Urgent Debates — Social Development, Ministry—Security of Private Information
The fourth and fifth applications are from Jacinda Ardern and Metiria Turei seeking to debate the Government’s failure to protect private information at the Ministry of Social Development. The failure is a particular case of recent occurrence for which there is ministerial responsibility. The requirement of recent occurrence refers to when the member became aware of the matter rather than when it actually occurred. Given the need for public confidence in the Government’s handling of sensitive personal information, particularly at this time when, and in an area where, further shared information systems are proposed, I consider the matter important enough to warrant the immediate attention of the House by way of urgent debate. As Jacinda Ardern lodged her application first, I call on Jacinda Ardern to move that the House take note of a matter of urgent public importance.
I move, That the House take note of a matter of urgent public importance. Every single New Zealander has a right to feel concerned about this massive breach of privacy that has occurred within the Ministry of Social Development. This is by far the worst breach of privacy that I have seen, not just as a member of Parliament but as a citizen. I would bet that every single member in this House would be severely challenged to find a breach more serious than this one. But there is actually some competition for that title. In recent times we have seen breaches by both ACC and the Inland Revenue Department—serious breaches. In fact, ACC in particular grabbed the headlines for a long period of time, and I expect that this breach will do the same. This time we add the Ministry of Social Development to that list.
Unlike ACC, where specific information was sent to an individual claimant, this breach is different. In this breach any member of the public could have walked, and did walk, into a Work and Income office and accessed a publicly available kiosk to view the personal and private information of some of our most vulnerable New Zealanders. It is utterly astounding that that could happen in this country, but it points to a cavalier approach to privacy and to the protection of information by this Government.
The buck has to stop somewhere. It is all well and good for Ministers, time and time again, to stand up and call these issues operational. But the protection of information held by the Government goes to the heart of people’s trust in the State. This cannot be left as an operational matter to public servants. This is a matter very much at the heart of what the Government must be doing and must be held to account for. But we saw today the level of accountability that this Minister wants to take. She was quick to say this was an operational matter, and we will come to whether or not that is a fair claim.
But, first, let us review the background of what has happened in this incident. Recently, an individual who wished to stay anonymous encountered an issue with Work and Income kiosks. Let us be clear about the vulnerability in the system. This individual did not hack into Work and Income systems. Unlike what the Prime Minister and, at times, the Minister have implied, they did not need to know what they were looking for to find this information. They needed to know only how to use a mouse and click it as little as three times. They literally clicked on “open file” in Microsoft Office in order to access this vital and key information. Linking a public Work and Income kiosk system to the main database of the Ministry of Social Development is unforgivable in this day and age. Even the most lay of people when it comes to IT issues would understand that that would be a risk and would put vulnerable people at risk.
The individual who discovered that issue contacted the Ministry of Social Development—it took several days for the Ministry of Social Development to respond to the original call—and the main query they had was, like Facebook or Google, whether it gave any kind of remuneration for vulnerability testing of systems. The Ministry of Social Development responded last Wednesday, but in the intervening period Keith Ng, a blogger and an investigative journalist, had been approached by this individual. Keith took a look himself. What he found was devastating.
Let us start at the top. Firstly, there was contractors’ information: full names, hours worked, pay rates, and pay details for all Ministry of Social Development contract workers, including for media trainers—probably coming in handy at this present time.
Secondly, there were doctor and radiology invoices with full names of candidates for adoption, foster parents, and Limited Service Volunteer candidates—some of our youngest and most vulnerable on Government support. In others, there were invoices from doctors in radiology for X-rays of children in care and protection with their full names and their chief complaint—the cause of their abuse. Some of these were X-rays for injuries and broken limbs.
There was debt collection information. The Ministry of Social Development debt collection unit uses Veda Advantage for its debt collection needs, and when it invoices it includes a list of people who owe it money.
But then there are the invoices that relate most specifically to our most vulnerable children. There were phone bills from Telecom for Child, Youth and Family homes and care and protection facilities. Although some of this information may be publicly available, what would of course not be known is who resides there and the phone logs that were made to those addresses. There were pharmacy invoices, including prescriptions, that identified not only children in Child, Youth and Family care but also the medication they are taking, including antidepressants and, in some cases, cancer-related medication. There were legal bills, which in some cases included historical claims against Child, Youth and Family—obviously, in some cases, for abuse.
The availability of this information is an indictment on this Government and, it has to be said, on this Minister. She may claim, as she has done in the House today, that this was an operational matter, but in 2009 she wrote a letter to Bill English as part of her review finding value for money within her Government department, as all departments did. When she wrote to Bill English she said the following: “Whilst the Ministry has a strong focus on reducing its national office numbers there are also substantial plans to automate frontline services for clients through the use of online and other IT solutions.”—a specific reference to the use of kiosks in Work and Income offices. She went on to say: “I will be monitoring the progress of these plans regularly with the Ministry’s Chief Executive.” Quite clearly, the Minister did not do that. She did not monitor the automation of those services. She did not even follow what the Ministry of Social Development had done in terms of review.
Even the ministry itself undertook external reviews, which found vulnerabilities that this Minister did not even know about. How can she claim that this was an operational matter when she told her own Minister of Finance she would monitor it and, clearly, she did not? She has claimed that it is “disturbing” that her department did not act on vulnerabilities that were identified by an IT analysis. I find it disturbing that she did not act. I find it disturbing that she did not know of such a flaw in her own system.
But let us come to what was happening within information and communications technology within the ministry generally. Let us be clear. The systems were developed in-house. It was not a contracted activity originally. It was done in-house, by her staff and by her team, and the systems were rolled out in 2010. At almost the same time Treasury was asking Government departments to save $130 million per annum on information and communications technology costs. Something had to give and, quite clearly, it did.
There were also contractors involved—this is true. There has been some suggestion that those information and communications technology contractors themselves failed. In fact, the ministry implied that in some of its media conferences yesterday. But now it has retracted and stated that it is not sure, or can no longer be confident, that the ministry even followed up on a report from Dimension Data in April last year, which the ministry paid it $10,000 to complete. It did not even follow up on the flaws that that company identified. Dimension Data raised issues with the Ministry of Social Development. The ministry paid it $10,000 to do that, and then did nothing to follow up the problems it identified. That is an absolute outrage. The fact that this problem could have been prevented and was not is an absolute outrage.
It was not just an information and communications technology company paid by the ministry that found this problem. It has also been raised by a beneficiary advocacy group. Over a year ago it raised with the Ministry of Social Development issues with its system. There are two options. Either the ministry did not act on that information or it simply did not know what it was meant to be looking for. Either way, it is an epic fail, and this ministry has shown that it cannot be trusted with the personal, private information of vulnerable individuals.
But there is another matter that the Minister has referred to in the past week that has now been drawn into this debate, and that is the issue of the White Paper for Vulnerable Children. The children affected by this breach will, in most cases, be the very same children the Minister wants to protect through her white paper, which has been totally undermined by this incident. The Minister’s plan hinges on a database of vulnerable children being established and information shared. She herself acknowledges that faith in the system is critical for this database’s success. In the white paper she said: “While there is much to gain from better information-sharing about vulnerable children and their families, there are also associated risks, including a possible reluctance to use services if there is a perception that information will be shared,”. We have more than a perception that information will be shared. We have a perception now that information will be severely compromised.
She went on to point out that a similar system in the UK was dumped in 2010, in part because of concerns about the security of the system. She states that on the basis of this experience there are four key elements required for this system: social—and in that she lists “trust within and between agencies”—a legal framework, resources, and, finally, “Technical—system capability is part of the solution, but trust (that personal information will be shared when necessary and with the right people) should underpin computer system design …”. She herself has identified the very issue that could bring down the key element of her white paper, and it has already happened before she has even started. Two of the four elements that she says are needed no longer exist.
It is key that we do something to support and assist young children in this country and to prevent young children in this country from being abused, but the Minister has undermined her own ability to achieve that and must rebuild the faith in her department’s ability to hold and use information appropriately. But can this Minister do it herself with the record she has? Not only was external testing not followed up, and not only were public complaints not followed up, but the culture that she presides over through her own leadership is highly questionable.
It was not that long ago that the Privacy Commissioner was directly involved with this Minister over the release of personal details of someone on Government support. She was willing to release someone’s private information in order to deflect from the bigger issue around her leadership of welfare at that time, and she was unrepentant, even saying she would do it again. She has assured the House that she has not given the personal information of the original informant around the vulnerabilities of her system to the media. But we can be utterly forgiven for asking. The Ministry of Social Development advised her office of Ira Bailey’s name on Wednesday. On Thursday the Minister’s own political adviser looked at Ira Bailey’s LinkedIn profile. On Sunday the story broke. On Monday the New Zealand Herald suddenly had the name of that individual, and when so few people knew his identity it is absolutely right that the Opposition asks in order to figure out whether or not the Minister was trying to detract from what is the most pertinent issue here, and that is her ministry’s utter incompetence in dealing with the information of vulnerable New Zealand citizens.
Members of the public will make their own judgment as to whether or not this Minister and her department can be trusted with the information of our most vulnerable citizens. But this Opposition will continue to hold that Government to account for what is clearly a systemic issue and a massive, massive failure.
The public deserves to have full confidence that Government systems are robust and secure. We should all be able to trust that any personal information will not be revealed by human or systems error, and that that information should not be accessible by any unauthorised person. From what we have learnt over the past 48 hours it is clear that the Ministry of Social Development has breached that public trust. I cannot and I will not make excuses. An independent review has been called, and that needs to be given its due process so that we have all of the facts on the table. But I want to say to this House and to the public that it is not acceptable. It is being taken very seriously by this Government, by the chief executive, by the extended Government. I have received an apology from the chief executive, and I certainly have passed that on to all of New Zealand.
The members opposite are calling out. I am not sure whether everyone can hear them out there, but I think that while we are going through the independent review I will give them some of the background on the kiosks themselves, and on how long computers have been in Work and Income, and members might want to note that that goes right back to the late 1990s. So I think we had better be careful as to where we jump to conclusions in terms of where some of it has actually been set up.
There has also been a lot of misinformation, and I know that a lot of people out there are worried about what has been accessed. There are few things that I think need to be set in balance. Core systems were not breached, so people’s individual files as such were not accessible for the public or for anyone who was accessing that system. As the member who spoke before me, Jacinda Ardern, identified, though, a high level of personal information was accessed because of the four servers that were attached to the kiosks as such, or the computers there. Of those four, three were inaccessible and they could not get access to the information, I am told to believe, but with one of them, they could. I also want to make it really clear that they could not stand in the Work and Income office and read that information onscreen. What they had to do was download it, as the blogger did, then take it home and convert it into a readable file. So they were not standing in a Work and Income office as such and looking at it—he converted it down, and then had to take it and convert it into a file that was readable. That is the information I have had to date.
I just want to reiterate—because we have been getting a little bit of that kind of concern, as you can imagine—that at no stage was anyone able to go into the Social Welfare Information for Tomorrow Today (SWIFTT) or Cyras systems, which is where we run Child, Youth and Family. They are quite separate. They are password protected, so only staff can access them, and, actually, the staff have different levels of access to the information within that system, as well. So the blogger was not able to do that.
I am extremely disappointed, and I do not think that this is acceptable in any way, shape, or form. I am going to be as upfront and as transparent as possible, and I will put as much information out there as I can as we work our way through this process. I am happy to answer any questions as I can while also having respect for the processes as we go through the independent review. So just bear with me. It came to my attention on Sunday evening that the blogger had contacted a media outlet saying he had managed to get into the Work and Income systems via the kiosks. At that point I was told that all systems were going to be shut down so that there could be no further access to them, so that access was not possible. The first I knew of it being the actual kiosks was at 5.46 on Sunday evening. Then, as more staff worked overnight on the issue, I was formally briefed when I got to Wellington about 10 o’clock on Monday morning. I think the department’s immediate response to this situation was absolutely appropriate. It took the situation very seriously and moved swiftly to contain what is very obviously a serious security flaw. We demanded answers from the department and we got a few, but, I think, not enough to satisfy the public and certainly not enough to satisfy me. That is why the chief executive has called an independent inquiry, which is going to be run by Deloitte. It is important that the investigation got under way immediately, so it has already started. We should see the results of that within 2 weeks, but the further results are going wider into the second phase of what should be this review. It will take more time, and I think we need to do a scoping expedition first to then give the House a real time line on when we will get that back.
What did come to light last night was that a report was done in April 2011, and from what I have seen of the report it identifies this flaw in the system. What I cannot get answers on, and what I am asking the independent review to look at, is why, how, and when it was acted on—so if it was not acted on, why was it not, and if it was acted on, what has since gone wrong and made the information yet again available. So we are looking backwards, and that will all be investigated. When we discovered that, the chief executive and I wanted to put that out in a statement this morning so that we are quite clear on what we do know and what we do not know. It is been only about 36 hours now, but at that stage it had been only about 24.
I want to give some information about the kiosks themselves, because I do think this is important. What they are effectively, obviously, are computers that people can go into. They predominantly use them to write CVs, to update their CVs, and to job search. So they access the internet and from that they also access Microsoft Word, which is predominantly what they use to do their CVs on. Actually, computers have been available to the public through Work and Income since the late 1990s. The only difference now is that we have put them throughout the offices. Technology has caught up a little bit, and they look different because there is a stand that you stand at. But, actually, if you wanted to use that term, they have been around since the late 1990s. In those early years technology was obviously different, but the computers were more used for typing CVs. Over time Labour when in Government moved them more front of house so they were more easily accessible to the public. Beneficiaries were able to go in and search for jobs. They had been able to do that for years. Some were done in seminars. Most of them were able to go in separately. If you go to different Work and Income offices, you will see that some of them are in a room attached and some of them are in the main body of the building where people also go for benefit advice and income.
This is what happened in July 2010. As I say, the kiosks themselves effectively are a stand that has the computer in it, and the computers have been there for some time. We rented out the kiosks, which would be more front of line, which means that we were having people more self-servicing rather than using up all of the time going to case managers—they could actually access it themselves. In July 2010 they were trialled in six sites and in April the ministry made a business case and made the decision to roll them out. They have rolled out more than 700, I think from memory. So 730 have been rolled out across the country, but that just means we have replaced, in many places, the computers that are there and have put them in the stands of the kiosks.
The Ministry of Social Development has around 1,500 servers. What were visible were five of these, and, as I have said, no core systems were compromised, but I do not want to undermine that a totally unacceptable amount of personal information was available from the server that he could access. As I say, that one server very much failed to have the protections that it should have. As a consequence, all the servers are being looked at. We are checking all of our information and we are making sure that we know where it is and what is happening. As I said, we will work our way through a process here. I cannot change what has happened and I cannot look backwards. All I can do is assure the public that I am taking it very seriously and putting the checks and balances in place so that we can make sure that we have people knowing what is happening. I can give assurances that our review will be robust, that it will be transparent, and that there will be a change.
I will briefly touch on a couple of things that Ms Ardern raised in her speech. One was about Mr Bailey. The information that I have is that he contacted the ministry on Monday, 8 October and he received an answer within a day and a half, and he got a phone call back. As an aside, there has been this kind of innuendo that she makes that my staff members were looking into him. It would be quite common for someone to google someone whose name came up. In fact he looked at her LinkedIn file as well, so I suppose it is quite a common way of looking at each other’s social media. So perhaps the member could give it a go herself. [Interruption] Exactly, it is hardly the scoop of the day, is it? It is quite interesting that the members over there think that it has been leaked and everything else, where, I think, in fact we need to concentrate on what the issues are that are most important here. That is that people’s personal information was unacceptably contacted. They should not have had access to that level of information and that is the fact. I can see Lianne Dalziel yelling out over—
💬 Hon Lianne Dalziel: You should offer your resignation.
Well, should we talk about who should give their resignation? That member had to when she lied in unison, which was the actual reality of it, so I suppose she has personal experience of what that means to lie, but I have not. I have been absolutely factual with this House and that is where it sits. I can understand her anger, but she needs to calm down and have a bit of a look in the mirror—have a bit of a look in the mirror—if that is where she wants to look. As I said, I think this is unacceptable. [Interruption]
The ASSISTANT SPEAKER (H V Ross Robertson): Order!
I am going to stand up and be counted for it and I think that is reasonable. We will make sure that we are getting to the bottom of this situation and ensure that the public know about it.
The revelations of this massive breach of privacy and information and communications technology security failure at the Ministry of Social Development are a very clear indication of both a ministry and a Minister that are prepared to cut corners with scant regard for the privacy of the most vulnerable New Zealanders in this country. We would have thought that all of the Ministers of this National Government learnt the lessons from the debacle that we have seen at ACC, and that they—Paula Bennett, in particular—would call in their chief executive officers and chief information officers and seek assurances from their own people that nothing similar could possibly happen in their departments, and that if there were problems, they would take immediate action to remedy them. Some of those Ministers might have done that, but it is certainly clear that Minister Bennett did not. Minister Bennett learnt nothing from Minister Collins in the ACC breach, from the Inland Revenue Department breaches, nor even from her own disgraceful behaviour in breaching the privacy of two women—two mothers—who just happened to have the gall to disagree with her policy. This is the example that Minister Bennett has set for her ministry. This is not an operational issue; this is a leadership issue. This is a breach far worse than ACC, where human error was a significant factor.
I just want to reflect on some of the things the Minister has said today and in her answers to questions. She talked about how the Ministry of Social Development has breached the public trust and that New Zealanders should be able to trust that no information will ever be revealed intentionally or by error. She talks about how she is so extremely disappointed and how she is committed to a process that is upfront and transparent. But where is her statement, her commitment to zero tolerance for privacy breaches? Where has she locked down and made sure that there will be no such breaches?
She could not do that, because she has no credibility when it comes to privacy issues, because she herself released private information of beneficiaries that she got, I understand, from the computer in her very own office. She got it from that computer in her office, and released private information about the incomes of two women who were solo parents on the DPB, who then suffered very severe public consequences in terms of people who verbally attacked these women and frightened them in terms of the protection and security of their children. Paula Bennett breached the Privacy Act and was found to be in breach by the Privacy Commissioner. Did she apologise to those women? No, she did not. She did not say sorry to the women whose privacy she breached. In fact, did she guarantee that she would never do such a thing again, having been found to be in breach? No, she did not. She did not guarantee that information held by her and her ministry—private information—would never be released.
And now she has the gall to stand in this House and say that she is extremely disappointed with these failures, that she wants to be upfront and transparent, and that no information should ever intentionally be released. Well, this is the Minister who is leading the privacy breaches in her own ministry. She has set the standard for the Ministry of Social Development that it is OK to release any information you like, to not care for the protection of that information, and to have no respect for the people whose information is kept, and that has led to the kinds of breaches that we have seen—not just this recent Ministry of Social Development breach, but also the continual leaks that appear to be coming from her office. She should at least now have a zero-tolerance policy. She does not, which means that all the things that she said in this House today mean nothing and can guarantee nothing for New Zealanders.
This is a systems failure of gargantuan—enormous—proportions. The front door to the Work and Income office was left wide open and anyone—anyone—could walk in and access personal details about the location of vulnerable children in the care of Child, Youth and Family. And the ministry knew that there was that vulnerability. It knew in 2011, 18 months ago—more than that—that there was a problem with this information being accessible and it did not do anything about it.
I think one of the most shocking revelations has been around the information of vulnerable children that has been available. The Minister has gone on and on about protecting vulnerable children. She has gone out and stigmatised beneficiaries in the process of her supposed desire to protect vulnerable children. She has harassed people over the issue of vulnerable children and is punishing people through punitive welfare reforms to justify protecting vulnerable children, and yet her own ministry and her own process are unable to protect even the addresses of the children who have been removed from abusers. The addresses and private information of children who have been removed from abusive households have been available, potentially, to those abusers. Somebody described this as a potential shopping list for paedophiles. That is the risk that Paula Bennett has put vulnerable children under. She has exposed them to that risk. And has she committed to zero tolerance of any privacy breaches? No, she has not, and has herself been guilty of putting other children—the children of other beneficiaries—at risk themselves.
This is an information technology security failure that is so huge that there has been some analysis from Daemon Consulting. Matthew Poole is talking about the fact that the entire Work and Income New Zealand network, and probably the entire New Zealand Ministry of Social Development network, should be considered to be fully compromised, not to mention the Canterbury Earthquake Recovery Authority and the Families Commission, because some of that data was also available through the kiosk. Every server and workstation should now be considered to be accessible and controllable by people who are not employees of Work and Income or the Ministry of Social Development.
Bizarrely, even passwords were available on that information. Those passwords were stored as plain text, so anybody who has access to that file has access to the passwords of who knows how many other computers or files. Minister Bennett, in answer to a question today, said that the reason why this vulnerable kids information database will not be as vulnerable as the current system is that it will be password protected. Well, not if they keep the passwords as plain text on a system that is so accessible, at this point, by who knows whom. That information, that system, will not be at all secure until the entire system at the Ministry of Social Development has been secured, and who knows how long or what cost that will take.
Personal information may have been downloaded, false information uploaded, and existing information altered. There is a very high risk—even higher now—of internal fraud within the Ministry of Social Development as a result of this privacy breach. The Minister has tried to downplay some of the risk in these circumstances. She talks about data and information, but actually we are talking about people’s lives being affected here if there is serious information interference, such as people who are being convicted or accused of fraud, people who may be accused of overpayments on their benefits, and people who may lose access or entitlement to their benefits, possibly because false information has now been placed on the Work and Income files and there is no capacity to tell whether or not that is the case. All of those files are now compromised. It is not just a matter of data; it is a matter of whether those people will suffer the consequences in their daily lives of this failure—the most vulnerable New Zealanders, who do not deserve this kind of treatment. Of course, it is no surprise that it has happened on Minister Bennett’s watch, because she has, as I have said, already demonstrated scant—
💬 Charles Chauvel: It was inevitable it would happen.
Well, my colleague from Labour said it was inevitable that it would happen, because of her scant regard for privacy, and I think he is probably right.
Today we have also had a revelation from the Ministry of Social Development’s chief executive, Brendan Boyle, that in April of 2011 the ministry was informed about the flaws in the information system. Minister Bennett did not take that seriously, and nothing happened. Just last week, when Ira Bailey approached the Ministry of Social Development and did tell it that there was another failure in the system—a whole information security hole at the ministry—what did it do? Nothing. The ministry looked at him; the ministry investigated him. It did not bother to investigate his concern that there was a security breach in the information. It did not bother to go out and find the breach, and now it has been revealed to the whole public. The ministry can take full responsibility for that failure to check, when it had been told time and time again that this risk was present.
It has also been revealed that Ira Bailey’s name was leaked to the media, and again Minister Bennett has taken no responsibility at all for the consequences of the leak. In fact, she is so blasé about privacy breaches she said today she is not going to bother to find out whether or not her office leaked that name. That is her attitude. Her attitude is one of disgraceful disregard for the rights of New Zealanders. She does not deserve to be the Minister for Social Development if that is the kind of leadership that she is showing to New Zealanders. Thank you.
This is yet another case of the Government failing in its most basic duty to protect the rights of ordinary New Zealanders. If the Government collects, as it has in this case, important and personal information, and records that information, then it clearly has a duty of care to make sure that that information remains confidential. That is the basic function that has been breached in this case. There can, this time, be no excuses. There have been far too many occasions within Government agencies when breaches of privacy have occurred in just this first year of this term of this Government. First of all, we had ACC, we had the Inland Revenue Department, we had Work and Income, and now we have this. When is it going to stop? It cannot be allowed to go on and on and on.
Work and Income, in this case, has breached the public trust. It is not something that the public of New Zealand should let go past without protest. It is totally unacceptable. I listened to the Minister for Social Development and her apology, and I listened to her explanation today. I heard terms such as that some individual files were not breached, but one was. Well, what has that got to do with anything? It does not matter how many files are breached. It does not matter what information was obtained that should not have been obtained. It is not good enough, whether it is a lot or a few. I heard that only “a high level of personal information was accessed”, and that, of course, really does not matter either, because it is perfectly clear that important personal information was available through the department’s own facilities.
I also heard the Minister talk about being “disappointed” in the performance of the department, concerning these breaches of privacy being “not acceptable”. But what we really did not hear from the Minister was whether she was taking any personal responsibility for this, and whether she was actually going to make sure that nothing of this kind would happen in the future. Quite frankly, what I heard from the Minister was a totally inadequate response to such a serious issue.
The flaws in the department’s kiosk system should have been identified by any number of in-house or external reviews. I am making the assumption that in this department, like other departments, there are robust in-house reviews and there is a robust system of auditing as to the performance of privacy provisions within departments. I did not hear from the Minister any words about that, and I would like to know, and I am sure the public would like to know too.
In fact, we do know that in April last year the Ministry of Social Development paid for a report by Dimension Data, and it actually did expose a number of flaws in the system. Why did the Minister not talk about that? Why did the Minister not say what those flaws were? Why did the Minister not explain what has been done about those flaws? Or is she just not interested? Quite frankly, that is the impression I get, not just from this Minister but from this Government as a whole. It seems to be deeply and comprehensibly disinterested in the protection of the privacy of individuals in this country, in respect of their personal information.
Nothing whatsoever has happened about that particular review. We are left, in this case, with yet another example of a Government agency, clearly inadequately staffed and inadequately funded, where those high up in the hierarchy are merely going through the motions and ticking boxes, and they are not, in fact, making sure that the privacy of people is genuinely protected. New Zealanders deserve a lot better than that.
Under this Government we have, of course, seen a whole litany of these kinds of omissions. First amongst them was ACC, and we eventually had the resignation of a Minister. We have had breaches of privacy in the Inland Revenue Department, and now we have Work and Income. You have to ask: where is it all going? What is going to happen next? What will be the breach of privacy in what department or what agency next month? It cannot be allowed to happen. The only way that this Parliament can make sure it does not is to hold Ministers accountable. That, in fact, is what it is there to do. Ministers are responsible to this Parliament.
What I have heard from this Minister is just this: that she does not think this is so serious that she should have done a lot more about it. As a result, we have a comprehensive lack of trust in this Government by the public generally. When you heard the debate earlier today during question time, and some of the things stated by the Prime Minister, you would have had to ask yourself as an ordinary New Zealander whether you could have trust in him as the Prime Minister of this country. When you think about the performance of Mr John Banks in this House concerning the issues that have concerned him in recent times, as an ordinary New Zealander you would have to ask, basically, whether you could really have trust in that particular Minister. I do not think many New Zealanders would be prepared to answer in respect of either of those cases that they have full trust in those Ministers. As I have already said, we have already had a resignation from one Minister, Mr Nick Smith, and that came back to trust as well—trust in doing things properly and in accordance with correct procedures.
What we have with this Government is a culture of mistrust. There is a disconnect between the trustworthiness of this Government and the expectations of the people in this country, or what they should be. I have a number of questions to ask as a result of all this. First of all, the most obvious question of them all: where is the ministerial responsibility? Where is the accountability? This sort of thing has happened far too often—in far too many departments—and the Government just glosses over it. Well, it is time for this Minister to stand up and be counted. It is time for this Minister to resign. It is time for her to go. This issue is that important, and it cannot be allowed to go past. She should now really consider her situation. Why has she not demanded the resignation of her chief executive? That should also be called for.
In the end somebody has to take responsibility. It is not good enough for this to be glossed over once again. Why does nobody in this Government ever take responsibility for anything? It is always “Smile and spin your way out of these situations.” It is never “Let’s take responsibility.” This is the way it should be. That is what the expectation of this House must be—for that Minister to resign.
I am somewhat pleased to stand and take a call on this issue. I am not pleased, because there is absolutely no argument in this House that this security breach is appalling, and there is damage that has been done as a result of this breach. What I do find objectionable, though, is that members in this House stand here and say that they have not heard the Minister come to her feet and explain in some detail exactly what has happened. Instead, what do they do? They go into emotive language, and scaremonger about information that may have been made public. That is what I find offensive. The Minister stood here 10 or 15 minutes ago very clearly fronting this issue. She stood here, fronted the issue, and said she would make information available as it comes to her. She read an apology from the Chief Executive of the Ministry of Social Development.
I am impressed. I am impressed with how quickly, when this serious breach came to light, and how rapidly those kiosks were shut down. So as soon as the threat was identified, it was shut down. And then not even 2 days later—not even 48 hours later—not only is there an independent review under way but also the consultants, Deloitte, have been appointed and they are under way.
So there is no debate. There is no debate that this is a serious breach. But what there is a debate about is the fact that this side of the House fronts up, deals with issues as they go wrong, and focuses on the problem—not petty politics, not scaremongering, and not scaring the New Zealand public. I mean, it is an absolute joke that on Sunday morning, that member of the Opposition, Jacinda Ardern, went on television to say that she would support perhaps some of the issues in the White Paper for Vulnerable Children, but not even 48 hours later she is using this to attack those same children. And here we have another party suggesting that paedophiles would use this information as a shopping list. That is despicable. That is absolutely despicable language in this House. There is a breach. We recognise that. The Minister and the chief executive have got onto it. They are dealing with it. So what is important now is that this issue is taken into focus, and that it is looked at in every level of detail possible to ensure that it does not happen. This is a problem. We are not saying it is not. The Minister stood there 15 minutes ago and fronted up with some detail about what information was potentially accessed. She talked about how absolutely mortified she was that there had been a breach. So for that side of the House to then use it to attack the very constructive work in the White Paper for Vulnerable Children, which over 10,000 New Zealanders have contributed to, is despicable.
This is a Government that is focusing on what is important. It is focusing on what is important to New Zealanders. I am not going to stand here and have criticism of a Minister who I believe is the most courageous Minister for Social Development we have had in this country. Is she going to sit back and let generations rot on benefits? No, she is not. She is taking the hard calls. She is reforming the system that that side of the House did not have the guts to deal with. She is dealing with the issues of fraud. Constituents in my electorate—
💬 Chris Hipkins: I raise a point of order, Mr Speaker. I did not interrupt the member immediately, because I was expecting you to interrupt her. The member cannot accuse other members of the House of lacking guts.
💬 Mr DEPUTY SPEAKER: Well, technically the member is right. Generally, we apply that ruling when the word is referring to an individual. It was used in general terms. In my view, it is inappropriate, and I would just ask the member to desist.
As I was saying, this is a Government that is focusing on what matters to New Zealanders. What matters to New Zealanders is having a system of welfare that supports those in need, and recognises that work is the best opportunity for families and children. We are taking the hard calls to protect the most vulnerable in this society, not playing petty politics with them like that side of the House.
The member who has just resumed her seat, Louise Upston, accused members on this side of the House of trying to distract attention from the true subject matter of the debate. Well, that is actually what she just did in the final couple of minutes of her speech. What this is all about is whether or not we have a Government that can guarantee the security of data that it holds on behalf of New Zealanders. Plainly, it cannot.
Just have a look at the examples that have occurred over the last couple of months. We had in September the Inland Revenue Department breaching the privacy of 30 people. At the same time, in the 2 weeks ahead of the tax return deadline 70,000 phone calls to the Inland Revenue Department went unanswered, and it has $7 billion worth of tax yet to collect. This is a department that needs decent IT. It is being starved of decent IT. The Minister of Revenue in perpetuity, apparently, the Hon Peter Dunne—he has been the Minister now for 7 years—seems to have no urgency in his mind about addressing this. He says there is a plan to upgrade the Inland Revenue Department’s systems over the next 10 or so years. Well, who knows how many privacy breaches there will be over that time?
And then there is ACC. The Privacy Commissioner recently examined how the private information of 6,748 people was sent to Bronwyn Pullar with ACC’s compliance. It is just mind-boggling that that could occur. The independent inquiry into ACC on that occasion found “such an error was more likely to occur because of systemic weaknesses within ACC’s culture, systems and processes.” Then, of course, Bronwyn Pullar’s details somehow miraculously made it into the public domain. It is only necessary for me to quote the former president of the National Party, Michelle Boag, who said: “When you can’t send a communication to a Government minister without fearing that the privacy of that communication is going to be breached, that’s very, very dangerous.” That was Michelle Boag in the New Zealand Herald on 28 March.
Then we come to the departments that are within the responsibility of this Minister. In 2011, 10 Work and Income staff had to be sacked after two inquiries into breaches of privacy. Seven staff were dismissed for appalling breaches, including sharing information with family members, and three were sacked after a second inquiry for breaching the so-called zero-tolerance policy that was in place at that department. Well, some zero-tolerance policy! Then in September 2012 Work and Income sent a client’s private details to another client. Someone’s one-page application was included in a pile of papers the client received at the meeting. When the client rang Work and Income to report it, the client was asked to just destroy the document. Then in August 2012 there was a further breach. A woman who was absolutely vigilant about her safety was called at home by a man who said he was conducting a survey to ascertain whether she was happy with her experience with Work and Income. He knew her name and had information about her. She had never consented to the release of that information. That is the record of this Government on protecting privacy and keeping data secure.
In answer to the previous speaker, the reason why members on this side of the House have real issues about the sincerity of this Minister on this issue can be summed up when we look at the way that she dealt with the privacy breach in relation to Natasha Fuller. The Human Rights Commission found that Paula Bennett breached that woman’s privacy. She was asked whether she would do the same thing again and she said: “it would depend on the circumstances”. The Prime Minister backed her to the hilt. That is the culture of compliance that we have under this Government. The apology that we heard that was read out by the Minister cannot be taken seriously, because of the Minister’s form and the handling of this issue: blacken the names of the people who reveal the breach, say that they were after money, and leak their identity to the media.
We have got a real issue here. We have got a Law Commission report on privacy half implemented. We have got another Law Commission report on the Official Information Act, which is inadequate. Nothing less than a royal commission into the security of the way the Government holds the data of individual New Zealanders is going to be able to fix this problem. If we do not see it from this Government, we are going to see it, hopefully, through a member’s bill, because I am certainly keen to see one drafted to bring about that reality.
I think the Minister for Social Development has done all that she could in the last 48 hours or so since learning of this appalling breach of privacy. No one is arguing that it is anything other than just that. For the Opposition to say that the Minister is insincere I think does obscure the problem that we have to deal with here. It does make it very personal, when in fact the reality is that this is something that could have happened to any Government at any time. It is not unique to the current circumstances. If members are realistic and honest about it, they will accept that these systems have been in place for a very long time, and, therefore, have had some of the vulnerabilities that have occurred, or come to light, I should say, in the last several months. What it does indicate is that we are now living in a world where a great deal of our information is held electronically, not just by State agencies but by many private sector agencies as well. Very few people would write cheques these days, for example, preferring to do everything by electronic means. It is simply the world that we live in. That does not excuse the appalling breach of security that has occurred inside this system. I am very, very certain that the Government wants to get to the bottom of this particular issue and to sort it out.
I am also very much in admiration of the Minister for being so upfront in saying exactly what it is—an appalling breach of private security—and not trying to create any degree of obfuscation through various excuses that might have previously been offered by other Ministers, and I speak about Ministers from other Governments in the past. The reality is that the Minister has done all that can be done at this point and continues to supervise a programme that will fix this problem. Mr Chauvel calling for a royal commission on this shows, I think, that he has not thought through exactly what he is asking for. This is an issue that is not necessarily confined to the State sector. It is one that could well affect the private sector. Indeed, there are some very interesting cases before the courts at the moment about privacy, about breaches of privacy, and about the way in which people’s individual intellectual property, in fact, is dealt with, as well. We live in an age of increasing electronic activity. We live in an age where all of these things do need to be well looked after, and the commitment from the Minister and from the Government is to sort this matter out.
It gives me no pleasure to speak on this motion. I think I share the sentiments of all those in the House here today when we see a security breach where private information has obviously been put in the public domain unnecessarily. That situation is unsatisfactory and it is disappointing. I am sorry that this has happened. But it is about taking leadership and action, and this Minister—and I stand to support this Minister, Paula Bennett—has fronted with the chief executive, she has fronted to this House today, answering all the questions that have been put to her, and she will continue to fight for vulnerable children and she will continue to fight for the truth in this matter. And the truth is that at this point in time no one knows. I do not know what happened and how this information became public. Lianne Dalziel does not know what happened. Across the floor here, the Green and the New Zealand First members do not know what happened. But there is an independent investigation that is being carried out, and no stone will be left unturned in order to get to the truth of the matter. We hear cries from the Opposition of royal commissions of inquiry and we hear cries for resignations, when what is required here is calm, what is required here is leadership, and what is required here is restraint, in order to get to the bottom of these matters.
So I stand to support the Minister, I stand to support the independent investigation that is going on, and I stand to support the reforms that this Government is doing in the area of social development. That includes welfare reforms, in terms of streamlining those reforms. It includes the white paper reforms that the Minister clearly outlined last Thursday. It includes reforms to help the vulnerable, the poor, and those in need. So I am not happy to speak on this motion, but I am certainly here to say that this Government is doing everything in its power to get to the bottom of this case, to get to the truth, and to ensure that in future, systems will be put in place in order for us to protect and safeguard the private information of our citizens. It is about the confidence and trust in our Government, and that is what is being done. Thank you.
The very last sentence that the member who just spoke, Peseta Sam Lotu-Iiga, said was absolutely true. This is about the confidence and trust New Zealanders can have in their Government. There are some questions that all New Zealanders will be asking around this release of private information. How did it happen? Who knew or should have known about the situation? When did they find out, and, when they found out, what did they do about it? Those are very legitimate and reasonable questions for every New Zealander to be asking.
So how did this happen? It actually starts back in 2009. There is a paper trail that starts back in 2009, when Bill English wrote to Ministers in the incoming National Government and asked them what they were going to be doing to save money. One of the questions that he asked them was around what they were doing with regard to staff numbers. Of course, let us consider that in context. The context is that at the time the unemployment rate was going up, the economy was in a downward spiral, and there was clearly going to be more demand on Work and Income staff to provide front-line services.
What was Paula Bennett’s response to that? Paula Bennett’s response to that was to say—and I am quoting directly from a paper that Paula Bennett has signed off—that “Whilst the Ministry has a strong focus on reducing its national office numbers there are also substantial plans to automate frontline services for clients through the use of online and other IT solutions.”, i.e. the kiosks in the office. She stated: “I will be monitoring the progress of these plans regularly with the Ministry’s Chief Executive.” So how did this begin? How did those kiosks come to be in the Work and Income offices in the first place? The Minister made a conscious decision, in the context of rising unemployment, that rather than employ more people at the Ministry of Social Development to deal with that challenge and to provide support to the people who were going to be coming into the Ministry of Social Development and into Work and Income offices, she decided that she would put computer terminals in the offices instead. It was a conscious decision by the Minister that resulted in this problem.
Who knew or should have known is the next question that we then come to. Who knew or should have known? Should the Minister have known about this? When they decided to implement this IT solution by putting kiosks in the front-line offices, with access to databases, did the Government Communications Security Bureau get asked about that, and did it provide advice to the Government? If it did not, why not? That is actually its job. That is what the bureau is there for. Members of this House all have electronic devices that have restraints placed on them by Parliament on the advice the Government Communications Security Bureau. This is its job. It proactively goes in, looks at the IT systems of Government departments, and places requirements and restrictions on the use of those IT systems. So when it did this, when the Government decided, on Paula Bennett’s direction—it is in her letter here—that it was going to put kiosks in Work and Income’s offices rather than employing staff to deal with people, and to allow people access to its IT system, did it get the bureau involved, and did it check to make sure that its system was going to be robust? If it did not, then Paula Bennett has some serious questions to answer about that, because she is the Minister responsible and this system was implemented under her direction. It was her initiative. She is responsible for it.
The next question then becomes “When did they find out?”. Taking aside how we got here, when did they find out and what did they do about it? The kiosks were rolled out in 2010, and they were told in April last year that there were potential vulnerabilities within the system. So the question is what happened then? What happened then? When the Government found out there were potential vulnerabilities in the system, what happened then? That was April last year—that is a year and half ago—so why is it that this problem was not identified and fixed at the time? Beneficiary advocates reportedly told the Ministry of Social Development 1 year ago that there were issues with this problem. Again, why was it not looked into at the time? Why was it not fixed at the time?
On Monday last week the Ministry of Social Development became aware of the problem—on Monday last week. It took it until Wednesday to tell the Minister that there was this problem. That is a problem in itself. Taking 2 days to tell the Minister that there had been a serious breach of privacy is not good enough. That is the first problem. So Paula Bennett found out on Wednesday. It was Sunday, when a blogger released all of the information online, before it became public. I want to know what Paula Bennett was doing for the 4 days in between. What did Paula Bennett do last Wednesday when she found out about this, and why was it that people could still access that on Sunday? That is simply not good enough, and the public of New Zealand should be able to expect better from Ministers in this Government.
What did Paula Bennett do? Did she have her officials into her office straight away to find out what was going on? Did she contact the Government Communications Security Bureau at that point, knowing that this is the bureau’s fundamental job? Did she contact it at that point? I will tell you what: if Ministers find out that their departments’ databases containing private information about New Zealand residents and New Zealand citizens have been accessed inappropriately, and they do not immediately require some action to investigate what is going on and to make sure the problem is shut down, then they are negligent. They are totally and utterly negligent. Paula Bennett found out about this on Wednesday—last Wednesday. Yet Sunday, when it became clear on the blogs, was the first the public knew about it—late on Sunday night. Paula Bennett had that information for 4 days, and what did she do? What inquiries did she launch? What steps did she take to make sure that databases were shut down or sealed off until she knew that they were secure? Four days is a long time. A hell of a lot of information can be accessed in that time, and a heck of a lot of damage can be done in that time—4 days.
It is now over a week since the Ministry of Social Development found out about this situation and we are debating it in Parliament, the public having found out about it only yesterday, a week after the ministry was first informed about it. Why is that? Why did it take a week before the public found out about it? In that week, were any of the people whose information was accessed informed that their information had been accessed? If information, for example, was accessed—and I am only going on reports here—about children living in safe houses, what steps were taken as soon as the Government knew that that information had been accessed? What steps were taken to protect those people?
These are legitimate questions that the Government must front up and provide answers for. This is not good enough. This is a serious breach, a release of information involving some very vulnerable people, and for the Government to take a week to reveal that to the public is simply not good enough. For the Minister to sit on this information for 4 days is simply not good enough. The public is entitled to expect better.
To come back to the very first point that I made and to pick up Sam Lotu-Iiga’s point, this is about trust and confidence in the Government, and if its handling of this situation is any guide to go by, the public cannot have any. They cannot have any trust and confidence that the Government will take their private and personal information, treat it carefully and responsibly, and make sure that it is not released for purposes that it was not collected for. Trust and confidence in the Government will be seriously eroded by this, not just by the fact that it happened, not just by the fact that it happened because of Budget funding cuts, not just because the Government sat on it when it found out about it, but because the Government, when it did find out about, did not do what it should have done. It has been negligent, and the Minister has been negligent in her handling of this situation—full stop.
I can say, I think, with a reasonable amount of credibility that I am one of only a few members in this House who made my living developing computer systems before I came to Parliament. Yes, it was actually prior to the internet coming to New Zealand.
💬 Hon Lianne Dalziel: I was going to say, I thought you were a bit old.
Even so, there were communication systems on the airline system that allowed people to hack into the mainframes of stuff we developed. Whenever an issue like this occurs, I think the Minister has, in the words of that great Led Zeppelin song, “two paths you can go by”. You can either try to hide, obfuscate the issue, justify what happened, and so on, or you can do what I think Minister Bennett has done absolutely admirably, and that is to be open, admit there is a serious issue, actually move heaven and earth to try to identify what the issue is, and fix the matter urgently. I want to say to the member Chris Hipkins, who has just finished his speech, that his facts were wrong. Yes, Minister Bennett on Monday was alerted that there was a risk to information. But that alert did not say where it was or what it was, but just that it was an unknown risk that needed some identification.
💬 Chris Hipkins: But what did she do?
The member has just now played beautifully into my hands, because the Minister got KPMG to start trolling through the Ministry of Social Development’s systems to find what it was that could be the risk and where it could lie. I am told that KPMG did not come back to the Minister until Sunday, identifying that it was the kiosks. For that member to be standing in this House today and saying that the Minister knew back on Monday and let a whole week of all this exposure go on without her doing anything is just factually incorrect. What the Minister did was to get KPMG immediately. It can happen to any one of us. Just about every Minister in the Government has departments that have information held on their departments’ computers.
God knows, on 5 March next year Statistics New Zealand, one of my ministries, will collect incredible information in the census about individuals. I have gone out of my way to ensure that that stuff will be protected and kept safe and that no individual records will be made available. But Minister Bennett did exactly what she should do. And I want to say to members on the other side of this House that it is quite possible that these sorts of security breaches occurred while they were Ministers. It is quite possible that people would have been into the systems and seen information, but it did not quite get to be as exposed in those days because there were not things like bloggers around who felt it was really neat to get some coverage for blogging that stuff.
💬 Hon Trevor Mallard: When we were Ministers?
Yes. Blogging came into fashion only just towards the end of the Labour Government. Blogging has been around only 4 or 5 years now. It was not around in the early 2000s. I want to remind this House that we did not even have the internet in New Zealand 20 years ago. It came in only in 1993, and we are in 2012. So it is not yet 20 years for the internet.
So Minister Bennett did exactly the right thing. When you come to be the Opposition, there are, again, two paths you can go by. You can start screaming and yelling and blaming the Minister because she allowed a security breach in a computer system, or you can actually demand that she take action to identify what the issues were, to make sure they are being fixed immediately and that any security holes in the system are being closed off, and to identify a regime that will prevent any such failures in the future. And, again, I believe that is what Minister Bennett has done beautifully. She has actually gone in to identify what matters are at risk in the system and so on. If it is any member of this House’s advocacy that the Minister should know there is a security hole in some hardware/software networking, then I tell you that you are wrong. I tell you that you are wrong because I can tell you that it occurs even at the highest echelons of information technology—for example, Microsoft, probably the world’s biggest developer of information technology systems, has every now and then had to put out an announcement that it found a security hole in its Internet Explorer, or it found a pinhole in the back of some internet protocol of one particular product, and it has had to put out a fix, otherwise people would be able to breach the firewalls and breach the internet protocol, and so on. So to any member of this House prepared to get up and say that Minister Bennett should have somehow been crawling underneath the computers, pulling out all the internet cables and the ethernet plugs, and checking the IP addresses and what protection there was, I say that what Minister Bennett had to do was rely on her department giving her an assurance that when it brings a system into the market place like it did, it puts those protections in place.
But these sorts of things can and will happen again. They will happen even when there is another Government in this country in years to come as more and more information gets put online, as more and more sophisticated systems are out there, and as more and more sophisticated hackers find ways to go through some form of a click-box server in the Ukraine, come back via a pinhole in the firewall somewhere, and pick up stuff. What does that mean? Well, we could actually shut up shop and not put any information on the internet at all. We could go back to parchment and quill pens and go back to the old days, and I am sure there are some people around who think we should do that. But the rest of the world is moving on to putting its information on to information systems where they have phenomenal value, where people can go and read stuff, and so on. But, having said all that, there will always be risks. I hear, I think it was, Chris Hipkins say that we should have got the Government Communications Security Bureau in, but even the Government Communications Security Bureau will not be able to identify every hole in every piece of software wherever. Only when that hole or that security risk is found should the actual Minister, the department, the computer people, KPMG, and whoever else move heaven and earth to fix it, and that is what has gone on here. I actually ask all members of this House, especially from the Opposition, to be a bit careful about what they are advocating. I am happy for them to advocate that Ministers should step up to the mark and demand to find out how this happened. I am happy that she steps up to the mark and demands that immediate action is taken to close off the loop in it. I am happy that she demands—
💬 Hon Lianne Dalziel: Leadership on privacy!
I am hearing something from Lianne Dalziel about privacy. Paula Bennett, like every other member of this House, believes truly in the need for privacy for individuals. No one in this House wants privacy breaches of information to be out. This was a failure of an information technology system. I look at stuff that I have rolled out of my ministry. I look at things like SmartGate and the taking of photos as you come through customs and whether there may be a breach in that. I have asked and asked, I have been assured, and I have gone and had a look at it, and I am quite confident that there is not. But if anyone ever identifies a breach in that, I can assure you that, like Paula Bennett, I will move heaven and earth to close down the risks, to shut down that system, and reopen it only when I am confident that we have found that particular bug.
But I finish as I began: big issues can occur even across the most sophisticated developers in the world, and huge companies with billions of resources have identified those risks. Well, the Ministry of Social Development got this wrong, Paula Bennett has said so, and Paula Bennett is fixing it. I think we should be very proud to have a Minister of her calibre.
The debate having concluded, the motion lapsed.
🗣️ Spoke in this debate (10)
- Dame Rt Hon Jacinda Ardern (New Zealand Labour Party — List Member)
- Hon Paula Bennett (New Zealand National Party — Member for Waitakere)
- Hon Gerry Brownlee (New Zealand National Party — Member for Ilam)
- Charles Chauvel (New Zealand Labour Party — List Member)
- Hon Chris Hipkins (New Zealand Labour Party — Member for Rimutaka)
- Hon Peseta Sam Lotu-Iiga (New Zealand National Party — Member for Maungakiekie)
- Lockwood Smith (New Zealand National Party — List Member)
- Metiria Turei (Green Party of Aotearoa / New Zealand — List Member)
- Hon Louise Upston (New Zealand National Party — Member for Taupō)
- Maurice Williamson (New Zealand National Party — Member for Pakuranga)