Electronic Data Safety Bill
I move, That the Electronic Data Safety Bill be now read a first time. I nominate the Commerce Committee to consider the bill. New Zealanders need to have the utmost confidence that their personal information held by the Government is secure and private. There have been numerous and very high-profile incidents in recent years that have shaken that confidence. The establishment of an Electronic Data Safety Commission, which is what this bill does, will help restore confidence.
This should not be a partisan issue. Every member of this House understands the need for privacy and security of information in conducting their role as an MP. We must ensure that the information the State holds regarding members of the public is treated with the same care and respect we expect the information we deal with as MPs to be treated. We must ensure that the electronic systems used are robust, resourced, modern, and regularly audited. But there is a growing body of evidence that this is not the case. If the Governmentâs intention today is to vote against this bill because it claims that the numerous issues with data security over recent years are minor, isolated incidents and that they have been addressed by a few internal appointments, then I ask that the Government put that claim to the test by establishing the Electronic Data Safety Commission to reassure the public.
There is a widespread perception that personal data is not safe with the Government. If that perception is misplaced, then this commission will show that. The Privacy Commissionerâs 2014 annual survey of the public showed that 63 percent of them rate their level of concern about the privacy of their information as high and that this number has remained very high over recent years. The Privacy Commissionerâs office gets notified of an increasing number of data breaches every year, the vast majority in the public sector. In the 2013-14 year, the total figure was 113, up from 16 in 2008-09. Of those, 86 were in the public sectorâacross the Government, and in the hospitals and other health agencies. These are important breaches, and they are significant.
Almost a year ago the previous Minister of Justice, Judith Collins, announced significant changes to the Privacy Act that would give the Privacy Commissioner more powers to compel public and private sector organisations to report privacy breaches. In May 2014 Judith Collins said it was vital that New Zealanders have confidence in our privacy laws and that people know that their information is in safe hands. She said she was going to introduce legislation for the mandatory reporting of data breaches, with new offences, increased fines, enhanced powers for the Privacy Commissioner, and various other things. That was nearly a year ago, and that legislation is not even on the Order Paper. Where is it? Well, a little birdie tells me that it might have got lost. That is a significant worry, and I ask the current Minister of Justice where that legislation is.
There are fundamental concernsâfundamental concernsâabout IT governance and accountability, as well as the wider Government attitude to privacy that have got to be addressed. The National Government must answer for a long line of recent privacy breaches that include breaches at ACC, the Ministry of Social Development, the Earthquake Commission, Housing New Zealand, the Medical Council of New Zealand, Immigration New Zealand, and, most recently, the Ministry of Justice. Two other very recent privacy breaches include the Southern District Health Board, labelled incompetent after accidentally sending the private health details of 60 patients to a member of the public. In January this year a privacy breach blunder resulted in the personal details of more than 600 females, some as young as 13, who had had abortions in the central North Island being given to Fairfax Media. These are recent occurrences. These have not been dealt with.
This is systemic. Today I revealed in question time that there are deeply concerning high-level risks identified within the Department of Internal Affairs, which Peter Dunne is the Minister of, that are leaving Government networks vulnerable to attack, including security controls that are not functioning, a lack of ability to investigate malicious activity, and insecure information being transmitted over the Department of Internal Affairsâ cloud provider networks and other cloud provider networks. But the Minister has denied that under his watch any Government system has gone live without accreditation from the New Zealand Institute of Safety Management and sign-off from the Chief Executive of the Department of Internal Affairs.
Well, you would think the Government would have learnt from Novopay. You would think it would have learnt from the bungles. It is my understanding that there have been IT systems going live without accreditation and without sign-off. They include the âDesktop as a Serviceâ cloud-provider networks. Many vendor systems are either insecure, accessed by foreign nationals locally, accessed by contractual agreements with third parties overseas, often with poor sanitation of data, or all three of those together. These are extremely important, significant issues happening right now in one of our most important Government agencies. John Key has been consistently blasĂŠ in the face of recurring privacy breaches. There is a distinction between one-off mistakes and a systemic, widespread privacy problem that is not being resolved.
The commission of inquiry in my bill is needed because more and more personal information is being collected electronically by the Government, and we need to ensure that guidance and proper rules are set in place to protect the privacy of New Zealanders in an increasingly sophisticated environment. I know that many members on the Government side claim to take data security and the privacy of the public very seriously. Well, now we get to see whether they live up to their rhetoric by supporting this bill.
National should vote for this bill because this bill will assist the Government in achieving one of its Better Public Services targets. Target 10 is that âAn average of 70 per cent of New Zealandersâ most common transactions with government will be completed in a digital environment by 2017.â The number is currently at 46 percent. To lift this to 70 percent by 2017, New Zealanders will need to have greater confidence in the security of their transactions. A commission that assesses the problems with data security and recommends solutions can only help the current Government in achieving this target. It would be somewhat perverse for the Government to vote against this bill for purely partisan reasons when it actually helps it achieve one of its stated election promises.
Peter Dunne should support this bill. The Minister of Internal Affairs claimed today in question time that he believes that New Zealandersâ personal information is being managed securely in his department. Well, he needs to vote for the bill to prove that this is the case. He originally pledged to support this bill, as you heard in question time, but that was before he got caught out leaking confidential documents to the media and then attempted to mislead the public about that. After he was stood down as the revenue Minister, a few months later he wasâwithout any hint of ironyâappointed as Minister of Internal Affairs, responsible for data security. Well, if Mr Dunne wants to have any credibility, he should be up here today voting for this bill to show that there is probity and that there are proper processes happening within his own ministry.
David Seymour, the ACT member for Epsom, in his maiden speech spoke of liberty and of improving public policy so that âfree individuals may flourishâ. Well, surely if Mr Seymour is going to be true to his libertarian beliefs, he must vote for this bill to ensure that the State is handling the information of private individuals, which is the private property of those individuals, in the most appropriate and careful manner. Voting this bill through to select committee is the first step, so that we can receive public submissions on the security of data and discuss how the effectiveness of the commission could be improved. We owe it to the public to ensure that their personal information is treated with the respect it deserves.
I would like to begin my contribution on the first reading of the Electronic Data Safety Bill in the name of the Labour Opposition member Clare Curran by congratulating her on actually having her bill drawn. However, I have to start by saying that I do not support this bill.
This bill proposes to establish a special commission of inquiry. Clare Curran often talks in this House about technology and how fast technology is actually moving, but this bill refers to privacy breaches in 2012. I guess that is the nature of membersâ bills. When she actually wrote the bill it was related to the privacy breach in the Ministry of Social Development back in 2012. This is also about privacy breaches within Government agencies, the capacity of Government agencies to manage and hold personal information, and also how significant privacy breaches can be avoided in future and any other related matter.
National is definitely committed to Better Public Services and to increasing the use of Government services online. Ensuring that the public actually have confidence in the information and communications system forms a crucial part of the work that we do. When the breaches happened in 2012, let me say that there were individual departments that had their own reviews, which cost the Government departments money, and they are working to fix those things by even appointing a Government Chief Privacy Officer, a function that was established in 2014.
If we were to have a commission of inquiry, as this bill proposes, there would be three members and it would be chaired by a lawyer. The commission would be required to report to the Prime Minister within 12 months. It would also investigate various privacy breaches that have occurred in the past within various Government agencies. The commission would also examine the agenciesâ capacity to respond to breaches in the future.
To me, this bill is all about having a talkfest, once again. I mean, Metiria Turei in an earlier bill talked about the Government not putting money into children who are not having breakfast and lunches. I was not actually here to listen to her speak so I am not sure exactly what she was talking about, but I just heard a little bit about children going hungry in schools, which is a very, very important issue. But Clare Curran is willing to spend $4.4 millionâor even $11.5 million, which a commission of inquiry would, in fact, costâto do this. A talkfest, to do what? I am totally at a loss as to what she thinks she can actually achieve.
It is as if the Government is not already doing something. The Government is, in fact, doing something about privacy breaches. A commission of inquiry should also be considered only when the situation is so unusual that no other approach will fix the problem. There are other reviews under way, as I said earlier. For example, the Ministry of Social Development contracted Deloitte to undertake a review of the privacy breach that it had had. ACC contracted KPMG and Information Integrity Solutions to report into the privacy breach that it had had.
Privacy breachesâwe all want to protect our privacy. I mean, as the mother of a teenage son, I want to protect his privacy. I do not even have my sonâs photograph on my campaign material. I try to protect my privacy by not including him in the material that I send out to the electorate when I am campaigning.
The Government Chief Information Officer also has the ability to assist agencies in addressing issues, as happened with the Earthquake Commission, and that was back in 2013, when that breach actually happened. The Government Chief Information Officer was asked by the head of the State Services Commission to look into information and communications technology security and privacy. The Privacy Commissioner already has the ability to investigate privacy breaches and report to the Prime Minister any matter affecting the privacy of the individual, including the need to, or the desirability of, taking legislative or administrative or other actions to give better protection to the privacy of the individual. So would the commission of inquiry that Clare Curran wants to establish do more than what we are already doing? A commission of inquiry would cost even more money. For me, this bill is not something that I would support.
Going back to 2012, the review of the publicly accessible information system by the Government Chief Information Officer was commissioned by the State Services Commissioner, and it has resulted in a range of measures to strengthen the security of New Zealandersâ personal information, including the establishment of the Government Chief Privacy Officerâs functions.
Recently there was the story of Sony. It is a huge conglomerate and it will have spent so much money on trying to protect its data and trying to protect its copyright of material, like the movies that it is developing and the shows that it is working on. If somebody wants to filter that organisation and it is attackedâin terms of cyber-attacking, which Clare talked aboutâthey will do it. Sony was attacked. All that work it has done, working in privacy, was released to the public.
If somebody is intentionally trying to break into something, they will do it. That does not mean that I do not support the work that the Privacy Commissioner is doingâI really support that. What I am actually saying is that if somebody intentionally wants to attack, then they will do so, and they can possibly breach that security wall that we might put up.
The Privacy Maturity Assessment Framework has also been developed to help agencies assess their existing capability and implement appropriate improvements, as well. There is an expectation, and the Privacy Maturity Assessment Framework was developed and tested in collaboration with privacy practitioners from across Government. There are best-practice models around. Having a commission of inquiry is certainly not one of them, and I am not prepared to support the member spending millions of dollars on a talkfest. I do not support this bill.
There is an old joke doing the rounds in the Pacific that at least now New Zealand is listening to them because the Government Communications Security Bureau (GCSB) is wholesale harvesting their data. The same joke has been going around in New Zealand that the first time the National Government has listened to New Zealanders is when it got the GCSB to do it. That is, of course, an extreme example of what we are talking about here: the necessary privacy that must be attached to citizensâ information, be that at the routine level of avoiding breaches and stuff-ups, the systemic level of developing systems that are resilient and robust to those accidents, and, even more important, the systemic level of avoiding the deliberate attempts by third parties to access the private information of New Zealanders.
Before I go into those three layers, for which this special commission of inquiry is essential, let me just quickly note the fallacy in the previous speakerâs contribution. Her line of argument was that because one of the examples quoted by my colleague Clare Curran dated from 2012, the bill was no longer needed because everything had all been fixed. Well, my colleague has done a data pull on stories of Government privacy breaches since January 2015, and there are plenty of them. There is a Northland Regional Council breach. There is an abortion data-leak error from Lakes District Health Board to Fairfax Media. There is the Broadcasting Standards Authority claim around the Valley Animal Research Centre. There is a Plunket privacy breach in Taranakiâthat is an NGO sector rather than the Government sector. There is the Southern District Health Board, and so on and so forth. So there are plenty of examples.
If you want the statistics, the Privacy Commissioner has helpfully compiled them. They tell us several interesting things. Since 2012, when the memberâs quoted example was concluded, the number of Government privacy breaches has actually gone up. In the last year Labour was in office it was 13. In the most recent year under investigation, which is 2014, there were 86. It has gone up from 13 to 86. What is worse is that the private sector equivalentâthe whole private sector, which is two-thirds of the economyâhad only 27. So the one-third of the economy that is the Government run by the National Party had 86 major privacy breaches, and there were only 27 in the rest of the economy.
What kinds of causes were there, according to the Privacy Commissioner? There was unsafe website design, loss or theft of physical data files, loss or theft of portable storage devices, improper employee browsing that was not prevented, electronic information sent to the wrong recipient, or physical information sent to the wrong recipient. These are all causes.
Let us come back to that staircase of issues. At the bottom level is an individual agency that has a stuff-up, whether it is a computer design error or whether it is an employee error, and they can be extremely serious. The member opposite quoted some cases where third-party consultants had been called in to investigate them. It is good in so far as it goes, if the report is thorough, and if the agency acts on the recommendationsâwe all know they usually gather dust on the doorstepâand they are implemented. But what an individual report cannot do is it cannot look at the system, and it cannot look at the links between different agencies and the protocols that run and necessarily should run across the whole of Government.
That is when we get into the second tierâthat is, systemic data security design. Not long ago the Government did a project on authenticating individuals. The Government wants to take individual transactions with Government online up from 46 percent to 70 percent. We live in the age of big data. These privacy issues are going to become more and more and more important.
And then we get to the third tier, which is deliberate use of private data. That happens every day, admittedly. Internet service providers, website hosting companies, and everybody else seem to have systems where they harvest data about their users and then onsell it to third parties or use it to target their own activities. We need to make sure that the Governmentâs protocols around all three layers are tight. That is why we need this commission of inquiry. That is why we need this bill.
Thank you for the opportunity to speak on this bill. I have a level of support, really, for some of the areas that Ms Curran has spoken about. I was actually quite pleased to hear Mr Cunliffe speak about the concerns about peopleâs private information in the commercial sphere, and everywhere else, because having been the victim of someone who decided to hack into someone elseâs private information and then make money off it by providing it to that well-known receiver of stolen information, Nicky Hagerâwho masquerades as a journalist, but is basically a hack who takes money off people who are stupid enough to buy his booksâlet me just say that I agree with quite a lot of what has been said so far.
I expect members on that side of the House, who are suddenly all worried about peopleâs personal information, to tell us about what they were doing visiting that other well-known hacker, Kim Dotcom, and what they were doing masquerading around with that Nicky Hager and using his book and stolen information to try to beat down the Government. All of a sudden I hear a lot of noise coming from the Opposition members, who clearly do not like the truth. They like to stand up in the House and pontificate about private information, but, by golly, they do not like it when we tell them the truth about their filthy little friend Nicky Hager and their big mate Kim Dotcomâsomeone who I hope one day will quickly be extradited. He can have his day in court, which he apparently wants to have. Would that not be great?
Let us have a real, serious talk about Government informationâ
đŹ Hon David Cunliffe: I raise a point of order, Mr Speaker. The Standing Orders provide that it is improper for a member to draw other members into disrepute. I seek your advice. Is it proper for a member to draw themselves into disrepute?
The ASSISTANT SPEAKER (Lindsay Tisch): No, look, that is not a point of order. The member is quite within her rights to express the way that she feels.
Well, for goodnessâ sake! Why is that man no longer the leader of the Labour Party? Why is he not? Oh, that is right, he took it to the worst defeat it has ever had since 1906. But, hey, whateverâhe tried, he was there, he did not conquer. There you goâwhatever.
Now let us get back to it. Why is it that we have these privacy breaches in the Government sphere? Basically, because we have much more data. Secondly, there always were privacy breaches. People used to have hard-copy files. People would trawl through them. They would have a look at things. Nowadays, fortunately, if they do that in an electronic file, they can get found out.
Now, with a click of a button, with a click of the mouse, we can send information all the way around the place. It is easy to make mistakes. Is that OK? No, it is not. We already have the Office of the Privacy Commissioner. We already have the Privacy Commissioner. We already have reports on it.
đŹ Clare Curran: Whereâs the new privacy laws?
Ms Curran has quite rightly said, in reference an excellent comment I made last year around introducing a bill around thisâit was an excellent comment, I would have to say, if I may say so myselfâand I am sure it is progressing. But it takes a lot of work to get that sort of bill into the House because it is extremely complicated.
I think that is one of the things where we now do not accept that it is OKâoh, except, apparently in the political sense; if you are going through other peopleâs information and you are on the left, it suits youâto actually go through peopleâs private information and use it. But many of us have worked this out. We use online banking. Many of our communications are online.
đŹ Kanwaljit Singh Bakshi: Passports are online.
There are passports online. We have to have confidence in our system, and that is why I think it was a really good thing to have the Government Chief Information Officer so that we could actually get all the systems working together.
There is this balance between giving people the right to be able to access things online and to work online with the Government and Government agencies, and, at the same time, putting in place measures to protect their privacy. The two are actually quite competing. We have got techie people who are there to try to make it all happen and to make it happen fast, and then we have got people like lawyers and others who are saying: âHang on, youâve got to be careful.â So that is the balance. That is why we need somebody who looks after it. That is why I am very confident that we have measures in place to improve the system. I am sure that when there is a new bill on the Privacy Act, we will all be happy to support it.
It is good to speak in favour of this bill. I would like to acknowledge Clare Curran for her efforts on behalf of us all, actually, because it is actually really important that we all have a level of protection that currently does not exist. There is this sorry list of privacy breaches in the State sector that need to be rectified. We are in a brave, new world, but it is not very brave or satisfactory for many people whose privacy details have been exposed through a number of debacles and breaches. In fact, when the last speaker, Judith Collins, was speaking about nasty little hackers, I thought she was talking about Cameron Slater, who does actually fulfil that criterion of being quite an unpleasant person in the way he talks about other people. I am going to defend the right of people to talk about important issues. I do think that Nicky Hager is a citizen who brings issues into the light, which is quite different from exposing privacy. We actually need to know what is going on in our country. We need journalists who can do that. We also need protection, and that is why this bill is important. The vulnerable, who are in a relationship with the State with the private details of their own, very personalâsometimesâcircumstances, need protection.
The Electronic Data Safety Bill establishes a special commission of inquiry, and it was inspired by the Ministry of Social Development kiosk privacy breach. I think we were all pretty horrified at the ease with which Keith Ng was able to access this through a very simple system, basically through an open file. I have some sympathy for people working in Government departments who make mistakes with technology. I am sure that if I worked there, I would be one of those people. But what we need is rigorous oversight and excellent modern systems, and we need to have a commission such as is suggested here to really set up a decent framework so that this cannot keep happening to ordinary people. I am speaking here not as an expert on this technology, who is definitely Gareth Hughes and not myself; I am speaking here as the human rights spokesperson because, actually, the human rights of citizens who are engaging with departments such as the Ministry of Social Development, Work and Income, and ACC really need to know that when they sit in a room and tell someone a story about themselves and give their very personal and sometimes extremely traumatising details to that personâwhether it is at Work and Income or ACCâthose details will actually stay private. Those very personal, traumatic stories that people find it hard enough to tell in order to get some support that the State should actually support them withâif they then become part of the public domain, it is very, very scary.
What was scary about what happened with the Ministry of Social Development was that it had an utterly inadequate process in place. It was not protecting the confidential details. The full names of children, for example, in the high and complex needs programme were exposed, and I do not see how that is beneficial to those children, let alone the rest of us. There was a list exposed of everyone who owed the ministry money, which is pretty extraordinary because it is so easy to make assumptions about this kind of stuff without knowing the background, and there were addresses for their family homes in care protection facilities, for the Child, Youth and Family Services homes. That is the kind of information that in the wrong hands is really damaging. Also, although there was an independent investigation by Deloitte, and it found some pretty serious things, that was not really sufficient. It was damning about governance and it showed that security was not being consistently considered.
The investigation also showed that some more investigation was needed and that privacy breaches were pervasive across Government departments. Which Government departments, you might ask? Well, I have mentioned the Ministry of Social Development and ACC. In respect of ACC in particular, 6,500 client details were able to be accessed, and those are people who have been victims of not just accidents at work in the conventional sense but sexual violenceâpeople who have experienced extremely traumatic experiences. Novopay was also another one. Teachersâ details were available to previous employers and to other schools. There is a proper process for that; it is called the Teachers Council. But this was actually through insufficient internet care, insufficient protection. And then, of course, there was Work and Income. To add to that, there was the Earthquake Commission. There were breaches exposing thousands of client details. In the Ministry for the Environment it was 150 clientsâ private email addresses. I could go on and on but the Assistant Speaker is indicating that I should not. We support this bill because this stuff is rife, it is rampant, it is not OK, and we need to do something about it. So we support Clare Curranâs efforts.
Thank you for the opportunity to speak on the first reading of the Electronic Data Safety Bill in the name of Clare Curran. First of all, I would like to clarify that the National Party will not be supporting this bill. The second thing that I would like to emphasise is what the Hon David Cunliffe mentioned as an example: that during the Labour period there were 13 breaches; during Nationalâs period there have been 86 breaches.
đŹ Hon David Cunliffe: Just in the last year.
Yes, yes. So here I would like to give an example. When I became a member of Parliament in 2008 we used to do everything on paper in the select committees. We did not have anything electronic; everything was done on paper. Today everything is online, which means there is an increase in the data and in electronic transactions in Parliament itself. I am not trying to justify that even a single breach is acceptable, but I am telling you that there is an increase in the data that is happening right now. Technology is changing and so much is happening.
Coming back to what this Government wants to do and what it has done in the past 6 years, we have time and again stated our commitment towards providing better public services. Furthermore, we have taken dramatic steps towards providing an online platform for the delivery of many Government services, such as electronic passport applications. Here I would especially like to mention the Hon Chris Tremain, who was the architect of getting passports online and introducing RealMe. It is very important that we follow the technology. Of course, when we want to provide ease of services to New Zealanders, we want to also ensure that the private and personal information of those using these services is protected and that the general public has got confidence while using these services.
The Government has already accepted that there have been many lapses, but there have been remedies that have been put in place. We have also moved swiftly towards ensuring that any further lapses do not take place. The need to set up a royal commission of inquiry, which will cost taxpayers between $4.5 million and $11 million, appears to be very futile. I think New Zealanders will appreciate that if this kind of money was invested in providing front-line services at our schools and hospitals or building infrastructure, it would be a better utilisation of money than setting up an inquiry. There are other reviews that are being used or can be used in case of lapses, if required.
I think history will tell us that the royal commission has been used only when a situation has been so unusual that no other approach will work. The Ministry of Social Development contracted Deloitte, one of the big four auditing firms in the world, to study the privacy breaches in its information security system management. ACC contracted KPMG, another one of the big four auditing firms in the world, to look into its information systems. I think both these reviews would have served the purpose far better than a review of agenciesâ IT systems. Furthermore, it is highly likely that the royal commission may end up asking for the IT system to be reviewed and for necessary measures taken to ensure that such mistakes are not repeated. Basically, what the member wants to achieve in multiple areas can be achieved by taking this straightforward approach. With these words I once again confirm that the National Party will not be supporting this bill.
Kia ora, Mr Assistant Speaker. New Zealand First had a very strong discussion in caucus about this particular bill. Originally, it was the cost of the inquiry that concerned us and whether we felt it was necessary, because we already knew that there were some reviews going on. So there were some reviews in the systems, and the National Party members continued to repeat that that was adequate. What is unfortunate is that after those reviews, more breaches happened, so New Zealand First has decided that it will be supporting this bill. We would like to see it go to a select committee.
There has been a very interesting series of contributions by National Party members to date. The contribution from Melissa Lee and the contribution from the member, Kanwaljit Singh Bakshi, who has just resumed his seat, both made it sound like we have moved into a digital world so therefore it is too bad, you are just going to have to accept being hacked. That is really interesting because Melissa Lee saidâand she repeated it again and again, if you look at her contributionâthat if somebody wants to attack you, they are going to attack you, they are going to steal your information. This bill is not actually necessarily all about people being attacked.
đŹ Kanwaljit Singh Bakshi: This is for the royal commission.
Mr Bakshi just said the same thing. Apparently he has forgotten, because he is repeating himself now. This bill is not necessarily about being hacked. This bill did not come out of somebody hacking information; this bill came out of Government departments dropping itâdropping itâand accidentally sending it to other people. This bill is not about each individual Government department.
The members on the other side like to use the phrase, and they have used it in this House todayâhere we go; I had better get it rightââa whole-of-Government approachâ. They like to use the phrase âa whole-of-Government approachâ, and that is exactly what Ms Curran is suggesting in this bill. That is exactly what the purpose is. If you have a look at the last sentence of the explanatory note of the bill, it says: âThe Commission will also examine the agenciesâ capacity to respond to breaches in the future and how best to prevent further future unauthorised access to private information.â, but it is across Government departments. It is about the point of weakness. That is what we see that actually needs to be addressed here. That is what is different from Deloitte and KPMG. It is not about a single department; it is about this point of transference between departments.
Since these reviews were done, this Government has actually put through several pieces of legislation in the last 3 yearsâ2012, 2013, and 2014. One of them has actually been a mass collection of data of every school-leaver in this countryâevery school-leaver in this country. I am referring to the Social Security Amendment Bill. Every 16, 17, and 18-year-old New Zealander now has, under their National Student Number, all their academic data sent to the Ministry of Social Development. The Ministry of Social Development then outsources this data about these young peopleâs academic outcomes to contracted people in certain areas around New Zealand, and a risk analysis is done on every single one of those young people. How likely are they to become a beneficiary? What are their parental circumstances? Are they the child of a parent who is on a benefit? This data is all done. It has all been brought into play through the Social Security Amendment Bill, and that data is now held, like it has never been held before, by this Government.
All that Ms Curran and this bill are suggesting is that it is actually worth $4.5 million to the New Zealand public to do a commission of inquiry to have a look at the weak points of transference around this data and others because we have seen data leak out from this Government and its departments. Surely, if ever there was a saying, âA stitch in time saves nineâ is one of them. If we keep having to employ KPMG and if we keep having to employ Deloitte to go and look at breaches when they happen for each individual department, how much will that add up to? Instead of investing $4.5 million, let us get the systems right, across Parliament, because the cloud is a reality. We know that it is here. Let us look at it in its reality and make sure the New Zealand public believes that it is safe. We urge the Government to just vote the bill through to the select committee.
National does not support this bill, the Electronic Data Safety Bill, and neither do I. To pick up on one of the points that Tracey Martin raised, she said that doing this $4.5 million inquiry would save money. Well, I have seen enough inquiries over the years in different contexts. The inquiry itself, I am afraid, Ms Martin, will eventually say: âActually, what we need to do is bring in a whole range of other experts to continue engaging with the Government.â, so I do not think this is a cost saver. I think it is really good to bring you into it, reallyâ
đŹ Tracey Martin: Why do you hate talking to people, Mr OâConnor?
What do you mean? I love it. I have spent most of my life talking to people and it is a fantastic thing.
You know, the people of TÄmaki are not clamouring for this bill. It would be remiss of me as a constituent MPâ
đŹ Tracey Martin: How do you know?
Because, actually, I spend an inordinate amount of time with the good people of TÄmaki, which is perhaps one of the reasons it has one of the highest majorities in the country. When I look across the House, you do have to wonderâ
đŹ Jami-Lee Ross: Whatâs Tracey Martinâs majority?
Exactlyâyou have to look at the number of National MPs here. The good thing is that none of that has to be leaked or broken.
I do want to acknowledge Clare Curranâ[Interruption]
The ASSISTANT SPEAKER (Lindsay Tisch): Order!
We clearly have got a data safety issue carrying on here between two members. I do want to acknowledge Clare Curran in responding to this. A memberâs bill is an important thing in identifying what is an important issue. I think we on this side do see the importance of privacy, which we see as wanting to protect New Zealandâs data, and I think we as a Government and through the various departments take data safety very, very seriously. I know that in my time working in various Government departments I was very cognisant that this is peopleâs lives expressed in information, and this Government, as I say, is taking it very seriously. It was noted by an earlier speaker that there has been an increase in reported breaches. In fact, that shows the increased vigilance of the Government. We are working jolly hard.
Sitting suspended from 6 p.m. to 7.30 p.m.
It would be remiss of me, I knowâ
đŹ Tracey Martin: Oh no.
And Tracey Martin, in particular, is looking forward to this continued contribution of convivial elegance, I am sure.
As we were finishing before the dinner break I was stressing that the National Party is very keen on privacy. I think there is actually a very good story to tell here first and foremost over vigilance. I think that is indicated by the Government noting where there are breaches. I think one of the things about privacy is that we do not live in a utopian world. There are always going to be, for better or worse, privacy breaches in the public or private sector. It is not something we want. It is not something that is desired. If you were the particular person who has been affected you would not be terribly pleased, but the nature of communications is that you have always got to leave a door open in order to allow that information to flow. We have heard from other colleagues, such as the Hon Judith Collins earlier, and I know that the other side know of their own situations where they have sent emails to the wrong people. But if you are going to have communication, then a door, as I say, has to be open, and there is always the chance for problems, so it is about mitigating that.
I think, ultimately, at the heart of why this side of the House is not keen to progress this particular bill is that an inquiry, a discussion, a committee, or a looking into things is actually not going to cut the mustard. A big chunk of that is because the Government already is working in this space. We have a cyber-security plan for Government information and assets. We know that Government agencies are always already working together. We have appointed a Government Chief Information Officer. I think that is something we have learnt from other countries and have very happily appointed. This person is strongly identifying the issues and making the changes that are needed. I know that one colleague across the House talked about this whole-of-Government approach and how strange this is. Well, actually, the National Government knows there is strength in pulling together and by having all the departments talking in relation to the Government Chief Information Officerâ
đŹ Tracey Martin: Thatâs not what I said. I said the exact opposite.
I hear someone across the House has presumed that I might have been referring to her. We are working in this space. No breach is acceptable, but we also understand that breaches will happen. They are opportunities for this Government, the Government Chief Information Officer, and the agencies to make their systems more robust. I am very confident, as I have thought about this bill and the speech tonight, that we are putting the right systems in place, and we continue to put the right systems in place. We are a Government that reacts accordingly and to the needs of what we hear. And if I may finish on thatâoh no, I have been given the signal. On that I shall finish and I am very grateful that my speech was not electronically leaked beforehand.
I am pleased to rise and take a call on the first reading of the Electronic Data Safety Bill which has been presented to the House by Labour MP Clare Curran. The Greens are supporting this bill, which is a response to continued very serious privacy breaches within the Ministry of Social Development and other Government departments. We have seen breaches over the last few years in ACC, Novopay, Work and Income, the Earthquake Commission, the Ministry for the Environment, the Ministry of Education, and Immigration New Zealandâthe breaches go on. We have had breaches from within Government departments and breaches from the very leadershipâthe Ministers of those departments, the Ministry of Social Development and the Ministry of Justice, two critical ministerial positions when it comes to considering privacy.
Really, this bill, we believe, speaks to the issue of trust and the ability of New Zealanders to trust that this Government will solve those problems of privacy when the leadership it has shown has run so counter to the principles of privacy. It is clear this is a deeply serious issue that needs a serious solution. It is concerning to hear Ministers of the Government say that there is no need for this bill because everything has been sorted. They speak as if this is such a thing of the distant past when the last major breachâin fact, of 600 ACC clientsâ dataâoccurred just this year in January. This is not an issue of the distant past. The Green Party takes privacy seriously. One of our members Gareth Hughes has a memberâs bill on internet rights and freedoms, which will ensure the right to privacy online, a right that currently is not legally protected within New Zealand law.
I would like to speak this evening briefly a little more on this special need for a commission of inquiry into the Ministry of Social Development privacy breaches, and, most important, the need for an independent inquiry with official status to look at systemic issues within the Ministry of Social Development, because at the end of last year the Office of the Auditor-General released a report on complaints within the Ministry of Social Development. Within this report it found that there was significant room for improvement in the processing and recording of complaints, and it expressed concern about the lack of ministry-wide analysis of complaints to identify systemic problems, which goes to the very heart of this bill, because if we cannot trust the ministry to identify complaints in relation to privacy and put systemic responses in place, then we need an independent inquiry. This is clearly telling us that we cannot have that trust because those systems are not in place.
We have been hearing this concern from advocates and lawyers for quite a while on a much wider level. Again, it speaks to our ability to trust. Recently, Frances Joychild QC also raised the issue of the lack of power and legal support for beneficiaries experiencing problems in the system. She has written a very, very powerful article on this and the need for us to actually start turning round what has become a drastic imbalance of power. Again, it speaks to our ability to trust and the need and importance for this bill. We have seen examples of legal rulings happening in courts against the Ministry of Social Development where it has not even, after a ruling against it, put systems in place to ensure a policy change. We cannot have any trust in this ministry at the moment when it refuses to put the systems in place to turn it round even with court rulings against it. We need privacy reporting to be public. We need an inquiry. Just recently, we have heard of casesâ
đŹ Mr DEPUTY SPEAKER: Electronic data is what we are debating.
It is absolutely about electronic data in relation to the Ministry of Social Development and privacy, which is what this bill is about. We have had somebody contact us where they have been to the Privacy Commissioner, they had had a ruling in their favour, but that was a confidential ruling and they have evidence that no systems change or policy change has been put in place as a result of that ruling. We have no systemic ability to respond to breaches at the moment. Because of that lack of ability to trust in the system, we need this independent inquiry. The Greens fully support this bill because it answers the publicâs lack of trust.
I am rising to speak on the Electronic Data Safety Bill. Can I first say that I think electronic data protection is important, it is vital, and it is paramount in the 21st century. Although I am not on the Commerce Committee, I am on the Social Services Committee, so patient data and records and their stories, and the protection of that data, is paramount as well. It is an area that I am extremely interested in. I was very interested to read about the key driver to this bill in the general policy statement, the hacking of 7,000 documents from the Ministry of Social Development computer network through Work and Income self-service kiosks. This included medical records, personal data, and pay rates.
I think electronic data protection is important because we are using information technology a lot more these days. Some of us are buying our groceries online, some of us are reading books online, and I have heard of some people finding love online. I am very much proud of our Government, which is committing to essential infrastructure and information technology around our ultra-fast broadband and our Rural Broadband Initiative. This essential infrastructure is valued by all constituents in my electorate of Waimakariri, a rural electorate. You very much need essential infrastructure for a strong economy and for the well-being of our people.
Data management and protection are vital. I think back to the stories I read post-earthquake when there were a lot of health care systems and IT systems that had crashed so patients were presenting to health care services they had not been to before and health care professionals were making treatment decisions that were not based on the data they would normally have if their health IT system had been up and running. So it is great to hear about the innovation now of sharing vital primary, secondary, and allied health information, but that will come at a risk when you share information across boundaries, across sectors, and across organisations.
I do not believe that a commission of inquiry, with an expense of about $4 million to $10 million, is the way forward. I also think a commission of inquiry should be for an unusual situation; it should not be used for business as usual. We do have precedent and we do have benchmarking from other reviews into privacy breaches and information management security. These are the Ministry of Social Development contracting Deloitte and ACC contracting KPMG.
What we do know is that across the government IT work is under way to address electronic data protection issues. We have a cyber-security plan for Government information, and assets and agencies are already systematically working towards addressing some of these issues. I know from my own career working in healthâspecifically, mental healthâand setting out new health care services that you do need to think along the whole system and along the whole continuum around data protection not only in terms of simple things like passwords for tablets, phones, and PCs but right up to risk management strategies and looking at issues around risk assessments in plans. We know from our own experience in this precinct of using our swipe cards, and levels of accessibility are paramount to that data as well. We know in health and social services that as there are bigger multi-agencies working now, we need to understand how much our patients are consenting to their data being shared and ensuring their data is protected as it goes across sectors and organisations.
To conclude, we have a Government Chief Information Officer who is working to address data security and has been asked by the head of State services to look into data security. We have a Privacy Commissioner. This is why I do not support this bill. Thank you.
I call Clare Curranâ5 minutes in reply.
Can I lament the lackadaisical, ill-informed, shallow response from the Government members on this bill. I could have used stronger words, but can I lament and say and predict that they will rue the day they made them, given the very strong likelihood of further significant data breaches and mismanagement of IT projects going forward and how important this is. Really, this bill was quite simple. It created a mechanism that would have been an armâs-length approach to a really important and significant issue. It really would not have cost very much to provide more confidence, surety, and trust across New Zealand, across our public sector, and across Parliament around IT issues, which I would have thought was an important matter in 2015 in the current environment. I mean, the New Zealand Parliament cannot even get its own IT right and has no resilience in its system. This is largely as a result of a systemic underfunded approach. If you look at that as a microcosm of what is happening across the public sector generally, you would think that we would be treating this with a bit more seriousness.
I want in my closing remarks not to focus on the puerile responses from across the House, but actually to just point to some real life examples and some ones that are happening right now and are of real seriousness and significance. I am pleased to see that the Attorney-General is sitting in the House. He might be actually listening to some of these.
Last year there was a project undertaken around the number of computers across Government agenciesâwhether they are departments or agencies, including health boardsâthat still had a software programme on them that had run out of date and was no longer being supported. The programme was called Windows XP. I undertook that project because it had been pointed out to me by a number of significant people in the tech industry how important it was for the public sector to not have holes in its IT programmes and be unsupported. I did that, and eventually I discovered, after a lot of effort, that there were more than 40,000 computers still on Windows XP and that the cost was well in excess of $1 million for extended support from Microsoft, and some of them were not actually being supported. The risk that poses to New Zealand and our public sectorâand this is just one exampleâis quite significant. There are exponential risks beyond that currently operating right now in our public sector, including a number of public-facing computer systems that people go and use every day that have great big gaping holes in themâgreat big gaping holes. This will come to light. I have warned the Government. I have asked questions of the Minister of Internal Affairs today about itâdeny, deny, deny. He said there was no issue.
A special commission of inquiry into this would have created a responsible armâs length approach. It has the support of most of Parliament; it should have the support of the whole of Parliament. It is not a big dealâ$4 million versus $45 million to fix Novopay and $130 million of extra spending on the Inland Revenue Department system. This is shameful, it is wrong, and it is irresponsible. It is just frankly irresponsible for the Government not to take this approach when we cannot even get our own IT right in our offices in our own Parliament. There is no resilience. There is no back-up system. Why can we not do it across the Government and take a proper approach to this? Not supporting this bill is just, quite frankly, irresponsible.
đŁď¸ Spoke in this debate (10)
- Kanwaljit Singh Bakshi (New Zealand National Party â List Member)
- Chester Borrows (New Zealand National Party â Member for Whanganui)
- Hon Judith Collins (New Zealand National Party â Member for Papakura)
- David Cunliffe (New Zealand Labour Party â Member for New Lynn)
- Hon Clare Curran (New Zealand Labour Party â Member for Dunedin South)
- Catherine Delahunty (Green Party of Aotearoa / New Zealand â List Member)
- Matt Doocey (New Zealand National Party â Member for Waimakariri)
- Melissa Lee (New Zealand National Party â List Member)
- Jan Logie (Green Party of Aotearoa / New Zealand â List Member)
- Hon Tracey Martin (New Zealand First Party â List Member)