Examination of Witnesses (Questions 1-19)
RT HON
ED MILIBAND
MP, SIR GUS
O'DONNELL KCB AND
MR JOHN
FIENNES
16 JULY 2008
Q1 Chairman: I normally say it is a great
pleasure to have our witnesses. I am not sure on this occasion
that it is an entire pleasure given what we are talking about,
but it is very nice nevertheless to see you. We are delighted
to have Ed Miliband, Minister for the Cabinet Office, Gus O'Donnell,
Cabinet Secretary, Head of the Home Civil Service, and John Fiennes,
former Senior Civil Servant in the Cabinet Office concerned with
data security, now working elsewhere in government. We are here
because we think that the series of data losses represented a
challenge for public administration. That is the area we are therefore
concerned with, and we will ask you about it in one form or another.
It may be worth reminding ourselves of the background to this.
I am sorry to run through the dreadful history yet again, but
the facts are that, first, in October 2007 HMRC lost two discs
containing the Child Benefit records of 25 million people. Next,
it was discovered in December 2007 that, several months before,
a United States company under contract to the DVLA had lost the
personal details of three million learner drivers. Third, in December
2007, nine NHS trusts lost the records of 168,000 people, almost
all of them children. Fourth, in January 2008 a Ministry of Defence
laptop was stolen. It contained the names and passport numbers
of one million people, including 600,000 military recruits. Fifth,
in June 2008, in two almost simultaneous incidents, sensitive
intelligence and security documents were left on trains from London
Waterloo station. Sixth, also in June 2008, Hazel Blears had her
laptop stolen, and it held a number of confidential government
documents in unencrypted form. That is the backcloth to the meeting
we are having today. Before we start, I cannot resist mentioning
a seventh loss. The Government's response to this Committee's
report on Politics and Administration and to our report on Ethics
and Standards have both gone missing. These responses were due
in May and June 2007. It may be that they are in the post, by
some courier; it may be that they are sitting at Waterloo station;
but we have not seen them. What is particularly striking, of course,
is that it is the Cabinet Office that issues the instructions
to departments to reply to committees within two months. Not two
years but two months. The procedures are there, but they have
clearly not been followed. Someone more impish than me might ask
whether this was a responsibility for a civil servant or for a
minister. Having said that, and expecting a response shortly,
I will ask if any of you would like to say something by way of
introduction.
Mr Miliband: Maybe
I will start, Chairman. First of all, on the two responses concerned,
I apologise that they have not come back to you earlier. They
raise a number of issues that were part of the Constitutional
Renewal Bill and we thought that it was right, as that process
was underway, to reply to you. We do now owe you a reply, as you
have pointed out. We will endeavour to get it to you as soon as
we can. One of them certainly, around ministers and civil servants,
raises a number of issues around accountability, which are important
issues and we want to get you the best possible reply. We will
endeavour to do so as soon as we can. Let me say something about
the particular subject that you have called us to speak to you
about today and let me make four, very brief opening points. First
of all, you have listed a number of recent events around the loss
of personal data. It is worth sayingand this is in no sense
shirking our responsibilitythat these events happen in
the public sector and in the private sector as well. The Walport/Thomas
report issued last Friday in a way draws our attention to the
fact that, across government and across the whole of our society,
there is a need to raise our game to do better in terms of the
culture of protecting personal data and security. That is the
first point I would want to make: that the recent events do show
what we already knew, which is that there is a big task here for
government. Secondly, there is a temptation to say, "Why
is government collecting this data in any case?" and I think
it is worth saying a brief word about why that is. There is some
research that David Varney did around the transformational government
agenda, which showed that, for example, if you suffer a bereavement
you have to tell public authorities of some description 44 times
about your bereavement. When people ask why does data-sharing
happen, it is often to try to make services better for the citizen.
Therefore, I do not think that the response to recent events should
be to say, "We shouldn't be sharing data". I think that
the response should be to be doing better in terms of the safety
and security of that data. That is my second point. Thirdlyand
Gus will say something about thisI think that his report,
in which he was ably assisted by John Fiennes, is an important
contribution to the process of doing a better job of safeguarding
personal data. I suppose I see the core idea being that we have
to recognise that personal data is a precious commodity, with
all the precautions that must be attached to that. Finally, just
to say something about the Cabinet Office role in this area, it
is our responsibility to set the standards and rules for the protection
of data; to assist departments with the delivery of those rules
and standards; and also to report to Parliament annually, which
we have undertaken to do as part of Gus's report, on data security
in government. Departments do have to take their own responsibility
for looking after their data but we do have an important role
in setting those rules and standards, and monitoring how the new
regime is progressing. With that, I will hand over to Gus.
Q2 Chairman: Before you do, you have
mentioned the Thomas/Walport review that came out at the end of
last week. One thing they do say, of course, is that because many
people are obliged to give their information to the public sector,
and not quite so much so in the private sector, that gives a particular
obligation on the public sector to be secure in its usage of that
information. Is that not a big point?
Mr Miliband: That is a very important
point. I take this very, very seriously and I take the public
sector's responsibility, for which I share a responsibility, very
seriously. The only point I am making is that what that report,
other incidents that have happened, and the Information Commissioner's
report show is that there is a big job to be done across our whole
society in taking the security of personal data seriously.
Sir Gus O'Donnell: On your question
about reports, I did issue one to you today in response to one
of your requests about honours. You will have received thata
regular update report. In general what we are trying to do, whilst
a number of the issues covered in the other two areas are complex,
we have tried to respond to some of the points you have made in
those reports in very practical terms. For example, you made a
point about the Civil Service; so Civil Service legislation is
going through. We are trying to do things, therefore, rather
than just to respond. However, I do apologise for the delay. On
this report, I would like to reinforce what Ed said about the
importance of our sorting out these issues, so that we get public
trust and so that, if we have that trust, we have the ability
to get the public's trust to allow us to share databecause
that is the answer to improving public services in so many areas.
I think that the Walport/Thomas review backs that up. It is important
for us to establish trust, therefore. That is why we have had
exhaustive reports. You will have seen the Poynter report, Sir
Edmund Burton's report and my own report. The Prime Minister asked
me to do that. There are a number of recommendations out of those
reports. We are accepting nearly all of those recommendations
and moving forward. To my mind, it is hugely important. My report
should be regarded as a process, not an event. A number of issues
in my report we actually acted on straightaway, rather than waiting
for the report to be published. With the MoD laptop issue, for
example, when it became clear that there were some unencrypted
laptops out there with large amounts of personal data on board,
I banned the use of unencrypted laptops containing large amounts
of personal data. I did not wait for the publication of the report;
I just did it. I thought that it was really important and urgent
that we tied down that area of potential losses. We have therefore
done that. We have given the Information Commissioner the power
to conduct spot checks in departments and, basically, the review
set out a framework to allow us to improve mattersthrough
training, through sensitising people to the fact that data (and
I think this is the culture issue) are as important as personal
wealth, if you like. We actually have to change the culture so
that people will regard personal data in the same way they regard
financial matters. That is why at the heart of the report there
are a number of issues for permanent secretaries, as accounting
officers, to think of protecting personal data in the same way
they protect finances. That is why we have put into the Statement
of Internal Control for the accounting officer, which we send
to the National Audit Office, requirements about data in just
the same way that we would have requirements about finances. Finally,
throughout the review we have had a lot of very constructive help
from Richard Thomas himself. That relationship has worked well.
We have tried to ensure that all of these different reviews have
complementary recommendations and that we are backing each other
up. In the process of going through these, when I was chairing
the steering committee, I made sure that the various recommendations
from the sub-reports were incorporated in ours.
Q3 Chairman: Thank you for that,
and I am sure that we shall want to explore a number of these
issues. What I want to ask you first, though, is, given this catalogue
of failures, of data losses, putting it all together, how serious
is it for the reputation of public administration in this country?
Sir Gus O'Donnell: I would say
that this is an area where we obviously need to do better. There
is no question about that. I made my point about reputation. We
need to have a good reputation so that people are prepared to
trust us with their data, particularly in online settings. The
fact is that people are trusting us in increasing numbers. Even
if you take the example of HMRC, if you had thought there was
a loss of trust on HMRC, particularly online data, then you might
have thought that the online filing would have gone down. I am
pleased to say that it has actually gone up by 30%: more than
you would have expected by simply the trend extrapolation. People
are trusting us to operate online. They are also using online
services more than ever before. The fact is that we have a system
where DWP, for example, have something like 22 million transactions
per week. We are in the area where there are a lot of transactions,
but it is hugely important for our reputation, for our ability
to personalise public services, that we find actually secure ways
of protecting and sharing data where appropriate. The thing we
cannot do is close everything down. If we close everything down,
there is a risk that we will make sins of commission, i.e. not
sharing data when we should, which could cause as many problems
as sharing it when we should not.
Q4 Chairman: I am not sure from that
answer whether you are saying this is extremely damaging, or whether
in fact it is not very damaging because life goes on.
Sir Gus O'Donnell: No, it is serious.
There is absolutely no question about that. As the Walport/Thomas
review makes clear, issues of data protection are not just throughout
the public and private sectors of this economy: I could give you
examples from countries around the world where they are having
exactly the same issues. As we have moved to this age where we
are putting vast amounts more data into computer systems and the
like, the potential for this has gone up enormously. Therefore,
we need to up our game to improve what we are doing to protect
data, and we are certainly working very hard on that. That is
why in my report there are a number of measures, which are designed
to increase our reputation. If you ask me what is the most important
onewe are doing things on accountability, on scrutiny,
on technological changesit is culture change.
Q5 Chairman: Did you know that there
was a problem here, waiting to explode like this?
Sir Gus O'Donnell: We knew that
we were increasing the amounts of data. We knew that we had given
ever more detailed guidance out to departments. I was not aware,
for example, of the problem that was there, that the guidance
was not being followed in various cases, and I think that is
Q6 Chairman: Is that not the absolutely
crucial issue? When I read the Poynter review and the Burton review,
they are all saying in terms, "There was an issue here, waiting
to happen. These were data losses that were inevitably going to
happen, given the failure of proper systems and proper enforcement".
That is what they say and that is what is revealing about these
reports. It is not just, as it were, to do with the particular
circumstances; they are all saying, "There were systematic
failures here that meant that this was the inevitable outcome".
That is why I ask you if you knew that there were systematic failures.
Sir Gus O'Donnell: What they found
was that the guidance was there, but actually there was not the
question of testing whether that guidance was being followed.
It was the question of implementation that was crucial.
Q7 Chairman: Yes, that is the issue.
If you look at it, it is the gap between these high-flown policy
statements and actually what the practice is. That is what is
revealed by all these reports from different departments. The
Burton report on the MoD loss does a nice little summary of all
the key documents that government had issued about this area.
First, Risk: Improving Government's Capability to Handle Risk
and Uncertainty, produced by the Number 10 Strategy Unit in
November 2002. Secondly, A United Kingdom Government Strategy
for Information Assurance, produced by the Cabinet Office
in July 2003. Thirdly, in 2005, Transformational Government
Enabled by Technology, produced by the Cabinet Office. Fourthly,
A National Information Assurance Strategy, revised by the
Cabinet Office in June 2007. We have had a plethora of documents
in this area, saying what the good practice should be. Yet, when
we have these incidents and we have inquiries into the incidents,
it turns out that there is systematic failure to implement any
of this.
Sir Gus O'Donnell: Remember, it
is the Cabinet Office's responsibility to ensure that we provide
central guidance to departments and then it is the departments'
responsibility to implement that guidance. What we have found
in my report, which is why we have concentrated on this, isyou
are absolutely rightthere is an issue there that that guidance
is either too complex or, in some casesin the HMRC case
and the Burton casethere were issues where it was not being
followed at the frontline. That is why my report has emphasised
the issues related to scrutiny, spot checks, all sorts of ways
of ensuring that the guidance is implemented. I think that we
have a responsibility in the sense of making sure that our guidance
is not too complex, and is actually such that we can get it to
all of the key personal data-holders in a form in which it is
very simple for them to understand and they know precisely, in
practical terms, what they have to do. I think that is the area
where we have concentrated, looking forward: can we make it easier
for someone to comply with, as you say, quite comprehensive guidance
that has been issued already.
Mr Miliband: Can I add to that,
Chairman? I also think the point Gus makes about culture is absolutely
right. You listed the reports that government had done. You then
talked about the Defence and HMRC reports, and the fact that they
found that a lot of the good intentions and good rules were not
being implemented. One of the things that Gus's report recommends
is training for everyone involved in handling sensitive data about
what the requirements of that are; more training, I believe, for
the more senior people who are information asset owners (IAOs),
about what the responsibilities of that involves; a new rule that
in the Statement of Internal Control, signed off by the accounting
officer, there is a statement about information assurance and
the security of data. In a way, you are right: government needs
to do a lot better and to raise its game. I think that we are
right to say that part of thisand in a way it concurs with
your questionis not simply about issuing documents; it
is about changing the culture as far as personal data is concerned.
We all know that changing the culture in any large organisation
is difficult. I do not say that as an excuse or an alibi; I just
say that as a statement of fact. Is part of our task collectively
across government to change the culture on this? Absolutely rightyes,
it isand I think that Gus's report will help in that process.
Q8 Chairman: With all the talk we
have had over the years, about "up-skilling government"
and all the rest of it, it turns out that you have been issuing
all this guidance from the centre, but on the ground, where it
matters, implementation just was not happening. People will ask,
"If that is the case in this area, perhaps all the other
guidance that you are issuing from the centre is also not having
any effect down through the systems". That is why I ask you
whether you had a sense that this was the case.
Sir Gus O'Donnell: I have been
in the Civil Service a long time and I am aware of cases where
we used to issue lots of guidance. I can go back to the Treasury's
investment appraisal guidance, issued in the early 1980s, when
we did have the experience of issuing guidance and then checking
on whether or not it was being used, to find that mostly it was
not being used. We do understand that it is important. That is
the whole thrust of my report, as Ed says: to make sure that we
have procedures in place that will allow us to ensure that our
guidance is being implemented; for example, spot checks.
Q9 Chairman: I will ask you one more
thing on this and then I will hand over to colleagues. On this
question of what happens on the ground and who is responsible,
when I read these reports I was looking in each caseand
this is what I think a member of the public, paying their taxes,
would ask about these systemsat whose job was it to ensure
that these systems were working? That all this guidance was being
implemented? I find, reading the reports, that there are all kinds
of people whose job it is seemingly to make sure that happens.
There is the accounting officer, of course, and we are told that
is the ultimate responsibility. Then there are information asset
owners and there are senior information risk owners. Someone might
say, "If there are these people whose job it is to keep an
eye on data systems and to make sure that they are robust and
doing what we want them to do, were they asleep on the job?"
It turns out in the HMRC case that they did not even know what
was going on. They were not involved in the issues that produced
the data loss. What has happened to those people?
Sir Gus O'Donnell: In the case
of HMRC, as the Poynter report makes clear, it did never go above
senior executive officer levelthat issue about what should
be handled with the NAOand it should have done; so that
was an error of procedure. They should have done something differently.
Those people who are in place in departmentsand, yes, there
have been senior information risk officers (SIROs) in departments,
for example, in the Home Office, for a couple of yearsthat
is because we have been moving to manage this situation for a
while. Information asset owners are in my report. That is new,
is it not?
Mr Fiennes: Exactly. This is a
new requirement being put on departments and one of the ways in
which their discretion has been limited, and we have defined the
minimum role these people have to perform. These are people not
at board level; these are people involved in particular business
areas, involved in knowing the detail of what information is stored
in an area, who is using it, from where it is coming and where
it is going, and the purposes for those flowsto give that
granularity of grip to which you have been referring. The important
part of the report in this respect is that it seeks to make more
transparent where people may not be playing their full role here.
For example, we have a requirement for the accounting officer
to make their judgment in the Statement on Internal Control, based
on annual assessment provided to him by the SIRO, who is the board-level
champion in these issues. The SIRO is required to get input from
each of the people dealing with particular information assets.
So you have a series of people giving assurance about performance
and practice, about different aspects of the organisation, against
different elements of the controls that are in place.
Q10 Chairman: Let me bring this to
a head if I can and then we will perhaps come back to it in another
form. As I understand it, every department already had a senior
information risk officer in place, whose job it was to oversee
these systems. Then we have had all this run of data losses. These
senior information risk officers were clearly not doing their
job, were they? That is the kind of question that people would
ask; because we now know, from department to department, there
were faulty systems, not working. We know that there was a defective
history. I think that what people want to know nowand,
reading your report, Gus, I am still not clear what the answer
to this isis there now going to be some identifiable person
in every bit of government, to ensure that these systems are robust
and who carries the can if things goes wrongand who is
this person?
Sir Gus O'Donnell: To take an
example like Revenue & Customs, there are a very large number
of people there dealing with personal data. Therefore, when it
comes to, "Who should we train on these new systems? Who
should we make sure is accountable?" the answer is, "Everybody";
so we are training the whole of HMRC on this. No matter how senior,
how junior, it is important that we train them all. For every
individual caseif you take the Child Benefit caseit
will then be clear who the information asset owner for that area
is. The answers will be making people aware of the accountability
structure. That is certainly true, but there are other dimensionslike
we can change the technology such that you would not be able to
download that amount of data in the first place without strict
controls. If you did download it, you would have to download it
onto something that was encrypted and, if you did want to transfer
it somewhere, you would have to transfer it in an encrypted form.
There are multiple layers of protection that we need to put in
place. One of them is making the accountability right. There will
beyou are absolutely righta SIRO on every board,
who will ultimately be accountable for the risk management systems.
It is not just them, however; it is all the people all the way
down. To take the MoD case, there were very clearly some breaches,
and the individual naval officerI think that action was
taken in that case. Where there are problemsand we mention
this in the reportwe will look at what the appropriate
disciplinary proceedings are for every specific case.
Q11 Chairman: Again, I am putting
it from the point of view of the ordinary citizen and taxpayer.
When these things happen, they just want to know, who was responsible
for it. If everyone is accountable, then in a sense nobody is
accountable. Somebody has to carry the can for every bit of government
and every operation that it engages in. We know that in this area
something has gone fundamentally wrong, and therefore there needs
to be put in place someone whose job it is to make sure that all
this guidance is being followed.
Sir Gus O'Donnell: Absolutely,
and that is what the SIRO is for and that is the board-level person
ultimately responsible for doing this. Then, all the way downbecause,
as I say, the masses of data that big departments like DWP and
HMRC are involved inthere will be information asset owners
along the way, who will regard this information as their personal
asset, look after it, protect it, and ensure that all the rules
are being complied with.
Q12 Chairman: So if we have a data
loss from this point, we shall know precisely whose job it was
to make sure it did not happen, shall we?
Sir Gus O'Donnell: Once we have
implemented all of the things that are in my report, then, yes.
Q13 Chairman: So no more fuzzy accountability?
We shall know exactly whose job it was?
Sir Gus O'Donnell: Like I say,
once we have implemented everything that is in there, yes.
Q14 Mr Prentice: On that point, it
is like closing the proverbial stable door after the horse has
bolted, is it not? I hate these clichés, but they just
sum it up.
Sir Gus O'Donnell: There are a
lot of horses still in there!
Q15 Mr Prentice: I wanted to ask
you about your interim progress report on data loss, which was
published in December. You talked about the senior information
risk owners and said that all departments were required in February
2004you mentioned the Home Office two years ago, and that
is four years ago" ... to appoint a Senior Information
Risk Owner ... as accountable for the ownership of information
risks within that Department". Tony asked if these people
were sleeping on the job. What Civil Service grade are they? Are
they named individuals? Could I go to the Civil Service Year Book,
for example, and find out who the senior information risk owner
is in Revenue & Customs? Did they submit reports, flagging
up concerns about the way in which data security could be compromised?
Sir Gus O'Donnell: The SIROs would
all have been at board level; so this would have been something
for the boards to consider. I do not know in the individual cases
whether these would have been issues. You would have to look at
their risk registers and the like, to see whether there were discussions
of individual points. The point is, this is something that has
become more and more important. It is certainly true that, following
the big data lossesthat is why I did my reportwe
have certainly improved the accountability. We have added in,
which I think is important, these information asset owners, which
are at a lower level. There will be rather more of them and they
will be able to report up to the SIRO, to allow that accountability
to be taken and followed through in much more detail.
Q16 Mr Prentice: Paul Gray has gone,
of course. He carried the can. No one else has been disciplined.
Sir Gus O'Donnell: If you take
the Burton case, the naval officer who was involved has received
an administrative censure.
Q17 Mr Prentice: That was the first
disciplinary case in the MoD, I think.
Sir Gus O'Donnell: That is right.
That was the laptop loss. Any follow-up will be for the military
chain of command. As you say, Paul Gray stood down. I think that
if it is clearand this is one of the issues, which is why
we need to clarify the guidance, and the respective responsibilities
and accountabilitiesthen we do take action. People somehow
think that there are not consequences in the Civil Service, and
there are. Thirteen hundred people were terminated last year in
the Civil Service.
Q18 Mr Prentice: Just a few other
points. I got a letter from the Chancellor in response to an issue
I raised in the Chamber with him, telling me that Revenue &
Customs have appointed 40 data guardians. These are basically
information risk people below board level, who have a particular
job responsibility to look after these matters.
Sir Gus O'Donnell: Indeed, yes.
Q19 Mr Prentice: These data guardians
are going to be appointed across all departments?
Sir Gus O'Donnell: That is what
HMRC are doing.
Mr Fiennes: The data guardian
is more about providing a second pair of eyes in particular business
areas, as I understand it; whereas the IAO is designed to be an
individual with executive responsibility in the particular area,
to make sure that what is going on is robust. What you have in
HMRC is an additional requirement, which they have put in place
in response to their particular circumstances.
Mr Miliband: I think it is worth
sayingand John will correct me if I am wrongto clarify
this point about the SIROs and the IAOs. The information asset
owners are people designated to own the specific datasets and
pieces of information within the department; a SIRO has the overall,
board-level responsibility.
Mr Fiennes: That is right. It
is also fair to point out that, in the report that we have issued,
we have spelled out in more detail the requirements on the SIROs
in order to discharge their role. For instance, in providing annual
assessment to the accounting officer, which covers the waterfront
of the particular measures that we have put in place and making
sure that they have the input from the different parts of the
department that you need to make that judgment.
|