Examination of Witnesses (Questions 80-99)
RT HON
ED MILIBAND
MP, SIR GUS
O'DONNELL KCB AND
MR JOHN
FIENNES
16 JULY 2008
Q80 Kelvin Hopkins: This leads on
to my concern with the fact that we have now people moving in
and out of the Civil Service, but the career civil servant who
was recruited from university and immediately had drilled into
him or her the values of the Civil Service, knowing that they
were going to spend the whole of their lives in the Civil Service,
and finish up with an honour of some kind no doubt, felt this
very strong sense of being in an organisation permanently and
absorbing its values. Now we have dodgy American businessmen moving
in and out of such as the Department of Healthand I will
give you chapter and verse if you like, Edbut they do not
have those civil service values. They are interested in business,
making a bit of cash, thinking about their business life after
the Civil Service. It is a quite different culture. Do we not
want to start to think about where we have gone wrong in some
ways?
Sir Gus O'Donnell: First of all,
I do not know what the number is but 99.X% of the Civil Service
never get honours. Just be careful about that. The vast proportion
do not. In terms of do I think it is a mistake to have a more
diverse Civil Service in the sense of getting people from different
backgrounds? No, I do not. I think for those people that came
in and the only organisation they ever knew was the Civil Service
it certainly gave them some values but I would say that innovation
was not their strongest point, commercial skills were not their
strongest point. There are requirements within the Civil Service
to have people of the highest commercial skills. Policies have
changed, requiring us to manage outsourced contracts, requiring
us to negotiate with the private sector. I want the Civil Service,
and I think it is important in terms of value for money and ensuring
that taxpayers' interests are protected, to have those commercial
skills. I do not think a Civil Service that just took people in
on day one and never brought anybody in from the outside would
not serve the taxpayer as well as the Civil Service that we have
today.
Q81 Kelvin Hopkins: These values
about promoting outsourcing, have they not been imposed upon you
by misguided politicians, and if you had your way would you not
like to have a proper Civil Service rather than having it outsourced
to people of dubious motive?
Mr Miliband: No.
Q82 Chairman: I would like to put
it differently by saying that as far as I am aware there were
no dodgy American businessmen implicated in any of these data
losses, were there?
Sir Gus O'Donnell: No.
Kelvin Hopkins: My points are made.
Q83 Mr Prentice: Gus, you told us
at the very beginning that if we were going to take data from
citizens they should have trust in the Government and so on. The
Information Commissioner said in October 2006 that we were moving
towards a surveillance society. He may have said we were already
in a surveillance society. What is your view? Do you think we
are in a surveillance society, Ed?
Mr Miliband: I do not recognise
that description, and you have got to then break this down. I
do remember that interview. I think it was an interview in The
Times, at least that was the one I read, with the Information
Commissioner where he used some of these phrases. When I think
about CCTV, for example, and we do have a rather large proportion
of the world's CCTV, as I understand it, when I think about what
my constituents, or indeed yours, Gordon, think about CCTV and
the way it can make them feel safer
Q84 Mr Prentice: Yes, but that is
an easy number, CCTV, is it not?
Mr Miliband: That was one of the
things that the Information Commissioner may have been referring
to; I do not know, but in a way, instead of having these grand
descriptions, let us talk about the specific elements of them.
One element that is often raised is CCTV.
Q85 Mr Prentice: But if we have CCTV
and it is linked to face recognition technology, so it can track
Paul Flynn here
Mr Miliband: I have got no plans
to track Paul Flynn.
Q86 Mr Prentice: that raises
issues. You said at the very beginning that instead of, I do not
know, was it 47 transactions
Mr Miliband: 44.
Q87 Mr Prentice: you could
do it in one.
Mr Miliband: Yes.
Mr Prentice: And it gets back to what
the Chairman was saying earlier about the Government's policy
to personalise services. If you are going to tailor services to
the individual, if you were going to personalise them, you need
a lot of information about the individual, building up profiles
of the citizen who may need meals-on-wheels and because of that
may need social services support, may need help to get to hospital
and so on. Is the reality not that over the coming years we are
going to see a huge amount of information harvested from citizens,
and if it does go wrong in future, it will go wrong on a mega
scale? It will not just be 25 million names and addresses, bank
account details and national insurance numbers; it could be that
and a lot more.
Paul Flynn: Let me just say
Q88 Mr Prentice: No, you cannot.
I am not asking you.
Mr Miliband: I am tempted to say
"order, order".
Paul Flynn: If my face is recognised
I might well in future at my time of life be grateful if someone
tells me where I am and possibly who I am.
Q89 Chairman: Rather than have this
conversation amongst the Committee I think we would quite like
to have an answer.
Mr Miliband: Let me just say two
things and Gus may want to add something. It is easy to say that
it is a big brother state that we are seeing. Take the example
of ID cards, which in a way is a big innovation. Some people say,
"I am worried"because this has been said by some
people"that every transaction I do using my ID card
will somehow be on a central database". That is not true.
It will not be on a central database. Okay, some people will make
claims about surveillance but it is important to look behind those
cases.
Q90 Mr Prentice: Can I just stop
you there?
Mr Miliband: Let me just finish
the point. It is important to look behind those cases. The second
point I wanted to make, and this is important, I think, is that
sometimes we are thinking about this on a grand scale of how you
link up databases, for example, to ensure that the Tell Us Once
project means you do not have to tell people 44 times that you
have been bereaved, but it is also about, and I see this as the
minister responsible for social exclusion, how many times I go
out and meet people who say, "We are trying to help particular
individuals in difficult circumstances and I will tell you what
the biggest problem is for us. It is information sharing, not
being allowed to share information about individuals, about them
being in trouble", for example, and I have talked to Ed Balls
about this, kids who face a bereavement, their teacher not being
allowed to be told that they have suffered a bereavement. I think
there is a macro level to this and there is a micro level.
Q91 Mr Prentice: No, I understand
that. That was the sense of commission that Gus was talking about
earlier where there is a need to share data but you do not for
other reasons. I do not want to go off beam here, but on the National
Identity Register, it was originally the proposal that every time
someone was asked for the card and it was swiped it would be held
on the National Identity Register. That was the original proposal.
Mr Miliband: I do not know; you
may well be right.
Q92 Mr Prentice: I am telling you
it was.
Mr Miliband: That is not the proposal
now, so there we are.
Q93 Mr Prentice: Oh, well, I can
sleep more easily in my bed if that is the case. Can I just finish
on this point because it is something that the Deputy and maybe
the Information Commissioner have written about and which, Gus,
you flag up in your report, and that is the Privacy Impact Assessment.
Is the Privacy Impact Assessment going to trump everything else,
that you think there may be a good reason to share information
between the DWP and the Home Office but maybe there is a privacy
issue and the privacy impact assessment would stop that? How does
it work?
Sir Gus O'Donnell: It is very
rarely you will have things that are lexicographic in that sense,
that you will have one thing trumping everything else. There will
be issues about privacy which you will want to take into account
when considering how you manage a particular data sharing issue.
If we come back to the example you wanted on health, you would
say that there could be enormous gains from being able to have
available to pharmacists around the country some information so
that if you happened to fall ill in that area and went in they
would know that you were allergic to certain things. Let us say
you were unconscious so they could not find out, so there would
be some way of assessing that sort of data. That kind of thing
is an obvious gain but there will obviously be a risk associated
with that. These things tend to be trade-offs; they are not black
and white and you just have to assess the risk of having much
greater access to that personal data. The interesting thing is
that when you ask people, "Do you want us to share your data
for these sorts of things?", overwhelmingly the answer is
yes because they can see the personal benefit to them in terms
of improved services.
Q94 Mr Prentice: But we do not ask
everyone, do we, whether they want their information shared? It
would be a different kettle of fish if we asked individuals.
Sir Gus O'Donnell: For example,
the Tell Us Once project is based on a consents procedure. There
is an interesting question about whether in certain cases we want
to have the right to always share, that is certainly true, but
in general this is about having individuals telling us that they
are happy for us to share.
Q95 Mr Prentice: Finally from me,
are we going to see what one of these privacy impact assessments
looks like?
Sir Gus O'Donnell: Certainly.
Mr Fiennes: The Information Commissioner
is keen on these assessments. There is guidance on his website
about what they look like and they are used internationally. They
are not a sort of "go/no go" assessment. What they are
is a structured way to think about the potential impacts on privacy
of approaching something in a particular way, what the risks are
and how you mitigate them to make sure you take a conscious decision.
It is like the Data Protection Act from that point of view. It
does not say, "The following things are allowed and the following
things are not allowed". Of course, it depends on the purpose
for which you are using them and the safeguards that you have
in place, so it is a way of ensuring those situations are factored
in in a systematic way at the point of design, which is the best
time in which to build in the security that you need.
Sir Gus O'Donnell: Another analogy
would be a regulatory impact assessment.
Mr Prentice: Yes; thank you.
Q96 Chairman: As we end could I ask
a couple of final questions? Gus, you have mentioned along the
way the importance you attach to clear record keeping. This is
a subject for a different inquiry but I just want to be sure that
you are satisfied that in an electronic age government is now
keeping the kinds of records that it used to keep and that they
will be available notwithstanding all the issues that we know
now about the keeping of data, that the record of government is
going to be intact.
Sir Gus O'Donnell: There are two
aspects to that. If you remember, Terry Burns when he was Permanent
Secretary of the Treasury was quite a long way ahead of his time
in terms of moving the Treasury onto an email system and we had
a famous electronic filing system called Panagon, which was very
difficult to use. It is certainly the case that during that transition
period when people were starting to use emails for the first time
there were some problems around that in terms of electronic data
recording. That is one issue and we are trying to go back and
see how important that was. The second issue, which is important
and which we have collectively divvied up around departments to
solve, is what you might have thought of as straightforward. Once
you have saved all these digital records you might think, "That
is it. This is a lot more secure than paper". Actually, it
is not. Digital records deteriorate through time and we are going
through a process led by National Archives to sort out ways of
preserving digital records because it is not as well known as
it should be that if you just keep a digital record on a computer
it will deteriorate, it will not last for ever, and so we are
taking active steps to enhance those digital records to ensure
that does not happen.
Q97 Chairman: That is important.
A journalist said to me the other dayand you can tell me
whether this is true or notthat Number 10 only keeps its
email records for three months and then they go into a kind of
deep freeze, which is immune from FOI requests. Is that true?
Sir Gus O'Donnell: Virtually all
organisationsprivate or public sectorwill have email
deletion policies, which is that for the standard email of, "Yes,
I am happy to join you for lunch" kind of thing, those that
are not classified as records, will have an automatic deletion
date. Automatic deletion dates vary through time, but, and this
is for all those people that think they have deleted things from
their computers, you could delete stuff from a computer, you could
delete it from your recycle box. I could certainly find it again.
Technically, no problem. It does take a bit of time. You have
to go back onto the hard drive and all the rest of it but, for
example, when we were doing the cash for honours investigation,
we were asked by the police to search our systems for certain
key words and we searched them all. There is no such thing as
an email that has disappeared, subject to that first point about
digital deterioration, but that is a question of many years. You
can find emails.
Q98 Chairman: Okay; we may come back
to that. You mentioned along the way that you thought the Government
hadyour phrase was "strong reporting requirements".
Sir Gus O'Donnell: On breaches?
Q99 Chairman: Yes, in relation to
breaches. Of course, we know that in the HMRC case that was not
the case. One of the issues revealed by the inquiries was that
the breach was not immediately reported, and indeed they have
still not been able to establish why there was such a long delay
in reporting it. What I would like to know is exactly what the
practice is and what the practice is going to be about the logging
of all data losses, and also of near misses because in the preface
to your report you say, "Every loss or near miss, must make
us more determined ... ". What I am really asking you is,
are we now getting a proper log of all the losses and all the
near misses right across government?
Sir Gus O'Donnell: There are requirements
under the Data Protection Act to notify these, but what we have
said in the report is that all departments will report in their
annual reports to you, Parliament, their data breaches and they
will have a little section which goes into what they are doing
about the issues. For losses I think it is fairly clear. They
will all be reported to the Information Commissioner. I think
there are some de minimis issues. You would not want to
cover everything, but anything significant I think will be important.
The question about near misses is an interesting one because it
is really a question of precisely how well we can define what
constitutes a near miss, as to how accurately we can report all
of those. That is something where we are working on precisely
how best to meet that requirement.
|