Gov't sets out to recover fees from PA
By Nick Heath
Published: 10 September 2008 15:45 GMT
The Home Office has dumped the firm that lost details of 84,000 prisoners last month and says it will push to recover its costs.
PA Consulting Group (PA) has become the first company to have a government contract terminated for losing public information after the August breach.
Now the Home Office says it will seek to recover costs associated with the termination of the three-year contract, worth £500,000 per year.
The firm was contracted to run the JTrack system, a database used by the Home Office and the police to keep track of offenders.
silicon.com's Full Disclosure campaign - what we are asking for...
silicon.com wants the government to review its data protection legislation and improve the reporting of information security breaches in the public and private sectors.
We are calling for greater public debate and for the government to consider legislation that would require organisations that suffer information security breaches to alert their customers if there is a chance the breach has put individuals' sensitive personal data at risk.
We want to hear your views about this campaign and the issues it raises. Make your voice heard by leaving a Reader Comment below or emailing us at editorial@silicon.com.
The information lost included names, convictions, prisoner ID codes and details of drug treatment programmes of 84,000 prisoners in England and Wales.
Home Secretary Jacqui Smith said in a statement to parliament that the loss of the memory stick containing the data, which went missing after being left in an unsecured place in PA's offices, was "a clear breach of the robust terms of the contract covering security and data handling".
She said: "Based on the findings of the inquiry, the Home Office have decided to terminate this contract.
"My officials are currently working with PA to take this work back in house without affecting the operation of JTrack or the PPO [prolific and other priority offenders] programme.
"Data transfers to PA for JTrack were suspended immediately following the incident, data handling has now been transferred to the Home Office, and the system is fully operational."
The management consultancy firm has been paid almost £100m over three years for its services by the Home Office and its agencies, with individual consultants from the company being charged to the department at an average of more than £1,000 per day.
Since 2004 the company had been contracted as a development partner for the government's national identity cards scheme - to help with design, feasibility testing, business and procurement elements of the project.
Smith continued: "We are reviewing our other contracts with PA, specifically from a data handling and security perspective."
Reporting the incident to the Information Commissioner the Home Office judged the risk from the data loss to be "low" but the government has commissioned a separate report into the incident and is reviewing the way it regulates data security among its contractors.
A spokeswoman for the Home Office said: "As the contract was terminated the Home Office is applying the right to recover the costs associated with the termination.
"This is estimated to be within the costs payable to PA to run JTrack, so it should be at least cost-neutral if not beneficial to the Home Office."
In a statement, a PA spokesman attributed the loss to "human failure".
He said: "A single employee was in breach of PA's well established information security processes."
He added the Home Office had confirmed that PA's information and security management were robust, with the "exception of this single incident".
how about dismissing any pl,ans they helped specif...
Karen Challinor - soon to be prisoner # 9995768143
Can we sack the home office now for all THEIR data...
Anonymous
On this basis can we terminate the HMRC contract f...
Iain Hepburn
Will a Home Office Director get sacked? There seem...
Charles Smith
You should have experience of some or all of the following: Client services, marketing campaigns, campaign documents/packs, delivery of work ...
Security Engineer - London, City - Cisco/Checkpoint/Watchguard/CISSP - 40k-50k We are urgently looking for a network (wired and wireless) engineer to ...
The role is specifically responsible for making sure that the company fully meets its contractual and service commitments to this new client across ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Nick Heath
Let's shine a light into the public sector IT money pit
With £16bn being spent, why is productivity still falling?
Tim Ferguson
BBC is taking tech seriously, so give it a break!
Auntie is the envy of the world but doesn't get the credit it deserves at home...
Peter Cochrane
Peter Cochrane's Blog: Open info for all?
Government stonewalling citizens
Nick Heath
Home Office CIO on taming tech and why ID cards are good news
Interview: Annette Vernon, Home Office CIO
Nick Heath
NHS records, Google and Microsoft: Where do you want your data?
Politicians: Heal thyself
Alan Hunt
NHS network: Time to get secure
Patient data in need of a check up