Skip to main content

Proceeding contribution from Baroness Miller of Chilthorne Domer (Liberal Democrat) in the House of Lords on Wednesday, 23 April 2008. It occurred during Debate on bill on Criminal Justice and Immigration Bill.


Criminal Justice and Immigration Bill

moved Amendment No. 95: 95: After Clause 76, insert the following new Clause— ““Data protection: additional offences (1) After section 55 of the Data Protection Act 1998 (c. 29) insert— ““55A Data protection: additional offences (1) A data controller must not— (a) intentionally or recklessly disclose information contained in personal data to another person, (b) repeatedly and negligently allow information to be contained in personal data to be disclosed, or (c) intentionally or recklessly fail to comply with duties under section 4(4). (2) Subsection (1)(a) does not apply if the data controller can show that the disclosure— (a) was necessary for the purpose of preventing or detecting crime, (b) was required or authorised by or under any enactment, by any rule of law, or by the order of a court, or (c) was justified in the particular circumstances as being in the public interest. (3) This section shall apply whether or not the data controller is— (a) a relevant authority under section 29, or (b) exercising a relevant function under section 31. (4) A data controller who contravenes subsection (1) is guilty of an offence.”” (2) In section 63 of the Data Protection Act 1998, omit subsection (5).”” The noble Baroness said: My Lords, this amendment concerns the additional offences under the Data Protection Act that we believe should be brought in. Data controllers currently do not face anything like adequate sanctions if they intentionally or recklessly disclose information, or indeed are repeatedly negligent. We did not spend very much time on this issue in Committee because we were so taken with the fact that the Government might withdraw the entire clause, so we had a fairly limited debate. However, I went back and read what the Minister said: "““We are committed in principle to the introduction of new sanctions under the Data Protection Act for the most serious breaches of principles. The proposals that we will bring forward will be part of a consultation paper that is being written at the moment. I am sympathetic to the intent of the amendments proposing new sanctions under the Data Protection Act, but we should await the result of the consultation before considering what legislation should be taken forward””.—[Official Report, 5/3/08; col. 1116.]" On the face of it that is entirely reasonable, but we know the pressure of legislative time. The amendment is very simple in what it seeks to do and has the benefit of covering data breaches by government officials. Goodness knows, this is not exactly a new issue. The Government have had time to address it. In 2002 in another place my honourable friend Paul Burstow revealed that a total of 1,354 government-owned computers had gone missing over the previous five years, while much more recently, as noble Lords will be aware, vast amounts of data, whether from Her Majesty’s Revenue and Customs or the health sector, have been lost. The issue has been around for a long time, and not only in government sectors. The private sector, as we know, can be negligent, and it can do all sorts of things with data that it should not do. Both the public and private sectors need to be covered by further sanctions, which is the reason for our amendment. The Conservatives have also tabled an amendment in this group, to which I am sure they will speak. It has as many merits as our own when it comes to the public sector, but they have chosen to leave the private sector entirely out of it. The difficulty with that is that if you are a member of the public, it does not matter if it is the public sector or the private sector that has lost your data; the fact is, your data have been lost. The public need to depend on data controllers to be absolutely reliable and to do their utmost to safeguard people’s personal information. For that reason, we should aim to cover both public sector and private sector data controllers. With the increased blurring of the lines between the public and private sectors—I appreciate that this is often covered by contracts; indeed, I think the wording in the Conservative amendment mentions government contracts—it will not always be simple. Surely the public have an absolute right to expect data controllers in charge of any private information to be given immense incentives to be as careful as possible with it. I quote the Prime Minister’s own words after Her Majesty’s Revenue and Customs lost its data: "““When mistakes happen in enforcing procedures, we have a duty to do everything that we can to protect the public””.—[Official Report, Commons, 21/11/07; col. 1179.]" One thing the Government could do is to accept our amendment, which would greatly strengthen the provisions of the Bill. I beg to move.


Secondary information

Type
Proceeding contribution
Reference
700 c1535-7 
Session
2007-08
Chamber / Committee
House of Lords chamber
Subjects
Disciplinary proceedings Data protection Criminal proceedings Crime Armed forces Crimes of violence Court orders Burglary Journalism Offenders Protest Newspaper press Religion Religious buildings Freedom of association Self-defence
Legislation
Ecclesiastical Courts Jurisdiction Act 1860
Criminal Justice and Immigration Bill 2006-07 to 2007-08
Link
View this Proceeding contribution on www.publications.parliament.uk