(4 years, 7 months ago)
Commons ChamberI am always happy to encourage free association of workers. It is part of who we are as a civilised society. The hon. Lady represents the great city of Durham, so many of her constituents will be public sector workers in Durham prison and Frankland high-security prison, which is not too far away. We should value that ethos of public service, wherever it comes from, and I am sure she will join me in paying tribute to those CRC members of staff—we hope they will make the transfer to the NPS—who have been serving the public diligently, even though they have been in the so-called “bad” private sector.
The Secretary of State may not wish to talk about ideology, but will he reflect on morality? Does he think it is morally right to make private profit out of incarceration and rehabilitation, because I do not?
(4 years, 10 months ago)
Commons ChamberKeeping the public safe from harm is the first duty of any Government. The terror attack in Streatham earlier this month sadly demonstrated that sentencing laws were not working as they should. People’s lives were being put at risk by the automatic early release of terrorist offenders without scrutiny by the Parole Board. Now that the Terrorist Offenders (Restriction of Early Release) Bill has passed all its stages in both Houses, convicted terrorists will serve at least two thirds of their sentence before being considered for release.
The introduction of emergency legislation is not a step that the Government would ever take lightly, but the law was not working and we had a responsibility to act. I am pleased that this House agreed with that assessment and we were able to get the new law on the statute book as a matter of urgency.
Since 2010, the Conservatives have cut more than a third of all funding to local authorities’ domestic and sexual violence services. I have constituents coming to see me who are in shelters for months or even years because the facilities are not there. When are the Government going to bring forward the domestic abuse Bill, which has cross-party support, so that we can give justice to victims?
The hon. Gentleman will be glad to know that we intend to bring that Bill forward very soon indeed—well before Easter—so that we can debate it. He made a point about local government services; no doubt, he will have welcomed the announcement on the local government settlement that was made yesterday. He will know from his own experience of local authorities, as indeed I know from my local authority, that choices can be made to offer direct assistance. For example, with women’s shelters and refuges, decisions on non-domestic rates can help the funding of those services. Important decisions were made about how homelessness and housing support was given to make sure that the interests of those centres were put first and foremost, because they are not just shelters but places of rehabilitation and support.
(5 years ago)
Commons ChamberMay I welcome my hon. Friend to this House? He and I have known each other for a number of years and have campaigned together, and he will make an outstanding advocate for the people of Broxtowe. With regard to the issue of television licences, we believe that there is a case to examine decriminalisation. About one in 12 cases in the magistrates courts are taken up with television licence default. We want to consult on the matter, take evidence and see whether there is a better way forward.
(6 years, 1 month ago)
Commons ChamberUrgent Questions are proposed each morning by backbench MPs, and up to two may be selected each day by the Speaker. Chosen Urgent Questions are announced 30 minutes before Parliament sits each day.
Each Urgent Question requires a Government Minister to give a response on the debate topic.
This information is provided by Parallel Parliament and does not comprise part of the offical record
It is very easy, in the eye of a storm, to cast caution to the winds and throw away sensible and well worked out convention. This is not the time for us to do that.
May I express my sympathy for the Solicitor General, who has been sent out today to defend the indefensible and take one for the team? May I also say, however, that responsible government means respecting the will of the House? How on earth can the Government ask the House to support the withdrawal agreement if at the same time they show contempt for a previous major decision that the House has made?
The hon. Gentleman is a reasonable man and an honourable Member. I ask him to listen carefully to the Attorney General, to read the documents—as I know he will—and then to reach a judgment after the next sitting day, when he will hear in full the legal basis for the Government’s decision.
(6 years, 2 months ago)
Commons ChamberDealing with illicit finance through the prosecution of money laundering offences is a priority for the Crown Prosecution Service and the Serious Fraud Office. Prosecutors have not identified any specific concerns regarding the effectiveness of prosecutions under the Proceeds of Crime Act 2002. We continue to use the Act, as it has evolved, to good effect.
I have a constituent who has been convicted, I believe wrongly, for fraud. Despite the prosecution accepting that he made no financial gain whatever from the allegations, the SFO went after him and his wife, who is entirely unconnected. Does the Solicitor General think that is fair and what possible avenues for redress do I have for my constituents?
I am grateful to the hon. Gentleman for raising the case. It would be invidious of me to comment on a particular case. I will simply say that there are different mechanisms within the Act that allow the pursuance of criminal proceeds. It might well be that in that case another mechanism is being used, but I will be happy to look at it further and write to him.
Royal Assent
(8 years, 8 months ago)
Public Bill CommitteesI am grateful to my hon. and learned Friend, who is right to pray in aid that subsection, which sets out the bones on which we flesh out the procedure in the code of practice.
I am getting a bit confused. My understanding was that these provisions applied only to communications service providers. I think it was the hon. and learned Member for Edinburgh South West who raised the question of Apple, which to my mind is not a communications service provider, but the Minister responded in the same terms. Will he clarify who exactly we are talking about and who the provision is intended to cover?
The hon. Gentleman is right to make that important point and to steer us back on to the straight and narrow. I am not criticising the Committee for trying to bring the Bill to life with some examples. We are indeed talking about communications service providers, not third parties, which is important in the context of the Bill.
(8 years, 8 months ago)
Public Bill Committees(8 years, 8 months ago)
Public Bill CommitteesI am delighted to see you back in the Chair, Ms Dorries, as I break my couple of sessions’ silence; it is always very reassuring. I certainly do not wish to keep the Committee here all night, but I will reiterate a point that I made earlier in our considerations, and that relates to the retention of certain data. As my hon. and learned Friend the Member for Holborn and St Pancras pointed out, we understand the need for data retention. However, on looking at the Bill, I am still not entirely satisfied that the Government have taken into account the need for additional security for data retention.
I look to the Minister for reassurance that, when telecommunications and internet providers and suchlike are obliged to retain data, there is a consequent obligation on them to maintain it securely. We know that several such providers have problems with internet security: we saw that with the TalkTalk hack, and we believe another large provider has been hacked recently. Those attacks were on personal data; the Solicitor General and I have had exchanges in this room about the potential for charging them as theft—about whether the sanctions against somebody who committed that offence would be contained in existing legislation.
This part of the Bill needs to look at obliging or maintaining a minimum acceptable level of security, to provide security and privacy for people whose data may have been accepted. I realise that it might not necessarily be covered in detail in the new clause, but now might be a good time for the Ministers to consider whether they believe internet security and the security of personal data held under the terms of clause 79 should be considered in the Bill. Do they believe guidance should be given to telecommunications providers to maintain that security, or do they feel that it is not relevant and that they are quite satisfied with the status quo? I must say that I am not. Notwithstanding the need for the retention of individual data, as described so eloquently by my hon. and learned Friend, it remains a major concern of mine that individual privacy and data are at risk: it puts a question mark over the whole clause and over the areas we are discussing.
I am grateful to hon. Members for a wide-ranging debate. I would first like to reiterate on behalf of the Government the position adopted by the Joint Committee on the draft Investigatory Powers Bill, which quite clearly indicated its conclusion that the case was made for a retention period of up to 12 months for relevant communications data. In the report from David Anderson QC, “A Question of Trust”, recommendation 14 is:
“The Home Secretary should be able by Notice (as under DRIPA 2014 s1 and CTSA 2015 s21) to require service providers to retain relevant communications data for periods of up to a year”.
There we have it: the Government are acting upon the specific endorsement of an independent reviewer and a Joint Committee of this House. There is an element of the waving of the proverbial shroud when it comes to the retention of data, because the word “relevant”, which is contained in the second line of clause 78(1), is the governing word here. It is very important to remember that this is not carte blanche for the Secretary of State to authorise communications service providers to retain everything for 12 months. That is not the case. Where there is no case of necessity and proportionality for a 12-month period, a shorter period must be adhered to. Indeed, if the material is not relevant, it falls outwith the ambit of any such authorisation.
I reassure the hon. Member for City of Chester, who makes quite proper points about the integrity of data, that he is right to make them. That issue affects all those in this room and beyond. He is also right to allude to the criminal law. I reassure him that communications service providers have to comply with the Data Protection Act 1998 and the Privacy and Electronic Communications (EC Directive) Regulations 2003, which together contain those requirements that the data is appropriately secured. When he has the time—which I am sure is as precious to him as it is to the rest of us—chapter 16 of the draft communications code of practice contains an entire set of provisions relating to the security, integrity and, indeed, destruction of retained data, which very much underpin the principles of why CSPs have to operate and will give him the reassurance that he properly seeks about the position with regard to individual data and people’s privacy.
Data retention legislation has existed in this country since the Anti-terrorism, Crime and Security Act 2001, which allowed the Secretary of State to enter into voluntary agreements with telecommunications operators so that they could retain data that otherwise would be deleted. The Data Retention (EC Directive) Regulations 2007 were the first piece of data retention legislation that provided for the Secretary of State to require the retention of such data. We currently have DRIPA 2014 and the data retention regulations of that year. We hope to replace those with the provisions in the Bill. A very important point is that there is nothing new about these proposals. Our data retention legislation has always had the Secretary of State involved in the process and there are very good reasons for that. It has worked successfully until now. As I have indicated, it has been recommended to us by David Anderson.
The amendments that have been tabled seek to drive a coach and horses through all of that. There is a simple and blindingly obvious reason why we wish to maintain the system of data retention. For example, when a crime happens or a child goes missing, it is impossible to know in advance which data would be relevant in any subsequent investigation. It is therefore important that we require the retention of all relevant communications data that matches a certain description wherever it is necessary and important. Because it is impossible to know which data will be the most relevant in advance of any crime, it is impossible to know whether a specific piece of data will be of value to MI5 in locating a terrorist, for example, or to the National Crime Agency in identifying a paedophile, or for any other legitimate purpose. For that reason it does not make sense for those authorities to apply for retention warrants individually. What makes sense is for the requirement of all relevant public authorities to be considered together. The person best placed to do that is the Secretary of State. Public authorities set out their requirements for data retention to the Home Office and they are then carefully considered. As they usually overlap, the Secretary of State is able to identify the specific telecommunications operators and specific data types that it is necessary and proportionate to make subject to data retention notices. As the full costs of data retention are covered by the Secretary of State, only he or she can decide whether or not the benefits of data retention are proportionate to the costs.
There has been some discussion about cost again today. The £170 million figure is based on the cost of our anticipated implementation, which takes into account data that is already obtained under existing legislation. We noted the evidence of BT when it talked about the costs being dictated by its implementation approach, and we continue to discuss implementation with those communication service providers likely to be inspected. Whatever the final cost, however, the important underwriting by the Government is a vital factor in giving reassurance to the industry, not only on the practicability of these measures, but on the importance therefore of involving the Secretary of State.
My worry is that if we went down the road proposed by the amendments, we would end up with a rather confused system that would not allow for the overall benefits of retaining a particular type of data, because the judicial commissioner would only ever be able to consider the benefits to the particular public authority applying for a warrant. It would therefore be impossible to judge the overall necessity and proportionality of requiring a particular company to retain a particular dataset.
We have heard about new clause 10 and its provisions. Given that it is impossible to predict in advance what data would need to be retained, this approach relies on data being retained only after a crime has been committed and/or an investigation has begun. Preservation only works if the data are there to preserve and it is of limited benefit without an existing retention scheme. Without data retention, data protection rules require that the data that are no longer needed for business purposes must be deleted. Without data retention, the data that are needed would not exist. Therefore, the regime of warrantry—the double lock, indeed the proposals put forward by Opposition Members—none of it would matter, because the material would not be there. That is particularly relevant when it comes to the increasing move of criminals and their ilk away from conventional telecommunications to the internet and internet connections.
A number of reports published by the EU Commission show the value of communications data and why the concept of data preservation, as envisaged in new clause 10, is not a viable alternative. In a Europe-wide investigation into online child sexual exploitation, of the 371 suspects identified here in the UK, 240 cases were investigated and 121 arrests or convictions were then possible. Of the 377 suspects in Germany, which does not have a data retention regime, only seven could be investigated and no arrests were made.
I have explained why the existing data retention regime that the Bill replicates is the appropriate model. May I deal with the change proposed by a set of amendments that involve changing the word “may” to “must” in clause 78(2)? That would require a data retention notice to cover certain issues. I am sympathetic to the aim of the amendment, because I am in favour of specific requirements, but the amendment is misconceived because subsection (7) already requires that a retention notice must specify the operator to whom it relates, the data which are to be retained, the period of retention, the requirements and restrictions imposed by the notice, and information on costs. Subsection (2) sets out the scope of what a notice may require and subsection (7) requires that the notice must make clear what is required. The two subsections are therefore aimed at different things.
The effect of this amendment would be to require a notice to cover issues that it might not have any reason to cover. For example, a retention notice may
“make different provision for different purposes”.
With respect, it therefore does not make sense to say it must make different provision for different purposes, because a notice may not relate to those different purposes. I would argue that there is therefore nothing to be gained by moving these amendments. That is all I wish to say, but for those reasons I urge hon. Members to withdraw the amendments.
I beg to ask leave to withdraw the amendment.
Amendment, by leave, withdrawn.
Clause 80 ordered to stand part of the Bill.
Clause 81
Data integrity and security
Question proposed, That the clause stand part of the Bill.
I seek the Minister’s guidance. Throughout our considerations, I have spoken of my fears whether data held under this Act are held securely. I hope that clause 81 will address many of my fears; I seek the Minister’s advice on whether it lays responsibility on communications providers to maintain those data securely. I simply reiterate my concern that when theft does take place, there has to be a consideration of an offence of unlawful possession of stolen data, on the basis that the communications provider that has suffered the theft would also be legally responsible for that theft when the provider is in fact a victim of the theft itself. Bodies that seek to obtain illicitly a person’s private communications data may try to make financial gain as a result. Is the Minister confident that clause 81 gives me the kind of assurances that I have been looking for on internet security? Is there sufficient deterrent, in terms of possession of unlawfully obtained data, that might be included later in the Bill?
The hon. Gentleman has been consistent in stating his concerns. I assure him that clause 81 contains the sort of requirements that he would reasonably expect. It sets out the matter clearly. It should be read in conjunction not only with other legislation that I have mentioned, such as the Data Protection Act 1998 and the Privacy in Electronic Communications Regulations 2003, but with clause 210, which provides for the Information Commissioner to audit the security, integrity and destruction of retained data, and the codes of practice to which I referred earlier. The provisions in the communications data draft code of practice go into more detail about the security arrangements.
We had a discussion some days ago about the existence of adequate criminal legislation. The Bill has a number of provisions that relate to those who hold data, and we discussed whether existing legislation could cover those who come into possession of the data unlawfully. I say to the hon. Gentleman that I will take the matter away and consider it, and come up with a proper considered response to his query.
Question put and agreed to.
Clause 81 accordingly ordered to stand part of the Bill.
Clauses 82 and 83 ordered to stand part of the Bill.
Clause 84
Enforcement of notices and certain other requirements and restrictions
(8 years, 9 months ago)
Public Bill CommitteesI am extremely grateful to my hon. and learned Friend. She is quite right. In fact, not only is there the offence of misconduct in public office, as it is now constituted, having been reformed from the old offence of misfeasance, but we have provisions in the Wireless Telegraphy Act 2006, the Computer Misuse Act 1990 and, as I have already mentioned, the Data Protection Act 1998. I therefore consider that the new offence we are introducing in clause 9, combined with relevant offences in other legislation, in particular the provision in section 13 of the Data Protection Act 1998, provides appropriate safeguards. On that basis, I respectfully invite the hon. and learned Lady to withdraw the amendment.
It is, as always, a pleasure to see you in the Chair, Ms Dorries. The Solicitor General has given examples of wide-ranging powers that are available to protect the public. I was grateful to listen to his contribution. However, during Second Reading I queried the Home Secretary’s position on the new offences that are being created. Many of the offences the Bill refers to, particularly in clause 9, relate to the regulation of investigatory powers. My concern is that later the Bill requires internet service providers, for example, to amass a large amount of personal data, and there is a danger that those data may be stolen rather than intercepted. I gave the example of a newspaper perhaps finding a low-grade technical operator in a telecommunications company, passing a brown envelope to them and stealing a celebrity’s internet connection records. I am concerned that the offence in clause 9 of unlawfully obtaining communications data does not go far enough.
I bear in mind the Solicitor General’s comments on other protections that are available, but would he or the Government consider an offence of not just obtaining but being in possession of unlawfully obtained communications data, which would strengthen the protections given to members of the public? We all know that the kind of scenario that I am expressing concern about has not been unknown in the last few years, as various court cases have demonstrated—though I should not discuss their details. Is the Minister satisfied that the protections he has outlined and those raised by the hon. Member for South East Cambridgeshire are sufficient, or should we take this clause a bit further, to give the public broader and wider protection of their privacy and the security of their internet and telecommunications transmissions?
It is a pleasure to follow my hon. Friend because I want to develop the point. This is a welcome clause, it is right that it is here, and we support it. However, we question whether it goes far enough. It only covers obtaining communications data. We think that serious consideration should be given to an overarching offence of misuse of the powers in the Bill. At the moment, there are specific provisions in relation to intercept which are replicated frim RIPA and we now have this welcome provision, but there is no overarching offence of misuse of the powers in the Bill.
It is all very well to say that there is the tort of misfeasance in public office. That is not the equivalent of a criminal offence. It has all sorts of tricky complications when one tries to apply it in practice. It is fair to say that there are other bits of legislation that might be made to fit in a given case, but it would be preferable and in the spirit of David Anderson’s approach for a comprehensive piece of legislation for an overarching criminal offence to be drafted, either out of clause 9 or in some other way, relating to misuse of powers in the Bill. It has been a source of considerable concern in the past and I ask the Government to think about a wider offence that would cover all the powers, because comms data are only one small subset of the issues and material information we are concerned with.
I have two short supplementary points. In subsection (3) there is a reasonable belief defence. It would be helpful if the Minister said a bit more about that. May I also foreshadow the inconsistency that we will need to pick up as we go along in the way reasonable excuse and reasonable belief are dealt with in the Bill? It is set out in subsection (3), but there is an inconsistency in other provisions that I will point to when we get there.
My other point is to ask the Minister to consider whether obtaining communications data unlawfully is a sufficient definition to make the offence workable in practice. I put my questions in the spirit of supporting the clause, but I also invite Ministers to go further and consider drafting a clause that covers the misuse of powers in the Bill, rather than simply saying that if we fish about in other bits of legislation or common law we might find something that fits on a good day. In my experience, that is not a particularly helpful way of proceeding.
I am grateful to my hon. Friend, who served with distinction on the Joint Committee. That provision relates to creating a statutory duty, which, with respect to her, is slightly different from some of the arguments we are having about criminal sanctions. However, it is important to pray that in aid, bearing in mind the mixed approach we need to take in order to hold public office holders and public authorities to account when dealing with this sensitive area.
The Bill provides a great opportunity for us to put into statute a new offence, which will, together with the other agencies, provide a robust regime that will add to the checks and balances needed in this area in order to ensure that our rights to privacy are maintained wherever possible, consistent with the Government’s duty towards the protection of our national security and the detection and prevention of crime.
I am grateful to the Solicitor General for that clarification. My concern about his reliance on, for example, the Data Protection Act is what happens in the scenario I described, which I do not believe is so unbelievable, bearing in mind the experiences that hon. Members of this House have had in the past few years with the theft of their information. One problem that his solution presents is that if, for example, my personal data were stolen and published, the only recourse I would have is to the telecommunications provider, which is in a sense a victim itself. The real villains and culprits—the people who stole the information and published it—would not be covered by the Data Protection Act, which is why I seek consideration of extending the clause or guidance from the Solicitor General.
I hear what the hon. Gentleman says. I have already indicated that I will consider the matter further. I will simply give this solution. He mentioned the stealing of information. Information is property, like anything else, and of course we have the law of theft to deal with such matters. I do not want to be glib, but we must ensure we do not overcomplicate the statute book when it comes to criminal law. I will consider the matter further, and I am extremely grateful for his observations.
Question put and agreed to.
Clause 9 accordingly ordered to stand part of the Bill.
(8 years, 9 months ago)
Public Bill CommitteesQ You could still handle those investigations and deal with them, but when it was apparent that they are of a sufficiently serious nature you can involve the police, who are then able to make the applications on your behalf, so you would not need access under the terms of the Bill.
Mark Astley: It is a valid point, but I believe that the powers are there for the trading standards, who do a really good job, and they have done an excellent job so far in dealing with high-level crime.
Q In the last year for which records are available, which I think is 2015, about half a million applications for access to comms data were made. About 0.4% of those were local authority applications.
Mark Astley: That is correct.