PARLIAMENTARY DEBATE
Uber: Personal Data Theft - 23 November 2017 (Commons/Commons Chamber)
Debate Detail
We are verifying the extent and the amount of information. When we have a sufficient assessment, we will publish the details of the impact on UK citizens, and we plan to do that in a matter of days. As far as we can tell, the hack was not perpetrated in the UK, so our role is to understand how UK citizens are affected. We are working with the Information Commissioner’s Office and the National Cyber Security Centre, and they are talking to the US Federal Trade Commission and others to get to the bottom of things.
At this stage, our initial assessment is that the stolen information is not the sort that would allow direct financial crime, but we are working urgently to verify that further, and we rule nothing out. Our advice to Uber drivers and customers is to be vigilant and to monitor accounts, especially for phishing activity. If anyone thinks they are a victim, contact the Action Fraud helpline and follow the NCSC guidance on passwords and best practice.
More broadly, the general data protection regulation and the new Data Protection Bill, which is currently before the other place, will introduce a package of tougher measures to address data breaches. Delayed reporting is already an aggravating factor, but the new Bill will require organisations to report breaches likely to impact on data subjects to the Information Commissioner within 72 hours of becoming aware of one. In serious cases, they will also have to notify those affected by the breach. The commissioner will have increased powers to respond in the way that she considers appropriate, including with fines of up £18 million or 4% of global turnover. We are making further assessments as I speak, and we will keep the public and the House updated.
UK authorities have acted swiftly since the security breach came to light, so will the Government therefore push for the toughest penalties to punish Uber for this outrageous dereliction of its ethical and legal obligations to the public? Under EU law, Uber could face a fine of €20 million or 4% of its annual global turnover—whichever is greater—but the maximum fine from the ICO is just half a million pounds. Will the Minister review the maximum fines in the UK once we leave the EU? In any case, does he really think that a fine will cut it in this case? Does he think that a company that covers up the theft of data and pays a ransom to criminal hackers can possibly be considered a fit and proper operator of licensed minicabs in our towns and cities? If not, what are the Government going to do about it? When Transport for London finally took action over Uber’s abysmal safety record, the Conservative party handed out leaflets attacking the Mayor. Does the Minister agree that that is not a good look for the Government today, and will he revisit that choice?
Like the Minister, I am pro-tech, pro-competition and pro-innovation, but given that Uber stands accused by the Metropolitan Police of failing to handle serious allegations of rape and sexual assault appropriately, given that Uber has to be dragged through the courts to provide its drivers with basic employment rights and to pay its fair share of VAT and given that we now know that Uber plays fast and loose with the personal data of its 57 million customers and drivers, is it not time that the Government stopped cosying up to this grubby, unethical company and started standing up for the public interest?
I would be grateful if the Minister answered the following questions. Can he give us a rough idea—I know he said he was looking into the precise figures—of how many customers and drivers in the UK had their personal information compromised by the hack and what kind of data was compromised? What was the first contact Uber had with the Government and when did it happen? When did he personally become aware of this security breach? In his view and that of the Government, has Uber broken current UK law? If Uber has not done so already, will the Minister or the Secretary of State call Uber into the Department immediately, or over the weekend if necessary, to explain itself and give more information about the breach?
Given the magnitude of the breach, has the Minister satisfied himself about the facts of the case, particularly given that if regulation requires strengthening, we can do it right now in the other place in the Data Protection Bill, as he has pointed out? I think that he said in his answer that he learned about the breach on Tuesday. Can he confirm that despite that, just yesterday in the House of Lords, the Government blocked the ability of consumer groups such as Which? to initiate action for victims of data breaches? Will he commit now—I think that he said he was prepared to make some movement—to reversing that position when the amendment comes before the House of Lords on Report, to show that we are on the side of consumers and employers, not huge corporations that are careless with our data?
The hon. Gentleman asked when I personally knew about the breach. I knew about it when I was alerted by the media. As far as we are aware, the first notification to UK authorities—whether the Government, the ICO or the NCSC—was through the media. He asked whether Uber has done anything illegal under current UK law, which of course would be a matter for the courts, but I think there is a very high chance that it has.
The hon. Gentleman asked about taking action on behalf of data subjects following a data breach. I am strongly in favour of people being able to take action following a data breach, and we are legislating for that. The question debated yesterday in the other place was whether people should have to give their consent to action being taken on their behalf, and the whole principle behind the Data Protection Bill is to increase the level of consent required and people’s control over their own data. The proposed amendment pushed in the opposite direction, which is why we rejected it yesterday, but we will have the debate in this House, too.
Contains Parliamentary information licensed under the Open Parliament Licence v3.0.