Thursday, August 06, 2009

Questions over security of ID database

Mark Pack links to this item in Computer Weekly, which reports that nine staff have been sacked from their local authority jobs for snooping on personal records of celebrities and personal acquaintances held on the core database of the government's National Identity Scheme.

The report says that they are are among 34 council workers who illegally accessed the Customer Information System database, which holds the biographical data of the population that will underpin the government's multi-billion-pound ID card programme.

They also provide some details on the breaches by council workers:

What is especially worrying is that they say that this may just be the tip of the iceberg. Many of the breaches were discovered after sample checks, raising concerns that other breaches may gone undetected.

It seems that over 200,000 government officials have access to the database, including staff at 480 local authorities, and numerous government departments, including the Department of Work and Pensions, HM Revenue & Customs, and the Courts Service. The Child Support Agency uses the database to trace missing parents.

Clearly, this project amounts to more than just a collection of information to back up an ID card scheme. It is being used widely for a large number of applications and possibly being linked to other databases as well. With so many people having access to it there must be huge concerns about security and confidentiality. The Government needs to start providing more assurance on that aspect whilst at the same time being more open and transparent about how the data is being used.

A level of oversight to provide accountability is essential in my view. It cannot be right that this sort of database is administered from behind closed doors without those on it having the ability to check the information it holds on us and how it is being used.


well its reported to the journos when its celebrities...if it was yer average tom, dick and harriett (which i am one of ) it would not get anywhere near newspapers...just in the ether of pubchat. All u goota do is figure out who the press/info team is on councils, work out there routine and where they do there piss ups and listen over there shouldders...
There should be no love, but the love of Big Brother....
It is clear that not enough is done in induction training of local governemt staff to inculcate a culture of respect for privacy and security of personal data.
