Examination of Witnesses (Questions 100-105)
RT HON
ED MILIBAND
MP, SIR GUS
O'DONNELL KCB AND
MR JOHN
FIENNES
16 JULY 2008
Q100 Chairman: It is not the case
that all losses have to be reported to the Data Protection Commissioner.
Sir Gus O'Donnell: Significant
ones.
Q101 Chairman: But it is important
that all this gets reported. What I really want is an assurance
that from now on in the reports that are being done each year
by departments, we shall have a list of all data losses and, I
would argue, near misses, because if it is true, as you say, that
you learn as much from near misses as you learn from data losses
we should have those too.
Sir Gus O'Donnell: What we say
in the report is that the annual reports that every department
publishes, will have a list of significant data losses in them.
I hear what you say about near misses. It is absolutely important
that we learn from near misses, and I think we need to make sure
that we have some sort of reporting requirement there. At the
moment what my report says is that we will report losses.
Q102 Chairman: But you may give some
more thought to that?
Sir Gus O'Donnell: Indeed.
Q103 Chairman: Can I just ask you
this, and this is really the end and it goes back to where we
started about the difference between issuing the guidance and
what happens on the ground? When I look at the time line for improvements
that you have given us, and I know that there is always the caveat
that there are no guarantees that data losses will not happen,
either in the public or the private sector; we know that, but,
given all that you have said and all that you say in your report
about the chronology of improvements and who is going to be responsible
and so on and the culture change and everything else. If after
October this year we had the kinds of examples of data losses
that we have seen in the last year, that would be a calamity for
the reputation of government, would it not?
Sir Gus O'Donnell: All I can do
through the report is to say that we hope to increase the security
and protection of data considerably by all of these measures.
It will be for departments primarily to be responsible for implementing
all of these. We will push really hard from the centre. As you
say, I think the data losses we have had already put at risk individuals'
identity. That is a terrible thing. I want to minimise the probability
of that. I cannot put that probability at zero.
Q104 Chairman: No, I understand that.
What I am saying to you though is, given all that you are doing
and given your attention now to the follow-through on this issue,
if we had data losses on the scale that we have had before and
if we had inquiries into those data losses that revealed systemic
failures that would be a calamity for government, would it not?
Sir Gus O'Donnell: And the fact
that Paul Gray stood down I think brought this home to permanent
secretaries very clearly, that this is a hugely important responsibility
for them.
Q105 Chairman: I think that is your
way of saying it would be.
Sir Gus O'Donnell: Look: this
is absolutely important for us. I have told people that in terms
of their training and development budgets this is the number one
priority. It is really important. I come back to this: it is really
important for the public that we are able to give them better
public services by earning their trust by protecting the data
so that we can use it to improve the public services we offer.
That is the way I think about it and it is the way I explain it
to people. Improving trust is hugely important.
Chairman: Okay. We are really grateful
for today. It is a session we did not want to have. It is one
that we hope we will never have again, but thank you for coming
and discussing the issues with us.
|