Information Age: News, analysis & insight for IT & business leaders

 
4 July 2009

Government slammed by data breach reports

26 June 2008  

The MoD and HMRC are being called to account over two high-profile incidents of data loss

The MoD and HMRC have been hit with enforcement notices from the Information Commissioner’s Office (ICO), following the release of two damning reviews into major data breaches.

The HMRC lost a pair of discs containing personal and financial details of 25 million people under the Child Benefit scheme, while the MoD lost a laptop containing details of 600,000 people.

The departments will be fined if they fail to adopt the recommendations in the Poynter and Burton reports, into the HMRC and MoD respectively.

Information Commisioner Richard Thomas said while the major data-loss incidents had been well publicised, “It is deeply worrying that many other incidents have been reported, some involving even more sensitive data.”

HMRC claims already to have implemented 39 of the 45 recommendations contained in the Poynter report at a cost of £155 million; these include the appointment of a senior official to the post of ‘director of data security’ and ‘data guardians’ in each department, imposing a complete ban on the transfer of unencrypted bulk data to removable media, and disabling the download function on all laptops.

Chancellor Alistair Darling apologised “unreservedly” to the House of Commons over the incident: “It is quite clear the loss was entirely avoidable.”

The MoD has also accepted the 51 recommendations in the Burton report. Both government departments must provide annual progress reports for the next three years.

Meanwhile Justice Minister Michael Wills is calling for “data minimisation”, a model that would avoid “gigantic databases where anyone can go and search. I think the security implications of that are horrendous."

“There is a clear need for radical change in government in how we handle data. We don't handle data in the same way as we handle money, and I think we should,” he said.

Further reading

Data theft is a people issue It is important to understand the legal context for guarding against data theft, says Warren Wayne of law firm Bird & Bird.

Little faith in ID safeguards Internet banking and retailing could easily be sacrificed for identity protection.

Find more stories in the Security & Continuity Briefing Room


Comments 

There are currently no comments on this article

People who read this also read...

PeopleSoft's rising sales leave Oracle in a quandary

PeopleSoft has reported stronger than expected fourth quarter results, heaping pressure on rival Oracle to either raise its hostile takeover bid for a third time or to abandon it completely.

Informer

Infoconomist's monthly review of the top technology sector stories, together with informed comment on the wider implications of the news.

MergeOptics pragmatic approach to networking

The forecast multi-billion dollar market for optical switching technology has so far failed to materialise, partly because production processes remain unrefined and costly.

 
Advertisement

White Papers

Read article

10 Really Good Reasons To Use Predictive Analytics

Whitepapers

Here are 10 really good reasons predictive analytics can help your business.

Read article

10 Ways Predictive Analytics Can Help You

Whitepapers

Predictive analytics is a powerful tool that helps organizations solve key challenges by using business knowledge to drive efficiencies and strengthen their competitive advantage.

Read article

12 Key Points to Consider When Selecting a Network Scanning Solution

Whitepapers

Discover the 12 key points your company should consider before you evaluate and select a vulnerability assessment solution.

More