You are here: silicon.com > Public Sector > News

Reports in full: HMRC and MoD data breaches

News analysis: The damning findings and recommendations

Tags: full disclosure, data loss, mod

By Nick Heath

Published: 26 June 2008 17:28 GMT

Independent Police Complaints Commission (IPCC) report

The IPCC was looking into events leading up to the loss of data and considering whether any criminal conduct or disciplinary offences had been committed by HM Revenue & Customs (HMRC) staff.

The report's findings were:

  • Processes for data handling at HMRC's offices in Washington in Tyne and Wear were "woefully inadequate".
  • Individual members of staff were not to blame for losing the missing Child Benefit data CDs.
  • There were failures in institutional practices and procedures concerning the handling of data.
  • It identified an absence of a coherent strategy for mass data handling and "less than effective" practices and procedures.
  • A complete lack of any meaningful computer systems, a lack of understanding of the importance of data handling and a 'muddle through' ethos.
  • Staff prioritised getting the data to the National Audit Office over the appropriate security measures.
  • Staff found themselves working on a day-to-day basis without adequate support, training or guidance about how to handle sensitive personal data appropriately.
  • Staff lacked understanding of how to protect data at the highest level.
  • An HMRC internal review of data procedures at the time of the event, which could have prevented the data loss, was given a low priority.
  • No attempt was made to check on whether the data transfer in October had been authorised or the password or encryption protection of the data during transfer.
  • It says that many reforms have taken place at HMRC and are continuing as improvements are rolled out across the department.
  • It referred its findings to the information commissioner.
  • Reluctance by HMRC staff to trim down the full amount of data contributed to the loss.
  • It found no visible management of data security at any level.
  • There was a lack of appreciation of data protection principles in the act.

Recommendations:

  • HMRC should review the security controls and protocols associated with generating large volumes of data, and the subsequent handling of that data.
  • HMRC should develop a data security strategy, training strategy and communication strategy for all HMRC staff to raise awareness and understanding of data protection and data security.
  • HMRC should take steps to ensure it complies with the requirements of the Data Protection Act at all times.
  • HMRC should report any breaches of security promptly, something that did not occur in this case.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

silicon.com Public Sector
Get the latest public sector news straight to your inbox. Sign up for the PS newsletter today!


  • Jobs
Consumer Consultant

Ability to present elements of the overall project findings in client meetings.Develop high-level project expertise: Understand the reasoning behind ...

Complaints Handling Consultant

Complaints Handling Consultant, Public Sector, LondonOur Public Sector client requires a Complaints Handling Consultant to conduct a review of ...

Area Sales Manager- Air Conditioning / HVAC

Area Sales Manager / Sales Engineer - Air Conditioning / HVAC Looking to join a rapidly expansive company? The Candidate You must have several years ...

Nick Heath
Let's shine a light into the public sector IT money pit
With £16bn being spent, why is productivity still falling?

Tim Ferguson
BBC is taking tech seriously, so give it a break!
Auntie is the envy of the world but doesn't get the credit it deserves at home...

Peter Cochrane
Peter Cochrane's Blog: Open info for all?
Government stonewalling citizens

Nick Heath
Home Office CIO on taming tech and why ID cards are good news
Interview: Annette Vernon, Home Office CIO

Nick Heath
NHS records, Google and Microsoft: Where do you want your data?
Politicians: Heal thyself

Alan Hunt
NHS network: Time to get secure
Patient data in need of a check up

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.




Quick Sitemap Links: