HMRC has been criticised by MPs regarding the standards of data protection it maintained while collecting biometric data on customers for security purposes, a process that generated complaints from taxpayers, at a PAC hearing into HMRC performance
Jon Thomson, head of HMRC defended the organisation about the way it had handled data compliance over telephone recordings, which were criticised for failing to give taxpayers the opportunity to consent to using biometric voice recording as part of the taxman's new security procedure.
This followed a complaint currently being investigated by the Information Commissioner’s Office (ICO) regarding the use of customer’s voice recordings as a biometric security protocol on telephone call.
Thompson told MPs: ‘There has been a complaint which has been lodged with the Information Commissioner’s Office and we are working with the ICO about how this process works - whether there was explicit consent so the ICO can make a judgment on that complaint.’
The committee pressed Thomson asked what process HMRC went through to validate the process used to collate the data and how they justified its legality.
Thompson said: ‘We believe that the messages about this were clear enough that it was implicit that you were giving permission for HMRC to collect that data. The aim of that is to improve the level of security so [the taxpayer] could access services…We believed it was implicit and therefore lawful.’
Conservative MP Lee Rowley extensively questioned the text of the introductory message given to callers who were enrolled in the process, questioning whether the process gave an implicit understanding that the protocol was optional.
Thompson noted that despite the complaints, it was HMRC’s position that the process abided by the law: ‘We think it was implicit. It’s not explicit that if you did not say that, you would have moved on. We have now made it explicit or you can say “no”.’
It was suggested by the committee that the usage of recordings of customer voice data violated general data protection requirements (GDPR) for failing to explicitly allow customers to opt-out of the service. The committee noted that in the enrolment process there was no explicit consent in the statement provided to telephone customers, as would be required under both the data protection act (DPA) and GDPR.
Thompson replied that the investigation of the complaint was ongoing but that he believed that the process, which required a positive action from the customer, carried within it the implicit ability to decline the service. He argued against the committee’s position that there was no opt-out offered to customers, taking the attitude that it required a positive action by the customer in order to be enrolled.
When asked about the timeframe, Thompson noted that the complaint was lodged with the ICO in June and the investigation was ongoing according to the office’s own processes.
The committee also noted that a privacy assessment relating to voice identification was dated March 2017 but that data was being collected from January of that year, and asked if data was therefore being collated without compliance approval. Thompson said that he ‘could not answer that’. It was also noted that the privacy statement that appeared on HMRC’s website appeared a year after its stated publication date.
The committee asked: ‘If it is determined that your “impliciteness” was not sufficient for the ICO, will you delete all of the voice recordings that you have recorded since this process began.’
Thompson noted that 7m customers have so far registered for the process and that HMRC would determine what process to carry out once the judgement from the ICO was passed down.
Report by James Bunney