Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts

Monday, September 29, 2008

Official charged over lost secrets

There is always a storm whenever data is lost and then all goes quiet as the issue is kicked in to the long grass of inquiries and internal reports. The suspicion is that these are just a cover up so that nobody is held to account.

It is therefore good to see that someone is being charged for a fairly serious loss of terror related data:

The Cabinet Office official who left top secret documents on a train in June is to be charged under the Official Secrets Act, the BBC has learned.

The individual was on secondment from the Ministry of Defence when he left two highly classified documents on a train to Waterloo
What really surprised me though was this response:

BBC defence correspondent Frank Gardner said the move came as a surprise to many in Whitehall.
Really? Someone subject to the Official Secrets Act (OSA) losses secret data and those in Whitehall are surprised. This must go to the heart of the attitude of the Civil Service to their duties and responsibilities. They seem to think that if us plebs make a mistake, lets say forgetting to declare all our income for tax purposes as a genuine oversight, then it OK for the full might of the state to come tumbling down on our heads. They also think its OK to send heavies round to a Director's house without warning to distress goods even when it was there mistake that got the tax bill wrong.

Yet they break the law and they are surprised! Why am I not surprised?

Lets be clear about this, people who work in sensitive areas are made fully aware of what the OSA entails. When I worked in some sensitive areas whilst in the Army the OSA was read out to us every 3 months, and it was made very clear that their would be no excuse for breaching it and the full force of the law would be applied if we did. Furthermore, I had to sign the OSA every year and also confirm in writing that I fully understood what I was signing and the consequences for breaching the Act.

If you don't want to be covered by the OSA all you have to do is say no and they will find you another posting.

So I have no sympathy for this person, they knew what their responsibilities were and by losing those documents broke the law. I hope they are punished severly, if found guilty, as a warning to others that we will not accept such lax behaviour with the security of the state.

And just in case you think those documents weren't important or that AQ isn't really a threat, that's not the point. The documents were covered under the OSA and should have been treated as such.

Let us not forget that these were "five eyes" secret ie information only to be shared between USA, Canada, Australia, New Zealand and ourselves. If the other countries lose confidence in our ability to keep this information secure then the source of a great deal of our intelligence could dry up.

Wednesday, November 21, 2007

Why the data was being sent to the NAO

I would like to thank my MP, David Liddington, for the very quick response this afternoon when I emailed him asking why the data was being sent to the NAO. He sent back the following from Hansard, within the hour:

I attach the Hansard report of today's question to the Prime Minister from Edward Leigh MP, Chairman of the Public Accounts Committee, to which the NAO reports.

Mr. Edward Leigh (Gainsborough) (Con): Is the Prime Minister aware that when the Department for Work and Pensions ran child benefit, it did a full audit on 20,000 names? When it was passed to the Inland Revenue, that was cut to 2,000 names, which is why the National Audit Office had to check its figures. Is he further aware that those protocols were agreed at a high level in March between the NAO and the Inland Revenue, and when the NAO asked for narrow details-not people's personal bank accounts-the Revenue said that to disaggregate that information would be too burdensome for the organisation? Those decisions were, therefore, taken at a high level. Is that not the image of a department that has had too much work loaded on it at the same time as it is cutting staff?

As you can see, the NAO has a duty to audit the payment of Child benefit, as any other benefit, but asked HMRC for a narrower range of information than they insisted on providing. During the exchanges following the Chancellor's statement yesterday, Mr Leigh said that the NAO had asked for a list of national insurance numbers so that they could create a sample on which to carry out the audit. The NAO's general practice is to examine a sample of benefit payment records for audit purposes. The NAO specifically asked for personal details, other than NI numbers, to be excluded.


I also heard on the radio that the underlying reason was that HMRC would have had to make a payment to their IT contractor.

Jesus, Mary and fucking Joseph, for the sake of a few fucking quid they send 25m personal records in the post. Presumably the NAO would have had to pay for the data to be extracted as well, so no saving to us, just some wankers' budget. For fucks sake, haven't they got a brain cell between them! And these were meant to be senior managers, it makes you wonder about the mental capabilities of the junior civil service.

If somebody cannot be tried for a wilful breach of the Data Protection Act then the wankers who drew up the act should be shot as well.

And to make it worse England have just conceded 2 goals while I type this!