News: 1657608909

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK Info Commissioner slams use of WhatsApp by health officials during pandemic

(2022/07/12)


The UK Information Commissioner's Office (ICO) on Monday issued a reprimand and called for a review of how and whether messaging services should be used for government business practices, after finding widespread and potentially dangerous use of private email, WhatsApp and other messaging tools by officials at the Department of Health and Social Care (DHSC).

The actions ordered by ICO came after a year-long investigation as to whether the DHSC was compliant with the UK General Data Protection Regulations (GDPR), the UK Data Protection Act 2018 and the Freedom of Information Act 2000 during the COVID-19 pandemic.

The investigation was sparked by July 2021 complaints concerned with the potential loss of information from public records due to communication practices that used tools not managed by the Department.

[1]

According to the ICO [2]report [PDF], confidentiality and security of personal data was put at risk by use of privately operated comms tools.

[3]

[4]

"This investigation has found failings at DHSC in compliance with both transparency and personal data protection obligations," wrote information commissioner John Edwards.

"There was extensive use of private correspondence channels by Ministers, and staff employed by DHSC. Evidence more widely available in the public domain also suggests this practice is commonly seen across much of the rest of government and predates the pandemic," declared the ICO in its online [5]summary of the report's findings.

[6]Cookie consent crumbles under fresh UK data law proposals

[7]Health trusts swapped patient data for shares in an AI firm. They may have lost millions

[8]Clearview AI fined millions in the UK: No 'lawful reason' to collect Brits' images

[9]Tech pros warn EU 'data adequacy' at risk if Brexit Britain goes its own way

The next review, the one regarding practices, will identify systemic risks, areas for improvement, and ways to be more consistent in communication approaches across departments. It will also include a look into what issues might have been specific to the pandemic.

The ICO said it has ordered the DHSC "to improve its management of Freedom of Information requests and address inconsistencies in its existing FOI guidance."

[10]

The [11]reprimand [PDF] issued to DHSC orders the Department to improve its data handling processes and procedures, per the requirements of the UK GDPR. It states the DHSC has violated processing operations related to storage limitation, integrity and confidentiality, security of processing and more.

Although the ICO is taking a hard stance against the use of non-formal communication, it does go some way to recognize that its creeping prevalence in the public service might just reflect the times.

"It is important to stress that the ICO does not take the view that the DHSC, and public bodies in general, should never send information containing personal data to private communication channels," argued director Steve Eckersley in the ICO's reprimand to DHSC. He went on to explain that communications with personal data must, however, adhere to UK data protection law.

[12]

Eckersley said it was understandable to use private correspondence channels during the pandemic, but the lack of oversight inherent to the communication methods presents risks.

Edwards echoed the sentiment in the official report, stating "the pandemic placed extreme demands and stress on our public services" and that it was "understandable" some ministers and officials relied on "new technologies to make their work and their lives more manageable." But Edwards also said new or alternative comms technologies do not relieve anyone of data security and transparency obligations.

"This is not solely a product of pandemic exigencies. But rather a continuation of a trend in adopting new ways of working without sufficient consideration of the risks and issues they may present for information management across government over several years preceding the pandemic." ®

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ys1GQirGNjOKteVOJ830@AAAAAI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://ico.org.uk/media/about-the-ico/documents/4020886/behind-the-screens.pdf

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ys1GQirGNjOKteVOJ830@AAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ys1GQirGNjOKteVOJ830@AAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2022/07/behind-the-screens-ico-calls-for-review-into-use-of-private-email-and-messaging-apps-within-government/

[6] https://www.theregister.com/2022/06/17/cookies_crumble_in_uk_data/

[7] https://www.theregister.com/2022/07/06/sensyne_nhs_deals/

[8] https://www.theregister.com/2022/05/23/clearview_ai_ico_fine/

[9] https://www.theregister.com/2022/05/17/uk_eu_data/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ys1GQirGNjOKteVOJ830@AAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://ico.org.uk/media/about-the-ico/documents/4020887/dhsc-reprimand.pdf

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ys1GQirGNjOKteVOJ830@AAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



Potemkine!

To sum it up, all these ministers and officials gave all these potentially sensitive data to MetaFeckbook.

Those guys who are in charge of taking care of the People have an idiotic behaviour and the IT knowledge of a 11yo kid. They don't listen to any security advice. That isn't a surprise, but it's sad nonetheless.

hitmouse

They gave their data to everyone. If they used WhatsApp or Facebook Messenger then the transmitted images land in local phone storage where they are freely available to any backup provider plus random image app vendors

we all know one big reason

tiggity

Was so that dodgy dealings / info passing to their mates was outside recorded official channels

It's not about "getting things done", its about hiding activities from legitimate scrutiny.

Re: we all know one big reason

Anonymous Coward

I don't know why you've been downvoted when this is quite obviously why they've been using whatsapp

Perhaps we have a Blojo fanatic lurking amongst us.

Re: we all know one big reason

Tom7

This is just paranoid conspiracy-theorising.

Go have a good look at the data protection practices of your average NHS trust. Use of WhatsApp for staff communication - including discussion of patient information - is absolutely rampant. It's a data protection and management nightmare but no-one seems to be doing anything to rein it in. This has come from the bottom up, not the top down.

I'm personally aware of two cases where a whole ward were required to join a WhatsApp group and a member of staff used the resulting access to personal phone numbers to stalk other members of staff. Nothing can be proved because he deleted all the conversations from WhatsApp soon after they happened and no-one thought to screenshot them.

Re: we all know one big reason

Dan 55

It's very probably IT ineptitude down at the hospital, [1]it's certainly not in any government department .

[1] https://www.opendemocracy.net/en/opendemocracyuk/what-is-uk-government-hiding-on-whatsapp-we-have-no-idea-thats-the-problem/

"a review of how and whether messaging services should be used for government business practices"

Pascal Monett

This is just preparing the road to another trough where billions will be spent for a "government-secure messaging system" which will never actually see the light of day.

Mark my words.

wobball

Corruption of the highest order is why they used it, obvs! The UK Govt already had secure comms in place but they were monitored so not fit for their purpose! So they decided to use a meeting platform that routed via middle earth along with this wotsapp farce where it was always obvious it was 'cos they are corrupt, to the highest order.

J.G.Harston

A lot of it is bone-headed users, managers, controllers, directors who think: I scream from the rooftops to chat with my kids and mates, of course I also scream from the rooftops to chat with staff colleagues about confidential patient data.

Filippo

Every now and then, government officials may be using private comms in order to hide unsavory activities.

However, you really don't need to go looking for conspiracies. In the vast majority of cases, they do it simply because it's slightly more convenient, and they - much like the general public - are either unaware or uncaring of the resulting privacy issues.

The thing is, we, as a society, really do not have a culture of privacy. I do make an effort to protect my privacy, and I think so do most people who read TheRegister's comment pages. But the vast majority out there? They say they want privacy, but only if they don't have to lift a finger for it.

I mean, they barely tolerate having to click an "I Agree/Disagree" button on a website, an action that literally only takes the lift of a finger. Switching messaging app? Nope. Logging in to your secure email? Not even on the table. IMHO, it will take decades before people really understand what privacy means.

Never attribute to malice that which can be attributed to laziness, stupidity or ignorance.

tiggity

@Filippo

They are public servants

That applies to MPs and the civil servants who they work with in parliament.

Arguably the most important people in the country in terms of how they can affect what happens.

With such power there should be full accountability, activities must be transparent and open to full inspection / audit.

.. Yes there will still be circumvention (e.g. easy to avoid digital & use non audited "paper" messages & judicious use of shredders), but it should be made as difficult as possible to get up to "secret" activities.

I'm a "nobody", but everything I do at work is recorded (various forms of approved communication only to be used). Any local / cloud data gets checked to make sure no data is stored in the wrong place or beyond time allocated to work with it & that its purged ASAP. That's all just for GDPR compliance (as, for my work I sometimes need access to third party PII)

.. so it wouldn't hurt the people running*our country to embrace audit culture given some of the massively sensitive information they have access to.

With the current near zero transparency then unsurprisingly a lot of people assume corruption everywhere. Personally I think there are some MPs with a bit of integrity but the corrupt chancer element seems to have increased markedly over the years (or at the very least become less hidden).

* opinions may vary on how good a job they are doing

Debug is human, de-fix divine.