Skip to main content

Proceeding contribution from Theresa Villiers (Conservative) in the House of Commons on Monday, 17 December 2007. It occurred during Ministerial statement on Department for Transport Data Storage and Use.


Department for Transport Data Storage and Use

Following the catastrophic breach of confidentiality at HMRC, we have another serious failure of data security, leaving more than 3 million people at risk of identity fraud. The importance of confidentiality to the Department for Transport's agencies and contractors is particularly acute given the value of information on vehicles and drivers to car criminals and rogue drivers, so it is with great concern that we have listened to today's statement from the Secretary of State. I am grateful to her for giving advance notice of her statement. Turning to some of the measures that the Secretary of State is taking to improve data security in the future—merging the DVLA and the Northern Ireland Driver and Vehicle Agency database, moving to a secure courier method of transferring data, and circulating guidance on the Data Protection Act to agency chief executives and senior officials—the question we have to ask is: why are these things being done only now, after the disaster at HMRC? Surely they are basic common sense and basic good practice in line with the legislation that the Government themselves voted for? The Secretary of State has referred to the Department's circulating information to agency chief executives, but she has not referred to the contractors of the agencies which are the cause of the problem that she has identified today. Will the Secretary of State confirm that no vehicle details have been lost in this latest data failure? Will she confirm exactly how many people have been affected by the failure? What reassurance can she give to the 3 million young people whose personal data have been compromised? What steps should they be taking to safeguard their interests and minimise the damage caused by the incident? Will she admit that the hard disc was not encrypted, and that it was not even password-protected? Is there any indication of criminal involvement—was there any evidence of a break-in? When were Ministers first informed about the problem? The Secretary of State has told us that the agency in question was informed in May. Why has she come to the House only now to tell us what has happened? What has been happening in the interim few months to safeguard this data and do something about the problem? What grade of staff was responsible for the breach of the rules announced today? What requirements do the Secretary of State's Department and its agencies require of their contractors for the storage and copying of data on discs by those contractors? What is the structure of responsibility under her Department's data controller to make sure that, right across her Department, its agencies and their contractors, confidentiality rules are complied with? What steps have her Department and its agencies taken to ensure that their contractors make sure that all those with access to data are properly trained and sufficiently senior to understand the importance of complying with these critically important rules? Have the police been informed of the incident? Are any disciplinary measures being taken as a result of the incident? Will any sanctions be imposed under the Data Protection Act? Were appropriate rules obeyed for exporting data outside the UK, as the data went missing in Iowa? Who gets the bill for any losses arising from misuse of lost data—the taxpayer, or the victim of identity theft? Does the Secretary of State agree that this incident—as well as the HMRC disaster—is another blow to her plans for an untested ““spy in the sky”” national road-pricing scheme? How can the public possibly trust her Department with information on every journey made by every one of the 33 million vehicles on Britain's roads if it cannot be trusted with the data that it already has? As far back as February 2006, the Government admitted that they had a problem with data handling by their agencies. The then Minister for Transport announced a review aimed at producing a system that would protect the public from misuse of their information. He emphasised the following:"““The Government take very seriously their responsibilities for protecting individuals' legitimate expectations of privacy and confidentiality.””—[Official Report, 16 February 2006; Vol. 442, c. 123WS.]" In the review announced, the Information Commissioner expressed his serious concern about the importance of ensuring that the information overseen by the Department for Transport was protected and properly treated, yet in the past two weeks we have learned that the DVLA sent the personal details, including motor convictions, of anything up to 1,215 drivers to the wrong people, that it lost data for 7,600 Northern Ireland vehicles and drivers in the post, and that the unencrypted discs were actually posted on 20 and 21 November—after the news of the HMRC disaster was made public. Taken together with the catastrophe at HMRC, this is further evidence of systemic failure in the Government's handling of private data, and evidence of a basic lack of competence by this Government. Quite simply, the Government are failing in their duty to obey their own laws on data protection, and failing in their primary and fundamental duty to protect the interests of the people whom they were elected to serve.


Secondary information

Type
Proceeding contribution
Reference
469 c626-7 
Session
2007-08
Chamber / Committee
House of Commons chamber
Subjects
Data protection Databases Computers ICT Driving Standards Agency Driver and Vehicle Licensing Agency Personal records Security
Link
View this Proceeding contribution on www.publications.parliament.uk