The Department does not have any personal data for which it is responsible stored or processed overseas.
The Department’s information technology is provided mainly through contracts with external suppliers. The contracts place obligations on contractors to provide IT and data management systems that meet government security standards, including the standard for Information systems risk management known as HMG Infosec Standard 2, and the Ministry of Justice’s own security policies and standards.
The contracts place obligations on contractors to comply fully with all legislative requirements, including the relevant provisions of the Data Protection Act.
There is also provision for the Department to undertake audits to ensure compliance with all provisions of the contracts. For example, all new systems, and any that involve a significant upgrade or change, are subject to rigorous audit before acceptance into live service.
The Department also has appropriate measures in place to protect the confidentiality and integrity of its data and systems. For example, contracted staff employed by Her Majesty’s Prison Service (HMPS) and the National Probation Service, are security cleared to an appropriate level commensurate with the level of access they have to data.
Our IT suppliers are contractually obliged to maintain the Department’s IT systems in accordance with government security standards, and the relevant provisions of the Data Protection Act. Assurance that these security standards are being met is obtained through compliance with the HMG standard for information systems risk management, known as HMG Infosec Standard 2.
The Ministry of Justice and its agencies undertake a formal programme of audits each year as well as carrying out other internal reviews as required. The scope of these audits is dependent on the reason for the audit taking place, or the specific terms of reference for the review. Past audit programmes undertaken by the former Department for Constitutional Affairs have contained a number of audits that have included coverage of systems and procedures incorporating aspects of personal data, including their storage and processing. Audit reports have been issued and action taken where necessary.
Her Majesty’s Prison Service (HMPS) is subject to continuous audit, under the oversight of the NAO. The results are considered by the HMPS’s audit committee.