Examination of Witnesses (Questions 40-59)
RT HON
ED MILIBAND
MP, SIR GUS
O'DONNELL KCB AND
MR JOHN
FIENNES
16 JULY 2008
Q40 David Heyes: This effort that
is going into training and changing the culture, this huge expenditure,
is it in any way being mirrored in the private sector firms that
are working on contract, for instance to HMRC?
Sir Gus O'Donnell: Our main point
with contracts, and I will ask John to come in on this, is basically
to sayand you are absolutely right, there are certain areas
where there is a private sector part, and what we have got to
do is ensure the same standards are applied in all those private
sector contracts. We are going through a process of analysing
all of those contracts. Obviously this is quite a lengthy process.
John, do you want to say something on that?
Mr Fiennes: Just to reinforce
what you said, really. New contracts would incorporate the same
provisions, where they are relevant to the contractor. It is worth
bearing in mind that the nature of the contract changes from situation
to situation; so in some cases there may be a number of people
who have access to data to do work day-to-day and they obviously
need to be alive to certain sorts of risks. In other situations,
where there is IT support for example, you have people with very
extensive user rights, for example to create and move large amounts
of data. In that situation the challenge is a different one: it
is about making sure you have the appropriate controls in place
to make sure people treat those rights with the appropriate respect.
What that means is that the sort of training you give will vary,
depending on the situation. So what we have is insertion into
new contracts of provisions to ensure that the new requirements
are rolled out, and discussions with existing contractors to ensure
that equivalent protections are in place. I think it is worth
saying that we had contacts with business both as a source of
expertise during the review but also as contractors and the response
we got was very positive. People were keen to do the right thing
and to make sure that data security did not become an issue in
the contract; so they were approaching it in a very practical
and pragmatic way in general, which was encouraging.
Q41 David Heyes: So these areas will
be more tightly specified in future contracts and you are working
on improving the existing contract scope?
Mr Fiennes: Exactly. The clear
aim has to be for the same requirements to apply across the piece.
Q42 David Heyes: Is there a cost
attached to that? Are the contractors saying, "Okay, we'll
introduce large-scale retraining and training for our staff within
this existing contract, but there's a cost attached to it"?
Mr Fiennes: Yes. My understanding
is that these sorts of changes in contracts happen, and with these
large contracts, quite often: and that costs are attached to changes
What you have is a relationship between the department and the
contractor which deals with these changes. The point is that,
with goodwill on both sides, those things can be dealt with and
that is what we believe will happen.
Q43 David Heyes: Do you know whether
that potential additional contract cost within existing contracts
is contained within this £155 million figure that we have
been quoted?
Mr Fiennes: Unfortunately, I do
not know the answer to exactly what the £155 million includes.
I am sorry.
Sir Gus O'Donnell: I think that
even ex-post it will be quite hard to answer your question. We
have got the OGC[1]
working for us on a model new contract and clauses that we will
put in. When you renegotiate a contract, obviously the supplier
to us will want to keep that contract. Our starting point will
be, "If you do business with us, you have got to follow these
data protection requirements"and then it will be a
negotiation.
Q44 David Heyes: The broad thrust of
the question is obvious. Where the failing is within the Civil
Service and you directly control it, then you can take action.
If it is a failing that is in whole or in part the fault of the
contractor, it is much more difficult to get hold of it. How do
you go about imposing those changes? You say that contractors
are willing and co-operative, but they do not need to be.
Sir Gus O'Donnell: They will want
the business and, if they do not come up to the standards that
we meet and if they are seen to fail those standards, then they
will lose the business. It is as clear as that.
Q45 David Heyes: In the reading I
have doneand we have had a huge amount of reading and so
some of it has been skating across the surfaceI have come
across the idea of an information charter, which you recommend
in your report. Help us to understand a little better what you
have in mind by "information charter".
Sir Gus O'Donnell: There is a
great deal of detail.
Q46 David Heyes: Briefly then.
Mr Fiennes: Just very briefly,
this is the notion that if departments were more transparent about
the information they held and how they were using it and how individuals
concerned about that would be able to respond then that would
improve confidence. So what you have in the report is two things.
You have a fairly short information charter talking about how
the department will handle data and what people can do about it
if they are unhappy with that. That is reproduced in the report
but that will be published by departments. The second thing you
have is work by departments to consider whether they can provide
more information in public about particular information assets
and particular information sets, about how they are handled and
what they are used for, which is again designed to build transparency
which we touched on earlier. I think this is an area where practice
may continue to evolve because we need to find a way of getting
the right information to people. They need to understand what
is going on and how the work that is being done is designed to
improve services and their conditions without, frankly, drowning
people in information that gets in the way of what they really
want to achieve, which is, if things are wrong, to put them right.
Sir Gus O'Donnell: It emerges
out of Thomas/Walport again where they are saying that we should
be clear with the public about what data is being used for and
under what circumstances can it be shared and you have got this
whole business about terms and conditions in the private sector
when you tick these little boxes and you have suddenly said that
it can be shared in all sorts of ways. What we want to be is very
clear with the public, when they are providing information to
us, what we can use it for, and what we cannot.
Q47 David Heyes: Some departments
are well down the road on implementing the information charter
idea, but noticeably HMRC have not recently implemented it, the
MoD have not, and it is quite coincidental but I understand also
that the Cabinet Office have not yet implemented the information
charter idea. Is that right?
Sir Gus O'Donnell: We are not
a big user of personal data. Quite a lot of the data we have got
we want to keep very secure.
Q48 David Heyes: We have had thousands,
millions, of people responding to petitions and the like. Surely
there are huge quantities of personal data coming your way nowadays?
Sir Gus O'Donnell: We have, certainly
through the Number 10 website, personal email addresses.
Q49 David Heyes: So for you it is
not a priority?
Sir Gus O'Donnell: It is very
important and we will do the information charter, but I am saying
that I think where it is most important is where you are collecting
large personal data, things like national insurance numbers, bank
account details and the rest of it. We do not do that in the Cabinet
Office.
Q50 Mr Prentice: Specifically on
that, should individuals have a right under the information charterit
may be buried in there somewhereto be notified, if their
data is compromised, if there has been a data loss, a security
breach? Should individuals have that right?
Sir Gus O'Donnell: It is a very
good question. When the HMRC issue first came to light, our first
priority was to talk to the banks, and to protect those individuals
whose bank account details were compromised. That is the first
thing we do, look after personal security so that the individuals
concerned will not be adversely affected by it. We have a strong
responsibility for that to be our first point of call, and then
we have lots of reporting requirements. It is interesting in the
private sector, that report that was out about marketing organisations.
The worrying thing I found from that was that some two-thirds
of them over the last 24 months had reported either data loss
or data theft. 90% of that went unreported, so whereas we have
got strong reporting requirements I think one of the issuesand
I know Richard Thomas is looking at thisis the question
of reporting requirements for the private sector.
Q51 Paul Flynn: Is there any information
that any individual has been harmed by these breaches of security?
Mr Miliband: We do not have any
information.
Q52 Paul Flynn: This is part of the
same question really. Have you got any information that these
breaches of security are worse than similar breaches in the private
sector? Can anyone make a judgment on that?
Sir Gus O'Donnell: On the question
of harm, certainly with HMRC and the data losses we have not found
the disks, but we have no reason to believe that any of that information
has been compromised, and similarly with the MoD laptops. Like
I said, that is not to say that they are not out there somewhere
and someone might in the future use them, I cannot guarantee that,
but so far there have been no examples from those cases. There
obviously have been a number of cases in the private sector where
information has gone astray. Precisely how much I do not think
anyone has really got to the heart of because there is this question
of some being unreported and that creates something of a problem.
I have had representatives of the private sector come and talk
to a group of permanent secretaries about the issues in the private
sector and about data losses they have experienced, and it is
certainly true if you look again at what is in Walport/Thomas
that the private sector is facing exactly the same sets of issues.
Because we have got this explosion of data that is out there you
will find that there some losses.
Q53 Paul Flynn: But someone who finds
a private sector disk is not likely to take it straightaway to
a newspaper possibly. I think perhaps all of the issues are calamities
for the Government and a PR nightmare for the Government now.
In terms of the positive case that you put forward today about
the improvement in the amount of data collection that people enjoy.
Do you not think that there has been a lack of a proper defensive
position put forward, possibly by yourself, Ed?
Mr Miliband: You make an important
point, which is about the overall reason for doing this. Gus was
talking earlier about the way in which, despite the losses, people
have still been using the technology that is out there. For example,
I think 10 million people a year now renew their car tax discs
online, and that relies on data sharing. The Climbié inquiry
from a few years ago, talked about the need for data sharing and
information sharing in the most sensitive social services cases,
so I think where you are completely right about this is that we
need to go out there on the front foot and say, "Look: we
are not doing this because we want to snoop on people or because
we want to get lots of information. We are doing this because
we want public services to work better". Having said that,
I think Tony's initial questions and comments are correct, which
is that you do need to command public confidence in the collection
of that data.
Q54 Paul Flynn: But if there is no
information that anyone has been harmed by the leaks they could
possibly be no worse than what is happening in the public sector.
Can I ask you, Gus, if you ever feel like Adolf Hitler must have
felt in the bunker in his final days (final hours, actually),
when he was ordering armies into battle and ordering fleets to
sea and nothing was happening outside, because you have given
us details of all the information you have put out, and apparently
it did not even reach 10 Downing Street when we hear from Jonathan
Powell that he said that when he was at Number 10 he regularly
cycled home with highly sensitive documents, "I was worried
I would be mugged as, quite illegally, I was carrying huge amounts
of classified material in my backpack?" Should he be prosecuted?
Sir Gus O'Donnell: He no longer
works for the Government.
Q55 Chairman: It is revealing though,
is it not?
Sir Gus O'Donnell: Like I say,
there is a culture change that is required and it is not just
junior staff; it is throughout organisations. Certainly you will
find that in the Civil Service I instil this. This is what we
are about. You will see us with briefcases and it is very important
for us that we manage our data securely, that we manage paper
handling, because we have got it all the time, but yes, that should
not have been happening.
Q56 Paul Flynn: It is commendable
that the staff are taking their work home with them, but Alistair
Darling said in the Commons that the IPC found no evidence of
misconduct or criminality about any member of the staff at HMRC,
and in the Data Protection Act the principle clearly states that
appropriate technical organisational measures "shall be taken
against unauthorised or unlawful processing of personal data and
against any accidental loss or destruction or damage to personal
data". These persons responsible did break the law, including
Jonathan Powell.
Sir Gus O'Donnell: It is not for
me to interpret the law. That is a matter for the police and then
the CPS in time. All I would say is that I certainly would not
condone anyone taking classified material not in the appropriate
way, ie, double protected in a locked briefcase.
Q57 Paul Flynn: Mr Fiennes, can I
ask you about your career? This was a particular responsibility
of yours, I believe. How do you look back on this? You are no
longer doing that job at the moment. Was it a promotion for you
to go from your previous job to your present job and, if so, why?
Sir Gus O'Donnell: SorryI
think you may have misinterpreted that. I have used John to do
reports for me. He helped in the border security report and I
brought him in to do this report. This was not his area of responsibility
within the Cabinet Office. I brought him from other work, to work
on this specific report.
Q58 Paul Flynn: But we have talked
in the past about the way people get promoted in the Civil Service
and the "unimportance of being right" principle in the
Civil Service which we have discussed in the past. I thought this
might have been an example, but clearly it is not.
Sir Gus O'Donnell: No.
Q59 Paul Flynn: The Information Commissioner
has only got £10 million but what he seems to be wanting
to create on the Civil Service, this huge body that you head,
which uses consultants in a way that --- a figure I saw the other
day was that for every public sector employee, there is £10,000
spent on consultants. This is the money going in, but he wants
to create, as I understand it, a great incubus on the body of
the Civil Service that is again going to be using tens of millions
of pounds of public money to do the job that top civil servants
should be doing anyway.
Sir Gus O'Donnell: First of all,
I am very pleased to say the amount spent on consultancy is diminishing
within the Civil Service and that is good.
1 Office of Government Commerce Back
|