Select Committee on Public Accounts Minutes of Evidence


Examination of Witnesses (Questions 140-159)

MR DAVE HARTNETT CB AND MR NICK LODGE

17 DECEMBER 2007

  Q140  Mr Touhig: You knew there was a new approach but you did not know exactly what it was?

  Mr Hartnett: I have known subsequently but—

  Q141  Mr Touhig: You did not at that time have any idea?

  Mr Hartnett: No. The child benefit process owner who leads on this did not know.

  Q142  Mr Touhig: You said earlier that the NAO was demanding as auditor and that you had great respect for it; yet you did not treat it with much respect, did you, when it asked for this information in a particular way and you really said, "Well, sorry, you are going to get it as we will deliver it". This is not what the customer wants, it is what the provider of the service wants to give.

  Mr Hartnett: I am not about to criticise the NAO in that way.

  Q143  Mr Touhig: I am not criticising them. I am asking you.

  Mr Hartnett: What I am going to say is that my experience of dealing with auditors in different contexts is that they can be demanding.

  Q144  Mr Touhig: Yes, you said that but we have got emails here in which the NAO make clear the information they do not want. You have ignored that and you have told them they are going to have what you are going to provide. Is that the way you should be treating the body that is set up to scrutinise government expenditure on behalf of Parliament? It is a bit contemptible, is it not?

  Mr Hartnett: No, I do not think so at all, and I think I have explained that already in that I believe, and this can be tested, that what was happening here was that the individual who received the email and responded did not know that in Waterview Park it was possible to cut down data and that she was concerned that we would have to go to EDS to get a cut-down version at cost. I do not think that is contemptible at all.

  Q145  Mr Touhig: So you would say that this is really a one-off approach, that really your department has a much more responsive approach when they get requests from the NAO than, "We will give you what we will give you and tough if it does not do you any good"?

  Mr Hartnett: We have a proud history of being responsive to the NAO. I hope Sir John will confirm that.

  Q146  Mr Touhig: Yes, but it has not worked in this case, has it?

  Mr Hartnett: It has not worked in this case and it is—

  Q147  Mr Touhig: That is the point I am making, but you say that is not a cultural thing in the department. This is a one-off, that as a supplier of information to the body that is set up by Parliament and responsible to Parliament to scrutinise public expenditure you have a much more realistic and supportive approach and that you would condemn this sort of approach, but you basically said to the NAO, "We know what you have asked for but we are not giving it to you"?

  Mr Hartnett: I expect people in my organisation to be ready to challenge NAO requests for data when the data is available in another form there and to make sure it is what we should be doing, but our people recognise that the NAO have a statutory right, that they respond to Parliament and that we have to provide data.

  Q148  Mr Touhig: My time is up. I am sure as Acting Chairman you will probably make sure that message goes back.

  Mr Hartnett: Of course.

  Q149  Chairman: Just to clear something up, you said a moment ago about your SEO that she was concerned that she would have to go to EDS, you said something like that, and that this would be costly, but even if she had to go to EDS why should it have been so costly? It is in various reports that EDS should have only charged relatively small sums for stripping out this information.

  Mr Hartnett: As I explained early on in this hearing, on the limited evidence I have seen I think our SEO felt that the data was available on site in Waterview Park to the auditor who was there and that to get a stripped-down version of it without the accounts information she would have had to go back and pay money, and because the information was there in Waterview Park she was questioning whether that was the right thing to do.

  Q150  Angela Browning: Mr Hartnett, we have heard a lot of questions today that you have not been able to give a full answer to purely because of the Poynter inquiry but nonetheless you are in charge now and the fact that you have appointed Mr Lodge does seem to indicate that you realise that, whether you can or cannot come to conclusions about this individual incident, changes have to be made to your systems and I assume you assume that those systems have to be changed pretty quickly.

  Mr Hartnett: Absolutely, and they are not the only changes we need to make.

  Q151  Angela Browning: Can I just say to you that you have denied to colleagues here this afternoon that there is systemic failure within HMRC. This is not the first time, is it, that unencrypted CDs have found their way the wrong way? If you look back to September 2005, an unencrypted CD with the names and addresses, dates of birth and bank details of UBS customers was lost in the post, and at that time HMRC said it was: "a one-off incident" and that you were urgently reviewing procedures. Did you not learn lessons from that? Did it not prompt you to look more closely at your security and the safeness of your systems at the time?

  Mr Hartnett: It did prompt us to look at those procedures and for some time now we have been discussing with representative bodies of financial institutions how best we can pass data to each other where that needs to happen in the most secure and encrypted way, and I am very pleased to say that those discussions are at an advanced stage, but different financial institutions have different approaches to security and we are just working through that with them now.

  Q152  Angela Browning: That was two years ago. Let us just take a look at what has been happening this year before we get to the matter that is under consideration by the Committee today. I am going to go through this rather quickly, but in April 2007 hundreds of HMRC documents were found strewn down a street in Nottingham. The documents were the details of the trading of a customs officer, including details of interviews with passengers suspected of smuggling cigarettes via an airport, and details of people's VAT returns. In the following month, May, 42,000 families' tax credits and bank details were posted to the wrong people after a printer error, and we all had the benefit of a statement on the floor of the House by the Chief Secretary to the Treasury saying how HMRC took confidentiality very seriously, had robust procedures, et cetera. In August 400 people's details were on a laptop that was left in a stolen car. A staff member had been using the PC for a routine audit of tax information. He had been keeping the laptop in the boot of a car in contravention of your own rules. In September records of 5,000 people's details were sent from HMRC to Standard Life's pension department in Edinburgh, and then we have September where we heard on a BBC Watchdog programme that HMRC caused personal details to be sent to the wrong people and an information expert said that the details could easily be used to apply for credit cards or loans and even to access bank accounts. Then we had a statement by the Financial Secretary to the Treasury in October who in a parliamentary answer said that between October 2006 and September 2007 2,111 reported breaches of security were recorded by HMRC in its 700 offices employing 90,000 staff. I can fully understand your defence of your staff, and very laudable that is, but you are the guy in charge. You have a serious problem and I really do think, from the answers we have had this afternoon, that you should be accepting and making appropriate changes now, regardless of when the Poynter inquiry reports, to resolve these security problems. I do not think we have heard anything this afternoon, apart from Mr Lodge's appointment, that has convinced me that somehow you are accepting the scale of the problem you have got at HMRC. What are you doing about it?

  Mr Hartnett: A lot of things. We have already talked about shutting down the ability of our people to use our IT system to copy things unless they need to. We have identified new rules for bulk data movements. We have made our directors accountable for data in their area. Many of the issues you have just gone through involve in one way or another our relationship with contractors. We are looking at that very carefully indeed. I would just say that Mr Poynter's interim report starts by saying—and I am not complacent about this in any way—that the things he would have wanted us to do we have already done. We have been very active. We have got a lot more to do.

  Q153  Angela Browning: We heard that when people join as new members of staff it is flagged up to them, I think you said, on day one the importance of security.

  Mr Hartnett: Yes.

  Q154  Angela Browning: Can I just say, as somebody who in a former existence was involved in the corporate sector with training, that it is no good just having rules? Part of the training process should be to ensure that staff fully understand the procedures and systems, and if the systems are not working you need to change the systems. What do you actually do to make sure that people who leave confidential information on laptops in their car boot or send CDs through the wrong system understand their role in your organisation?

  Mr Hartnett: We have stressed again and again to our people the importance of maintaining the security and confidentiality of data relating to our customers.

  Q155  Angela Browning: Can I just interrupt you. Is that through a formalised and systematic training programme?

  Mr Hartnett: We do have a training programme. We have regular reminders to our people. Our guidance is on the intranet and we have a very detailed training programme on day one for people who join us and we have refreshers as well.

  Q156  Angela Browning: It is a management failure, is it not? What about the line managers? It is nice to have access to have it on the intranet or what we in the old days used to call the manual of procedures, and in organisations there would be a hard copy of that but I appreciate it is all on the intranet net now, but what about your line managers? What responsibility do they take for making sure that staff actually put these things into practice?

  Mr Hartnett: Our line managers have been told on many occasions to ensure that our people follow this approach. Mr Poynter is looking at this. We are talking to Mr Poynter now. He has assured me that as he comes across issues that we need to act on he will tell me about them, we will not be waiting for his spring report, and we will be acting. I am, Mrs Browning, as concerned as you are that we get this right, and as Mr Poynter records somewhere in his interim report, we want to become a world class data handling organisation and we have got some work to do to achieve that.

  Q157  Angela Browning: Do you have any Investors in People certification?

  Mr Hartnett: We have had Investors in People certification.

  Q158  Angela Browning: Have you got it now?

  Mr Hartnett: I would need to go and look. The areas of business that I was responsible for had it, and had it renewed.

  Q159  Angela Browning: With the downsizing of the personnel you employ, are you genuinely investing in proper training in making sure that people are properly inducted? Does everybody get a proper induction course?

  Mr Hartnett: I believe that everyone does get proper induction.



 
previous page contents next page

House of Commons home page Parliament home page House of Lords home page search page enquiries index

© Parliamentary copyright 2008
Prepared 21 November 2008