Data guardians sit within each HMRC business units’ usual line management chain. The director of each business unit in HMRC is ultimately accountable for the data security arrangements in their respective business unit and as the principal accounting officer for HMRC, the chairman has ultimate responsibility for data security.
All staff in HMRC have a personal responsibility for protecting the data in their care in line with the Data Protection Act. For further advice staff can refer to their data guardian, each of whom has responsibility for the data security arrangements in a particular HMRC business unit.
HMRC provides its staff with controlled access to customer information to facilitate the delivery and maintenance of service to customers.
Access to HMRC systems is assigned according to user-roles within the organisation, and not grade. Information on users according to grade is not available and could be collated only at a disproportionate cost.
HMRC and its agency the Valuation Office Agency have in place a range of measures and procedures in relation to training and guidance on data protection and data security and transfer. Information on number of staff who have undergone training, the length of time spent by each and the cost of training is not available and could be collated only at a disproportionate cost.
HMRC has a strict policy forbidding staff to access customer records, unless they have a legitimate business need. Breaches of this policy are taken seriously and any breach will result in the commencement of disciplinary proceedings. Each case is treated on its merits but in many cases, the disciplinary penalty for breach is dismissal.
During the year ended 31 December 2007, 192 HMRC staff—from a headcount of just over 90,000—were disciplined or dismissed for inappropriate access to personal or sensitive data, reflecting the strength of HMRC’s internal disciplinary procedure. However, this represents less than 1 per cent. of total staff for each of the three years in question.
No other information is available on the breakdowns requested in this question.
HMRC records security incidents and does not record information in the form requested.
Since April 2005, HMRC has discussed 11 data security incidents involving customer information with the Information Commissioner’s Office as a matter of good practice and to ensure appropriate lessons are learned from such incidents.
HMRC has introduced more stringent controls which require that transfers of bulk data on removable media only take place where there is adequate security protection. The transfer of personal data only takes place when it is essential to do so due to a business critical need or in order to meet the HMRC’s legal obligations.
No such security incidents have been recorded by the Treasury, the Office of Government Commerce or the Debt Management Office.