alistair darling
R E L A T E D   C O N T E N T
ADVERTISEMENT

HMRC leak raises prospect of new data rules

Will the loss of two CD-roms make the government overhaul its security procedures?

Rosalie Marshall, IT Week 22 Nov 2007
ADVERTISEMENT

The HMRC data loss scandal could lead to an overhaul of UK security procedures, leaving IT directors facing the prospect of having to deal with new regulations that aim to guard against future privacy breaches.

The loss of two discs containing the confidential details of over 25 million child benefit recipients, including their bank and social security details, has been widely viewed as the worst breach to have occurred in the UK, and forced the resignation of HMRC chairman Paul Gray. Calls for tighter security controls across the public and private sectors have been heard from all corners in the wake of the incident.

“Searching questions need to be answered about systems, procedures and human error inside both HMRC and the National Audit Office,” said Information Commissioner Richard Thomas. He advised organisations to address security and data protection safeguards “with the utmost vigour” in light of the breach.

Alex Brown, a partner at international law firm Simmons & Simmons, said the incident will “turn the spotlight on the enforcement process” of the Data Protection Act, adding that the current process is too lenient. “The [Information Commissioner] will only hand out criminal sanctions if firms fail to comply with the enforcement notice. [But this is] too little, too late,” he said.

Ant Allan, an analyst at Gartner, agreed that punishment for not following security procedures needs to be made more severe, adding that fines carry less weight than custodial sentences when punishing organisations that fail to live up to industry standards.

Allan pointed out that many US states had introduced breach notification laws in response to these types of incidents. The HMRC data loss could lead to renewed calls for similar rules in the UK because there was a gap of about a month between the discs being lost and the public being informed.

But Allan said that any new legislation should lay out clear principles to guide organisations and be more limited in specific functions.

Efforts to raise awareness of data security risks and best practice could be a more useful response than introducing new legislation, Allan argued. He pointed out that when a full set of data is needed from HMRC, the usual practice is for an auditor to undertake the work – not a junior member of staff. “It shows that there is not enough corresponding awareness of policy in an organisation,” he added.

Jamie Cowper of PGP Corporation attributed the problem to the public sector focusing on securing their networks “to the utmost degree” with firewalls, but not considering the data.

See also:

The House of Lords is not happy with the government's response to its calls for more net security  01 Nov 2007
a padlockA major new industry initiative could ensure the quality and security of software  23 Oct 2007
GuardianEdge’s Alan Fudge says US-style data breach notification laws are heading this way  21 Sep 2007
Houses of parliamentRecommendations include the introduction of data security breach notification law in the UK  10 Aug 2007
Council admits accidentally exposing cardholder data  27 Jul 2007

All Privacy & Data

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
SQL Database Administrator - Aylesbury - £DOE Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the Grass Roots Group, which is ... more >
London, United Kingdom | City of London
ICT Project Officer - Guildhall, London EC2 18-month fixed-term contract Bring your project management expertise to one of the country's most prestigious institutions. The City of London is the local authority for the Square Mile, ... more >
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
Business Analyst - £35,000 - £50,000 + benefits - Aylesbury    Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the ... more >
Central London, United Kingdom | MI5 Security Services
Windows Technician - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to help us ... more >
More job opportunities