Skip to main content

Departmental Data Protection

Volume 470: debated on Wednesday 9 January 2008

To ask the Chancellor of the Exchequer on how many occasions in (a) his Department and (b) its agencies confidential data have been downloaded on to compact discs (i) without and (ii) with encryption in the last 12 month period for which figures are available; how many of those discs have been posted without using recorded or registered delivery; what procedures his Department has in place for the (A) transport, (B) exchange and (C) delivery of confidential or sensitive data; what records are kept of information held by his Department being sent outside the Department; what changes have been made to his Department’s rules and procedures on data protection in the last two years; on how many occasions his Department’s procedures and rules on data protection have been breached in the last five years; what those breaches were; what procedures his Department has in place on downloading confidential data on to computer discs before its transfer; what technical protections there are in his Department’s computer systems to prevent access to information held on those systems which is not in accordance with departmental procedures; and if he will place in the Library a copy of each of his Department’s rules and procedures on the protection of confidential data on individuals, businesses and other organisations. (168263)

I refer the hon. Member to the statement given in the House by my right hon. Friend the Chancellor of the Exchequer on 20 November 2007, Official Report, columns 1101-04.

On 20 November, the Chancellor announced an independent review of HMRC’s data handling procedures to be conducted by Kieran Poynter, chair of PricewaterhouseCoopers.

The review will cover the steps that should be taken to ensure any further measures are adhered to consistently by all staff. The interim report was published on 7 December 2007 and is available in the Library of the House.

I also refer the hon. Member to the remarks I made on 28 November 2007, Official Report, column 344, setting out the three key steps all staff in HMRC must now follow for bulk data transfers.

Further, as announced by the Prime Minister on 21 November 2007, Official Report, column 1179, the review by the Cabinet Secretary and security experts is looking at procedures within Departments and agencies for the storage and use of data. A statement on Departments’ procedures will be made on completion of the review.

To ask the Chancellor of the Exchequer which Minister in his Department reviewed the formal document submitted by the Departmental Security/IT Officer following the risk assessment and risk management process for information security. (169755)

Her Majesty’s Revenue and Customs is operationally independent of Ministers. It is established by statute and run by a board of Commissioners who are responsible for operational matters.

The risk assessment and risk management processes for information security are kept under constant review by HM Revenue and Customs.

To ask the Chancellor of the Exchequer on what occasions he has met the Departmental Security Officer who last carried out a periodic security review of (a) his Department and (b) HM Revenue and Customs in accordance with the manual of protective security. (169759)

Treasury Ministers discuss a wide range of issues, including security, with officials in the Departments for which they are responsible.

To ask the Chancellor of the Exchequer (1) when HM Revenue and Customs first carried out a risk assessment in accordance with section 0 (12) of the manual of protective security after its establishment; and when it last carried one out; (169760)

(2) when his Department carried out risk assessments in accordance with section 0 (12) of the manual of protective security over the last five years;

(3) when the last periodic review of security risks in (a) his Department and (b) HM Revenue and Customs took place in accordance with section 0 of the manual of protective security;

(4) when the last reassessment of risk was carried out by (a) his Department and (b) HM Revenue and Customs in accordance with section 0 (24) of the manual of protective security.

Both HM Treasury and HM Revenue and Customs keep their security policies and procedures under constant review. They use the Cabinet Office Manual of Protective Security as the basis for ensuring that adequate and proportionate security measures are applied to protecting information, in all its forms, in their care. From that publication, they derive their own security policies and standards. Assurance activities test compliance with each Department’s security policies and standards.

To ask the Chancellor of the Exchequer (1) what internal reports on data security have been submitted to Ministers in his Department in the last five years; and on what date each was submitted; (173370)

(2) what (a) reports on and (b) reviews of data security in HM Revenue and Customs have been ordered by Ministers in the last five years; and on what date each was (i) ordered and (ii) received.

Her Majesty’s Revenue and Customs is operationally independent of Ministers. It is established by statute and run by a board of Commissioners who are responsible for its operations but answerable to Parliament through the Chancellor. Treasury Ministers discuss a range of issues and tasks relating to the administration of the Department with officials in the Departments for which they are responsible.

To ask the Chancellor of the Exchequer whether personal data for which his Department is responsible is (a) stored and (b) processed overseas; and if he will make a statement. (176012)

To ask the Chancellor of the Exchequer what obligations his Department and its agencies place on contractors in relation to the audit of personal data and IT equipment. (176470)

Contractors working for HM Treasury (HMT) and its agencies are required to agree to comply with Acceptable Use Policies prior to using any IT equipment or receiving access to network systems and the Government Secured Intranet. There are a number of contracts currently in use within HMT and its agencies. It is not possible to comment on each one individually, however HMT's General Terms and Conditions of Contract and the Model Contract Terms (produced by Office of Government Commerce) contain Data Protection Clauses, which require all contractors to be registered under the relevant parts of the Data Protection Act 1998 and to ensure that the applicable provisions of the Data Protection Act are complied with.

To ask the Chancellor of the Exchequer what audits his Department and its agencies have carried out in relation to personal data and IT equipment in each of the last 10 years. (176487)

HMT and its agencies undertake either a formal programme of audits each year or carry out internal reviews which incorporate audits of personal data (of the general public and employees) and IT equipment. The extent and focus of these audits is dependent on the specific terms of reference for each review and a large number of audits have been carried out each year in the last 10 years that relate to these areas.