(1Â month ago)
Grand CommitteeMy Lords, in moving Amendment 17, I will also speak to Amendment 28, which is closely related. Amendment 17 is in part a probing amendment about what constitutes an incident and the circumstances in which reporting is obligatory. It does not affect the amendment that I think the Government will move immediately afterwards.
As drafted, Clause 15 gives the very strong impression that an incident “capable of having” an adverse effect on security must be reported. If this is the case, it constitutes a much wider definition of what should be reported than if it were described as an incident “likely to have” an adverse effect. I think it is a widely held view—it is certainly the case in the industry and a point with which I agree—that “likely to have” would be far too wide a definition and would lead to extensive overreporting and an undue and unnecessary burden on regulators. Looking at the drafting, I asked myself what was the point of the “capable of having” definition in Clause 15.
I shall put forward a hypothesis. It would be very helpful if the Minister could confirm that it is a correct understanding of the existing draft, and that it does not mean that all incidents capable of having an adverse effect on security will need to be reported. Is it right to say that the definition in Clause 15 of what constitutes an “incident” applies across the whole of the regulations, and therefore feeds into security as well as reporting duties? That is to say, firms have a preventive duty to defend against what could be and what could happen, as well as what is likely to happen. That is a preventive duty. Can the Minister confirm that the phrase “capable of having” means that firms should have adequate preventive policies, but it is not—this is where the point comes in—the trigger for an incident to be reported, because in each case this requires it to have affected or be affecting the system?
I am making a distinction between “capable of having”, which applies to a duty to pursue preventive policies, and the trigger of the duty to report, which lies not in the phrase “capable of having” but in “likely to have”. Then there are examples of what I am saying in the regulations, and I can cite them: Regulation 11(3)(a), on page 21 at line 35; Regulation 12A(2)(a), on page 26; and Regulation 14E(2)(a), on page 29 at line 27. If the Minister can confirm that, within existing structures, what I have said is correct—there are no circumstances in which “capable of having” would be the reporting trigger—that would be a very helpful clarification. I will listen closely to the Minister’s reply on this point.
There is a “however”: there is a snag when it comes to the introduction of data centres, and that is the object of my Amendment 28. Data centres sit outside the existing structures that I have just talked about but, as yet in the drafting, there are no reporting trigger regulations for them. It is intended that the data centres should be, in future, big players in the system, so it matters that there is a gap in our information about the circumstances in which they would have a duty to report. It is an odd anomaly. New Regulation 11A(3)—on page 23, from lines 13 and 14 onwards—makes reportable
“an incident which could have had … a significant”
effect, whether or not it had any impact at all or anything was affected. As there is no list of factors for judging what constitutes a significant attack in the Bill, it makes it quite difficult to interpret.
For the operators of essential digital services and managed service providers, such factors are set out expressly in the new regulations in the Bill. However, they are absent for data centres. Why is this the case? What is the rationale for what appears an anomaly? It means that, when reporting an incident, a data centre has to do so when any of the following have had, or were likely to have,
“a significant impact on the operation or security of the network and information systems relied on to provide the data centre service … a significant impact on the continuity of the data centre service … or … any other impact, in the United Kingdom or any part of it, which is significant”.
These are very wide definitions of liability to report, and the discrepancy between them and those applying to other operators seems neither sensible from a security point of view nor fair for different business circumstances, as there will be all sorts of different businesses using data centres.
Although I hope that this will not be the case, I fear that the Government may say that the thresholds and factors for all categories of business will be set out in secondary legislation and subject to consultation. I ask the Minister to think hard about the adequacy of that reply. We are talking here about a penalty-backed duty, which is the core element of the Bill; it is not some minor point. It would seem a poor legislative approach in a foundational Bill for a new regime to fail to define the factors leading to a penalty for a significant segment of providers, when there are indicators in the Bill for other categories of provider. Those other players have different, less demanding and more sensible terms for a trigger for reporting. If data centre regulations need to be different from those for the other players that I have mentioned and the rest of the market, can the Minister explain why? It is the kind of complexity that will give the sectoral approach to regulation a controversial reputation, because it immediately raises the issue of making different rules for people who are apparently, in practice, in the same category. I hope that is not the case and that the issue can be resolved by remedying the drafting.
To sum up, in addition to my request for a clear statement from the Minister about the trigger for a duty to report in existing structures being related to the likelihood of an adverse effect on security and not on capability, I hope she will also take seriously the need to level the playing field for data centres on this issue and remedy what seems an important defect in the drafting of the Bill. I beg to move.
My Lords, I will speak to this core group of amendments on incident reporting, in particular to Amendment 165, standing in my name, while addressing the other amendments in this group. First, Amendment 17, which was very cogently set out by the noble Baroness, Lady Neville-Jones, addresses what has emerged as one of the most contentious technical faultlines, in our view, across Part 2 of this Bill: the statutory threshold that triggers mandatory incident reporting to the designated competent authority, the NCSC. As the Bill is drafted, Clause 15 fundamentally widens the reporting net by redefining a reportable incident to include any event that is merely “capable of having” an adverse effect on the security of network and information systems, as the noble Baroness described.
While one can readily understand the cyber security community’s desire for complete visibility, in practice, the phrase “capable of having” is an operational disaster. In the daily reality of enterprise networking, thousands of automated port scans, routine phishing lures and perimeter firewall probes occur every hour. Almost every single one of these low-level events is technically capable of having an adverse effect, if multiple defensive layers were to fail simultaneously. By forcing businesses to notify regulators under threat of £17 million penalties whenever an event is merely “capable” of causing harm, the Government will unleash an administrative tsunami of defensive reporting.
Rather than enhancing national security, this compliance overload will drown NCSC analysts in background noise, making it far harder to detect sophisticated state-sponsored attacks. Amendment 17, in our view, would resolve this by replacing “capable of having” with the objective standard of “likely to have”. This would restore the established probability threshold used across UK regulatory frameworks, ensuring that mandatory notifications are reserved strictly for genuine material threats where there is a real likelihood of operational compromise.
This issue is compounded by the Government’s own drafting amendments, specifically Amendments 19, 36 and 44, which replicate the ultra-broad definition of compromise throughout parts 2 and 3. By removing “users” from Clause 15 and redefining data compromise to cover any event affecting data stored or processed on a system, the Government are dramatically expanding the notification net to include technical data anomalies that cause zero destruction or loss to actual customers. Combining this sweeping definition of data compromise with the low “capable of having” trigger will hugely affect responsible operators. It will force critical suppliers and small digital providers to spend their limited resources filling in compliance paperwork, rather than actively defending their infrastructure.
We risk creating a reporting system that captures everything and understands nothing. We must have objective reporting thresholds. By accepting the noble Baroness’s Amendment 17, restoring the “likely to have” test, we would ensure that mandatory reporting delivers high-quality actionable threat intelligence, rather than an unmanageable flood of routine notifications.
Under the new reporting regime, hundreds of incidents will be notified to regulators and the NCSC, but at present the Bill lacks any mechanism to ensure that aggregate intelligence is shared with Parliament or industry. Under Amendment 165 in my name, I propose that the Government lay an annual anonymised report before Parliament, detailing incident volumes, sector breakdowns and principal attack vectors. This would provide software developers and CNI operators with the situational awareness needed to harden defences.
(1Â year, 10Â months ago)
Grand CommitteeMy Lords, this is a fairly disparate group of amendments. I am speaking to Amendments 8, 9, 10, 24, 30, 31 and 32. In the first instance, Amendments 8, 9, 10 and 30 relate to the question that I asked at Second Reading: where is the ambition to use the Bill to encourage data sharing to support net zero?
The clean heat market mechanism, designed to create a market incentive to grow the number of heat pumps installed in existing premises each year, is set to be introduced after being delayed a year due to backlash from the boiler industry. If government departments and partners had access to sales data of heating appliances, there would be a more transparent and open process for setting effective and realistic targets.
I have been briefed by Ambient, a not-for-profit organisation in this field. It says that low visibility of high power-consuming assets makes it challenging to maintain grid stability in a clean-power world. Low visibility and influence over future installations of high power-consuming assets make it difficult to plan for grid updates. Inability to shift peak electricity demand leads to higher capacity requirements with associated time and cost implications. Giving the Government and associated bodies access to utility-flexible tariff data would enable the Government and utilities to work together to increase availability and uptake of tariffs, leading to lower peak electricity demand requirements.
Knowing which homes have the oldest and least efficient boilers, and giving public sector and partners access to the Gas Safe Register and CORGI data on boiler age at household level, would mean that they could identify and target households and regions, ensuring that available funds go to those most in need. Lack of clarity on future clean heating demand makes it challenging for the industry to scale and create jobs, and to assess workforce needs for growing electricity demand. Better demand forecasting through access to sales data on low-carbon heating appliances would signal when and where electrification was creating need for workforce expansion in grid management and upgrade, as well as identify regional demand for installers and technicians.
The provisions of Part 1 of the Bill contain powers for the Secretary of State to require the sharing of business data to customers and other people of specified description. It does not indicate, however, that persons of specified description could include actors such as government departments, public bodies such as NISO and GB Energy, and Ministers. An expanded list of suggested recipients could overcome this issue, as stated in Amendment 9 in my name. It makes no provision for the format of information sharing—hence, my Amendments 8 and 10.
In summary, my questions to the Minister are therefore on: whether it has been considered how the primary legislation outlined in the Bill could be exercised to accelerate progress towards clean power by 2030; whether climate missions such as clean power by 2030 or achieving net zero are purposes “of a public nature” in relation to the outline provisions for public bodies; and whether specifying the format of shared business data would enable more efficient and collaborative use of data for research and planning purposes.
Coming on to Amendments 24, 31 and 32, the Bill expands the potential use of smart data to additional public and private sector entities, but it lacks safeguards for sensitive information regularly used in court. It makes specific provision for legal privilege earlier in the Bill, but this is not extended in provisions relating to smart data. I very much hope that the Government will commit to consult with legal professions before extending smart data to courts.
Many of us support open banking, but open banking is being used, as designed, by landlords to keep watching tenant bank accounts for months after approving their tenancy. Open banking was set up to enhance inter- operability between finance providers, with the most obvious example being the recent new ability of the iPhone wallet app to display balances and recent transactions from various bank accounts.
Open banking approval normally lasts six months. While individual landlords may not choose this access, if given a free choice, the service industry providing the tenant-checking service to landlords is strongly incentivised to maximise such access, otherwise their competitors have a selling point. If open banking is to be added to the statute book, the Bill should mandate that the default time be reduced to no more than 24 hours in the first instance, and reconfirmed much more often. For most one-off approval processes, these access times may be as short as minutes and the regulations should account for that.
Coming on to Amendment 31, consumers have mixed feelings about the potential benefits to them of smart data schemes, as shown in polling such as that carried out a couple of years ago by Deltapoll with the CDEI, now the Responsible Technology Adoption Unit, as regards the perceived potential risks versus the benefits. Approximately one-quarter of respondents in each case were unsure about this trade-off. Perhaps unsurprisingly, individuals who said that they trusted banks and financial institutions or telecommunications providers were more likely to support open finance and open communications, and customers who had previous experience of switching services more frequently reported believing that the benefits of smart data outweighed the risks.
Is it therefore the Government’s expectation that people should be compelled to use these services? Open banking and imitators can do a great deal of good but can also give easy access to highly sensitive data for long periods. The new clause introduced by Amendment 31 would make it the same criminal offence to compel unnecessary access under these new provisions as it already is to compel data provision via subject access requests under the existing Data Protection Act.
Amendment 32 is a probing amendment as to the Government’s intentions regarding these new smart data provisions. In the Minister’s letter of 27 November, she said:
“The Government is working closely to identify areas where smart data schemes might be able to bring benefits. We want to build on the lessons learned from open banking and establish smart data schemes in other markets for goods and services.”
I very much hope that the Minister will be able to give us a little taste of what she thinks these powers are going to be used for, and in what sectors the Government believe that business can take advantage of these provisions.
My Lords, I support Amendment 7 introduced by my noble friend Lord Arbuthnot, for the reasons that he gave. The amendment was designed to have the effect of increasing the reliability and handling of information inside any system. If, as I would certainly support, we want to see information and data in digital form circulated more readily, more freely and more often, it is very important that people should trust the system within which it happens. That is where the need to assure the cybersecurity of the system becomes very important and is a companion note to this Bill.
(8Â years, 9Â months ago)
Lords ChamberMy Lords, I introduced the same amendment in Committee and do not intend to repeat what I said then. I am glad to say that, since I put down that amendment, there has been a very helpful meeting between DCMS officials, the Genetic Alliance UK and Unique. I very much hope that that meeting will form the basis of a solution on which we can build for Third Reading. I thank my noble friend the Minister for his personal contribution to the progress that we have made.
My understanding is that at that meeting it was accepted that an amendment would have to be brought forward to ensure the legality of the work of patient support groups. My understanding also is that the Government would prefer to do this by their own amendment, and I am certainly very happy to accept that. I also hope that it will be possible to agree such an amendment before Third Reading.
My noble friend has said that he is concerned about defining the scope of the amendment. I certainly accept that that is a legitimate issue. The family of patient support groups is quite large, but I accept that it is right to prevent any amendment becoming a loophole for evasion of the Bill’s provisions. I am conscious of that issue. However, the purpose of the amendment is not controversial and I am happy to look to finding words and drafting that will both safeguard the points that we want to make and provide the right scope for the amendment. It would be highly desirable to be able to deal with this matter in our House.
I hope and trust that my noble friend will be able to confirm that he shares my understanding of the point that we have now reached and that he will be able to give me an assurance at least of best endeavours to present a government amendment at Third Reading. I might say that Genetic Alliance and other patient support groups stand ready to help in any way that they can to meet this deadline.
My Lords, I will speak briefly to support the noble Baroness, Lady Neville-Jones, in her amendment. Clearly, this is of great importance to patient groups. I very much hope that the Minister will carry on the good work and come back at Third Reading with something substantive for the benefit of patient organisations that collect vital health information from their members, so that they will not be required to destroy or anonymise data. Without amendment, the Data Protection Bill has the potential to seriously damage the work of these patient support groups and hinder the work of certain public agencies, too, such as Public Health England and NICE—so I very much support the noble Baroness.