Advertisement
Promo

Disaster recovery Toolkit

Watchdog: HMRC did breach data laws

Tom Espiner ZDNet.co.uk

Published: 18 Dec 2007 14:54 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The organisation responsible for administering the UK's data-protection legislation has said the government breached data laws when millions of records were stolen in the data debacle at HM Revenue & Customs.

Twenty-five million records of people claiming or receiving child benefits were lost in transit last month between HMRC and the National Audit Office.

The Information Commissioner's Office said on Tuesday that the government had failed to adequately safeguard the personal data. "It is clear that there was a breach of data-protection requirements," said Richard Thomas, the information commissioner.

After the disclosure of the breach, the government appointed PricewaterhouseCoopers chairman Kieran Poynter to report on the causes. Alistair Darling, the chancellor of the exchequer, presented Poynter's interim findings to Parliament on Monday.

Following Darling's speech, Thomas said: "We have received a copy of Kieran Poynter's initial report and discussed its contents with him. We will decide what further action to take [against HMRC] once the final PricewaterhouseCoopers report is available."

However, despite the concerns of the Information Commissioner's Office (ICO), the sanctions it can currently impose are weak. The current maximum penalty for breaking data laws is a £5,000 fine.

In the aftermath of the HMRC fiasco, the government promised the ICO greater powers of inspection. Darling said in his speech on Monday that data-protection legislation and penalties would be strengthened. "The prime minister has already announced the information commissioner will have the power to conduct spot checks on departments," said Darling. "There will now also be new sanctions under the Data Protection Act for the most serious breaches of its principles."

Read this

Feature
Governments prepare for 'cyber cold war'

Analysis: Security experts have warned that governments are regularly monitoring and attacking the critical national infrastructures of other nations

Read more +

The ICO, which has been asking for greater powers since its inception in 2001, welcomed the government's proposals. "I welcome the government's commitment to strengthen the powers of my office, enabling us to carry out inspections of organisations which collect and use personal information and to put in place new sanctions for the most serious breaches of data-protection principles," said Thomas.

The information commissioner added that public confidence in new government data schemes, such as the National Identity Register, would be shaken unless the government tightened security and privacy.

"Privacy matters more than ever before, especially as so much of our personal information is now collected and shared," said Thomas. "Public trust and confidence must be earned through tighter security and other data-protection safeguards. Retaining trust and confidence also relies on organisations not collecting or sharing excessive information in the first place."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
7 out of 7 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:











Discussions

adamjarvis adamjarvis

Using Windows Is Like...

Sunday 8 November 2009, 10:03 AM

1 comment
roxyrohit roxyrohit

reply

Saturday 7 November 2009, 6:35 PM

37 comments
roxyrohit roxyrohit

reply

Saturday 7 November 2009, 6:35 PM

37 comments
roxyrohit roxyrohit

reply

Saturday 7 November 2009, 6:35 PM

37 comments
Video icon

Video


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters