Skip to main content

Proceeding contribution from Ruth Kelly (Labour) in the House of Commons on Monday, 17 December 2007. It occurred during Ministerial statement on Department for Transport Data Storage and Use.


Department for Transport Data Storage and Use

I was about to congratulate the hon. Lady on the way in which she has treated this matter, and while it is of course serious, we should look at the facts in this case and communicate them, as appropriate, to the public. I think that she acknowledged that in her opening remarks. It is of course right that there is good practice in government, and that agencies, chief executives of those agencies and the Department for Transport have on them the duty to follow that good practice, and to make sure that any transfer of data complies with those standards, as indeed should the transfer of data outsourced to contractors or, as in this case, outsourced to contractors in a country other than the United Kingdom. In this specific case, the external contractor, Pearson, was under an obligation to follow the principles laid down in the Data Protection Act. There is a ““safe harbour”” relationship with the United States where that may be appropriate, and these data were outsourced in that spirit. The hon. Lady asked whether any vehicle details were involved, and I can confirm that they were not. She asked how many people were involved. I said in my statement that just over 3 million individuals were involved. She suggested that the data were somehow sent by post—they were not. As I set out in my statement, a hard disc drive was not found in the secure location of the external contractor in Iowa City where the contractor had expected to find it—on the shelf. It has assured us that it was formatted specifically to Pearson's specific standards in a form that could not readily be accessible to a third party, and that nor was that hard disc drive labelled in such a way as to draw overt attention to its contents. I have asked that Pearson notify the police. It tells me that it did not do so originally because it did not believe that a crime had been committed. However, I think it only sensible that the police be informed in this sort of situation. The matter was first brought to my attention on 28 November. On 3 December, I sought comprehensive advice from the Information Commissioner as we were in the process of establishing the full facts of the case. On Friday afternoon, the Information Commissioner gave us the benefit of his advice, which was that he did not think in this case that the risks to the public were substantial, or that any of the individuals concerned needed to be notified directly. However, it was also said that it was appropriate to make available an advice line and use of a website that people could access. Issues to do with the Pearson contract are, of course, being reviewed by my Department, and if any appropriate action is required, it will be taken. The right thing to do in such situations is to look at the facts in perspective. We should consider the risk to the public and whether appropriate measures have been taken by Ministers, when they are involved, to ensure that such a situation does not happen again. The Information Commissioner's initial view is first, that the risk to the public is not substantial and secondly, that appropriate security measures have been taken. I intend to ensure that the agencies and the Department learn the lessons, and I have identified key actions to be taken that I think will further protect the public in the months to come.


Secondary information

Type
Proceeding contribution
Reference
469 c627-8 
Session
2007-08
Chamber / Committee
House of Commons chamber
Subjects
Data protection Databases Computers ICT Driving Standards Agency Driver and Vehicle Licensing Agency Personal records Security
Link
View this Proceeding contribution on www.publications.parliament.uk