I refer the hon. Member to the statement given in the House by my right hon. Friend the Chancellor of the Exchequer on 20 November 2007, Official Report, columns 1101-04.
On 20 November, the Chancellor announced an independent review of HMRC’s data handling procedures to be conducted by Kieran Poynter, chair of PricewaterhouseCoopers.
The review will cover the steps that should be taken to ensure any further measures are adhered to consistently by all staff. The interim report was published on 7 December 2007 and is available in the Library of the House.
I also refer the hon. Member to the remarks I made on 28 November 2007, Official Report, column 344, setting out the three key steps all staff in HMRC must now follow for bulk data transfers.
Further, as announced by the Prime Minister on 21 November 2007, Official Report, column 1179, the review by the Cabinet Secretary and security experts is looking at procedures within Departments and agencies for the storage and use of data. A statement on Departments’ procedures will be made on completion of the review.
Her Majesty’s Revenue and Customs is operationally independent of Ministers. It is established by statute and run by a board of Commissioners who are responsible for operational matters.
The risk assessment and risk management processes for information security are kept under constant review by HM Revenue and Customs.
Treasury Ministers discuss a wide range of issues, including security, with officials in the Departments for which they are responsible.
(2) when his Department carried out risk assessments in accordance with section 0 (12) of the manual of protective security over the last five years;
(3) when the last periodic review of security risks in (a) his Department and (b) HM Revenue and Customs took place in accordance with section 0 of the manual of protective security;
(4) when the last reassessment of risk was carried out by (a) his Department and (b) HM Revenue and Customs in accordance with section 0 (24) of the manual of protective security.
Both HM Treasury and HM Revenue and Customs keep their security policies and procedures under constant review. They use the Cabinet Office Manual of Protective Security as the basis for ensuring that adequate and proportionate security measures are applied to protecting information, in all its forms, in their care. From that publication, they derive their own security policies and standards. Assurance activities test compliance with each Department’s security policies and standards.
(2) what (a) reports on and (b) reviews of data security in HM Revenue and Customs have been ordered by Ministers in the last five years; and on what date each was (i) ordered and (ii) received.
Her Majesty’s Revenue and Customs is operationally independent of Ministers. It is established by statute and run by a board of Commissioners who are responsible for its operations but answerable to Parliament through the Chancellor. Treasury Ministers discuss a range of issues and tasks relating to the administration of the Department with officials in the Departments for which they are responsible.
No personal data for which this Department is responsible is stored or processed overseas.
Contractors working for HM Treasury (HMT) and its agencies are required to agree to comply with Acceptable Use Policies prior to using any IT equipment or receiving access to network systems and the Government Secured Intranet. There are a number of contracts currently in use within HMT and its agencies. It is not possible to comment on each one individually, however HMT's General Terms and Conditions of Contract and the Model Contract Terms (produced by Office of Government Commerce) contain Data Protection Clauses, which require all contractors to be registered under the relevant parts of the Data Protection Act 1998 and to ensure that the applicable provisions of the Data Protection Act are complied with.
HMT and its agencies undertake either a formal programme of audits each year or carry out internal reviews which incorporate audits of personal data (of the general public and employees) and IT equipment. The extent and focus of these audits is dependent on the specific terms of reference for each review and a large number of audits have been carried out each year in the last 10 years that relate to these areas.