Skip to main content

Proceeding contribution from Baroness Walmsley (Liberal Democrat) in the House of Lords on Thursday, 21 June 2007. It occurred during Debate on Public Sector: IT Projects.


Public Sector: IT Projects

My Lords, I, too, am most grateful to the noble Lord, Lord Lucas, because in recent years there has been a proliferation of information databases on children. Indeed, a recent paper from the Information Commissioner lists 11 of them. They all raise issues of privacy, security and consent. I intend to restrict my remarks today to the proposed national child Information Sharing Index, now to be called ContactPoint, and the much smaller databases of biometric information that some individual schools compile, often without the permission of parents and with the tacit approval of the DfES. The ContactPoint database is to be universal. It will cover more than 11 million children and will potentially have 330,000 to 400,000 users. We are told that it will cost £224 million, which I suppose must be seen as a bargain in the light of the £12 billion cost of the NHS database and the £18 billion cost of the proposed national identity database. The £41 million per year that the database will cost to run, according to the Government, is a considerable amount of money, but the Government’s figures are disputed by the Information Commissioner, who believes that it could cost up to £1 billion. Perhaps some of this additional cost will be borne by local councils. Ifso, we should be told. However, the Information Commissioner has pointed out that the database throws up, "““real data protection and privacy issues which need to be addressed””." The declared objectives of the database are to bring together the various professionals working with each child and to make early intervention easier. Those are both laudable. However, the database will cover every child in the country, including those who have no special needs, and it will have no professional input, save from the school and general practitioner. Thus, there will be many children on the database who do not need to be there. When the database was first proposed, some of us suggested that the money could be better focused on ensuring that children’s services professionals, who work with the children who do need their services, had reduced caseloads and improved training, thus making sure that they had both the time and knowledge of how to interact with other professionals for the benefit of their young clients. The Government, however, did not agree, so we now need to know how they are getting on with addressing our concerns and when the database will go live. It is scheduled for next year. Is it on target? Many parents have expressed the same concerns that I raised when we debated the legislation during the passage of the Children Act 2004. There is no such thing as a totally secure database, and a large number of people will be able to access it. Although there is to be a two-part security authentication, the Government have recently seen fit in guidance to advise users not to access it from an internet cafe and not to leave it logged on when not working on their computer. That indicates the potential for misuse. How do the Government propose to monitor this? The sensitive information on the database would be invaluable to the predatory paedophiles who stalk the internet intent on child abuse. Some of it, such as contact with sexual-health professionals, is also very private. In addition, there will be information about the parents—for example, whether they are separated or single, whether they offer positive role models, whether they give the child a healthy diet and whether there is a problem such as drug or alcohol abuse. Therefore, it is not just a database of innocuous information about where the child goes to school, who has parental responsibility and who the GP is; it tells you a lot about the whole family. Most parents and children will not know what is on the database, whether it is accurate, how to change it if it is not, and who is being given access to it and so on. Although parents and their children will have the right to ask to see the information about them and challenge it if it is wrong, I am sure that few will do so. Can the Minister say how parents will be informed about their rights in this respect and whether he will report to Parliament about how many exercise those rights? There has been some media excitement about the fact that information concerning the childrenof some high-profile parents will be electronically shielded if they are considered to be at increased risk, but surely the Government can see the potential of risk to all vulnerable children—even those whose parents have never appeared in a tabloid newspaper. We even hear that Ministers may be able to decide to exclude their own children. Can the Minister tell us whether he has any such intention himself? There are also serious concerns about ““function creep”” into the proposed national identity register and other databases since the police have had new powers to access information on any database. It is clear to me that this information will be shared much more widely than any of us feared when we were debating the Bill that set it up. There are also concerns that the database will give rise to self-fulfilling prophecies, where children with a number of ““flags of concern””, as they are coyly called, will be treated as potential delinquents. The database will require enormous restraint and professionalism from those who access it. I hope they will all understand its potential for harm as well as good. The sheer size of the database is also a cause for concern. Some commentators are afraid that serious cases might be overlooked because of the amount of time spent inputting and accessing trivia. The same skill of identifying priority cases will be required with this electronic database as has always been required when dealing with a set of paper files. The computer will not replace professional judgment. Government IT projects have an appalling track record of breaking down. That was even admittedby Margaret Hodge when she told MPs on the Education Select Committee on 9 February 2007 that this gave her cause for concern. So, if professionals are relying on this database to alert them to signs of neglect or abuse, a breakdown could place vulnerable children at even greater risk. On another closely related matter, I should like to ask the Minister about the much smaller databases of unique biometric information that are being held by schools. As the Minister may know, I have for some time been expressing serious concern about the fact that some schools are taking children’s fingerprints for trivial uses such as registration, school dinners and use of the library, all of which can be better done in other ways. Most of this is done without the express permission of the parents, or even their knowledge in many cases. When I asked about this on 19 March, the noble Lord, Lord Adonis, said that schools receive ““fair processing guidance”” as to how to comply with the Data Protection Act, in which parents should be consulted about the collection and use of all information about their children. There is much evidence that that is not happening. How are the Government monitoring whether schools are complying with the Act? However, it has become clear that, in response to concerns, the DfES is working with Becta to produce guidance for schools. I have looked hard and can find no such guidance yet, despite the fact that, on 5 February, in answer to a Written Question from my colleague in another place, the Member for Leeds, North-West, the Minister, Jim Knight, promised that the guidance would be available on the Becta website by the end of March 2007. As of this morning it still was not there. In the mean time, there have been disturbing press reports suggesting that the guidance will not insist that schools obtain express permission from parents or guardians before taking fingerprints. On any interpretation of the fair-processing rules, that cannot possibly be compliant. This is a different kind of vulnerability: vulnerability to identity theft. These databases are not kept on stand-alone computers; they are on the ordinary school computers that are connected to the internet and are therefore vulnerable to attack by hackers. If I were an identity thief, I would get the data about 15 year-olds and wait patiently for a year until they got their first credit card. Then I would pounce. The risk is severe and yet the Government do not seem at all bothered. Besides, if there is nothing wrong with taking children’s fingerprints, why do the Government not ensure that schools are asking parents or at the very least informing them? They are not doing so and that is a disgrace.


Secondary information

Type
Proceeding contribution
Reference
693 c377-80 
Session
2006-07
Chamber / Committee
House of Lords chamber
Subjects
Contracts Civil servants Career development Freedom of information ICT Government departments Public sector Procurement Electronic government
Link
View this Proceeding contribution on www.publications.parliament.uk