Sam’s research has often hit a wall, either because of administrative reasons, or because the government deemed that the information requested should not be exposed to the public. But if the towers have collected, stored, shared and transmitted personal information and images of people crossing the English Channel in small boats, should they not have a say on who sees the data and how that data is used?

The Home Office has also maintained that the Anduril towers do not “collect, store or process any personal data,” and that therefore, “a Data Protection Impact Assessment (DPIA) is not required.” However, images of individuals and any personally-identifiable information fall under that which is considered personal data. The data of migrants, refugees and people seeking asylum, particularly those arriving by small boat, is collected by the towers and then transferred between organisations without care or transparency. 

With regard to whether or not the information has been used, or is intended to be used, for asylum cases in the UK, the Home Office said that the data collected by surveillance technologies is used to “detect small boat crossings and so reduce risk of Safety of Life at Sea.” They added that data is not collected for use in asylum cases, and “it is difficult to see how [the data] could be so used.”

In the same FOI request, in which Sam asks if data from these technologies could be “employed in the decision-making process for related criminal cases involving ‘irregular migration’”, the Home Office confirms that information from these systems has previously been used in criminal trials. The department will, however, “neither confirm nor deny which systems.” 

It is unclear how or why the Home Office has come to the conclusion that it will not share how data collected has been shared in criminal investigations. What it does point to is that the data – which is likely personally-identifiable – is used in ways that the data holders themselves are not privy to. What it might also signal is a different standard of care applied to the data of refugees and people seeking asylum than would be applied to a British citizen. 

The Home Office has already been embroiled in a couple of cases in which its technology overreaches and breaches basic human rights to privacy. The ICO, in 2024, issued an enforcement notice and a warning for “failing to sufficiently assess the privacy risks posed by the electronic monitoring of people arriving in the UK via unauthorised means.” Separately, an agreement between the NHS and the Home Office to share patient data – specifically with regard to checking immigration status – was suspended

While the agreement itself was suspended, it’s a revelation of the deep tendrils of data, and how a simple policy switch could expose a mountain of information about individuals and families that they have not previously consented to. As frequently as individuals are signing data access agreements each day for both public and private sector interactions, there is little awareness of what rights they might be signing away. 

We only have to look to the US, and their use of Medicaid information to track down refugees and people seeking asylum. And while there are logical legal challenges from a data privacy and protection standpoint, states are increasingly counting on immigrants not to exercise those rights, and designing invasive policy as such. 

Using the Subject Access Request as activism 

An individual who has crossed the English Channel, and who suspects that their personal data, such as imagery of them, has been captured by the towers can make a Subject Access Request (SAR). An SAR allows a person to request the release of all information that a public body such as the Home Office holds about them. In the context of migration, an SAR could also reveal how the data is transferred between bodies, and consequently how little control refugees and people seeking asylum have over their own data. 

Organisations can refuse to provide some or all of the information, the ICO warns, and Sam also worries that the assertion that data collected by the Anduril towers is not personal information might preclude it from being released under a SAR. 

Sam, along with the Migrants’ Rights Network team, hope to connect with people at migrant and refugee centres to speak about the potential value of submitting an SAR. “The courage involved in being involved with something like this will be significant,” Sam said. “I think it’s going to take us some time to find people who are willing to go through this particular process.”

His hope is that a Subject Access Request can help surface how the data collected by the Anduril towers, as well as additional surveillance infrastructure such as drones, planes, and cameras,  has travelled to or between UK government departments. The SAR could be the key to uncovering the data supply chain that begins at the point at which an individual’s image is captured by the towers. Making this information more visible might help others better advocate for their data rights as well.

Anybody, including individuals with active asylum claims, has a right to access information that is held about themselves, Sam tells me, adding that he is not aware of cases in which attempting to track down one’s own personal data has led to a negative impact on an asylum claim. That’s not to say it’s impossible, he warned. 

The technology we interact with every day, from personal devices to public infrastructure, collects personal data that is increasingly weaponised against individuals and families. Policies can change at the drop of a hat, with the state building more robust pictures of individuals and families through a patchwork of data. Despite legislation that claims to protect personal information, the case of the Anduril towers and the lack of transparency about its data supply chain show that there are limits to that protection, especially when so-called ‘national interest’ is concerned. 

For migrants and people seeking asylum, already in vulnerable positions and far away from their communities, this systemic exposure of their data – and a lack of care in how it is handled – is symbolic of their treatment more widely. Data, moving quietly and opaquely, pushes them around an already-unjust system. It is our information that lines the pockets of the technology companies. 

As a business journalist, I and many of my colleagues are often face-to-face with companies that have a clear, if subtle, mandate for the direction in which they wish to influence policy. We only need to look at lobbying records in various jurisdictions to understand that today, companies have a disproportionate amount of influence over citizens groups and community non-profits. 

The state, sold a surveillance solution that teeters on the edge of infringing rights, is either not held accountable by most of its citizens, or holds itself accountable with its own watchdogs. We must not look away from these strings of influence, or from the gradual clawing away of public accountability through private companies. 

What can you do?

Do:

  • Understand the legal implications: work with the Migrants Rights’ Network and lawyers on a Subject Access Request if you suspect your information is being held by the UK government
  • Get copies of your information: a breakdown of how to make a Subject Access Request, from the UK’s Information Commissioner’s Office. 
  • Get involved in Challenge the Checks, a campaign exploring how immigration law is entering the workplace and how digitised identity checks put immigrants’ data at risk. 

Read:

Learn:

    • Why Lush partnered with the Migrants’ Rights Network to fight against racism and for the rights of refugees and people seeking asylum. 
    • Liberty’s response to a major expansion of facial recognition by the UK Government.
    • Subscribe to The Download by Glitch, a UK charity working on ethical internet futures for Black women and gender-expansive people. 
Illustration by Naomi Gennery @nn.aa.ii

Guidelines and resources for writers
Looking to pitch an article idea? Head to our pitching guidelines to find out more.
Wanting to learn how to interview? Find out best practice and tips on interviewing with care and consent
with our ethical interviewing guidelines.

Writer
Canada
Illustrator / Designer
UK