{"id":39308,"date":"2022-07-13T04:30:00","date_gmt":"2022-07-13T04:30:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/39308"},"modified":"2022-07-13T04:30:00","modified_gmt":"2022-07-13T04:30:00","slug":"ico-calls-for-review-into-government-use-of-private-email-and-whatsapp-messages","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=39308","title":{"rendered":"ICO calls for review into government use of private email and WhatsApp messages"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/07\/ico-calls-for-review-into-government-use-of-private-email-and-whatsapp-messages.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Ministers, special advisers and government officials used private email accounts and messaging services, including WhatsApp, to share government advice, raising concerns about privacy and data protection, the information regulator has found.<\/p>\n<p>The use of private messaging services, which appears to have become \u201ccustom and practice\u201d across government, also raises questions about the government\u2019s compliance with the principles of freedom of information, a <a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2022\/07\/behind-the-screens-ico-calls-for-review-into-use-of-private-email-and-messaging-apps-within-government\/\">report<\/a> by the Information Commissioner\u2019s Office (ICO) found after a year-long probe.<\/p>\n<p>In an unprecedented move, the regulator <a href=\"https:\/\/ico.org.uk\/media\/about-the-ico\/documents\/4020887\/dhsc-reprimand.pdf\">reprimanded<\/a> the Department of Health and Social Care (DHSC) following the investigation into ministers\u2019 and officials\u2019 use of private email, WhatsApp and text messaging services for government business.<\/p>\n<p>It warned the department that if there were further incidents or complaints in future, the ICO may consider formal regulatory action.<\/p>\n<p>The probe followed complaints from Covid victims that ministers, including former health secretary Matt Hancock and senior government officials in the health and social security department, had used private messaging services to make \u201clife and death\u201d decisions during the pandemic.<\/p>\n<p>Information commissioner John Edwards this week urged the government to review the use of private email and messaging services after concluding that they were likely to be widely used for <a href=\"https:\/\/www.computerweekly.com\/opinion\/Move-with-the-times-in-defence-of-WhatsApp-in-government\">communication across Whitehall<\/a>.<\/p>\n<p>\u201cI understand the value of instant communication that something like WhatsApp can bring, particularly during the pandemic where officials are forced to make quick decisions and work to meet varying demands,\u201d he said.<\/p>\n<p>\u201cHowever, the price of using these methods, although not against the law, must not result in a lack of transparency and data security.\u201d<\/p>\n<p>Ministers and non-executive directors at the DHSC were making regular use of private communication channels, which included exchanges with companies offering PPE and Covid tests during the pandemic.<\/p>\n<p>The health department disclosed that ministers and officials had used 29 private WhatsApp accounts, 17 private text message accounts, eight private email accounts and one private LinkedIn account for government business.<\/p>\n<p>The ICO has asked the Covid-19 Public Inquiry to update its terms of reference to look at the quality of record-keeping by the government during the pandemic.<\/p>\n<p>The regulator said that even if the use of private communications channels was thought necessary at the start of the pandemic, it was concerning that the practice was still continuing with little oversight a year later.<\/p>\n<section class=\"section main-article-chapter\" data-menu-title>\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i><\/h3>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Confidential data shared\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Confidential data shared<\/h3>\n<p>Messages send by DHSC officials and ministers contained personal data, including names, contact details and information relating to individuals\u2019 work.<\/p>\n<p>A few emails sampled by the ICO contained special category data, including medical information, and a reference to an individual\u2019s political party membership.<\/p>\n<p>The ICO also found evidence that people in the DHSC had used private emails, rather than official government systems, to send restricted information.<\/p>\n<p>The DHSC lacked appropriate security controls over the use of private emails and messaging services, which created \u201can unnecessary level of risk\u201d, the ICO found.<\/p>\n<p>The department had not carried out any risk assessments and did not know where data, including some restricted information, was being stored, or whether it was being held in the UK.<\/p>\n<p>The failure of ministers and executive directors to exchange information on the DHSC network introduced risks including inappropriate access to government information, risks to confidentiality, and the risk that data could be lost, including information relevant to the long-term public record, the regulator said.<\/p>\n<p>\u201cThere were no steps in place to monitor, assess or otherwise check the use of third-party platforms,\u201d said the ICO report.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Freedom of information\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Freedom of information<\/h3>\n<p>The ICO found there was \u201cclear evidence\u201d provided by the DHSC that ministers were regularly copying information from their private accounts to government accounts in order to maintain a departmental record of events.<\/p>\n<p>However, the ICO said it would have been \u201csensible\u201d for the DHSC to put in systematic ways to capture information for the public record, even if it was as simple as requiring staff to copy emails into official email accounts.<\/p>\n<p>Instead, ministers were expected to review \u201csignificant volumes of material\u201d in their private email and messaging accounts to decide what information they should forward to their departments, the report found.<\/p>\n<p>But the scale of use of private channels of communication suggested that \u201con the balance of probabilities\u201d, there was a risk that \u201cmistakes may have been made by individuals in preserving parts of the public record during a historically significant period\u201d, the ICO said.<\/p>\n<p>\u201cWe consider it surprising that for such a prolonged and busy period, a more efficient process with reduced risk to information management was not put in place that would also reduce the potential impact on ministers\u2019 time,\u201d it added.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Call for government review\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Call for government review<\/h3>\n<p>The ICO has called for the Cabinet Office to carry out a strategic review into the use of private communications channels across government, and to identify the risk they pose.<\/p>\n<p>The ICO said the UK was \u201carguably out of step\u201d with countries such as New Zealand and Canada, which have updated their statutory requirements around the creation of government records. Northern Ireland and Scotland, for example, have introduced legislation creating a government duty to document information and decisions.<\/p>\n<p>There has been a \u201ccultural drift\u201d across \u201csignificant pockets of the public sector\u201d in the UK towards taking advantage of the benefits of new communications technology \u2013 without a strategic appraisals of the risk, said the regulator.<\/p>\n<p>Also, there has been no system-wide consideration of the measures that government may need to mitigate the risks.<\/p>\n<p>\u201cThis is not solely a product of pandemic exigencies, but rather a continuation of a trend in adopting new ways of working without sufficient consideration of the risks and issues they may present,\u201d said Edwards in a foreword to the report.<\/p>\n<p>The regulator\u2019s recommendations include keeping records of all individuals \u201cpermitted\u201d to use private emails and messaging services, and clear processes to capture information, for example when individuals leave quickly during reshuffles.<\/p>\n<p>Other measures could include strengthening ministerial and civil service codes to make clear the responsibilities of officials to maintain public records and ensure compliance with information rights law.<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Ministers, special advisers and government officials used private email accounts and messaging services, including WhatsApp, to share government advice, raising concerns about privacy and data protection, the information regulator has found. The use of private messaging services, which appears to have become \u201ccustom and practice\u201d across government, also raises questions about the government\u2019s compliance with [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":39309,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-39308","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/39308","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=39308"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/39308\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/39309"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=39308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=39308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=39308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}