Select Committee on Public Administration Minutes of Evidence


Examination of Witnesses (Questions 40-59)

RT HON ED MILIBAND MP, SIR GUS O'DONNELL KCB AND MR JOHN FIENNES

16 JULY 2008

  Q40  David Heyes: This effort that is going into training and changing the culture, this huge expenditure, is it in any way being mirrored in the private sector firms that are working on contract, for instance to HMRC?

  Sir Gus O'Donnell: Our main point with contracts, and I will ask John to come in on this, is basically to say—and you are absolutely right, there are certain areas where there is a private sector part, and what we have got to do is ensure the same standards are applied in all those private sector contracts. We are going through a process of analysing all of those contracts. Obviously this is quite a lengthy process. John, do you want to say something on that?

  Mr Fiennes: Just to reinforce what you said, really. New contracts would incorporate the same provisions, where they are relevant to the contractor. It is worth bearing in mind that the nature of the contract changes from situation to situation; so in some cases there may be a number of people who have access to data to do work day-to-day and they obviously need to be alive to certain sorts of risks. In other situations, where there is IT support for example, you have people with very extensive user rights, for example to create and move large amounts of data. In that situation the challenge is a different one: it is about making sure you have the appropriate controls in place to make sure people treat those rights with the appropriate respect. What that means is that the sort of training you give will vary, depending on the situation. So what we have is insertion into new contracts of provisions to ensure that the new requirements are rolled out, and discussions with existing contractors to ensure that equivalent protections are in place. I think it is worth saying that we had contacts with business both as a source of expertise during the review but also as contractors and the response we got was very positive. People were keen to do the right thing and to make sure that data security did not become an issue in the contract; so they were approaching it in a very practical and pragmatic way in general, which was encouraging.

  Q41  David Heyes: So these areas will be more tightly specified in future contracts and you are working on improving the existing contract scope?

  Mr Fiennes: Exactly. The clear aim has to be for the same requirements to apply across the piece.

  Q42  David Heyes: Is there a cost attached to that? Are the contractors saying, "Okay, we'll introduce large-scale retraining and training for our staff within this existing contract, but there's a cost attached to it"?

  Mr Fiennes: Yes. My understanding is that these sorts of changes in contracts happen, and with these large contracts, quite often: and that costs are attached to changes What you have is a relationship between the department and the contractor which deals with these changes. The point is that, with goodwill on both sides, those things can be dealt with and that is what we believe will happen.

  Q43  David Heyes: Do you know whether that potential additional contract cost within existing contracts is contained within this £155 million figure that we have been quoted?

  Mr Fiennes: Unfortunately, I do not know the answer to exactly what the £155 million includes. I am sorry.

  Sir Gus O'Donnell: I think that even ex-post it will be quite hard to answer your question. We have got the OGC[1] working for us on a model new contract and clauses that we will put in. When you renegotiate a contract, obviously the supplier to us will want to keep that contract. Our starting point will be, "If you do business with us, you have got to follow these data protection requirements"—and then it will be a negotiation.

  Q44 David Heyes: The broad thrust of the question is obvious. Where the failing is within the Civil Service and you directly control it, then you can take action. If it is a failing that is in whole or in part the fault of the contractor, it is much more difficult to get hold of it. How do you go about imposing those changes? You say that contractors are willing and co-operative, but they do not need to be.

  Sir Gus O'Donnell: They will want the business and, if they do not come up to the standards that we meet and if they are seen to fail those standards, then they will lose the business. It is as clear as that.

  Q45  David Heyes: In the reading I have done—and we have had a huge amount of reading and so some of it has been skating across the surface—I have come across the idea of an information charter, which you recommend in your report. Help us to understand a little better what you have in mind by "information charter".

  Sir Gus O'Donnell: There is a great deal of detail.

  Q46  David Heyes: Briefly then.

  Mr Fiennes: Just very briefly, this is the notion that if departments were more transparent about the information they held and how they were using it and how individuals concerned about that would be able to respond then that would improve confidence. So what you have in the report is two things. You have a fairly short information charter talking about how the department will handle data and what people can do about it if they are unhappy with that. That is reproduced in the report but that will be published by departments. The second thing you have is work by departments to consider whether they can provide more information in public about particular information assets and particular information sets, about how they are handled and what they are used for, which is again designed to build transparency which we touched on earlier. I think this is an area where practice may continue to evolve because we need to find a way of getting the right information to people. They need to understand what is going on and how the work that is being done is designed to improve services and their conditions without, frankly, drowning people in information that gets in the way of what they really want to achieve, which is, if things are wrong, to put them right.

  Sir Gus O'Donnell: It emerges out of Thomas/Walport again where they are saying that we should be clear with the public about what data is being used for and under what circumstances can it be shared and you have got this whole business about terms and conditions in the private sector when you tick these little boxes and you have suddenly said that it can be shared in all sorts of ways. What we want to be is very clear with the public, when they are providing information to us, what we can use it for, and what we cannot.

  Q47  David Heyes: Some departments are well down the road on implementing the information charter idea, but noticeably HMRC have not recently implemented it, the MoD have not, and it is quite coincidental but I understand also that the Cabinet Office have not yet implemented the information charter idea. Is that right?

  Sir Gus O'Donnell: We are not a big user of personal data. Quite a lot of the data we have got we want to keep very secure.

  Q48  David Heyes: We have had thousands, millions, of people responding to petitions and the like. Surely there are huge quantities of personal data coming your way nowadays?

  Sir Gus O'Donnell: We have, certainly through the Number 10 website, personal email addresses.

  Q49  David Heyes: So for you it is not a priority?

  Sir Gus O'Donnell: It is very important and we will do the information charter, but I am saying that I think where it is most important is where you are collecting large personal data, things like national insurance numbers, bank account details and the rest of it. We do not do that in the Cabinet Office.

  Q50  Mr Prentice: Specifically on that, should individuals have a right under the information charter—it may be buried in there somewhere—to be notified, if their data is compromised, if there has been a data loss, a security breach? Should individuals have that right?

  Sir Gus O'Donnell: It is a very good question. When the HMRC issue first came to light, our first priority was to talk to the banks, and to protect those individuals whose bank account details were compromised. That is the first thing we do, look after personal security so that the individuals concerned will not be adversely affected by it. We have a strong responsibility for that to be our first point of call, and then we have lots of reporting requirements. It is interesting in the private sector, that report that was out about marketing organisations. The worrying thing I found from that was that some two-thirds of them over the last 24 months had reported either data loss or data theft. 90% of that went unreported, so whereas we have got strong reporting requirements I think one of the issues—and I know Richard Thomas is looking at this—is the question of reporting requirements for the private sector.

  Q51  Paul Flynn: Is there any information that any individual has been harmed by these breaches of security?

  Mr Miliband: We do not have any information.

  Q52  Paul Flynn: This is part of the same question really. Have you got any information that these breaches of security are worse than similar breaches in the private sector? Can anyone make a judgment on that?

  Sir Gus O'Donnell: On the question of harm, certainly with HMRC and the data losses we have not found the disks, but we have no reason to believe that any of that information has been compromised, and similarly with the MoD laptops. Like I said, that is not to say that they are not out there somewhere and someone might in the future use them, I cannot guarantee that, but so far there have been no examples from those cases. There obviously have been a number of cases in the private sector where information has gone astray. Precisely how much I do not think anyone has really got to the heart of because there is this question of some being unreported and that creates something of a problem. I have had representatives of the private sector come and talk to a group of permanent secretaries about the issues in the private sector and about data losses they have experienced, and it is certainly true if you look again at what is in Walport/Thomas that the private sector is facing exactly the same sets of issues. Because we have got this explosion of data that is out there you will find that there some losses.

  Q53  Paul Flynn: But someone who finds a private sector disk is not likely to take it straightaway to a newspaper possibly. I think perhaps all of the issues are calamities for the Government and a PR nightmare for the Government now. In terms of the positive case that you put forward today about the improvement in the amount of data collection that people enjoy. Do you not think that there has been a lack of a proper defensive position put forward, possibly by yourself, Ed?

  Mr Miliband: You make an important point, which is about the overall reason for doing this. Gus was talking earlier about the way in which, despite the losses, people have still been using the technology that is out there. For example, I think 10 million people a year now renew their car tax discs online, and that relies on data sharing. The Climbié inquiry from a few years ago, talked about the need for data sharing and information sharing in the most sensitive social services cases, so I think where you are completely right about this is that we need to go out there on the front foot and say, "Look: we are not doing this because we want to snoop on people or because we want to get lots of information. We are doing this because we want public services to work better". Having said that, I think Tony's initial questions and comments are correct, which is that you do need to command public confidence in the collection of that data.

  Q54  Paul Flynn: But if there is no information that anyone has been harmed by the leaks they could possibly be no worse than what is happening in the public sector. Can I ask you, Gus, if you ever feel like Adolf Hitler must have felt in the bunker in his final days (final hours, actually), when he was ordering armies into battle and ordering fleets to sea and nothing was happening outside, because you have given us details of all the information you have put out, and apparently it did not even reach 10 Downing Street when we hear from Jonathan Powell that he said that when he was at Number 10 he regularly cycled home with highly sensitive documents, "I was worried I would be mugged as, quite illegally, I was carrying huge amounts of classified material in my backpack?" Should he be prosecuted?

  Sir Gus O'Donnell: He no longer works for the Government.

  Q55  Chairman: It is revealing though, is it not?

  Sir Gus O'Donnell: Like I say, there is a culture change that is required and it is not just junior staff; it is throughout organisations. Certainly you will find that in the Civil Service I instil this. This is what we are about. You will see us with briefcases and it is very important for us that we manage our data securely, that we manage paper handling, because we have got it all the time, but yes, that should not have been happening.

  Q56  Paul Flynn: It is commendable that the staff are taking their work home with them, but Alistair Darling said in the Commons that the IPC found no evidence of misconduct or criminality about any member of the staff at HMRC, and in the Data Protection Act the principle clearly states that appropriate technical organisational measures "shall be taken against unauthorised or unlawful processing of personal data and against any accidental loss or destruction or damage to personal data". These persons responsible did break the law, including Jonathan Powell.

  Sir Gus O'Donnell: It is not for me to interpret the law. That is a matter for the police and then the CPS in time. All I would say is that I certainly would not condone anyone taking classified material not in the appropriate way, ie, double protected in a locked briefcase.

  Q57  Paul Flynn: Mr Fiennes, can I ask you about your career? This was a particular responsibility of yours, I believe. How do you look back on this? You are no longer doing that job at the moment. Was it a promotion for you to go from your previous job to your present job and, if so, why?

  Sir Gus O'Donnell: Sorry—I think you may have misinterpreted that. I have used John to do reports for me. He helped in the border security report and I brought him in to do this report. This was not his area of responsibility within the Cabinet Office. I brought him from other work, to work on this specific report.

  Q58  Paul Flynn: But we have talked in the past about the way people get promoted in the Civil Service and the "unimportance of being right" principle in the Civil Service which we have discussed in the past. I thought this might have been an example, but clearly it is not.

  Sir Gus O'Donnell: No.

  Q59  Paul Flynn: The Information Commissioner has only got £10 million but what he seems to be wanting to create on the Civil Service, this huge body that you head, which uses consultants in a way that --- a figure I saw the other day was that for every public sector employee, there is £10,000 spent on consultants. This is the money going in, but he wants to create, as I understand it, a great incubus on the body of the Civil Service that is again going to be using tens of millions of pounds of public money to do the job that top civil servants should be doing anyway.

  Sir Gus O'Donnell: First of all, I am very pleased to say the amount spent on consultancy is diminishing within the Civil Service and that is good.



1   Office of Government Commerce Back


 
previous page contents next page

House of Commons home page Parliament home page House of Lords home page search page enquiries index

© Parliamentary copyright 2008
Prepared 28 August 2008