Skip to main content

Data Protection

Volume 475: debated on Wednesday 30 April 2008

To ask the Chancellor of the Exchequer pursuant to the answer of 27 February 2008, Official Report, column 1642W, on data protection, whether there is a separate line management process for HM Revenue and Customs data guardians. (195910)

Data guardians sit within each HMRC business units’ usual line management chain. The director of each business unit in HMRC is ultimately accountable for the data security arrangements in their respective business unit and as the principal accounting officer for HMRC, the chairman has ultimate responsibility for data security.

To ask the Chancellor of the Exchequer pursuant to the Answer of 27 February 2008, Official Report, column 1642W, on data protection, how many full-time equivalent data guardians HM Revenue and Customs has. (195912)

All staff in HMRC have a personal responsibility for protecting the data in their care in line with the Data Protection Act. For further advice staff can refer to their data guardian, each of whom has responsibility for the data security arrangements in a particular HMRC business unit.

To ask the Chancellor of the Exchequer how many employees of each grade in his Department (a) have access to confidential or sensitive data and (b) are authorised to download such data to disc; how many of his Department’s employees have undergone data protection training in the last 12 months; what the average length of time is that each employee of (i) his Department and (ii) his Department’s agencies has spent on data protection training; how many investigations of employees of his Department for improperly accessing confidential information have taken place in the last 12 months; how many such investigations resulted in cases of disciplinary action; and what the circumstances of each of those cases were. (168284)

HMRC provides its staff with controlled access to customer information to facilitate the delivery and maintenance of service to customers.

Access to HMRC systems is assigned according to user-roles within the organisation, and not grade. Information on users according to grade is not available and could be collated only at a disproportionate cost.

HMRC and its agency the Valuation Office Agency have in place a range of measures and procedures in relation to training and guidance on data protection and data security and transfer. Information on number of staff who have undergone training, the length of time spent by each and the cost of training is not available and could be collated only at a disproportionate cost.

HMRC has a strict policy forbidding staff to access customer records, unless they have a legitimate business need. Breaches of this policy are taken seriously and any breach will result in the commencement of disciplinary proceedings. Each case is treated on its merits but in many cases, the disciplinary penalty for breach is dismissal.

During the year ended 31 December 2007, 192 HMRC staff—from a headcount of just over 90,000—were disciplined or dismissed for inappropriate access to personal or sensitive data, reflecting the strength of HMRC’s internal disciplinary procedure. However, this represents less than 1 per cent. of total staff for each of the three years in question.

No other information is available on the breakdowns requested in this question.

To ask the Chancellor of the Exchequer how many breaches of data protection security there were in (a) his Department and (b) his Department’s agencies in each of the last five years; and if he will provide details of each breach. (168940)

To ask the Chancellor of the Exchequer how many security breaches relating to access to personal data occurred within his Department in each year since 1997. (169712)

To ask the Chancellor of the Exchequer how many confirmed data security breaches there have been in his Department in the last 36 months; and what action was taken after each occurrence. (170244)

HMRC records security incidents and does not record information in the form requested.

Since April 2005, HMRC has discussed 11 data security incidents involving customer information with the Information Commissioner’s Office as a matter of good practice and to ensure appropriate lessons are learned from such incidents.

HMRC has introduced more stringent controls which require that transfers of bulk data on removable media only take place where there is adequate security protection. The transfer of personal data only takes place when it is essential to do so due to a business critical need or in order to meet the HMRC’s legal obligations.

No such security incidents have been recorded by the Treasury, the Office of Government Commerce or the Debt Management Office.