UK data breach: stripping data 'would not have been costly'

Less than £50,000 would have paid for data stripping in HMRC disc fiasco

LONDON (12/06/2007) - It would have cost less than £50,000 (US$102,000) to strip confidential data from the records of 25 million people lost in transit between HM Revenue and Customs and the National Audit Office, HMRC's acting chair Dave Hartnett told MPs today.

Hartnett - acting up in place of Paul Gray, the former HMRC chair who resigned as the data loss scandal broke - made the admission to MPs on the Commons Treasury committee.

The acting HMRC chief also admitted that the child benefit data on the two CDs was the latest in a string of data security breaches, acknowledging that there had been seven breaches "of some significance" since the merger between Inland Revenue and HM Customs and Excise in April 2005.

The data held on the two CDs lost in Britain's biggest data security breach included bank details, NI numbers, and children's names, addresses and dates of birth.

Emails released by the National Audit Office last month confirmed that HMRC officials did not want to remove the sensitive information from the child benefit data sent to the NAO because this would cost extra.

Quizzed by the Treasury committee on the cost of desensitizing the information, Hartnett initially said: "I don't know the answer to that," noting that the "key issue is that the data should not have left our premises anyway".

But when pressed, he added: "I'd have thought it would be less than £50,000 but I haven't got the precise figure."

Registration is free, and gives you full access to our extensive white paper library, case studies & analysis, downloads & speciality areas, and more.

Hartnett later told the MPs that HMRC had subsequently established how easy it was to ensure data management contractor EDS stripped out the confidential details when it passed information to U.K. payments association Apacs as part of measures to protect bank accounts in the wake of the data loss scandal.

"When we needed to pass data to Apacs... we were able to segregate the data in the way you [the committee member] describe with our IT supplier -- and quickly -- and it is therefore a matter of huge regret that we did not do that before," he said.

In a statement that suggests HMRC believes the NAO is partly to blame for the data loss, Hartnett added: "But I think the important issue is that those who asked for and provided that data had stepped outside the procedures we had established."

Hartnett said he did not know how much the filtering of data for despatch to Apacs would have cost, but said no-one had alerted him that it was going to be a significant amount.



Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

Creating an AUP: Common myths & mistakes

Avoid the common myths & mistakes when implementing your AUP

Unleashing the power of virtualisation 2010

Find out more about cloud computing in European enterprises.

Email archiving: Top 10 myths and challenges

This survey looks at a number of challenges and myths around email archiving that may also slow adoption of full archiving.

Modernising IT: Strategies for improving service quality and reducing IT costs

No matter how many people you allocate, sinking more labour into old IT practices cannot concurrently meet rising demands on IT and cut costs. Read about cost-effective, automated ways to meet this challenge head-on.


CIO UK - Business - Technology - Leadership

Differentiate your company with complete CRM

Focused on productivity and empowerment and leveraging the natural rhythms people work
What defines Complete CRM? How businesses can better engage customers and users, manage customer transactions, and analyse results to adapt and take advantage of changing business and economic circumstances.

DOWNLOAD

Oracle White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One.

CIO are running a short survey to discover how UK businesses are managing internet and email misuse in the Enterprise.

COMPLETE SURVEY

Virtualisation 2.0
Driving to higher ground beyond the basics

Virtualisation can deliver unparalleled efficiency and cost reductions to your business, allowing direct access to servers and guaranteeing a dependable, rapid response in times of crisis. Read this e-book to learn more about consolidation, discover the latest technologies and find out how to reduce the TCO of virtualisation.

DOWNLOAD

Trend Micro



* *