Gateway reviews must look at privacy, says Information Commissioner

06 Mar 2008

Comment: 1

A Computing logo
jonathan bamford
Bamford: we do not want government systems to contravene data protection laws

The government is in talks with the personal information watchdog over plans to assess the privacy implications of public sector IT projects before they are launched.

The Information Commissioner’s Office (ICO) wants privacy impact assessments to be part of the Gateway review process, which examines the viability of IT schemes. But the government only wants project-specific controls.

Further reading

Compulsory assessments would save money and reassure the public, said assistant information commissioner Jonathan Bamford.

“We do not want the government to develop systems that may contravene data protection law and cost millions of pounds to put right,” he said.

“And we do not want systems to be developed that will not enjoy public confidence because people feel that their privacy is being eroded.”

Critics claim that technology has moved the privacy goalposts since legislation enabling major projects such as the identity card scheme was passed.

Gateway reviews assess government programmes at five different stages ­ from the initial business case through to looking at the lessons that have been learned from implementation.

Privacy impact assessments could guard against accidental violations because of technical progress, according to Bamford. “The implications of function creep in a project must be assessed before it goes ahead,” he said.

A privacy impact assessment (PIA) is an official ICO process that enables organisations to anticipate and address the likely effects of new initiatives, foresee problems and negotiate solutions.

The Office of Government Commerce (OGC) said the department will consider privacy issues for specific projects, but not as standard. “The use of PIA will be considered by the OGC as part of the evaluation of their risk management practices in appropriate projects,” said a spokesman.

Reader comments

'E. E. Doc Smith' - 'Whatever science can make, someone else can duplicate'

Whatever measures are included in the proposed ID cards to 'ensure' security will instantly become a target for criminals and terrorists around the world.

Any type of identity card, when illegally duplicated, has the effect of legitimising illegal activity.

Ask anyone involved in physical security and they will attest to the fact that in general if someone appears to have a legitimate pass it tends to allay the suspicions of those who are supposed to be on the lookout for criminals and terrorists.

Posted by: Paul Vine  10 May 2009

Have your say on this article

All fields required. Your email address will not be displayed on the site.

By submitting a comment you agree to abide by our Terms & Conditions

Technology Patent Wars

Large companies such as Microsoft, Facebook and Google have been hoovering up technology patents recently. Is this stifling innovation?

88 %

5 %

7 %