|
Driver and Vehicle Licensing Agency |
|
|
Financial Accounting Unit D 7 DVLA Longview Road Swansea SA6 7JL
|
|
|
Telephone |
01792 783792 |
Tom Finnie
[FOI #384 email]
|
Fax |
01792 788250 |
|
|
|
|
[email address] |
|
|
Website |
www.direct.gov.uk/motoring |
|
|
|
|
|
|
|
Your Ref |
Email of 16th May 2008 |
|
Our Ref |
FOIR 1064 |
|
|
|
|
Date: |
15 July 2008 |
|
|
|
Dear Mr Finnie,
Freedom of Information Request
In our reply to you of 17th June 2008 we stated that we were withholding answers to two of the questions you posed in your original request of 16th May 2008, as we needed more time to consider the public interest in disclosure. These questions were:-
b) What encryption scheme is used (in our database)?
d) What protection is in place to prevent the wholesale downloading of the database?
Answers:
b) We have decided to withhold this information in reliance on the exemption at Section 31(1)(a) of the Act. This exemption applies where the information would prejudice the prevention or detection of crime. To release the encryption/obfuscation scheme could facilitate those persons who would attempt to illegally access the EVL database. In considering the public interest in release we understand that release of information in general, promotes accountability, and helps individuals understand decisions made by government. However, we consider that to release an aspect of the security measures used to safeguard the personal information of members of the public would not be in the public interest.
Furthermore we also consider the exemption at Section 40(3)(b) of the Freedom of Information Act applies. The release of this information could aid inappropriate access to the information on the database. This would be in contravention of Principle 7 of the Data Protection Act 1998, which obliges a data controller to provide adequate security to protect personal data that it holds. We previously explained that the data is not encrypted but obfuscated. The release of the obfuscation scheme would be the same as disclosing the encryption key to a cipher.
d) We have decided to provide you with information that we hope satisfies your request. The database is protected by restricted access protocols, passwords and firewalls. All accesses to the database are monitored, logged and are traceable to individuals. Basic day-to-day accesses to the database by caseworkers and individual users only have access to one record at a time and have no `mass download' facility. Database Administrators are capable of copying databases but this is a highly controlled process and all database administrators have a higher level of security clearance.
The information supplied to you continues to be protected by the Copyright, Designs and Patents Act 1988. You are free to use it for your own purposes, including any non-commercial research you are doing and for the purposes of news reporting. Any other re-use, for example commercial publication, would require the permission of the copyright holder.
Most documents supplied by the Driver and Vehicle Licensing Agency will have been produced by government officials and will be Crown Copyright. You can find details on the arrangements for re-using Crown copyright on the Office of Public Sector Information website at:
If you are unhappy with the way the Agency has handled your request, you may ask for an internal review. You should contact Stuart Martinson, CMS, C3 East, DVLA, Longview Road, Morriston, SWANSEA, SA6 7JL, or by email, [email address] if you wish to complain in the first instance. If you are not content with the outcome of the internal review, you have the right to apply to the Information Commissioner for a decision. The Information commissioner can be contacted at:-
Information Commissioners Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
If you have any queries about this letter, please contact me. Please remember to quote the reference number above in any future communications.
Yours sincerely
David J Morgan
Financial Accounting Unit
Page 2 of 2
Page 1 of 2