Proceeding contribution from Baroness Noakes (Conservative) in the House of Lords on Tuesday, 20 November 2007. It occurred during Ministerial statement on HM Revenue and Customs.
HM Revenue and Customs
My Lords, I thank the Minister for repeating the Statement. This is a sorry tale of incompetence and mismanagement in the Treasury’s own back yard. We already knew that HMRC was prone to running computer systems which caused operational problems and that its operation of the tax credits system resulted in the incorrect payment of more than 40 per cent of tax credits. Now we are told that the records for 25 million individuals have gone missing. The Minister has told us that after 18 October when the junior official was first aware that the data were missing, the only thing that happened is that the official sent another copy of the information. Apparently, this person kept the information about the data loss to himself until 8 November. Can the Minister explain what kind of organisation would encourage its junior staff to behave in this way? There is something very wrong with an organisation that is incapable of admitting to errors or unable to respond to them. We have learnt something very distressing about HMRC’s culture and the way in which it behaves. This is not the first time that data have gone missing when in the care and custody of HMRC. A couple of months ago we heard that a disc with the confidential data of more than 15,000 people got lost between HMRC and Standard Life. In August 2007 it was reported on BBC radio that a laptop with confidential ISA data was stolen from an HMRC official’s car. It took a number of questions from my honourable friend Mr Mark Hoban to extract from HMRC the fact that 41 laptops went missing in the 12 months to September 2007. In May 2007, a faulty printer was blamed by HMRC for 42,000 families in receipt of tax credits having their bank account details revealed to other people, and only this week the BBC ““Watchdog”” programme featured other errors which caused misery and mayhem to the life of some individuals whose data were incorrectly released. When we debated the creation of HMRC under the Commissioners for Revenue and Customs Bill in early 2005, we noted with some concern that the integration of the Inland Revenue and Customs and Excise was proceeding with very little information about how the integration of the two organisations was going to be effected. We were concerned about the merging of two separate cultures without a clear plan of action and about the lack of specificity about the integration plans. It was clear to us that the Chancellor and his Treasury were fixated on realising £100 million of ongoing cost savings above all else. Unfortunately, we did not suspect that the organisation that would be created as a result of the Act would be so careless about the data of individuals. During the passage of the Bill, we pressed the Government hard on the data protection provisions and, in particular, wanted to be sure that the protection of confidential data was managed and overseen at the level of the board itself, with rigorous and documented procedures. We were only partially successful in persuading the Government to accept some changes to the Bill. We were often told that data protection was taken very seriously in both the Inland Revenue and in Customs and Excise and that we must not hamper the operational effectiveness of the organisation. We did not press all our amendments but, with the benefit of hindsight, we should have done so. Because we believe that data protection responsibilities need to start at the top, it is clearly right that the chairman of HMRC should resign. He and his fellow commissioners had plenty of warnings that things were not right and they should carry the can. But they are not the only ones and officials at all levels between the board and the junior official at the centre of this affair need to examine the part that they played, whether by act or omission, in this sorry tale. The Minister has said that Mr Poynter from PricewaterhouseCoopers will carry out a security review. Will the Minister make the terms of reference for that review available to Parliament and commit to making Mr Poynter’s interim and final reports available to Parliament? Will he also say how the Information Commissioner will be involved? I am aware that he is carrying out the wider review described by the Minister this afternoon, but will the noble Lord confirm that the Information Commissioner can have complete and unfettered access to HMRC to carry out his own investigations if he so chooses? I am sure that PricewaterhouseCoopers will carry out a review admirably but we would also like to be sure that the public sector’s own data protection expert will be able to pursue these issues. The disclosure of personal data without proper reason is illegal under data protection legislation and specific offences are built into the 2005 Act. There are data protection offences all over the statute book but I do not believe that they have been used much. Can the Minister confirm that all individuals who are found to have breached the law in this case will be considered for prosecution? Over the past few years the Government have created statutory data gateways all over the public sector and seem intent on creating one great data free-for-all across the public sector. It is all in the name of customer service and efficient service delivery but it carries with it great dangers. We were assured that HMRC has the confidentiality of data at its core. There is even a statutory confidentiality declaration made by each member of HMRC’s staff. If HMRC can make the kind of errors that we have heard about today, what could go wrong elsewhere in the public sector? We certainly await the review in which the Information Commissioner is involved and we hope that it will have at its heart the need to protect data and not compromise them in the name of modernisation. The case before us today involves child benefit records and therefore involves data concerning children. The organisation Action on Rights for Children has reminded us today of the concerns that it has expressed, and that we share, about the large children’s database that the Government intend to create. Will the Government pause its development and think again about the dangers of information held on databases about children, some of the most vulnerable members of our society? Will they commit to a full review of the national identity database which will underpin the identity cards that the Government propose? Every citizen in the land will fear for the security of his or her information which has been entrusted to the Government. The Government ought now to recognise that there are huge dangers for individuals when their information is transferred, however well intentioned the policy intent. There needs to be a full public debate on the collection, handling and use of personal data before we go any further on these issues—including the national identity database—and I hope that the Minister will commit to that too.
Secondary information
- Type
- Proceeding contribution
- Reference
- 696 c763-5
- Session
- 2007-08
- Chamber / Committee
- House of Lords chamber
- Subjects
- Child benefit Data protection Criminal investigation Bank services Fraud Personal records Lost property Postal services National Audit Office Security Resignations Revenue and Customs Courier services Gray, Paul
- Link
- View this Proceeding contribution on www.publications.parliament.uk
Librarians' tools
- Timestamp
- 2023-12-16 01:52:48 +0000
- URI
- http://data.parliament.uk/pimsdata/hansard/CONTRIBUTION_423357
- In Indexing
- http://indexing.parliament.uk/Content/Edit/1?uri=http://data.parliament.uk/pimsdata/hansard/CONTRIBUTION_423357
- In Solr
- https://search.parliament.uk/claw/solr/?id=http://data.parliament.uk/pimsdata/hansard/CONTRIBUTION_423357