Select Committee on Public Administration Minutes of Evidence


Examination of Witnesses (Questions 80-99)

RT HON ED MILIBAND MP, SIR GUS O'DONNELL KCB AND MR JOHN FIENNES

16 JULY 2008

  Q80  Kelvin Hopkins: This leads on to my concern with the fact that we have now people moving in and out of the Civil Service, but the career civil servant who was recruited from university and immediately had drilled into him or her the values of the Civil Service, knowing that they were going to spend the whole of their lives in the Civil Service, and finish up with an honour of some kind no doubt, felt this very strong sense of being in an organisation permanently and absorbing its values. Now we have dodgy American businessmen moving in and out of such as the Department of Health—and I will give you chapter and verse if you like, Ed—but they do not have those civil service values. They are interested in business, making a bit of cash, thinking about their business life after the Civil Service. It is a quite different culture. Do we not want to start to think about where we have gone wrong in some ways?

  Sir Gus O'Donnell: First of all, I do not know what the number is but 99.X% of the Civil Service never get honours. Just be careful about that. The vast proportion do not. In terms of do I think it is a mistake to have a more diverse Civil Service in the sense of getting people from different backgrounds? No, I do not. I think for those people that came in and the only organisation they ever knew was the Civil Service it certainly gave them some values but I would say that innovation was not their strongest point, commercial skills were not their strongest point. There are requirements within the Civil Service to have people of the highest commercial skills. Policies have changed, requiring us to manage outsourced contracts, requiring us to negotiate with the private sector. I want the Civil Service, and I think it is important in terms of value for money and ensuring that taxpayers' interests are protected, to have those commercial skills. I do not think a Civil Service that just took people in on day one and never brought anybody in from the outside would not serve the taxpayer as well as the Civil Service that we have today.

  Q81  Kelvin Hopkins: These values about promoting outsourcing, have they not been imposed upon you by misguided politicians, and if you had your way would you not like to have a proper Civil Service rather than having it outsourced to people of dubious motive?

  Mr Miliband: No.

  Q82  Chairman: I would like to put it differently by saying that as far as I am aware there were no dodgy American businessmen implicated in any of these data losses, were there?

  Sir Gus O'Donnell: No.

  Kelvin Hopkins: My points are made.

  Q83  Mr Prentice: Gus, you told us at the very beginning that if we were going to take data from citizens they should have trust in the Government and so on. The Information Commissioner said in October 2006 that we were moving towards a surveillance society. He may have said we were already in a surveillance society. What is your view? Do you think we are in a surveillance society, Ed?

  Mr Miliband: I do not recognise that description, and you have got to then break this down. I do remember that interview. I think it was an interview in The Times, at least that was the one I read, with the Information Commissioner where he used some of these phrases. When I think about CCTV, for example, and we do have a rather large proportion of the world's CCTV, as I understand it, when I think about what my constituents, or indeed yours, Gordon, think about CCTV and the way it can make them feel safer—

  Q84  Mr Prentice: Yes, but that is an easy number, CCTV, is it not?

  Mr Miliband: That was one of the things that the Information Commissioner may have been referring to; I do not know, but in a way, instead of having these grand descriptions, let us talk about the specific elements of them. One element that is often raised is CCTV.

  Q85  Mr Prentice: But if we have CCTV and it is linked to face recognition technology, so it can track Paul Flynn here—

  Mr Miliband: I have got no plans to track Paul Flynn.

  Q86  Mr Prentice:— that raises issues. You said at the very beginning that instead of, I do not know, was it 47 transactions—

  Mr Miliband: 44.

  Q87  Mr Prentice:— you could do it in one.

  Mr Miliband: Yes.

  Mr Prentice: And it gets back to what the Chairman was saying earlier about the Government's policy to personalise services. If you are going to tailor services to the individual, if you were going to personalise them, you need a lot of information about the individual, building up profiles of the citizen who may need meals-on-wheels and because of that may need social services support, may need help to get to hospital and so on. Is the reality not that over the coming years we are going to see a huge amount of information harvested from citizens, and if it does go wrong in future, it will go wrong on a mega scale? It will not just be 25 million names and addresses, bank account details and national insurance numbers; it could be that and a lot more.

  Paul Flynn: Let me just say—

  Q88  Mr Prentice: No, you cannot. I am not asking you.

  Mr Miliband: I am tempted to say "order, order".

  Paul Flynn: If my face is recognised I might well in future at my time of life be grateful if someone tells me where I am and possibly who I am.

  Q89  Chairman: Rather than have this conversation amongst the Committee I think we would quite like to have an answer.

  Mr Miliband: Let me just say two things and Gus may want to add something. It is easy to say that it is a big brother state that we are seeing. Take the example of ID cards, which in a way is a big innovation. Some people say, "I am worried"—because this has been said by some people—"that every transaction I do using my ID card will somehow be on a central database". That is not true. It will not be on a central database. Okay, some people will make claims about surveillance but it is important to look behind those cases.

  Q90  Mr Prentice: Can I just stop you there?

  Mr Miliband: Let me just finish the point. It is important to look behind those cases. The second point I wanted to make, and this is important, I think, is that sometimes we are thinking about this on a grand scale of how you link up databases, for example, to ensure that the Tell Us Once project means you do not have to tell people 44 times that you have been bereaved, but it is also about, and I see this as the minister responsible for social exclusion, how many times I go out and meet people who say, "We are trying to help particular individuals in difficult circumstances and I will tell you what the biggest problem is for us. It is information sharing, not being allowed to share information about individuals, about them being in trouble", for example, and I have talked to Ed Balls about this, kids who face a bereavement, their teacher not being allowed to be told that they have suffered a bereavement. I think there is a macro level to this and there is a micro level.

  Q91  Mr Prentice: No, I understand that. That was the sense of commission that Gus was talking about earlier where there is a need to share data but you do not for other reasons. I do not want to go off beam here, but on the National Identity Register, it was originally the proposal that every time someone was asked for the card and it was swiped it would be held on the National Identity Register. That was the original proposal.

  Mr Miliband: I do not know; you may well be right.

  Q92  Mr Prentice: I am telling you it was.

  Mr Miliband: That is not the proposal now, so there we are.

  Q93  Mr Prentice: Oh, well, I can sleep more easily in my bed if that is the case. Can I just finish on this point because it is something that the Deputy and maybe the Information Commissioner have written about and which, Gus, you flag up in your report, and that is the Privacy Impact Assessment. Is the Privacy Impact Assessment going to trump everything else, that you think there may be a good reason to share information between the DWP and the Home Office but maybe there is a privacy issue and the privacy impact assessment would stop that? How does it work?

  Sir Gus O'Donnell: It is very rarely you will have things that are lexicographic in that sense, that you will have one thing trumping everything else. There will be issues about privacy which you will want to take into account when considering how you manage a particular data sharing issue. If we come back to the example you wanted on health, you would say that there could be enormous gains from being able to have available to pharmacists around the country some information so that if you happened to fall ill in that area and went in they would know that you were allergic to certain things. Let us say you were unconscious so they could not find out, so there would be some way of assessing that sort of data. That kind of thing is an obvious gain but there will obviously be a risk associated with that. These things tend to be trade-offs; they are not black and white and you just have to assess the risk of having much greater access to that personal data. The interesting thing is that when you ask people, "Do you want us to share your data for these sorts of things?", overwhelmingly the answer is yes because they can see the personal benefit to them in terms of improved services.

  Q94  Mr Prentice: But we do not ask everyone, do we, whether they want their information shared? It would be a different kettle of fish if we asked individuals.

  Sir Gus O'Donnell: For example, the Tell Us Once project is based on a consents procedure. There is an interesting question about whether in certain cases we want to have the right to always share, that is certainly true, but in general this is about having individuals telling us that they are happy for us to share.

  Q95  Mr Prentice: Finally from me, are we going to see what one of these privacy impact assessments looks like?

  Sir Gus O'Donnell: Certainly.

  Mr Fiennes: The Information Commissioner is keen on these assessments. There is guidance on his website about what they look like and they are used internationally. They are not a sort of "go/no go" assessment. What they are is a structured way to think about the potential impacts on privacy of approaching something in a particular way, what the risks are and how you mitigate them to make sure you take a conscious decision. It is like the Data Protection Act from that point of view. It does not say, "The following things are allowed and the following things are not allowed". Of course, it depends on the purpose for which you are using them and the safeguards that you have in place, so it is a way of ensuring those situations are factored in in a systematic way at the point of design, which is the best time in which to build in the security that you need.

  Sir Gus O'Donnell: Another analogy would be a regulatory impact assessment.

  Mr Prentice: Yes; thank you.

  Q96  Chairman: As we end could I ask a couple of final questions? Gus, you have mentioned along the way the importance you attach to clear record keeping. This is a subject for a different inquiry but I just want to be sure that you are satisfied that in an electronic age government is now keeping the kinds of records that it used to keep and that they will be available notwithstanding all the issues that we know now about the keeping of data, that the record of government is going to be intact.

  Sir Gus O'Donnell: There are two aspects to that. If you remember, Terry Burns when he was Permanent Secretary of the Treasury was quite a long way ahead of his time in terms of moving the Treasury onto an email system and we had a famous electronic filing system called Panagon, which was very difficult to use. It is certainly the case that during that transition period when people were starting to use emails for the first time there were some problems around that in terms of electronic data recording. That is one issue and we are trying to go back and see how important that was. The second issue, which is important and which we have collectively divvied up around departments to solve, is what you might have thought of as straightforward. Once you have saved all these digital records you might think, "That is it. This is a lot more secure than paper". Actually, it is not. Digital records deteriorate through time and we are going through a process led by National Archives to sort out ways of preserving digital records because it is not as well known as it should be that if you just keep a digital record on a computer it will deteriorate, it will not last for ever, and so we are taking active steps to enhance those digital records to ensure that does not happen.

  Q97  Chairman: That is important. A journalist said to me the other day—and you can tell me whether this is true or not—that Number 10 only keeps its email records for three months and then they go into a kind of deep freeze, which is immune from FOI requests. Is that true?

  Sir Gus O'Donnell: Virtually all organisations—private or public sector—will have email deletion policies, which is that for the standard email of, "Yes, I am happy to join you for lunch" kind of thing, those that are not classified as records, will have an automatic deletion date. Automatic deletion dates vary through time, but, and this is for all those people that think they have deleted things from their computers, you could delete stuff from a computer, you could delete it from your recycle box. I could certainly find it again. Technically, no problem. It does take a bit of time. You have to go back onto the hard drive and all the rest of it but, for example, when we were doing the cash for honours investigation, we were asked by the police to search our systems for certain key words and we searched them all. There is no such thing as an email that has disappeared, subject to that first point about digital deterioration, but that is a question of many years. You can find emails.

  Q98  Chairman: Okay; we may come back to that. You mentioned along the way that you thought the Government had—your phrase was "strong reporting requirements".

  Sir Gus O'Donnell: On breaches?

  Q99  Chairman: Yes, in relation to breaches. Of course, we know that in the HMRC case that was not the case. One of the issues revealed by the inquiries was that the breach was not immediately reported, and indeed they have still not been able to establish why there was such a long delay in reporting it. What I would like to know is exactly what the practice is and what the practice is going to be about the logging of all data losses, and also of near misses because in the preface to your report you say, "Every loss or near miss, must make us more determined ... ". What I am really asking you is, are we now getting a proper log of all the losses and all the near misses right across government?

  Sir Gus O'Donnell: There are requirements under the Data Protection Act to notify these, but what we have said in the report is that all departments will report in their annual reports to you, Parliament, their data breaches and they will have a little section which goes into what they are doing about the issues. For losses I think it is fairly clear. They will all be reported to the Information Commissioner. I think there are some de minimis issues. You would not want to cover everything, but anything significant I think will be important. The question about near misses is an interesting one because it is really a question of precisely how well we can define what constitutes a near miss, as to how accurately we can report all of those. That is something where we are working on precisely how best to meet that requirement.



 
previous page contents next page

House of Commons home page Parliament home page House of Lords home page search page enquiries index

© Parliamentary copyright 2008
Prepared 28 August 2008