Baroness Byford
Main Page: Baroness Byford (Conservative - Life peer)Department Debates - View all Baroness Byford's debates with the Scotland Office
(7 years, 10 months ago)
Lords ChamberMy Lords, our amendments in this group add safeguards. The noble Lord, Lord Collins, referred to some of these: that sharing of information be minimal; that the authorised conduct be proportionate to the object of the exercise; that a privacy impact assessment be conducted; and that proposed measures be subject to public consultation.
In addition, we support the amendments advocated by the BMA. Amendment 89 would remove the subsection through which sharers of information are not bound by the principle of confidentiality. Amendment 93 is a further safeguard preventing an authorised sharer of information from disclosing identifiable health information. I look forward to the Minister’s response.
My Lords, in this group I tabled Amendments 100 and 196. Within this group we are debating data sharing and the putting in place of safeguards that make us confident in the next move to make life better for the majority of people. I have one or two direct questions, particularly on the level of data that will be supplied from one authority to another. For example, does the Bill intend that information be supplied on the number of households in a given postal area where child benefit is being claimed and/or where all adults are unemployed? Would it be up to the users of the data to extract a summary picture from details of, for example, names, addresses, whether benefits are received, whether householders are unemployed or any other data?
At any level of inquiry, I presume data will be transferred such as dates of birth and marital status that, were they to fall into the wrong hands, could be used to perpetrate private fraud. No one today has mentioned private fraud, but it can come about as a result of lack of security and safeguarding. Again, perhaps the Minister will indicate what relevant provisions there are. I am unsure whether I have missed some. At earlier stages of the Bill I mentioned the amount of fraud going on and it is horrifying. If the Bill can in any way tighten up on that, it would be an advantage.
For example, will personal information cover things such as whether an individual has a diagnosis of dementia or whether a family has been a cause of concern to the social work department in their own area? Who makes these judgments? At what stage are these activated? I may not have read the Bill carefully enough to find the missing answers. I pose these fairly simple questions to make sure that our safeguarding of this information is secure.
Amendment 100 is a probing amendment that seeks to complete the explanation of what information HMRC would disclose, providing examples of the circumstances under which it would be disclosed and a complete list of the groups or persons whose information would be handed over. This relates to Clause 30, of which we spoke earlier. Subsections (9) and (10) specify the well-being of persons or households and define well-being in terms of physical or mental health, contributions to society—which we have covered slightly earlier on and which is difficult; I should be glad of clarification on that—and emotional, social and economic well-being. The latter are easier to understand.
Clause 31 refers to people living in fuel poverty. Again, we debated this previously. Fuel poverty has been defined as,
“living on a lower income in a home which cannot be kept warm at a reasonable cost”.
Clause 32 also refers to people living in fuel poverty. I do not understand what is intended, nor what will be involved for those deemed to be affected. Defining well-being in terms of well-being suggests that definitions of those covered by this legislation could depend on the personal and political stance of those making those decisions. What is “lower income”? Within what limits do homes qualify under these clauses and who will rule that they cannot be kept warm at reasonable cost? What will be the limits of powers of such a decision-maker over, for example, someone who prefers to wrap up for three months of the year so they may enjoy their garden for nine; in other words, somebody who is living in a bigger house that costs more to heat? Will an individual be able to opt not to have personal information shared within local authorities and/or with gas and electricity suppliers?
Turning now to my Amendment 196 in this group, I do not pretend to know anything about the structure, organisation or responsibilities of HMRC. Hence, I do not understand whether an “official” is someone equivalent, say, to a board member in a quoted company. I fear, however, that that is unlikely to be the case. In this era of Facebook, Snapchat and the substitution of public opinion for demonstrable fact, I am unhappy—I do not know whether other noble Lords are—that perhaps a more junior member of HMRC could decide that disclosure would be in the public interest. In other words, where does the buck stop?
Disclosure of personal information, even supposedly non-identifying, should be done only on the authority of the head of the organisation. He or she presumably will have the knowledge, experience and breadth of understanding to be sure that it cannot be combined with other data to name individuals. He or she will also, presumably, be less likely to make errors of judgment, and of course a claim of ignorance of any such disclosure would not stand up to scrutiny, as they would obviously be at the most senior level.
My Lords, I will just pick up the noble Baroness’s last point about who is an official. There are examples, in other legislation, of references to “senior officials” and “designated officials”, which might be somewhere between the junior official she has in mind and the Permanent Secretary, but she is right to draw the issue to the Committee’s attention.
On an earlier group, the noble and learned Lord indicated that he was going to speak at greater length—I assume that may be on this group—on the reason for using the term “personal information” rather than “data”. Perhaps I may use my noble friend’s Amendment 213 to ensure that we get to share more of Government’s thinking. I understand the point about corporations, since in the one case, they come within the group covered, and in the other they do not. But I am still puzzled as to why such efforts have had to be made to deal with personal information and then to add in references to the Data Protection Act, rather than starting from the DPA—with any necessary exclusions—which would have taken us straight to the involvement of the Information Commissioner, the data protection principles and so on.
I wondered during the Statement whether to have a go at some alternative drafting for Report, but thought I had better wait for this discussion. But perhaps part of it boils down to a question on Clause 33(8), which says, in wording replicated elsewhere, that,
“nothing in section 30, 31 or 32 authorises … a disclosure which … contravenes the Data Protection Act”.
To look at it from the other end of that telescope, is there any personal information which is the subject of the Bill that would not fall within the DPA and therefore not be protected by that clause?