Skip to main content

Departmental Data Protection

Volume 470: debated on Monday 21 January 2008

To ask the Secretary of State for Justice whether personal data for which his Department is responsible are (a) stored and (b) processed overseas; and if he will make a statement. (176016)

The Department does not have any personal data for which it is responsible stored or processed overseas.

To ask the Secretary of State for Justice what obligations his Department and its agencies place on contractors in relation to the audit of personal data and IT equipment. (176467)

The Department’s information technology is provided mainly through contracts with external suppliers. The contracts place obligations on contractors to provide IT and data management systems that meet government security standards, including the standard for Information systems risk management known as HMG Infosec Standard 2, and the Ministry of Justice’s own security policies and standards.

The contracts place obligations on contractors to comply fully with all legislative requirements, including the relevant provisions of the Data Protection Act.

There is also provision for the Department to undertake audits to ensure compliance with all provisions of the contracts. For example, all new systems, and any that involve a significant upgrade or change, are subject to rigorous audit before acceptance into live service.

The Department also has appropriate measures in place to protect the confidentiality and integrity of its data and systems. For example, contracted staff employed by Her Majesty’s Prison Service (HMPS) and the National Probation Service, are security cleared to an appropriate level commensurate with the level of access they have to data.

To ask the Secretary of State for Justice what audits his Department and its agencies have carried out in relation to personal data and IT equipment in each of the last 10 years. (176473)

Our IT suppliers are contractually obliged to maintain the Department’s IT systems in accordance with government security standards, and the relevant provisions of the Data Protection Act. Assurance that these security standards are being met is obtained through compliance with the HMG standard for information systems risk management, known as HMG Infosec Standard 2.

The Ministry of Justice and its agencies undertake a formal programme of audits each year as well as carrying out other internal reviews as required. The scope of these audits is dependent on the reason for the audit taking place, or the specific terms of reference for the review. Past audit programmes undertaken by the former Department for Constitutional Affairs have contained a number of audits that have included coverage of systems and procedures incorporating aspects of personal data, including their storage and processing. Audit reports have been issued and action taken where necessary.

Her Majesty’s Prison Service (HMPS) is subject to continuous audit, under the oversight of the NAO. The results are considered by the HMPS’s audit committee.