alistair darling
R E L A T E D   C O N T E N T
ADVERTISEMENT

HMRC leak raises prospect of new data rules

Will the loss of two CD-roms make the government overhaul its security procedures?

Rosalie Marshall, IT Week 22 Nov 2007
ADVERTISEMENT

The HMRC data loss scandal could lead to an overhaul of UK security procedures, leaving IT directors facing the prospect of having to deal with new regulations that aim to guard against future privacy breaches.

The loss of two discs containing the confidential details of over 25 million child benefit recipients, including their bank and social security details, has been widely viewed as the worst breach to have occurred in the UK, and forced the resignation of HMRC chairman Paul Gray. Calls for tighter security controls across the public and private sectors have been heard from all corners in the wake of the incident.

“Searching questions need to be answered about systems, procedures and human error inside both HMRC and the National Audit Office,” said Information Commissioner Richard Thomas. He advised organisations to address security and data protection safeguards “with the utmost vigour” in light of the breach.

Alex Brown, a partner at international law firm Simmons & Simmons, said the incident will “turn the spotlight on the enforcement process” of the Data Protection Act, adding that the current process is too lenient. “The [Information Commissioner] will only hand out criminal sanctions if firms fail to comply with the enforcement notice. [But this is] too little, too late,” he said.

Ant Allan, an analyst at Gartner, agreed that punishment for not following security procedures needs to be made more severe, adding that fines carry less weight than custodial sentences when punishing organisations that fail to live up to industry standards.

Allan pointed out that many US states had introduced breach notification laws in response to these types of incidents. The HMRC data loss could lead to renewed calls for similar rules in the UK because there was a gap of about a month between the discs being lost and the public being informed.

But Allan said that any new legislation should lay out clear principles to guide organisations and be more limited in specific functions.

Efforts to raise awareness of data security risks and best practice could be a more useful response than introducing new legislation, Allan argued. He pointed out that when a full set of data is needed from HMRC, the usual practice is for an auditor to undertake the work – not a junior member of staff. “It shows that there is not enough corresponding awareness of policy in an organisation,” he added.

Jamie Cowper of PGP Corporation attributed the problem to the public sector focusing on securing their networks “to the utmost degree” with firewalls, but not considering the data.

See also:

The House of Lords is not happy with the government's response to its calls for more net security  01 Nov 2007
a padlockA major new industry initiative could ensure the quality and security of software  23 Oct 2007
GuardianEdge’s Alan Fudge says US-style data breach notification laws are heading this way  21 Sep 2007
Houses of parliamentRecommendations include the introduction of data security breach notification law in the UK  10 Aug 2007
Council admits accidentally exposing cardholder data  27 Jul 2007

All Privacy & Data

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Reading, Berkshire, United Kingdom | EDS
Job Title Netcool Designer / Engineer Location Reading Short Description: DII The DII project is contracted to supply both hardware and software infrastructure solutions to support the MoD transition to a common base solution, based ... more >
Inverness, United Kingdom | NHS Scotland
CORPORATE SERVICES E-HEALTH DEPARTMENT  RAIGMORE HOSPITAL INVERNESS TECHNICAL DEVELOPMENT TEAM IT TECHNICAL SPECIALIST  £24,103 to £32,653 PA An exciting opportunity has arisen to join the technical development team within the eHealth Department. We are looking ... more >
London, United Kingdom | City of London
ICT Project Officer - Guildhall, London EC2 18-month fixed-term contract Bring your project management expertise to one of the country's most prestigious institutions. The City of London is the local authority for the Square Mile, ... more >
London, United Kingdom | Feltham City Learning Centre
ICT Systems Administrator - Feltham City Learning Centre - £23,097 - £24,528 A full time ICT Systems Administrator to work in the Feltham City Learning Centre. This role requires a broad range of ICT skills ... more >
More job opportunities