Advertisement
Promo

Security management Toolkit

Home Office publishes data-sharing guidance

Tom Espiner ZDNet.co.uk

Published: 09 Oct 2008 17:18 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Home Office has published a code of practice for data sharing between public- and private-sector organisations.

The code, entitled Data Sharing for the Prevention of Fraud, is designed to give guidance to public authorities on disclosing information to third-party anti-fraud organisations. It was presented to parliament on Monday, following the enactment of sections 68 to 72 of the Serious Crime Act 2007 by statutory instrument last Wednesday.

Information commissioner Richard Thomas welcomed the code, writing in its foreword that "fraud prevention is a key priority for the public and private sectors alike."

"I welcome this high-level Code of Practice in terms of setting out some broad principles and considerations for participants," Thomas wrote.

The code states that it aims to ensure data is shared in a "necessary and proportionate" way, and that data sharing takes place within a framework that properly protects individuals' rights and the security of the data. It also says that the Serious Crime Act does not give public authorities the power to make disclosures that contravene the Data Protection Act.

However, one security expert disagreed. "The Code of Practice is supposed to regulate the infinite powers given under the Serious Crime Act, which specifically amends the Data Protection Act," security author 'Spy Blog' (who prefers to remain anonymous) told ZDNet.co.uk on Thursday. However, Spy Blog said the Serious Crime Act sections introduced a danger of function creep that was not addressed in the Code.

Read this

Q&A
Gartner: Authentication systems are 'fatally flawed'

Security analyst Jay Heiser gives his take on the rash of UK public-sector data losses and explains why authentication systems aren't up to scratch...

Read more +

"What starts as an ad hoc system [of data sharing] could become a system linking many private and public sector organisations automatically," said Spy Blog. "For example, insurance companies need to investigate fraud, all well and good, but insurance covers accident insurance, which means they need to view medical records. Claims looking at medical records get linked automatically, and everyone is linked."

Spy Blog added that the provisions of the code were too broad and may not make data sharing secure, as security methods such as encryption were not specified.

"It's so vague," said Spy Blog. "The thing that struck me is that even after all of the privacy and data breaches with lost laptops, CDs and USBs, there's no mention of encryption."

The Home Office said on Thursday that the code was designed to be "overarching", and that encryption was not specified as data could be provided by a "variety of means".

"The Code of Practice is designed to provide an overarching code for public authorities disclosing information under arrangements with a specified anti-fraud organisation," said a Home Office spokesperson. "The code requires public authorities to have appropriate technical and organisational measures in place to assure the security of information disclosed under these arrangements. These measures must be agreed with the specified anti-fraud organisation in an information-sharing document. As data may be disclosed to specified anti-fraud organisations by a variety of means, the code does not specify the exact security measures to be put in place."

The Home Office spokesperson added that the code provides examples of technical and organisational measures for public authorities to consider.

"One of these examples is for public authorities to ensure that 'all computers and buildings used for data processing have physical and logical access controls limiting access to certain individuals'," said the spokesperson. "Encryption for secure data transfer is one method that could be used to limit access."

The Code of Practice was not available on the Home Office website at the time of writing.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
5 out of 5 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Watchdog reveals illegal sale of phone...

The Information Commissioner's Office is preparing a prosecution file against a mobile operator's employees who allegedly sold on thousands of customers' details to a competitor. The... More

1 comment

Featured Talkback

In association with Network Liberation Movement
It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters