8 Viscount Camrose debates involving the Department for Digital, Culture, Media & Sport

Wed 12th Jul 2023
Thu 22nd Jun 2023
Online Safety Bill
Lords Chamber

Committee stage: Part 2
Thu 25th May 2023
Online Safety Bill
Lords Chamber

Committee stage: Part 2
Tue 16th May 2023
Online Safety Bill
Lords Chamber

Committee stage: Part 1
Wed 1st Feb 2023
Regarding Amendment 172 and calls for a single reporting portal, industry does not need another 12-month review. The answer was already on the amendment paper under Amendment 88 from the noble Lord, Lord Birt, which we discussed on Tuesday, establishing an office for cyber resilience as the single national threat-reporting hub, which sadly did not receive the approval of the Conservative Front Bench or, indeed, the government Front Bench.
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I start by thanking my noble friend Lady Neville-Jones for introducing this group and setting out her stall so clearly and compellingly. I apologise that some of the amendments that have been looked at here I had in my record as being part of the next group. So, if I do not cover them all now, they will be covered by my noble friend Lord Markham as we get into the next group.

Let me begin by outlining the amendments in my name and those of my noble friends Lord Markham and Lord Holmes of Richmond. The need for action on ransomware has never been higher. The NCSC handled 204 nationally significant ransomware attacks in the year to September 2025 that we know about—up by 130% on the year prior, leading the NCSC to name ransomware as the most pressing threat to the country in its annual report. Of course, one of the challenges we face with ransomware attacks is not knowing when they happen, to whom and how often. The victims too often have strong reasons, generally associated with legal liability, not to report them. This makes it challenging, if not impossible, for any government agency seeking to identify commonalities across attacks to pursue repeat offenders and warn vulnerable organisations.

We could seek to make reporting of such attacks mandatory, but at the risk of placing hacked organisations in an impossible position where public reporting creates a legal bind that worsens the damage already done by the attack. I take on board the cogent concerns expressed by the noble Lord, Lord Clement-Jones, but the moral hazard occurs today where companies do not report ransomware attacks, thereby damaging our collective ability to defend others yet to be attacked.

Our amendment therefore seeks to find a channel that reports the facts of the hack and the metadata around it in a way that is not disclosed beyond the agency charged with cyber protection and does not become public knowledge. I do not pretend that this will be straightforward. For instance, we would have to understand how to deal with FoI requests and so on. That is why we propose a consultation. But if we were able to achieve something on this basis, we would greatly enhance our ability to protect UK PLCs from these hugely damaging attacks.

Amendment 172 seeks to require a review on the impact of the new reporting requirements introduced by the Bill. Again, this is fairly straightforward. The strengthened incident reporting requirements are being introduced to allow the regulators and the Government to help with providers and suppliers who have been attacked. Whether these requirements actually serve that purpose, and whether they do so at the expense of providers, cannot yet be known, but we must be able to form an assessment and adjust if necessary. Everyone in this Room would accept that we need statutory agility in the face of fast-moving technology, and a review on these lines could and would enable just that.

For a similar reason, I support the desire for transparency in Amendment 165 in the name of the noble Lord, Lord Clement-Jones. This may even overlap with our own amendment; we could probably think about merging the two in some way. It seems clear that both Houses of Parliament should be informed as to what the reporting regime is being used for and whether it is fulfilling its function. I hope that the Minister agrees.

I very much support Amendment 17 in the name of my noble friend Lady Neville-Jones. We are going from an incident constituting an actual adverse event on the security of network and information systems to it being capable of having such an effect. Arguably—the noble Lord, Lord Clement-Jones, made this point very well—almost any incident would meet this condition. We need language that expresses genuine risk to avoid all incidents being caught in the net. This seems wholly pragmatic to me and I commend it to the Minister, to whose response I look forward.

Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments in this group; in fact, subsequent groups also speak to this question of the nature, scope and timeliness of incident reporting. What we are all trying to do, I think, is to get the right balance in reporting actionable information that can be used by regulators and the NCSC to improve the security of the United Kingdom and the entities that operate essential services within it. That is obviously what the Government have put forward. I have heard clearly the arguments made by noble Lords, some of which probe the intention and the detail, and I will attempt to clarify those as I speak.

First, I shall speak to Amendments 19, 36 and 44 in my name. Improving incident reporting under the NIS framework is a key pillar of the Bill. Without an understanding of incidents, our regulators and the NCSC cannot assist in recovery, assess risk and bolster resilience. The amendments that I have tabled will ensure that the incident reporting measures for regulated entities reflect what we are trying to achieve.

The Bill already requires relevant regulated entities to consider a list of factors when determining whether an incident is likely to have a significant impact and be reportable. This includes whether data relating to users is, or is likely to be, compromised. Government Amendments 19, 36 and 44 remove the reference to “users”, meaning that all data compromises relating to the relevant network and information system are in scope of incident reporting. This will enable key incidents to be reported, including the compromise of commercially sensitive information or the exposure of access details or usernames of the regulated service.

These incidents will need to be reported to the NCSC and the relevant regulator. I say in response to the noble Lord, Lord Clement-Jones, that that is the motivation behind the change to that categorisation. This will ensure that the regulators have full oversight of significant security compromises, supporting them to keep the UK safe and secure. We will shortly consult on what constitutes a significant impact and put further detail in secondary legislation and guidance.

I turn now to the amendments tabled by—

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I, too, support these customer notification amendments tabled by the noble Baroness, Lady Harding of Winscombe. As I have said, the noble Baroness brings vital lived experience, in more ways than I thought, from the front line of corporate crisis response. When a major cyber breach occurs, vague statutory requirements to notify customers

“as soon as reasonably practicable”

lead to corporate delay. Amendment 58 would replace this with a strict statutory 24-hour notification clock, while Amendment 65 would establish explicit harm triggers and require providers to provide actionable remediation advice to affected customers. Look at what Amendments 60 and 65, in particular, would achieve across Clause 16.

Under Amendment 65, notification would be explicitly triggered whenever an incident causes or threatens severe operational disruption, substantial financial loss or material harm to downstream users. Furthermore, Amendment 71 would place a positive duty on the provider to advise customers on immediate remediation steps that they can take. In the cyber realm, time is the attacker’s greatest ally. If a hospital, bank or small supplier is informed within 24 hours that their cloud or managed service provider has been breached and given technical instructions on how to isolate their systems, they can prevent contagion before it paralyses their operations. We must ensure that customer notification is prompt and meaningful, empowering downstream businesses to isolate compromised systems before contagion spreads, so we very strongly support these amendments.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I, too, thank my noble friend Lady Harding of Winscombe for tabling this important set of amendments, which we welcome, and for clarifying the refinements of the grouping process, which had slightly eluded me up to that point. As with the previous group, this would amend four key areas of, on this occasion, customer reporting. It would tighten the timing to notify customers; widen the incidents expected to be reported by removing the adverse impact criterion; add extra reporting triggers; and add an “advice on remedies” duty.

Of course, businesses should be supported in the case of cyber attacks and our priority must be preventing, containing and controlling such incidents, but this cannot come at the expense of the customers that businesses serve and depend on. Customers deserve to know when a firm they depend on is targeted, even if such an attack does not necessarily directly adversely affect them. They deserve to be informed promptly and they deserve to be informed of potential remedies.

It is worth saying that there is a welcome side effect to doing so, based on the premise that behaviours are the best guard against cyber attack. Constantly being aware that cyber attacks are going on will improve behaviours. As was said earlier, the goal is not to create panic but, on a continuum between insouciance and panic, we must imbue a point closer to concern more widely in the population to keep people aware that we are constantly at risk of being hacked. On these Benches we feel these are wise, pragmatic and helpful changes. I certainly hope the Minister agrees.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Baroness for raising important points around customer communication. As set out in the Bill, it takes forward the current duties to notify customers that the Bill places on data centres, OESs, RDSPs and RMSPs. That duty was designed to ensure that providers of key digital and data infrastructure services consider whether their customers are likely to have been adversely affected by a reported incident—whether through disruption of service, compromise of their data or exposure of their systems to cyber threats—and to notify them.

I will explain the logic in response to the point of the noble Lord, Lord Clement-Jones, about the importance of meaningful communication with customers. The reason we have drafted the Bill so that customer notification follows the 72-hour incident report is to ensure that regulated entities can focus on understanding the nature of the incident and contact customers when they are more likely to understand its potential impacts.

We have discussed the question of what an organisation might reasonably be expected to know within 24 hours of identifying an incident. The point is that customers should be communicated with in a timely manner, with sufficient information, so that they can take the necessary action. On that point, the rationale for 72 hours was to time it, for simplicity, with the 72-hour report. I am happy to consult further with the noble Baroness to explain the logic of the 72-hour and 42-hour requirement to communicate with customers, because the motivation is exactly the same: to have actionable and meaningful communication with customers.

I turn to the degree of depth of communication, the advice that can reasonably be put on regulated entities on technical measures, and what technical mitigations customers should take on their own. It is reasonable that the regulated entity should share what they know about the nature of the incident. The question about whether the regulated entity is in the right position to provide advice to customers on what mitigations they should take is both practical and technical. Would they have enough insight to have an effective understanding of the situation of the customers and a detailed understanding of the customers and their businesses in order to give effective meaningful advice in that way—or would that just be a requirement on the entities that would not have the intended impact? On that point, I am not quite persuaded that the line is drawn in the right position.

On keeping in touch, mentioned by the noble Baronesses, Lady Kidron and Lady Harding, I am happy to come back to that on Report to make sure that we have the right balance between the initial notification and the right type of customer communication.

--- Later in debate ---
I think we have had an extremely comprehensive and useful debate today, drawing on the considerable experience of all of us on boards. These two amendments are entirely practical and desirable, and I very much hope that the Minister will accept both of them.
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I thank the noble Baroness, Lady Kidron, for opening this debate on behalf of my noble friend Lady Morgan of Cotes. I will come to her amendment in a moment, after I touch on Amendment 167, tabled by the noble Baroness, Lady Ludford. Her comments, particularly about board ownership of cyber risk, were well founded and an extremely important foundation for the debate—as indeed were those of the noble Baroness, Lady Berger, who pointed out the difficulty of accelerating from zero cyber knowledge to sufficient. That is a non-trivial undertaking.

Amendment 167 is absolutely in line with the principle that we raised on the first day of this Committee in the form of Amendment 92B. It is the idea that executives should be held accountable for cyber security and resilience plans by their board and their shareholders, by reporting consistently on protections. This amendment, perhaps a little more explicitly, would require the same thing and I am very happy to support it.

I think Amendment 74 largely follows the same sentiment: that companies should and must be held accountable for their own cyber security. On this one, however, I need a little more persuasion. I am going to tread a little tentatively here, because I very much take on board the comments of my noble friend Lord Arbuthnot that we have not solved this problem yet and that carrying on as we are is probably not that sensible.

However, I do have some inner alarm bells ringing about this one. So, while we support the goal of making companies self-sufficient and accountable to their shareholders, this amendment would give the Information Commissioner powers to enforce compliance and sanction individual negligence. The concern here is that, as a matter of principle, the inner working of companies—who is accountable internally, to whom and for what—should be placed in a different category from the requirements placed upon them.

We should encourage companies to figure out internal issues themselves. By all means require board oversight of cybersecurity plans, as we have attempted to do, but my understanding is that this amendment would make it the Information Commissioner’s job to decide which individual is responsible when cyber attacks take place and are not adequately defended. I find this quite a tricky path forward, but I am clearly willing to keep talking and to be persuaded.

I am also concerned about the disincentives to become a director that this might put in place, because of what feels to me like the inherent uncertainties of the liabilities that may hang over board directors as they undertake these responsibilities. That being said, I, of course, completely agree with the underlying principle and look forward to hearing the Minister’s response.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Baronesses who introduced their amendments, including the noble Baroness, Lady Kidron, who did so on behalf of the noble Baroness, Lady Morgan, for raising the incredibly important topic of board accountability and senior management oversight. It is absolutely right that organisations, especially those delivering our essential services, are held properly accountable for their activities. That is why the Bill creates a more meaningful enforcement regime in terms of the maximum fines that can be levied—up to £17 million or 4% of turnover, whichever is higher—alongside a simpler process for taking that forward.

I also agree with the points made by the noble Baronesses, Lady Ludford and Lady Neville-Jones, and by my noble friend Lady Berger, on the extent of this being within the regulatory perimeter as well as the non-regulatory perimeter. Boards upskilling themselves and taking training seriously is absolutely imperative. That is why we have our Cyber Governance Code of Practice, which is at the heart of our approach to board and executive accountability. I personally feel that I am an extremely active proponent of this. For those who feel that we are not doing enough, I request their support in continuing to highlight that important code of practice in their own organisations, and on all the numerous boards they sit on, to make sure that we are governing cyber risk appropriately—and that many of the board directors they sit alongside are aware of it.

That is obviously not the limit of the approach that we are taking. We are going to introduce new security and resilience requirements in our secondary legislation. Our proposals will include a dedicated requirement on board-level governance, which will be consistent with the NCSC’s cyber assessment framework. It will cover issues such as organisational capability, senior responsibility, accountability for security and resilience, and effective risk escalation. In that way, we will connect the clarity on what is expected of boards with accountability through the enforcement regime.

I will touch on the point alluded to by the noble Lord, Lord Clement-Jones, on the EU’s regime. Individual liability for board-level members is not mandatory under NIS2. Different EU member states have taken different approaches to implementing the directive in this respect, so there is not a single model of implementation that the EU is following.

To conclude, I would also concur with the point that the noble Viscount, Lord Camrose, made on the importance of attracting those with cyber expertise to take on board-level roles and be able to contribute as part of the board accountable to shareholders in that way. We do not want to introduce anything that might disincentivise either senior executives with cyber expertise or those at board level from taking these very important roles.

I believe that, together with the enforcement regime and the security and resilience requirements, those two things will cement the importance of board and executive accountability firmly into the regime, in the way that noble Lords have highlighted today. That is the right approach.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

It is not the same. I wish to stress that the importance of strengthening cyber resilience can happen outside of legislation being put in place. There are many efforts that can go on to improve cyber resilience.

Moving on to the amendment of the noble Baroness, Lady Ludford, and her question about the scope, as well as the questions of the noble Lord, Lord Russell of Liverpool, about CRMs and so on, I do not know the specifics of this CRM. I am very happy to write after hearing of the attributes that were enumerated for its characteristics. Businesses that offer software as a service are in scope of the NIS regulations as cloud computing services, under the RDSP definition, if they meet the definitions in the Bill. In the case of the particular company that was mentioned, I do not know whether that would meet any definitions in the Bill.

Data protection legislation is obviously in place already, and processors are meant to have the systems in place for regularly testing, assessing and evaluating the effectiveness of their measures for ensuring the security of that processing. That legislation is already in place.

Moving on to the public sector, I will respond to the questions from the noble Lords, Lord Birt and Lord Clement-Jones. The Government are already taking equivalent steps to secure their own essential activities through the Government Cyber Action Plan, published in January this year. That plan applies to government departments, arm’s-length bodies and wider public sector organisations. It sets out clear expectations, targets and milestones at all levels to transform cyber security and resilience in the public sector. The outcomes of the plan are aligned with those of the Bill; there will be a consistent approach to strengthening cyber resilience across the public sector. Government departments are accountable for setting expectations and overseeing resilience across the sectors and organisations within their purview, while individual organisations remain responsible for managing their own cyber security and resilience.

This brings me on to Amendment 81A—

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

I thank the Minister for her point about the Government Cyber Action Plan, but do the strength of her arguments there not completely reinforce the urgent need to have the national cyber action plan, so that we can assess overall the cyber strategy of the nation and the role of the Bill within that strategy?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The cyber action plan is a very thorough document. It sets out a plan over many years to improve the cyber resilience of the Government and the public sector, which I think we all agree is absolutely needed. The fact that incidents are still occurring in the public sector reinforces the need to act. We will publish the cyber action plan and, as I mentioned two days ago, I will keep the Committee and the House updated on progress on that.

Education is an incredibly important sector, and the Department for Education takes an active approach to supporting the sector. This includes the Cyber Security Hub, providing schools in England with guidance, while the standards for schools and colleges help institutions to understand their cyber security requirements. Colleges have been required to meet cyber essentials since 2024, with more than 80% of colleges now meeting this requirement.

I come to the question of MHCLG and local government. The department is also taking meaningful steps and working with local authorities to increase their cyber defences. This includes the rollout of the cyber assessment framework for local government, which would be the equivalent to what is required in the cyber Bill, and the recently proposed revisions to the best value statutory guidance to set new expectations for local authorities on cyber resilience. That best-value duty provides an immediate and proportionate route to improving through existing governance and accountability mechanisms. In addition, MHCLG is supporting councils directly.

The question of electoral infrastructure and political parties, raised in Amendments 79 and 81D, is also incredibly important, as noble Lords have set out. The Government work with the NCSC to mitigate risks there. MHCLG specifically works with local authorities to strengthen their electoral cyber resilience and ensure electoral data is adequately protected. The Joint Election Security and Preparedness Unit has responsibility for co-ordinating election security. The MHCLG digital electoral services team maintains robust incident response arrangements to protect electoral systems and citizen data. As the noble Baroness, Lady Ludford, mentioned, the NCSC also has a broad package of support for political parties, candidates and elected representatives. This includes regular engagement with parties, which can access the NCSC’s active cyber defence services, as well as NCSC providing tailored advice to parties and candidates.

I have set all that out because the motivation behind bringing these matters into scope is to engender further action. I want to emphasise that further action is happening, whether or not it is within the scope of the regulatory perimeter.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

My Lords, if I may, I will reiterate points that the noble Lord, Lord Birt, has made. A number of us are struggling to keep up. Much of what the noble Lord, Lord Clement-Jones, said made a lot of sense, but I certainly do not feel sufficiently sighted on the amendments and I would like to request from the Minister a proper briefing as soon as we possibly can. We have multiple days in Committee and I feel that we will keep going round the issue of how AI is being addressed in the Bill. At the core, we are all trying to stand on both sides of the fence: we are very nervous of these powers, which appear to have been snuck in without much scrutiny, but, on the other hand, at Second Reading many of us were clear that we want to see AI captured in the Bill. I am very much in two minds and would welcome a proper briefing from the experts.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I thank the noble Baroness the Minister for introducing this debate and for her helpful advance briefings on these amendments. I also welcome all noble Lords back for what, I am sure, will be a productive Committee stage. It is worth noting at the start of Committee that, sadly, our cyber adversaries did not take the summer off. In July, a small power generator was attacked and, in August, an attack on Manchester Airports Group compromised the data of 8.7 million of its customers.

That said, I begin by saying that we on these Benches support the intention behind the Government’s amendments. I absolutely recognise the concerns expressed by all the other speakers thus far; procedurally, this is a very unusual way to go about it, but we support the intention. We have been calling for an increase in the scope of the Bill and for cyber security measures to be undertaken by businesses and individuals, rather than the Government, where possible. We feel that these new amendments go some way to achieving that.

However, while we support the intentions, the context around them remains challenging. The difficulty that we face when trying to scrutinise and improve this Bill—and I am sure that we will return to this—is that it essentially exists, at least for now, in a vacuum. The Government’s goals are the right ones and their intentions seem to be clear, but we lack the overall holistic framework that is so important for systemic, strategic approaches to cyber security. Perhaps when the Minister stands up she can provide an update on the publication date of the national cyber action plan because, as I said at Second Reading, a cyber Bill can stand or fall only in the context of an overall cyber defence strategy, and we need to see it.

Most evident is that this currently seems to be a Bill without a department. The amendments delegating and separating powers between the Secretary of State and the Chancellor of the Duchy of Lancaster reflect this. I am really concerned—I would appreciate some reassurance from the Minister on this—that the decision to scrap DSIT, the Department for Science, Innovation and Technology, has left this Bill in limbo. A minimum of 30 teams are being split across at least three departments, and this seriously important Bill, which we are all counting on to protect us from enemies known and unknown, is adrift between departments. At the very least, the Government should set out as soon as possible who will have lead responsibility when this Bill is passed.

I thank the Minister for her clarifying remarks on the referral schemes that her amendments introduce. As I have noted, we support the attempt to expand the scope of this Bill and give businesses the ability to be self-sufficient. That support extends to the establishment of a voluntary referral scheme. However, this new voluntary scheme needs to have a clear and accessible framework and a timeline for implementation. If it is to act as an extra layer of security outside the Government’s immediate remit, vendors must know what they are expected to report and the mechanisms for doing so. There is little use setting it up if these are not made explicit at the earliest opportunity. The consultation is welcome, but some idea as to the form the Government intend this scheme to take would be helpful, alongside an indication on timing. I hope the Minister can give more clarity in her closing remarks. If not, I hope she will be able to write to me and all Members of this Committee.

I was originally going to make the point that the mandatory referral of a vendor outside current NIS regulations will necessarily be ad hoc and that, as such, defining “qualifying transactions” would not be proper. Instead, Amendment 153 was an attempt to provide clarity for decision-making without inhibiting the Government’s ability to act. However, given that the Minister said in opening that the Government have no intention of setting up a mandatory referral scheme, we must question why they feel the need to give themselves the powers to do so. Powers should not be granted and come into existence if they are never to be used. At the very least, given that the Minister has now said that the Government would consult on the definition of a qualifying transaction before any scheme is established, the amendment should ensure as much. The Government will now have the opportunity to bring these amendments back on Report. The mandatory referral scheme should be redrafted to reflect the Minister’s statement and be conditional on the defining of qualifying transactions. I hope the Minister will agree to this.

Finally, let me make a general point about the definitions used in these amendments and throughout the Bill. The proposed criterion of being “essential to the economy” is unworkably vague. It is not an adequate representation of the different types and scales of risks. I suggest, for example, the Cyber Monitoring Centre’s five-level severity scale as a model more reflective of the grades of threats facing the United Kingdom. I am not arguing that it is necessarily the right model, but it is at least tested and quantifiable. I look forward to the Minister’s response.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their comments, views and questions, and I will endeavour to respond to them.

In respect of why the power is being granted to the Secretary of State or the Chancellor of the Duchy of Lancaster, it is to anticipate any unforeseen machinery of government changes. It is nothing more than that—to avoid future changes that would be needed when government departments change. On the skilled persons list, I am advised that that is currently available on the NCSC website, so it is accessible to all.

I come back to the heart of the questions: why is this power needed? It is needed because, even though we are taking powers on critical suppliers, it can be the case that vendors have the capability and intent to cause harm, particularly where they have a link to a third country. That is the element I would highlight today. It is through such vendors that a third country can gain access to or control of critical systems, enabling disruption to UK national infrastructure, surveillance through access to data at scale or espionage through access to sensitive information. The risk landscape is evolving quickly, which is why we are taking action now. On the questions posed by the noble Viscount, Lord Camrose, this is very much in the context of all the other things we are doing—all the other powers in the Bill, the scope of the Bill and the Government’s cyber action plan. This is an additional power focused in particular on being able to act earlier in a preventive manner.

On the definition of “qualifying transactions”, the amendment contains a power to create a statutory referral system. This system would need to state which procurements or transactions were in its scope, but, as the noble Viscount mentioned, we do not anticipate needing to do that now. The process of the Bill is such that we will enact both the mechanisms in the Bill and the voluntary referral mechanism. We will then be able, in the period of assessing the effectiveness of the Bill, to look at the effectiveness of the voluntary referral route. Should we need to introduce a mandatory route—obviously, we have done this in different areas of national security—we will be able to do so.

On scrutiny by Parliament, I appreciate that the fact that we tabled these amendments over the summer has meant that not everybody has been able to familiarise themselves with them and we have not been able to have as many in-depth discussions as we would normally when Parliament is sitting. I would be extremely happy to meet noble Lords with officials so that, after Committee, we can go through all the questions and points of detail that have been raised in this session on how these powers will be enacted, parliamentary scrutiny, the consultation process and all the elements that we have set out in our amendments.

A few noble Lords focused on AI. The power could be extended to high-risk AI models that are procured by operators of essential services. The test for using the vendor power direction does not specify or distinguish particular types of goods or services, in keeping with the technology-agnostic approach of the Bill. If an operator of an essential service were using a vendor-supplied AI model in connection with its network and information services, and this would give rise to a national security risk, it could be in scope of the power. That is very much in keeping with what I believe I said at Second Reading about other areas of connection with network and information services in the rest of the Bill and where that may apply to AI.

With that, I beg leave to withdraw—

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

Before the Minister sits down, I note that there are a lot of “just in case” elements of the Bill; to me, it feels that there are rather too many. For example, I refer the Minister back to the Chancellor of the Duchy of Lancaster v the Secretary of State. Any department is, at any time, subject to machinery of government changes, but never in any Bill that I have seen—admittedly, I have not seen that many—have both been specified, so why is it so in this Bill? Why do this now? Why not simply make a choice and amend later if necessary?

--- Later in debate ---
I urge your Lordships to support all these future-proofed AI protections and to reject the idea that we will be adequately protected under this Bill with a technology-neutral approach. We need to accept that, as the noble Lord, Lord Tarassenko, and many others, including the noble Baroness, Lady Harding, and the noble Lord, Lord Holmes, have shown us, there is a huge AI-shaped hole in this Bill.
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I shall begin with Amendment 12 in the names of the noble Lord, Lord Tarassenko, and the noble Baroness, Lady Kidron. I completely understand the necessity and urgency of taking action on these things. The noble Lord, Lord Tarassenko, set out the absolute urgency and the growing weight of the problem that we need to solve here. I have my doubts—I am delighted to carry on talking about this—about the significant expansion of and change in the role of AISI to take on these additional responsibilities. Those are practical doubts; I am certainly not disputing the desirability of fixing this problem.

Equally, we have to think practically about how this works alongside the Information Commissioner’s Office and the relative role of each. I thought my noble friend Lord Holmes set it out very well. We are going to need to look carefully at who regulates what—we are going to come to this in the next group—but we need to do so with quite a bit more information about their resources and goals and how we see each regulator taking this forward. I am afraid that there is a very much larger discussion that we will have to take forward on this matter.

Although I understand the desire to maximise the use of AISI in giving it these statutory functions via Amendment 85, we on these Benches are hesitant about consolidating powers in a separate non-governmental body. No matter how effective that body continues to prove to be in its original and existing role, taking power outside Parliament may not be the most effective way to ensure rigour and accountability. The Secretary of State should of course have regard to what AISI says and closely monitor its output, but I am concerned—although willing to be convinced on this—that placing it on a statutory footing risks diverting responsibility away from the Secretary of State. We hold the same position on Amendment 92. Giving AISI standard-setting, inspection and enforcement powers risks creating an unaccountable body with a greatly increased remit out of what is currently a vital and successful research body. I feel that that risk is too great for both sides.

Instead, we would rather see powers vested in the hands of accountable public figures. It is for this reason that we support the principle behind Amendment 84 in the name of the noble Lord, Lord Clement-Jones, which would provide the Secretary of State with the power to shut down AI systems during large-scale emergencies. It would also provide a necessary stopgap in the hands of an accountable Secretary of State while requiring Parliament to be informed of the decision taken. Additionally and importantly, it would not inhibit the growth of safe and responsible AI across the AI sector, which could be an additional worry with the pre-deployment checks in Amendment 85.

Amendment 75 tabled by the noble Baroness, Lady Kidron, would introduce red lines for relevant AI digital services. I confess that I was very impressed when I read the red lines because I thought that she had written them herself, but she gave away—perhaps foolishly—that they came from the brilliant Stuart Russell. Needless to say, the list is entirely sound, at least for today. We agree that AI services should not partake in actions that threaten the safety of individuals, businesses or nations, but our hesitation arises from the fact that, while their logic is clear, the red lines themselves are necessarily speculative at a moment in time, however eminent and wise their creator.

Further, AI models would have to demonstrate that they cannot perform the capabilities listed, so they would essentially be asked to prove a negative. Aside from the fact that this would place an administrative burden on the providers, as we all know, AI models develop in ways that are nearly impossible to predict and quantify. I am unclear how frontier labs would be able to engineer their models so that, for example, they would demonstrably not self-improve so as to pose

“a risk to the authenticity and integrity of the processed data”.

Similarly, I am unsure how the regulators will be expected to quantify these capabilities because, to a large extent, they are a function of not just ability but degree. In theory, the requirement not to support the development of chemical weapons might be violated by a model that simply gives basic chemistry lessons. Would that model be banned or would it be forced not to answer questions about chemistry? I do not want to trivialise this matter by giving too simple an example, but I am trying to convey just how difficult it will be to design the precise scope and extent of the necessary regulations. I worry that they currently seem arbitrary. They would be onerous on firms and regulators and slow down safe and responsible growth where it exists in our domestic AI industry.

I would suggest a different or additional approach, principles based rather than capabilities based. Ensuring, for example, that labs and associated businesses are focused on integrity, prevention, human control, threat minimisation and transparency, rather than attempting to regulate specific examples of AI malpractice, could prove more effective at serving the dual goal of AI growth and AI safety. As I have argued many times, I am afraid, in other Bills and debates, the only way legislation can keep ahead of technology is to pursue principles over rules about specific features.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I first congratulate the noble Lord, Lord Birt, on what is a really comprehensive vision expressed in this group of amendments. I speak in strong support of those amendments, on which both he and the noble Lord, Lord Londesborough, have spoken so cogently. Together, they address one of the most glaring defects of the architecture of this Bill: the fragmented, inefficient model of 12 separate sectoral regulators. I think that the noble Baroness, Lady Neville-Jones, asked the right questions about how to co-ordinate and how to be fair, but I am afraid I come to very different answers and to the same conclusion as the noble Lord, Lord Birt. Cyber threats are sector-agnostic. Malicious code and supply chain exploits do not respect the boundary between Ofwat, Ofgem or the CAA. Expecting 12 separate bodies to recruit scarce elite cyber forensic talent is a fantasy that results in weak, uneven enforcement.

Furthermore, multi-sector businesses face duplicative compliance obligations across separate competent authorities in the current scheme. Under Amendments 7, 9 and 11, the noble Lord, Lord Birt, would correctly widen the definition of digital service providers to include the creators, distributors and managers of software and digital platforms. As the Synnovis pathology attack proved so catastrophically to London hospitals, our critical infrastructure is entirely dependent on third party software code. If we do not bring software and platform providers into scope under Clauses 7 and 8, we leave the front door wide open to cyber crime. Amendment 88, in the name of the noble Lord, Lord Birt, which I actually prefer to my own Amendment 87, would replace this maze of regulators with a unified, specialised body, the office for cyber resilience. The OCR would centralise enforcement, establish common auditing baselines and maintain sector-specific expertise under a single roof.

Amendments 76 and 77 would ensure that, when the Secretary of State specifies new essential activities under Part 3, they must act on the expert recommendations of the OCR, targeting any activity whose disruption carries severe economic, societal or national security impacts. I entirely agree with what the noble Lord, Lord Holmes, had to say and think, sadly, that we would all benefit from a bit of musical accompaniment.

This structural foundation would enable a vital reform suggested by the noble Lord, Lord Birt: Amendment 89 would establish a register requiring software and platform providers to certify products as safe by design; and Amendment 91 would introduce annual independent cyber resilience audits modelled on statutory financial audits.

Under Amendment 90, the OCR would work hand in glove with the UK Cyber Security Council to validate and enforce workforce competence standards across all regulated entities. I remind your Lordships that Amendment 99, in the name of my noble friend Lady Northover, has been degrouped but is relevant to the relationship between the potential OCR and the UK Cyber Security Council.

This is a comprehensive but significant group of amendments that hang together extremely well. I urge the Government to look very closely at what could be a really effective scheme of regulation.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I thank the noble Lord, Lord Birt, for introducing this debate and all noble Lords who have spoken. I appreciate the rigorous strategic thinking that the noble Lords, Lord Birt and Lord Londesborough, have put into the proposal for an office for cyber resilience, but I will try to keep my remarks to the principle of a single regulator.

As others have set out very powerfully, I see the appeal of having a single regulator: it is easy to issue directives, to store data and information centrally, to take a systemic approach overall and to better manage the hiring of scarce, skilled resources. That said, as my noble friend Lady Neville-Jones pointed out, it is important to see the value of sectoral regulators supported by a centre-of-excellence model. More sector-specific expertise, more direct communication with the industry and more flexible approaches are all easier to achieve with smaller, more specific regulators. At a sufficient level of abstraction, it almost does not matter which of those models you go for; it is about having resourced, skilled and empowered people performing monitoring and enforcement activities, regardless of the body under which they sit.

More broadly, the point is that, while differences between a more centralised or more sectoral approach are worthy of debate—I do not think we would ever hit the extremes of either of those—what actually matters is ensuring that, whichever route the Government choose to take us, they make certain that the regulators are adequately resourced and that they exist within a wider strategy.

I am not sure, and look forward to finding out, whether the first of those is the case. The Government have chosen the more sectoral approach, but we do not yet know how the regulators are going to be resourced and what additional resourcing needs will be needed to cope with the increased responsibilities that will be laid at their door. I look forward to hearing from the Minister on how the regulators are going to be funded, how the funding needs will be calculated and how they are going to be supported in this significant expansion of their role.

The second point is that the regulators should exist as a part of a wider strategy, which is not currently the case. I apologise to noble Lords for banging on about this, but it is very difficult to get the past the hole in the Bill in the shape of a wider national cyber strategy. Whether the regulators are many or one matters little without the bigger picture into which they fit. In an ideal world, we would review the overall cyber strategy and then debate what regulatory structures might be appropriate to deliver it but, for now, sadly, that is not the world that we are in.

The Secretary of State—or, indeed, the Chancellor of the Duchy of Lancaster; it is not reassuring that we still do not know which one—must commit to publishing the national plan, after which we can assess the efficacy of its many parts.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Lords, Lord Birt and Lord Clement-Jones, for their introduction to this section and for setting out the motivation behind a single cyber regulator.

As others have pointed out, this is a question of sectoral expertise and cyber expertise. It is my view that, given the complex cyber landscape, establishing a single regulator would not be as effective as the approach that we are pursuing. Different sectors have different risks, technologies, operational environments, market structures and resilience challenges within their industries. To take an example, the energy sector has a greater reliance on operational technology—such as turbines, substations and gas pipes—as compared to the digital services sector, which is predominantly information technology-based. Noble Lords will see that the guidance on quantum, for example, differs in that respect. This is why expert regulators are needed to ensure compliance in a manner that reflects the realities of their sectors.

I do not recognise the assertion that there is a single internationally recognised model of best practice. There are very near neighbours who have the model that we are pursuing, which keeps the sectoral expertise. Additionally, I do not believe that it would be an effective use of resources to establish a new regulator, and the proposed 12-month establishment period would delay the implementation of this regime.

Finally, cyber would continue to exist within a multi-regulator landscape as there are separate regulatory approaches for telecommunications and financial services. I agree with the point made by many noble Lords—highlighted in particular by the noble Lord, Lord Holmes, both at Second Reading and now—that a consistent approach to implementing and enforcing the regime is crucial. The Bill will drive this through by establishing common security and resilience requirements and secondary legislation for all regulated entities, clear guidance for regulators, and a statement of strategic priorities setting common objectives that regulators must seek to achieve. These will cover issues such as governance, skills, risk management, business continuity, supply chains, incident response, and appropriate testing and exercising. They will be consulted on, and any relevant secondary legislation will be subject to the affirmative procedure.

Regulators will supervise and enforce the common requirements while providing guidance that is tailored to the risks and operational realities of their sectors. Crucially, information-sharing gateways and cost-recovery mechanisms will bolster the well-resourced, experienced regulators who stand ready to collaborate while best supporting their respective sectors. I believe that the Bill’s approach gets the right balance between sectoral expertise and a common approach.

On Amendment 91, which would require specific organisations to conduct an annual independent audit, I agree that independent assessments play an important role in providing assurance and leveraging external expertise; that is why the current framework already enables regulators to require independent audits or inspections. However, it is for the sectoral regulators to set the frequency and nature of audits, bearing in mind proportionality and their expertise in the risks and operational realities of their sectors. We will continue to drive uptake of assured independent audits across sectors, using the range of levers that the Bill provides. That is what the current framework provides for and what the implementation of the Bill will ensure.

I turn to Amendment 90, which would require the proposed OCR to work with the UK Cyber Security Council in order to ensure sufficiently qualified cyber security professionals among regulated entities; I note that the amendment laid by the noble Baroness, Lady Northover, on this topic will be debated later. The Government strongly support the need for the professionalisation of the cyber sector. We already work with the UK Cyber Security Council and regulators to encourage cyber professionalisation across NIS sectors. We also intend to set further expectations for regulators to encourage cyber professionalism through the Bill’s security and resilience requirements, which, as I just mentioned, will be set out in secondary legislation. They will address relevant training, skills and professional standards, and the Bill’s regulators must publish guidance on these requirements.

Baroness Kidron Portrait Baroness Kidron (CB)
- View Speech - Hansard - - - Excerpts

My Lords, I rise very briefly to support the noble Baroness, Lady Merron, and to make only one point. As someone who has the misfortune of seeing a great deal of upsetting material of all kinds, I have to admit that it sears an image on your mind. I have had the misfortune to see the interaction of animal and human cruelty in the same sequences, again and again. In making the point that there is a harm to humans in witnessing and normalising this kind of material, I offer my support to the noble Baroness.

Viscount Camrose Portrait The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Viscount Camrose) (Con)
- View Speech - Hansard - -

My Lords, Amendments 180 and 180A seek to require the Secretary of State to conduct a review of existing legislation and how it relates to certain animal welfare offences and, contingent on this review, to make them priority offences under the regulatory framework.

I am grateful for this debate on the important issue of protecting against animal cruelty online, and all of us in this House share the view of the importance of so doing. As the House has discussed previously, this Government are committed to strong animal welfare standards and protections. In this spirit, this Government recognise the psychological harm that animal cruelty content can cause to children online. That is why we tabled an amendment that lists content that depicts real or realistic serious violence or injury against an animal, including by fictional creatures, as priority content that is harmful to children. This was debated on the first day of Report.

In addition, all services will need proactively to tackle illegal animal cruelty content where this amounts to an existing offence such as extreme pornography. User-to-user services will be required swiftly to remove other illegal content that targets an individual victim once made aware of its presence.

The noble Baroness asked about timing. We feel it is important to understand how harm to animals as already captured in the Bill will function before committing to the specific remedy proposed in the amendments.

As discussed in Committee, the Bill’s focus is rightly on ensuring that humans, in particular children, are protected online, which is why we have not listed animal offences in Schedule 7. As many have observed, this Bill cannot fix every problem associated with the internet. While we recognise the psychological harm that can be caused to adults by seeing this type of content, listing animal offences in Schedule 7 is likely to dilute providers’ resources away from protecting humans online, which is the Bill’s main purpose.

However, I understand the importance of taking action on animal mistreatment when committed online, and I am sympathetic to the intention of these amendments. As discussed with the noble Baroness, Defra is confident that the Animal Welfare Act 2006 and its devolved equivalents can successfully bring prosecutions for the commission and action of animal torture when done online in the UK. These Acts do not cover acts of cruelty that take place outside the UK. I know from the discussion we have had in this House that there are real concerns that the Animal Welfare Act 2006 cannot tackle cross-border content, so I wish to make a further commitment today.

The Government have already committed to consider further how the criminal law can best protect individuals from harmful communications, alongside other communications offences, as part of changes made in the other place. To that end, we commit to include the harm caused by animal mistreatment communications as part of this assessment. This will then provide a basis for the Secretary of State to consider whether this offence should be added to Schedule 7 to the OSB via the powers in Clause 198. This work will commence shortly, and I am confident that this, in combination with animal cruelty content listed as priority harms to children, will safeguard users from this type of content online.

For the reasons set out, I hope the noble Baroness and the noble Lord will consider not pressing their amendments.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

The Minister has not dealt with Amendment 180A at all.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

I will be happy to write to the noble Lord.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

That really is not good enough, if I may say so. Does the Minister not have any brief of any kind on Amendment 180A?

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

I am sorry if the noble Lord feels that I have not dealt with it at all.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

The words “animal trafficking” have not passed his lips.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

I am sorry; I will have to write to the noble Lord.

Baroness Merron Portrait Baroness Merron (Lab)
- View Speech - Hansard - - - Excerpts

My Lords, I am sure the letter will be anticipated.

I am grateful to the noble Baroness, Lady Kidron, and the noble Lord, Lord Clement-Jones, for their support for Amendment 180. I appreciate the consideration that the Minister has given to the issue. I am in no doubt of his sympathy for the very important matters at stake here. However, he will not be surprised to hear that I am disappointed with the response, not least because, in the Minister’s proposal, a report will go to the Secretary of State and it will then be up to the Secretary of State whether anything happens, which really is not what we seek. As I mentioned at the outset, I would like to test the opinion of the House.

Online Safety Bill

Viscount Camrose Excerpts
Baroness Kidron Portrait Baroness Kidron (CB)
- View Speech - Hansard - - - Excerpts

My Lords, I enter the fray with some trepidation. In a briefing, Carnegie, which we all love and respect, and which has been fantastic in the background in Committee days, shared some concerns. As I interpret its concerns, when Ofcom was created in 2003 its decisions could be appealed on their merits, as the noble Lord has just suggested, to the Competition Appeal Tribunal, and I believe that this was seen as a balancing measure against an untested regime. What followed was that the broad basis on which appeal was allowed led to Ofcom defending 10 appeals per year, which really frustrated its ability as a regulator to take timely decisions. It turned out that the appeals against Ofcom made up more than 80% of the workload of the Competition Appeal Tribunal, whose work was supposed to cover a whole gamut of matters. When there was a consultation in the fringes of the DEA, it was decided to restrict appeal to judicial review and appeal on process. I just want to make sure that we are not opening up a huge and unnecessary delaying tactic.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

I thank all those who have spoken, and I very much appreciate the spirit in which the amendments were tabled. They propose changes to the standard of appeal, the standing to appeal and the appeals process itself. The Government are concerned that enabling a review of the full merits of cases, as proposed by Amendments 243 and 245, could prove burdensome for the courts and the regulator, since a full-merits approach, as we have been hearing, has been used by regulated services in other regulatory regimes to delay intervention, undermining the effectiveness of the enforcement process. With deep-pocketed services in scope, allowing for a full-merits review could incentivise speculative appeals, both undermining the integrity of the system and slowing the regulatory process.

While the Government are fully committed to making sure that the regulator is properly held to account, we feel that there is not a compelling case for replacing the decisions of an expert and well-resourced regulator with those of a tribunal. Ofcom will be better placed to undertake the complex analysis, including technical analysis, that informs regulatory decisions.

Amendment 245 would also limit standing and leave to appeal only to providers and those determined eligible entities to make super-complaints under Clause 150. This would significantly narrow the eligibility requirements for appeals. For appeals against Ofcom notices we assess that the broader, well-established standard in civil law of sufficient interest is more appropriate. Super-complaints fulfil a very different function from appeals. Unlike appeals, which will allow regulated services to challenge decisions of the regulator, super-complaints will allow organisations to advocate for users, including vulnerable groups and children, to ensure that systemic issues affecting UK users are brought to Ofcom’s attention. Given the entirely distinct purposes of these functions, it would be inappropriate to impose the eligibility requirements for super-complaints on the appeals system.

I am also concerned about the further proposal in Amendment 245 to allow the tribunal to replace Ofcom’s decision with its own. Currently, the Upper Tribunal is able to dismiss an appeal or quash Ofcom’s decision. Quashed decisions must be remitted to Ofcom for reconsideration, and the tribunal may give directions that it considers appropriate. Amendment 245 proposes instead allowing the Upper Tribunal to

“impose or revoke, or vary the amount of, a penalty … give such directions or take such other steps as OFCOM could itself have given or taken, or … make any other decision which OFCOM could itself have made”.

The concern is that this risks undermining Ofcom’s independence and discretion in applying its powers and issuing sanctions, and in challenging the regulator’s credibility and authority. It may also further incentivise well-resourced providers to appeal opportunistically, with a view to securing a more favourable outcome at a tribunal.

On that basis, I fear that the amendments tabled by the noble Lord would compromise the fundamental features of the current appeals provisions, without any significant benefits, and risk introducing a range of inadvertent consequences. We are confident that the Upper Tribunal’s judicial review process, currently set out in the Bill, provides a proportionate, effective means of appeal that avoids unnecessary expense and delays, while ensuring that the regulator’s decisions can be thoroughly scrutinised. It is for these reasons that I hope the noble Baroness will withdraw the amendment.

Baroness Merron Portrait Baroness Merron (Lab)
- View Speech - Hansard - - - Excerpts

My Lords, I am grateful to the Minister. I will take that as a no—but a very well-considered no, for which I thank him. I say to the noble Lord, Lord Clement-Jones, that we certainly would not wish to make him feel uncomfortable at any time. I am grateful to him and the noble Baroness, Lady Kidron, for their contributions. As I said at the outset, this amendment was intended to probe the issue, which I feel we have done. I certainly would not want to open a can of worms—online, judicial or otherwise. Nor would I wish, as the Minister suggested, to undermine the work, efficiency and effectiveness of Ofcom. I am glad to have had the opportunity to present these amendments. I am grateful for the consideration of the Committee and the Minister, and with that I beg leave to withdraw.

Online Safety Bill

Viscount Camrose Excerpts
Thursday 25th May 2023

(3 years, 3 months ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - - - Excerpts

My Lords, I rise to support Amendment 134, tabled by the noble Lord, Lord Stevenson, which was so ably introduced by the noble Baroness, Lady Merron. The Government accepted the Joint Committee’s recommendation that priority offences should be put in the Bill, and that is now contained in Schedules 5, 6 and 7. In particular, Schedule 7 sets out the priority offences. The noble Baroness, Lady Merron, has nailed it in setting out why these animal suffering-related offences fall within the Government’s criteria.

When the Government responded to the Joint Committee, they accepted our recommendation that we should put priority content in the Bill. As the noble Baroness, Lady Merron, said, the criteria are very clearly set out in paragraph 86 of their report:

“The prevalence of such content on regulated services … The risk of harm being caused to UK users by such content; and … The severity of that harm”.

The noble Baroness has absolutely set out how these offences fall within those criteria: the prevalence of these offences; the abuse that is present; the viewing by children and its impact on them; the impact on animal welfare, which would be positive if this content were treated as a priority offence; and the very strong public support.

Of course—the noble Baroness did not quite go here, but I will—there is a massive contrast with the inclusion of the encouragement of immigration offence in Schedule 7. These offences have far greater merit for inclusion in Schedule 7. I very much hope the Minister will accede to what I think is an extremely reasonable amendment.

Viscount Camrose Portrait The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Viscount Camrose) (Con)
- View Speech - Hansard - -

I thank the noble Baroness for her amendment and the noble Lord, Lord Clement-Jones, for speaking so powerfully, as ever. I very much recognise the harms and horrors of cruelty to animals online or anywhere else. The UK has a proud history of championing and taking action on animal welfare, and the Government are committed to strengthening animal welfare standards and protections.

Our Action Plan for Animal Welfare demonstrates the Government’s commitment to a brighter future for animals both at home and abroad and provides a foundation for conversations on how we can continue to improve animal welfare and conservation in future. I can also reassure your Lordships that this Bill will tackle some of the worst online activities related to animal cruelty.

Amendment 134 seeks to add certain specified animal offences to the list of priority offences in Schedule 7. It is worth reminding ourselves that the Bill will already tackle some of the worst examples of animal cruelty online. This includes, for example, where the content amounts to an existing priority offence, such as extreme pornography, which platforms must prevent users encountering. Equally, where content could cause psychological harm to children, it must be tackled. Where the largest services prohibit types of animal abuse content in their terms of service, the Bill will require them to enforce those terms and remove such content. Improved user reporting and redress systems, as mandated by the Bill, will make it easier for users to report such content.

The Bill, however, is not designed to address every harm on the internet. For it to have an impact, it needs to be manageable for both Ofcom and the companies. For it to achieve the protections envisaged since the start of the Bill, it must focus on its mission of delivering protections for people. Schedule 7 has been designed to focus on the most serious and prevalent offences affecting humans in the UK, on which companies can take effective and meaningful action. The offences in this schedule are primarily focused on where the offences can be committed online—for example, threats to kill or the unlawful supply of drugs. The offences that the noble Baroness proposes cannot be committed online; while that would not stop them from being added for inchoate purposes, the Government do not believe that platforms would be able to take effective steps proactively to identify and tackle such offences online.

Crucially, the Government feel that adding too many offences to Schedule 7 that cannot be effectively tackled also risks spreading companies’ resources too thinly, particularly for smaller and micro-businesses, which would have to address these offences in their risk assessments. Expanding the list of offences in Schedule 7 to include the animal cruelty offences could dilute companies’ efforts to tackle other offences listed in the Bill which have long been the priority of this legislation.

Beyond the Bill, however, the Government are taking a very wide range of steps to tackle animal cruelty. Since publishing the Action Plan for Animal Welfare in 2021, the Government have brought in new laws to recognise animal sentience, introduced additional legislative measures to tackle illegal hare-coursing, and launched the animal health and welfare pathway as part of our agricultural transition plan. We will, of course, continue to discuss these important issues with colleagues at the Department for Environment, Food and Rural Affairs, who lead on our world-leading protections for animals, but, for the reasons I have set out, I am unable to accept this amendment. I therefore hope that the noble Baroness will withdraw it.

Baroness Merron Portrait Baroness Merron (Lab)
- View Speech - Hansard - - - Excerpts

My Lords, I am grateful to the Minister for his considered reply, outlining the ways in which he believes the Bill supports where this amendment is going. I am also grateful to the noble Lord, Lord Clement-Jones, for his support. Indeed, it is my view that the criteria have been met for inclusion of these animal welfare offences in this list of priority offences. It is, of course, disappointing that the Minister does not share the view that we have expressed.

Perhaps I could pick up a point from the Minister’s response. It seems to me that something that is illegal offline should also be illegal online. If something is illegal under the various Acts referred to but there is user-to-user content of these animal cruelty films, for example, is the Minister saying that this will be covered by the Bill in its current form?

I note that the Minister has spoken of continuing discussions with Defra, which is very welcome. I am also requesting a meeting to pursue this. It is something on which we could make progress, and I hope that the Minister would be open to that. With that, I beg leave to withdraw the amendment.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - - - Excerpts

My Lords, I strongly support the amendment in the names of the noble Lords, Lord Knight and Lord Stevenson, as well as my noble friend Lady Featherstone. The essence of the message from the noble Lord, Lord Knight, about the need for trust and the fact that you can gain trust through greater transparency is fundamental to this group.

The Joint Committee’s report is now a historical document. It is partly the passage of time, but it was an extraordinary way in which to work through some of the issues, as we did. We were very impacted by the evidence given by Frances Haugen, and the fact that certain things came to light only as a result of her sharing information with the Securities and Exchange Commission. We said at the time that:

“Lack of transparency of service providers also means that people do not have insight into the prevalence and nature of activity that creates a risk of harm on the services that they use”.


That is very much the sense that the noble Lord, Lord Stevenson, is trying to get to by adding scope as well.

We were very clear about our intentions at the time. The Government accepted the recommendation that we made and said that they agreed with the committee that

“services with transparency reporting requirements should be required to publish their transparency reports in full, and in an accessible and public place”.

So what we are really trying to do is to get the Government to agree to what they have already agreed to, which we would have thought would be a relatively straightforward process.

There are some other useful aspects, such as the review of effectiveness of the transparency requirements. I very much appreciate what my noble friend just said about not reading transparency reports. I read the oversight reports but not necessarily the transparency reports. I am not sure that Frances Haugen was a great advert for transparency reports at the time, but that is a mere aside in the circumstances.

I commend my noble friend Lady Featherstone’s Amendment 171, which is very consistent with what we were trying to achieve with the code of practice about violence against women and girls. That would fit very easily within that. One of the key points that my noble friend Lord Allan made is that this is for the benefit of the platforms as well. It is not purely for the users. Of course it is useful for the users, but not exclusively, and this could be a way of platforms engaging with the users more clearly, inserting more fresh air into this. In these circumstances it is pretty conclusive that the Government should adhere to what they agreed to in their response to the Joint Committee’s report.

Viscount Camrose Portrait The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Viscount Camrose) (Con)
- View Speech - Hansard - -

As ever, I thank all noble Lords who have spoken. I absolutely take, accept and embrace the point that transparency is wholly critical to what we are trying to achieve with the Bill. Indeed, the chandelier of transparency reports should be our shared aim—a greenhouse maybe. I am grateful for everyone’s contributions to the debate. I agree entirely with the views expressed. Transparency is vital in holding companies to account for keeping their users safe online. As has been pointed out, it is also to the benefit of the platforms themselves. Confident as I am that we share the same objectives, I would like to try to reassure noble Lords on a number of issues that have been raised.

Amendments 160A, 160B and 181A in the name of the noble Lord, Lord Knight of Weymouth, seek to require providers to make their transparency reports publicly available, subject to appropriate redactions, and to allow Ofcom to prevent their publication where it deems that the risks posed by drawing attention to illegal content outweigh the benefit to the public of the transparency report. Let me reassure the noble Lord that the framework, we strongly believe, already achieves the aim of those amendments. As set out in Clause 68, Ofcom will specify a range of requirements in relation to transparency reporting in a notice to categories 1, 2A and 2B. This will include the kind of information that is required in the transparency report and the manner in which it should be published. Given the requirement to publish the information, this already achieves the intention of Amendment 160A.

The specific information requested for inclusion within the transparency report will be determined by Ofcom. Therefore, the regulator will be able to ensure that the information requested is appropriate for publication. Ofcom will take into account any risks arising from making the information public before issuing the transparency notice. Ofcom will have separate information-gathering powers, which will enable the regulator to access information that is not suitable to be published in the public domain. This achieves the intention of Amendment 160B. There is also a risk of reducing trust in transparency reporting if there is a mechanism for Ofcom to prevent providers publishing their transparency reports.

Amendment 181A would require Ofcom to issue guidance on what information should be redacted and how this should be done. However, Ofcom is already required to produce guidance about transparency reports, which may include guidance about what information should be redacted and how to do this. It is important to provide the regulator with the flexibility to develop appropriate guidance.

Amendment 165 seeks to expand the information within the transparency reporting requirements to cover the scope of the terms of service set out by user-to-user providers. I very much agree with the noble Lord that it is important that Ofcom can request information about the scope of terms of service, as well as about their application. Our view is that the Bill already achieves this. Schedule 8 sets out the high-level matters about which information may be required. This includes information about how platforms are complying with their duties. The Bill will place duties on user-to-user providers to ensure that any required terms of service are clear and accessible. This will require platforms to set out what the terms of service cover—or, in other words, the scope. While I hope that this provides reassurance on the matter, if there are still concerns in spite of what I have said, I am very happy to look at this. Any opportunity to strengthen the Bill through that kind of clarity is worth looking at.

Lord Stevenson of Balmacara Portrait Lord Stevenson of Balmacara (Lab)
- Hansard - - - Excerpts

I welcome the Minister’s comments. I am interrupting just because this is my amendment rather than my noble friend Lord Knight’s. The word “scope” caused us some disquiet on this Bench when we were trying to work out what we meant by it. It has been fleshed out in slightly different ways around the Chamber, to advantage.

I go back to the original intention—I am sorry for the extensive introduction, but it is to make sure that I focus the question correctly—which was to make sure that we are not looking historically at the terms of reference that have been issued, and whether they are working in a transparency mode, but addressing the question of what is missing or is perhaps not addressed properly. Does the Minister agree that that would be taken in by the word “scope”?

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

I think I probably would agree, but I would welcome a chance to discuss it further.

Finally, Amendment 229 intends to probe how Ofcom will review the effectiveness of transparency requirements in the Bill. It would require Ofcom to produce reports reviewing the effectiveness of transparency reports and would give the Secretary of State powers to implement any recommendations made by the regulator. While I of course agree with the sentiment of this amendment, as I have outlined, the transparency reporting power is designed to ensure that Ofcom can continuously review the effectiveness of transparency reports and make adjustments as necessary. This is why the Bill requires Ofcom to set out in annual transparency notices what each provider should include in its reports and the format and manner in which it should be presented, rather than putting prescriptive or static requirements in the Bill. That means that Ofcom will be able to learn, year on year, what will be most effective.

Under Clause 145, Ofcom is required to produce its own annual transparency report, which must include a summary of conclusions drawn from providers’ transparency reports, along with the regulator’s view on industry best practice and other appropriate information—I hope and think that goes to some of the points raised by the noble Lord, Lord Allan of Hallam.

Lord Knight of Weymouth Portrait Lord Knight of Weymouth (Lab)
- View Speech - Hansard - - - Excerpts

My Lords, just before the Minister moves on—and possibly to save me finding and reading it—can he let us know whether those annual reports by Ofcom will be laid before Parliament and whether Parliament will have a chance to debate them?

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

I believe so, but I will have to confirm that in writing. I am sorry not to be able to give a rapid answer.

Clause 159 requires the Secretary of State to review in total the operation of the regulatory framework to ensure it is effective. In that review, Ofcom will be a statutory consultee. The review will specifically require an assessment of the effectiveness of the regulatory framework in ensuring that the systems and processes used by services provide transparency and accountability to users.

The Bill will create what we are all after, which is a new culture of transparency and accountability in the tech sector. For the reasons I have laid out, we are confident that the existing provisions are sufficiently broad and robust to provide that. As such, I hope the noble Lord feels sufficiently reassured to withdraw the amendment.

Lord Knight of Weymouth Portrait Lord Knight of Weymouth (Lab)
- Hansard - - - Excerpts

My Lords, that was a good, quick debate and an opportunity for the noble Viscount to put some things on the record, and explain some others, which is helpful. It is always good to get endorsement around what we are doing from both the noble Lord, Lord Allan, and the noble Baroness, Lady Fox. That is a great spread of opinion. I loved the sense of the challenge as to whether anyone ever reads the transparency reports whenever they are published; I imagine AI will be reading and summarising them, and making sure they are not written as gobbledygook.

On the basis of what we have heard and if we can get some reassurance that strong transparency is accompanied by strong parliamentary scrutiny, then I am happy to withdraw the amendment.

Online Safety Bill

Viscount Camrose Excerpts
The noble Baroness, Lady Newlove, mentioned the research published by the Children’s Commissioner which showed that 40% of children did not report harmful content because they felt there was no point in doing so. That is pretty damning of the current situation. The noble Lord, Lord Russell, and my noble friend made the very strong point that we do not want to bog down the regulator. We see what happens under the data protection legislation. The ICO has an enormous number of complaints to deal with directly, without the benefit of an ombudsman. This scheme could alleviate the burden on the regulator and be highly effective. I do not think we have heard an argument in Committee against this; it must be the way forward. I very much hope that the Minister will take this forward after today and install an ombudsman for the Bill.
Viscount Camrose Portrait The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Viscount Camrose) (Con)
- Hansard - -

My Lords, the amendments in this group are concerned with complaints mechanisms. I turn first to Amendment 56 from the noble Lord, Lord Stevenson of Balmacara, which proposes introducing a requirement on Ofcom to produce an annual review of the effectiveness and efficiency of platforms’ complaints procedures. Were this review to find that regulated services were not complying effectively with their complaints procedure duties, the proposed new clause would provide for Ofcom to establish an ombudsman to provide a dispute resolution service in relation to complaints.

While I am of course sympathetic to the aims of this amendment, the Government remain confident that service providers are best placed to respond to individual user complaints, as they will be able to take appropriate action promptly. This could include removing content, sanctioning offending users, reversing wrongful content removal or changing their systems and processes. Accordingly, the Bill imposes a duty on regulated user-to-user and search services to establish and operate an easy-to-use, accessible and transparent complaints procedure. The complaints procedure must provide for appropriate action to be taken by the provider in relation to the complaint.

It is worth reminding ourselves that this duty is an enforceable requirement. Where a provider is failing to comply with its complaints procedure duties, Ofcom will be able to take enforcement action against the regulated service. Ofcom has a range of enforcement powers, including the power to impose significant penalties and confirmation decisions that can require the provider to take such steps as are required for compliance. In addition, the Bill includes strong super-complaints provisions that will allow for concerns about systemic issues to be raised with the regulator, which will be required to publish its response to the complaint. This process will help to ensure that Ofcom is made aware of issues that users are facing.

Separately, individuals will also be able to submit complaints to Ofcom. Given the likelihood of an overwhelming volume of complaints, as we have heard, Ofcom will not be able to investigate or arbitrate on individual cases. However, those complaints will be an essential part of Ofcom’s horizon-scanning, research, supervision and enforcement activity. They will guide Ofcom in deciding where to focus its attention. Ofcom will also have a statutory duty to conduct consumer research about users’ experiences in relation to regulated services and the handling of complaints made by users to providers of those services. Further, Ofcom can require that category 1, 2A and 2B providers set out in their annual transparency reports the measures taken to comply with their duties in relation to complaints. This will further ensure that Ofcom is aware of any issues facing users in relation to complaints processes.

At the same time, I share the desire expressed to ensure that the complaints mechanisms will be reviewed and assessed. That is why the Bill contains provisions for the Secretary of State to undertake a review of the efficacy of the entire regulatory framework. This will take place between two and five years after the Part 3 provisions come into force, which is a more appropriate interval for the efficacy of the duties around complaints procedures to be reviewed, as it will allow time for the regime to bed in and provide a sufficient evidence base to assess whether changes are needed.

Finally, I note that Amendment 56 assumes that the preferred solution following a review will be an ombudsman. There is probably not enough evidence to suggest that an ombudsman service would be effective for the online safety regime. It is unclear how an ombudsman service would function in support of the new online safety regime, because individual user complaints are likely to be complex and time-sensitive—and indeed, in many cases financial compensation would not be appropriate. So I fear that the noble Lord’s proposed new clause pre-empts the findings of a review with a solution that is resource-intensive and may be unsuitable for this sector.

Amendments 250A and 250B, tabled by my noble friend Lady Newlove, require that an independent appeals system is established and that Ofcom produces guidance to support this system. As I have set out, the Government believe that decisions on user redress and complaints are best dealt with by services. Regulated services will be required to operate an easy-to-use, accessible and transparent complaints procedure that enables users to make complaints. If services do not comply with these duties, Ofcom will be able to utilise its extensive enforcement powers to bring them into compliance.

The Government are not opposed to revisiting the approach to complaints once the regime is up and running. Indeed, the Bill provides for the review of the regulatory framework. However, it is important that the new approach, which will radically change the regulatory landscape by proactively requiring services to have effective systems and processes for complaints, has time to bed in before it is reassessed.

Turning specifically to the points made by my noble friend and by the noble Baroness, Lady Kidron, about the impartial out of court dispute resolution procedure in the VSP, the VSP regime and the Online Safety Bill are not directly comparable. The underlying principles of both regimes are of course the same, with the focus on systems regulation and protections for users, especially children. The key differences are regarding the online safety framework’s increased scope. The Bill covers a wider range of harms and introduces online safety duties on a wider range of platforms. Under the online safety regime, Ofcom will also have a more extensive suite of enforcement powers than under the UK’s VSP regime.

On user redress, the Bill goes further than the VSP regime as it will require services to offer an extensive and effective complaints process and will enable Ofcom to take stronger enforcement action where they fail to meet this requirement. That is why the Government have put the onus of the complaints procedure on the provider and set out a more robust approach which requires all in-scope, regulated user to user and search services to offer an effective complaints process that provides for appropriate action to be taken in relation to the complaint. This will be an enforceable duty and will enable Ofcom to utilise its extensive online safety enforcement powers where services are not complying with their statutory duty to provide a usable, accessible and transparent complaints procedure.

At the same time, we want to ensure that the regime can develop and respond to new challenges. That is why we have included a power for the Secretary of State to review the regulatory framework once it is up and running. This will provide the correct mechanism to assess whether complaint handling mechanisms can be further strengthened once the new regulations have had time to bed in.

The Government are confident that the Online Safety Bill represents a significant step forward in keeping users safe online for these reasons.

Lord Russell of Liverpool Portrait Lord Russell of Liverpool (CB)
- View Speech - Hansard - - - Excerpts

My Lords, could I just ask a question? This Bill has been in gestation for about five to six years, during which time the scale of the problems we are talking about has increased exponentially. The Government appear to be suggesting that they will, in three to five years, evaluate whether or not their approach is working effectively.

There was a lot of discussion in this Chamber yesterday about the will of the people and whether the Government were ignoring it. I gently suggest that the very large number of people, who are having all sorts of problems or who are fearful of harm from the online world, will not find in the timescale that the Government are proposing the sort of remedy and speed of action I suspect they were hoping for. Certainly, the rhetoric the Government have used and continue to use at regular points in the Bill when they are slightly on the back foot seems to be designed to try to make the situation seem better than it is.

Will the Minister and the Bill team take on board that there are some very serious concerns that there will be a lot of lashing back at His Majesty’s Government if in three years’ time—which I fear may be the case—we still have a situation where a large body of complaints are not being dealt with? Ofcom is going to suffer from major ombudsman-like constipation trying to deal with this, and the harms will continue. I think I speak for the Committee when I say that the arguments the Minister and the government side are making really do not hold water.

I thought in particular of the direct experience of the noble Baroness, Lady Harding, demonstrating the effect on her company—so substitute platforms for that—of knowing that you are being held to account. Having a system that helps the regulator understand in real time whether or not these companies are doing what they should—they are an early warning system and would know earlier than Ofcom would—just seems sensible. But perhaps being sensible is not what this Bill is about.
Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

I do not know about that last point. I was going to say that I am very happy to meet the noble Lord to discuss it. It seems to me to come down to a matter of timing and the timing of the first review. As I say, I am delighted to meet the noble Lord. By the way, the relevant shortest period is two years not three, as he said.

Baroness Newlove Portrait Baroness Newlove (Con)
- View Speech - Hansard - - - Excerpts

Following on from my friend, the noble Lord, Lord Russell, can I just say to the Minister that I would really welcome all of us having a meeting? As I am listening to this, I am thinking that three to five years is just horrific for the families. This Bill has gone on for so long to get where we are today. We are losing sight of humanity here and the moral compass of protecting human lives. For whichever Government is in place in three to five years to make the decision to say it does not work is absolutely shameful. Nobody in the Government will be accountable and yet for that family, that single person may commit suicide. We have met the bereaved families, so I say to the Minister that we need to go round the table and look at this again. I do not think it is acceptable to say that there is this timeline, this review, for the Secretary of State when we are dealing with young lives. It is in the public interest to get this Bill correct as it navigates its way back to the House of Commons in a far better state than how it arrived.

Baroness Kidron Portrait Baroness Kidron (CB)
- View Speech - Hansard - - - Excerpts

I would love the noble Viscount to answer my very specific question about who the Government think families should turn to when they have exhausted the complaints system in the next three to five years. I say that as someone who has witnessed successive Secretaries of State promising families that this Bill would sort this out. Yes?

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

I stress again that the period in question is two years not three.

--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

It is between two and five years. It can be two; it can be five. I am very happy to meet my noble friend and to carry on doing so. The complaints procedure set up for families is to first approach the service provider in an enforceable manner and should the provider fail to meet its enforceable duties to then revert to Ofcom before the courts.

Baroness Kidron Portrait Baroness Kidron (CB)
- View Speech - Hansard - - - Excerpts

I am sorry but that is exactly the issue at stake. The understanding of the Committee currently is that there is then nowhere to go if they have exhausted that process. I believe that complainants are not entitled to go to Ofcom in the way that the noble Viscount just suggested.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

Considerably more rights are provided than they have today, with the service provider. Indeed, Ofcom would not necessarily deal with individual complaints—

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

They would go to the service provider in the first instance and then—

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - - - Excerpts

What recourse would they have, if Ofcom will not deal with individual complaints in those circumstances?

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

I am happy to meet and discuss this. We are expanding what they are able to receive today under the existing arrangements. I am happy to meet any noble Lords who wish to take this forward to help them understand this—that is probably best.

Amendments 287 and 289 from the noble Baroness, Lady Fox of Buckley, seek to remove the provision for super-complaints from the Bill. The super-complaints mechanism is an important part of the Bill’s overall redress mechanisms. It will enable entities to raise concerns with Ofcom about systemic issues in relation to regulated services, which Ofcom will be required to respond to. This includes concerns about the features of services or the conduct of providers creating a risk of significant harm to users or the public, as well as concerns about significant adverse impacts on the right to freedom of expression.

On who can make super-complaints, any organisation that meets the eligibility criteria set out in secondary legislation will be able to submit a super-complaint to Ofcom. Organisations will be required to submit evidence to Ofcom, setting out how they meet these criteria. Using this evidence, Ofcom will assess organisations against the criteria to ensure that they meet them. The assessment of evidence will be fair and objective, and the criteria will be intentionally strict to ensure that super-complaints focus on systemic issues and that the regulator is not overwhelmed by the number it receives.

Baroness Fox of Buckley Portrait Baroness Fox of Buckley (Non-Afl)
- View Speech - Hansard - - - Excerpts

To clarify and link up the two parts of this discussion, can the Minister perhaps reflect, when the meeting is being organised, on the fact that the organisations and the basis on which they can complain will be decided by secondary legislation? So we do not know which organisations or what the remit is, and we cannot assess how effective that will be. We know that the super-complainants will not want to overwhelm Ofcom, so things will be bundled into that. Individuals could be excluded from the super-complaints system in the way that I indicated, because super-complaints will not represent everyone, or even minority views; in other words, there is a gap here now. I want that bit gone, but that does not mean that we do not need a robust complaints system. Before Report at least—in the meetings in between—the Government need to advise on how you complain if something goes wrong. At the moment, the British public have no way to complain at all, unless someone sneaks it through in secondary legislation. This is not helpful.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

As I said, we are happy to consider individual complaints and super-complaints further.

Lord Allan of Hallam Portrait Lord Allan of Hallam (LD)
- View Speech - Hansard - - - Excerpts

Again, I am just pulling this together—I am curious to understand this. We have been given a specific case—South West Grid for Learning raising a case based on an individual but that had more generic concerns—so could the noble Viscount clarify, now or in writing, whether that is the kind of thing that he imagines would constitute a super-complaint? If South West Grid for Learning went to a platform with a complaint like that—one based on an individual but brought by an organisation—would Ofcom find that complaint admissible under its super-complaints procedure, as imagined in the Bill?

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

Overall, the super-complaints mechanism is more for groupings of complaints and has a broader range than the individual complaints process, but I will consider that point going forward.

Many UK regulators have successful super-complaints mechanisms which allow them to identify and target emerging issues and effectively utilise resources. Alongside the Bill’s research functions, super-complaints will perform a vital role in ensuring that Ofcom is aware of the issues users are facing, helping them to target resources and to take action against systemic failings.

On the steps required after super-complaints, the regulator will be required to respond publicly to the super-complaint. Issues raised in the super-complaint may lead Ofcom to take steps to mitigate the issues raised in the complaint, where the issues raised can be addressed via the Bill’s duties and powers. In this way, they perform a vital role in Ofcom’s horizon-scanning powers, ensuring that it is aware of issues as they emerge. However, super-complaints are not linked to any specific enforcement process.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - - - Excerpts

My Lords, it has just occurred to me what the answer is to the question, “Where does an individual actually get redress?” The only way they can get redress is by collaborating with another 100 people and raising a super-complaint. Is that the answer under the Bill?

--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

No. The super-complaints mechanism is better thought of as part of a horizon-scanning mechanism. It is not—

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - - - Excerpts

So it is not really a complaints system; it is a horizon-scanning system. That is interesting.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

The answer to the noble Lord’s question is that the super-complaint is not a mechanism for individuals to complain on an individual basis and seek redress.

Lord Stevenson of Balmacara Portrait Lord Stevenson of Balmacara (Lab)
- View Speech - Hansard - - - Excerpts

This is getting worse and worse. I am tempted to suggest that we stop talking about this and try to, in a smaller group, bottom out what we are doing. I really think that the Committee deserves a better response on super-complaints than it has just heard.

As I understood it—I am sure that the noble Baroness, Lady Kidron, is about to make the same point—super-complaints are specifically designed to take away the pressure on vulnerable and younger persons to have responsibility only for themselves in bringing forward the complaint that needs to be resolved. They are a way of sharing that responsibility and taking away the pressure. Is the Minister now saying that that is a misunderstanding?

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

I have offered a meeting; I am very happy to host the meeting to bottom out these complaints.

Baroness Kidron Portrait Baroness Kidron (CB)
- View Speech - Hansard - - - Excerpts

I understand that the Minister has been given a sticky wicket of defending the indefensible. I welcome a meeting, as I think the whole Committee does, but it would be very helpful to hear the Government say that they have chosen to give individuals no recourse under the Bill—that this is the current situation, as it stands, and that there is no concession on the matter. I have been in meetings with people who have been promised such things, so it is really important, from now on in Committee, that we actually state at the Dispatch Box what the situation is. I spent quite a lot of the weekend reading circular arguments, and we now need to get to an understanding of what the situation is. We can then decide, as a Committee, what we do in relation to that.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

As I said, I am very happy to hold the meeting. We are giving users greater protection through the Bill, and, as agreed, we can discuss individual routes to recourse.

I hope that, on the basis of what I have said and the future meeting, noble Lords have some reassurance that the Bill’s complaint mechanisms will, eventually, be effective and proportionate, and feel able not to press their amendments.

Lord Stevenson of Balmacara Portrait Lord Stevenson of Balmacara (Lab)
- View Speech - Hansard - - - Excerpts

I am very sorry that I did not realise that the Minister was responding to this group of amendments; I should have welcomed him to his first appearance in Committee. I hope he will come back—although he may have to spend a bit of time in hospital, having received a pass to speak on this issue from his noble friend.

This is a very complicated Bill. The Minister and I have actually talked about that over tea, and he is now learning the hard lessons of what he took as a light badinage before coming to the Chamber today. However, we are in a bit of a mess here. I was genuinely trying to get an amendment that would encourage the department to move forward on this issue, because it is quite clear from the mood around the Committee that something needs to be resolved here. The way the Government are approaching this is by heading towards a brick wall, and I do not think it is the right way forward.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

My Lords, no Bill that we can devise now can ever offer a complete solution to every online risk while balancing all the competing priorities. But I welcome this Bill as a critical early step down a hard road, because it sets up an adaptive structure to respond to emerging technologies and needs. We heard the phrase “living legislation earlier”, and that expresses it very well.

I would like to offer three examples of what some of our future challenges in this space are going to be. The first is AI: given the sheer quantity of content and genuine difficulty of some decisions that have to be made about that content, no platform can make the delicate judgments at the huge speed and scale we are looking for without automated algorithmic solutions. That inevitably comes to mean AI overseeing our activity and, given the vast behaviour-modification capabilities of the large platforms, AI coming to modify our collective behaviour in ways we are unlikely to understand or control. However benignly intended, the results of such developments are far-reaching and unknowable.

Secondly, there is digital identity. We have heard some brilliant contributions about this and I think we can all agree that a cornerstone of dangerous behaviour online is anonymity. Age-verification checks are easily circumvented today and I wholly support, of course, the analysis and proposals of my noble friend Lord Bethell in this area. There is a broad principle here: that online behaviour should be guided by the same constraints as behaviour in real life. In my view, the only real way to bring that about is by requiring a digital identity for everyone. That is not to say that everybody has to identify themselves at all times, but they should be identifiable if the need arises and should criminal or dangerous behaviour take place.

Thirdly, and lastly, there is the issue of enforcement, particularly in Web 3.0. We can foresee the enforcement of compliance by well-known platforms led and owned by household names, but we are increasingly going to see more and more online services provided by much larger numbers of decentralised platforms, run by so- called DAOs—decentralised autonomous organisations. These are organisations without boards and managers; they do not necessarily have employees or even bank accounts. They are going to require very different levers of enforcement. Put simply, you cannot easily apply criminal sanctions with neither owners to arrest nor real assets to seize. I am pleased that the Minister and his team have already started thinking about these organisations, as discussed at the briefing that he kindly arranged last week.

Of course, worrying about these future problems in no way diminishes the very real challenges of the present, which have been covered so movingly in our debate today. However, none of the risks to online safety is going to get any easier to manage. The growth of malicious activity and extremism will be multiplied by the greater emotional intensity of the immersive experience that will be enabled by some of the virtual reality technologies that we are now starting to see come on to the market. With this Bill, we are making a bold and important start, which I welcome, but I fear that the harder part of our journey lies ahead of us.