Fears over council data
Councils to keep health files and bank details on computing cloud
PUBLIC bodies across Scotland are to be given the capability to outsource computer storage of sensitive information, raising fears that private data, including health records or bank details, could become vulnerable to hackers.
The Scottish Government is advertising a contract worth up to £20 million to provide IT equipment compatible with “cloud computing”, meaning information would be stored by third parties potentially thousands of miles away and accessed through the internet, rather than on an organisation’s own hard drives.
Ministers have said it will be up to individual bodies, including health boards, colleges, courts and councils, to decide how they use the new laptops, computers and other gadgets that will be bought through the new contract over four years, and whether they shift towards storing data on the cloud.
However, government guidance to public sector bodies distributed earlier this year described cloud computing as a “priority option” and said the technology could save cash, increase productivity and improve energy efficiency.
The move to spend millions of pounds on cloud-ready kit has raised fears a significant shift in strategy is taking place by the back door, with the public unaware of risks or privacy implications.
The same government strategy document acknowledged security risks associated with trusting a third party with data, while also indicating storing information overseas would mean it could fall under control of foreign governments.
Jim Killock, executive director of the Open Rights Group, said that if data was physically stored in America, controversial laws such as the Patriot Act or Foreign Intelligence Surveillance Act would mean sensitive information was being put into the hands of US security services.
Mr Killock, whose organisation is committed to protecting rights in the digital age, said: “It would be sensible to have a wider public debate rather than just putting these things out to tender and awarding contracts.
“The danger is that we just see these things as bureaucratic and technical, when the truth is that everybody’s privacy and data is potentially at risk. There needs to be clear accountability and debate.”
The Scottish Government believes that despite new security implications, moving to the cloud can offer benefits to public bodies, with some already making use of the technology and many members of the public using it regularly through popular applications such as Dropbox and Google Drive.
Dundee University is on course to save £500,000 in the coming years after shifting to a cloud-based email system, allowing it to cut administration, maintenance and staffing costs.
Willie Rennie, leader of the Scottish Liberal Democrats, backed calls for a public debate. He said: “The government should be more sensitive to this important area of controlling and storage of information. It affects everyone in their daily lives and there is great anxiety that the government does not take this seriously enough.”
A Scottish Government spokeswoman said the contract was not about the storage of data on remote third party servers, but would provide a “no commitment framework” to provide hardware that would help public sector bodies access cloud-based services.
She said: “The way in which these devices are deployed, managed and secured will be a decision for each organisation.”
‘‘ The truth is everybody’s privacy and data is potentially at risk. There needs to be clear accountability