Select Committee on Public Administration Minutes of Evidence


Examination of Witnesses (Questions 1-19)

RT HON ED MILIBAND MP, SIR GUS O'DONNELL KCB AND MR JOHN FIENNES

16 JULY 2008

  Q1 Chairman: I normally say it is a great pleasure to have our witnesses. I am not sure on this occasion that it is an entire pleasure given what we are talking about, but it is very nice nevertheless to see you. We are delighted to have Ed Miliband, Minister for the Cabinet Office, Gus O'Donnell, Cabinet Secretary, Head of the Home Civil Service, and John Fiennes, former Senior Civil Servant in the Cabinet Office concerned with data security, now working elsewhere in government. We are here because we think that the series of data losses represented a challenge for public administration. That is the area we are therefore concerned with, and we will ask you about it in one form or another. It may be worth reminding ourselves of the background to this. I am sorry to run through the dreadful history yet again, but the facts are that, first, in October 2007 HMRC lost two discs containing the Child Benefit records of 25 million people. Next, it was discovered in December 2007 that, several months before, a United States company under contract to the DVLA had lost the personal details of three million learner drivers. Third, in December 2007, nine NHS trusts lost the records of 168,000 people, almost all of them children. Fourth, in January 2008 a Ministry of Defence laptop was stolen. It contained the names and passport numbers of one million people, including 600,000 military recruits. Fifth, in June 2008, in two almost simultaneous incidents, sensitive intelligence and security documents were left on trains from London Waterloo station. Sixth, also in June 2008, Hazel Blears had her laptop stolen, and it held a number of confidential government documents in unencrypted form. That is the backcloth to the meeting we are having today. Before we start, I cannot resist mentioning a seventh loss. The Government's response to this Committee's report on Politics and Administration and to our report on Ethics and Standards have both gone missing. These responses were due in May and June 2007. It may be that they are in the post, by some courier; it may be that they are sitting at Waterloo station; but we have not seen them. What is particularly striking, of course, is that it is the Cabinet Office that issues the instructions to departments to reply to committees within two months. Not two years but two months. The procedures are there, but they have clearly not been followed. Someone more impish than me might ask whether this was a responsibility for a civil servant or for a minister. Having said that, and expecting a response shortly, I will ask if any of you would like to say something by way of introduction.

Mr Miliband: Maybe I will start, Chairman. First of all, on the two responses concerned, I apologise that they have not come back to you earlier. They raise a number of issues that were part of the Constitutional Renewal Bill and we thought that it was right, as that process was underway, to reply to you. We do now owe you a reply, as you have pointed out. We will endeavour to get it to you as soon as we can. One of them certainly, around ministers and civil servants, raises a number of issues around accountability, which are important issues and we want to get you the best possible reply. We will endeavour to do so as soon as we can. Let me say something about the particular subject that you have called us to speak to you about today and let me make four, very brief opening points. First of all, you have listed a number of recent events around the loss of personal data. It is worth saying—and this is in no sense shirking our responsibility—that these events happen in the public sector and in the private sector as well. The Walport/Thomas report issued last Friday in a way draws our attention to the fact that, across government and across the whole of our society, there is a need to raise our game to do better in terms of the culture of protecting personal data and security. That is the first point I would want to make: that the recent events do show what we already knew, which is that there is a big task here for government. Secondly, there is a temptation to say, "Why is government collecting this data in any case?" and I think it is worth saying a brief word about why that is. There is some research that David Varney did around the transformational government agenda, which showed that, for example, if you suffer a bereavement you have to tell public authorities of some description 44 times about your bereavement. When people ask why does data-sharing happen, it is often to try to make services better for the citizen. Therefore, I do not think that the response to recent events should be to say, "We shouldn't be sharing data". I think that the response should be to be doing better in terms of the safety and security of that data. That is my second point. Thirdly—and Gus will say something about this—I think that his report, in which he was ably assisted by John Fiennes, is an important contribution to the process of doing a better job of safeguarding personal data. I suppose I see the core idea being that we have to recognise that personal data is a precious commodity, with all the precautions that must be attached to that. Finally, just to say something about the Cabinet Office role in this area, it is our responsibility to set the standards and rules for the protection of data; to assist departments with the delivery of those rules and standards; and also to report to Parliament annually, which we have undertaken to do as part of Gus's report, on data security in government. Departments do have to take their own responsibility for looking after their data but we do have an important role in setting those rules and standards, and monitoring how the new regime is progressing. With that, I will hand over to Gus.

  Q2  Chairman: Before you do, you have mentioned the Thomas/Walport review that came out at the end of last week. One thing they do say, of course, is that because many people are obliged to give their information to the public sector, and not quite so much so in the private sector, that gives a particular obligation on the public sector to be secure in its usage of that information. Is that not a big point?

  Mr Miliband: That is a very important point. I take this very, very seriously and I take the public sector's responsibility, for which I share a responsibility, very seriously. The only point I am making is that what that report, other incidents that have happened, and the Information Commissioner's report show is that there is a big job to be done across our whole society in taking the security of personal data seriously.

  Sir Gus O'Donnell: On your question about reports, I did issue one to you today in response to one of your requests about honours. You will have received that—a regular update report. In general what we are trying to do, whilst a number of the issues covered in the other two areas are complex, we have tried to respond to some of the points you have made in those reports in very practical terms. For example, you made a point about the Civil Service; so Civil Service legislation is going through. We are trying to do things, therefore, rather than just to respond. However, I do apologise for the delay. On this report, I would like to reinforce what Ed said about the importance of our sorting out these issues, so that we get public trust and so that, if we have that trust, we have the ability to get the public's trust to allow us to share data—because that is the answer to improving public services in so many areas. I think that the Walport/Thomas review backs that up. It is important for us to establish trust, therefore. That is why we have had exhaustive reports. You will have seen the Poynter report, Sir Edmund Burton's report and my own report. The Prime Minister asked me to do that. There are a number of recommendations out of those reports. We are accepting nearly all of those recommendations and moving forward. To my mind, it is hugely important. My report should be regarded as a process, not an event. A number of issues in my report we actually acted on straightaway, rather than waiting for the report to be published. With the MoD laptop issue, for example, when it became clear that there were some unencrypted laptops out there with large amounts of personal data on board, I banned the use of unencrypted laptops containing large amounts of personal data. I did not wait for the publication of the report; I just did it. I thought that it was really important and urgent that we tied down that area of potential losses. We have therefore done that. We have given the Information Commissioner the power to conduct spot checks in departments and, basically, the review set out a framework to allow us to improve matters—through training, through sensitising people to the fact that data (and I think this is the culture issue) are as important as personal wealth, if you like. We actually have to change the culture so that people will regard personal data in the same way they regard financial matters. That is why at the heart of the report there are a number of issues for permanent secretaries, as accounting officers, to think of protecting personal data in the same way they protect finances. That is why we have put into the Statement of Internal Control for the accounting officer, which we send to the National Audit Office, requirements about data in just the same way that we would have requirements about finances. Finally, throughout the review we have had a lot of very constructive help from Richard Thomas himself. That relationship has worked well. We have tried to ensure that all of these different reviews have complementary recommendations and that we are backing each other up. In the process of going through these, when I was chairing the steering committee, I made sure that the various recommendations from the sub-reports were incorporated in ours.

  Q3  Chairman: Thank you for that, and I am sure that we shall want to explore a number of these issues. What I want to ask you first, though, is, given this catalogue of failures, of data losses, putting it all together, how serious is it for the reputation of public administration in this country?

  Sir Gus O'Donnell: I would say that this is an area where we obviously need to do better. There is no question about that. I made my point about reputation. We need to have a good reputation so that people are prepared to trust us with their data, particularly in online settings. The fact is that people are trusting us in increasing numbers. Even if you take the example of HMRC, if you had thought there was a loss of trust on HMRC, particularly online data, then you might have thought that the online filing would have gone down. I am pleased to say that it has actually gone up by 30%: more than you would have expected by simply the trend extrapolation. People are trusting us to operate online. They are also using online services more than ever before. The fact is that we have a system where DWP, for example, have something like 22 million transactions per week. We are in the area where there are a lot of transactions, but it is hugely important for our reputation, for our ability to personalise public services, that we find actually secure ways of protecting and sharing data where appropriate. The thing we cannot do is close everything down. If we close everything down, there is a risk that we will make sins of commission, i.e. not sharing data when we should, which could cause as many problems as sharing it when we should not.

  Q4  Chairman: I am not sure from that answer whether you are saying this is extremely damaging, or whether in fact it is not very damaging because life goes on.

  Sir Gus O'Donnell: No, it is serious. There is absolutely no question about that. As the Walport/Thomas review makes clear, issues of data protection are not just throughout the public and private sectors of this economy: I could give you examples from countries around the world where they are having exactly the same issues. As we have moved to this age where we are putting vast amounts more data into computer systems and the like, the potential for this has gone up enormously. Therefore, we need to up our game to improve what we are doing to protect data, and we are certainly working very hard on that. That is why in my report there are a number of measures, which are designed to increase our reputation. If you ask me what is the most important one—we are doing things on accountability, on scrutiny, on technological changes—it is culture change.

  Q5  Chairman: Did you know that there was a problem here, waiting to explode like this?

  Sir Gus O'Donnell: We knew that we were increasing the amounts of data. We knew that we had given ever more detailed guidance out to departments. I was not aware, for example, of the problem that was there, that the guidance was not being followed in various cases, and I think that is—

  Q6  Chairman: Is that not the absolutely crucial issue? When I read the Poynter review and the Burton review, they are all saying in terms, "There was an issue here, waiting to happen. These were data losses that were inevitably going to happen, given the failure of proper systems and proper enforcement". That is what they say and that is what is revealing about these reports. It is not just, as it were, to do with the particular circumstances; they are all saying, "There were systematic failures here that meant that this was the inevitable outcome". That is why I ask you if you knew that there were systematic failures.

  Sir Gus O'Donnell: What they found was that the guidance was there, but actually there was not the question of testing whether that guidance was being followed. It was the question of implementation that was crucial.

  Q7  Chairman: Yes, that is the issue. If you look at it, it is the gap between these high-flown policy statements and actually what the practice is. That is what is revealed by all these reports from different departments. The Burton report on the MoD loss does a nice little summary of all the key documents that government had issued about this area. First, Risk: Improving Government's Capability to Handle Risk and Uncertainty, produced by the Number 10 Strategy Unit in November 2002. Secondly, A United Kingdom Government Strategy for Information Assurance, produced by the Cabinet Office in July 2003. Thirdly, in 2005, Transformational Government Enabled by Technology, produced by the Cabinet Office. Fourthly, A National Information Assurance Strategy, revised by the Cabinet Office in June 2007. We have had a plethora of documents in this area, saying what the good practice should be. Yet, when we have these incidents and we have inquiries into the incidents, it turns out that there is systematic failure to implement any of this.

  Sir Gus O'Donnell: Remember, it is the Cabinet Office's responsibility to ensure that we provide central guidance to departments and then it is the departments' responsibility to implement that guidance. What we have found in my report, which is why we have concentrated on this, is—you are absolutely right—there is an issue there that that guidance is either too complex or, in some cases—in the HMRC case and the Burton case—there were issues where it was not being followed at the frontline. That is why my report has emphasised the issues related to scrutiny, spot checks, all sorts of ways of ensuring that the guidance is implemented. I think that we have a responsibility in the sense of making sure that our guidance is not too complex, and is actually such that we can get it to all of the key personal data-holders in a form in which it is very simple for them to understand and they know precisely, in practical terms, what they have to do. I think that is the area where we have concentrated, looking forward: can we make it easier for someone to comply with, as you say, quite comprehensive guidance that has been issued already.

  Mr Miliband: Can I add to that, Chairman? I also think the point Gus makes about culture is absolutely right. You listed the reports that government had done. You then talked about the Defence and HMRC reports, and the fact that they found that a lot of the good intentions and good rules were not being implemented. One of the things that Gus's report recommends is training for everyone involved in handling sensitive data about what the requirements of that are; more training, I believe, for the more senior people who are information asset owners (IAOs), about what the responsibilities of that involves; a new rule that in the Statement of Internal Control, signed off by the accounting officer, there is a statement about information assurance and the security of data. In a way, you are right: government needs to do a lot better and to raise its game. I think that we are right to say that part of this—and in a way it concurs with your question—is not simply about issuing documents; it is about changing the culture as far as personal data is concerned. We all know that changing the culture in any large organisation is difficult. I do not say that as an excuse or an alibi; I just say that as a statement of fact. Is part of our task collectively across government to change the culture on this? Absolutely right—yes, it is—and I think that Gus's report will help in that process.

  Q8  Chairman: With all the talk we have had over the years, about "up-skilling government" and all the rest of it, it turns out that you have been issuing all this guidance from the centre, but on the ground, where it matters, implementation just was not happening. People will ask, "If that is the case in this area, perhaps all the other guidance that you are issuing from the centre is also not having any effect down through the systems". That is why I ask you whether you had a sense that this was the case.

  Sir Gus O'Donnell: I have been in the Civil Service a long time and I am aware of cases where we used to issue lots of guidance. I can go back to the Treasury's investment appraisal guidance, issued in the early 1980s, when we did have the experience of issuing guidance and then checking on whether or not it was being used, to find that mostly it was not being used. We do understand that it is important. That is the whole thrust of my report, as Ed says: to make sure that we have procedures in place that will allow us to ensure that our guidance is being implemented; for example, spot checks.

  Q9  Chairman: I will ask you one more thing on this and then I will hand over to colleagues. On this question of what happens on the ground and who is responsible, when I read these reports I was looking in each case—and this is what I think a member of the public, paying their taxes, would ask about these systems—at whose job was it to ensure that these systems were working? That all this guidance was being implemented? I find, reading the reports, that there are all kinds of people whose job it is seemingly to make sure that happens. There is the accounting officer, of course, and we are told that is the ultimate responsibility. Then there are information asset owners and there are senior information risk owners. Someone might say, "If there are these people whose job it is to keep an eye on data systems and to make sure that they are robust and doing what we want them to do, were they asleep on the job?" It turns out in the HMRC case that they did not even know what was going on. They were not involved in the issues that produced the data loss. What has happened to those people?

  Sir Gus O'Donnell: In the case of HMRC, as the Poynter report makes clear, it did never go above senior executive officer level—that issue about what should be handled with the NAO—and it should have done; so that was an error of procedure. They should have done something differently. Those people who are in place in departments—and, yes, there have been senior information risk officers (SIROs) in departments, for example, in the Home Office, for a couple of years—that is because we have been moving to manage this situation for a while. Information asset owners are in my report. That is new, is it not?

  Mr Fiennes: Exactly. This is a new requirement being put on departments and one of the ways in which their discretion has been limited, and we have defined the minimum role these people have to perform. These are people not at board level; these are people involved in particular business areas, involved in knowing the detail of what information is stored in an area, who is using it, from where it is coming and where it is going, and the purposes for those flows—to give that granularity of grip to which you have been referring. The important part of the report in this respect is that it seeks to make more transparent where people may not be playing their full role here. For example, we have a requirement for the accounting officer to make their judgment in the Statement on Internal Control, based on annual assessment provided to him by the SIRO, who is the board-level champion in these issues. The SIRO is required to get input from each of the people dealing with particular information assets. So you have a series of people giving assurance about performance and practice, about different aspects of the organisation, against different elements of the controls that are in place.

  Q10  Chairman: Let me bring this to a head if I can and then we will perhaps come back to it in another form. As I understand it, every department already had a senior information risk officer in place, whose job it was to oversee these systems. Then we have had all this run of data losses. These senior information risk officers were clearly not doing their job, were they? That is the kind of question that people would ask; because we now know, from department to department, there were faulty systems, not working. We know that there was a defective history. I think that what people want to know now—and, reading your report, Gus, I am still not clear what the answer to this is—is there now going to be some identifiable person in every bit of government, to ensure that these systems are robust and who carries the can if things goes wrong—and who is this person?

  Sir Gus O'Donnell: To take an example like Revenue & Customs, there are a very large number of people there dealing with personal data. Therefore, when it comes to, "Who should we train on these new systems? Who should we make sure is accountable?" the answer is, "Everybody"; so we are training the whole of HMRC on this. No matter how senior, how junior, it is important that we train them all. For every individual case—if you take the Child Benefit case—it will then be clear who the information asset owner for that area is. The answers will be making people aware of the accountability structure. That is certainly true, but there are other dimensions—like we can change the technology such that you would not be able to download that amount of data in the first place without strict controls. If you did download it, you would have to download it onto something that was encrypted and, if you did want to transfer it somewhere, you would have to transfer it in an encrypted form. There are multiple layers of protection that we need to put in place. One of them is making the accountability right. There will be—you are absolutely right—a SIRO on every board, who will ultimately be accountable for the risk management systems. It is not just them, however; it is all the people all the way down. To take the MoD case, there were very clearly some breaches, and the individual naval officer—I think that action was taken in that case. Where there are problems—and we mention this in the report—we will look at what the appropriate disciplinary proceedings are for every specific case.

  Q11  Chairman: Again, I am putting it from the point of view of the ordinary citizen and taxpayer. When these things happen, they just want to know, who was responsible for it. If everyone is accountable, then in a sense nobody is accountable. Somebody has to carry the can for every bit of government and every operation that it engages in. We know that in this area something has gone fundamentally wrong, and therefore there needs to be put in place someone whose job it is to make sure that all this guidance is being followed.

  Sir Gus O'Donnell: Absolutely, and that is what the SIRO is for and that is the board-level person ultimately responsible for doing this. Then, all the way down—because, as I say, the masses of data that big departments like DWP and HMRC are involved in—there will be information asset owners along the way, who will regard this information as their personal asset, look after it, protect it, and ensure that all the rules are being complied with.

  Q12  Chairman: So if we have a data loss from this point, we shall know precisely whose job it was to make sure it did not happen, shall we?

  Sir Gus O'Donnell: Once we have implemented all of the things that are in my report, then, yes.

  Q13  Chairman: So no more fuzzy accountability? We shall know exactly whose job it was?

  Sir Gus O'Donnell: Like I say, once we have implemented everything that is in there, yes.

  Q14  Mr Prentice: On that point, it is like closing the proverbial stable door after the horse has bolted, is it not? I hate these clichés, but they just sum it up.

  Sir Gus O'Donnell: There are a lot of horses still in there!

  Q15  Mr Prentice: I wanted to ask you about your interim progress report on data loss, which was published in December. You talked about the senior information risk owners and said that all departments were required in February 2004—you mentioned the Home Office two years ago, and that is four years ago—" ... to appoint a Senior Information Risk Owner ... as accountable for the ownership of information risks within that Department". Tony asked if these people were sleeping on the job. What Civil Service grade are they? Are they named individuals? Could I go to the Civil Service Year Book, for example, and find out who the senior information risk owner is in Revenue & Customs? Did they submit reports, flagging up concerns about the way in which data security could be compromised?

  Sir Gus O'Donnell: The SIROs would all have been at board level; so this would have been something for the boards to consider. I do not know in the individual cases whether these would have been issues. You would have to look at their risk registers and the like, to see whether there were discussions of individual points. The point is, this is something that has become more and more important. It is certainly true that, following the big data losses—that is why I did my report—we have certainly improved the accountability. We have added in, which I think is important, these information asset owners, which are at a lower level. There will be rather more of them and they will be able to report up to the SIRO, to allow that accountability to be taken and followed through in much more detail.

  Q16  Mr Prentice: Paul Gray has gone, of course. He carried the can. No one else has been disciplined.

  Sir Gus O'Donnell: If you take the Burton case, the naval officer who was involved has received an administrative censure.

  Q17  Mr Prentice: That was the first disciplinary case in the MoD, I think.

  Sir Gus O'Donnell: That is right. That was the laptop loss. Any follow-up will be for the military chain of command. As you say, Paul Gray stood down. I think that if it is clear—and this is one of the issues, which is why we need to clarify the guidance, and the respective responsibilities and accountabilities—then we do take action. People somehow think that there are not consequences in the Civil Service, and there are. Thirteen hundred people were terminated last year in the Civil Service.

  Q18  Mr Prentice: Just a few other points. I got a letter from the Chancellor in response to an issue I raised in the Chamber with him, telling me that Revenue & Customs have appointed 40 data guardians. These are basically information risk people below board level, who have a particular job responsibility to look after these matters.

  Sir Gus O'Donnell: Indeed, yes.

  Q19  Mr Prentice: These data guardians are going to be appointed across all departments?

  Sir Gus O'Donnell: That is what HMRC are doing.

  Mr Fiennes: The data guardian is more about providing a second pair of eyes in particular business areas, as I understand it; whereas the IAO is designed to be an individual with executive responsibility in the particular area, to make sure that what is going on is robust. What you have in HMRC is an additional requirement, which they have put in place in response to their particular circumstances.

  Mr Miliband: I think it is worth saying—and John will correct me if I am wrong—to clarify this point about the SIROs and the IAOs. The information asset owners are people designated to own the specific datasets and pieces of information within the department; a SIRO has the overall, board-level responsibility.

  Mr Fiennes: That is right. It is also fair to point out that, in the report that we have issued, we have spelled out in more detail the requirements on the SIROs in order to discharge their role. For instance, in providing annual assessment to the accounting officer, which covers the waterfront of the particular measures that we have put in place and making sure that they have the input from the different parts of the department that you need to make that judgment.



 
previous page contents next page

House of Commons home page Parliament home page House of Lords home page search page enquiries index

© Parliamentary copyright 2008
Prepared 28 August 2008