Skip to main content

Proceeding contribution from Baroness Kramer (Liberal Democrat) in the House of Commons on Monday, 17 December 2007. It occurred during Ministerial statement on Department for Transport Data Storage and Use.


Department for Transport Data Storage and Use

I thank the Secretary of State for giving me half an hour's advance sight of her statement. The DVLA has form on mishandling data. In June 2006, it was caught selling data to private companies without adequate scrutiny, and in December this year, not only were confidential details sent to the wrong car owners as part of a survey, but the addresses, names and car particulars of nearly 8,000 owners from Northern Ireland were lost in the post on two uncoded discs. We now hear the mind-bending news that the records of 3 million candidates for the driving test are missing on a hard drive from what is interestingly called a ““secure facility”” belonging to a company in Iowa. If that happened last May, why was the Secretary of State—never mind this House—not informed? Is it not outrageous that the victims have not been informed? I challenge the idea that this is not substantial—an e-mail address was included among the information. One can only imagine the e-mails to people saying, ““Excuse me, but your payment for your driving test did not clear, so could you please resend the details?”” Will the Secretary of State confirm that the information was sufficient for fraudsters to use to create false identities? Does she know, or has anyone checked, whether any of the data have been used fraudulently? What information has been passed to the people involved so that they can put in place some kind of protection? The Secretary of State said that the information was outsourced in the spirit that it should be taken care of, but surely much more than that is involved. The message is clear: the culture must change. She has been saying that electronic data transfer will provide adequate protection, but even the Pentagon has been hacked, so surely that would just change the method by which data are either lost or stolen. Does she not agree that the Government should be minimising data holding and that rapid destruction of data should become part of their culture? While she is at it, will the Secretary of State be kind enough to tell me when she will answer the questions on data handling that I asked her Department on 27 November? Perhaps those questions were the reason why she got the information about Pearson on 28 November. Because I have received no answer, I would be interested to know what other information has gone missing that would be exposed by those questions. The magnitude of the loss that the Secretary of State announced will not be obscured by the measures that she mentioned, worthy though they might be, or those that the Chancellor announced a few moments ago. If my bank behaved like this, I would change it. Is not that an important message for the Government?


Secondary information

Type
Proceeding contribution
Reference
469 c629-30 
Session
2007-08
Chamber / Committee
House of Commons chamber
Subjects
Data protection Databases Computers ICT Driving Standards Agency Driver and Vehicle Licensing Agency Personal records Security
Link
View this Proceeding contribution on www.publications.parliament.uk