Asked by: Anna Sabine (Liberal Democrat - Frome and East Somerset)
Question to the Department for Science, Innovation & Technology:
To ask the Secretary of State for Science, Innovation and Technology, whether the Government has assessed the compliance of its contracts with Oracle Corporation with UK GDPR in light of the US CLOUD Act; and whether the Information Commissioner’s Office has been consulted on this matter.
Answered by Ian Murray - Minister of State (Department for Digital, Culture, Media and Sport)
Public sector digital services are expected to be secure, resilient and effective. This is supported by a framework of safeguards, including data protection legislation, UK security standards, the Cloud First policy, commercial rules and the Data and AI Ethics Framework.
Under UK data protection law, data controllers (including Government Departments) must ensure personal data is protected, including internationally. Where cloud providers may be subject to overseas obligations, such as the US CLOUD Act, Departments as controllers are responsible for assessing and, if necessary, mitigating the risks.
The UK has an adequacy decision for certain US transfers under the UK Extension to the EU-US Data Privacy Framework, which assessed US access laws, including the CLOUD Act. Where adequacy is not relied upon, organisations must use Article 46 safeguards, such as standard contractual clauses.
Given the ICO's role as the UK’s independent regulator, the Government has not had individual engagement on this matter specifically but note that Departments (as data controllers) ensure compliance and engage with it as appropriate.
Asked by: Anna Sabine (Liberal Democrat - Frome and East Somerset)
Question to the Department for Science, Innovation & Technology:
To ask the Secretary of State for Science, Innovation and Technology, whether the Government has conducted a legal assessment of the interaction between the US CLOUD Act and the use of Oracle’s UK Sovereign Cloud for public sector data.
Answered by Ian Murray - Minister of State (Department for Digital, Culture, Media and Sport)
Where cloud service providers may be subject to overseas legal obligations, including the United States CLOUD Act, departments are responsible as data controllers to assess and mitigate the associated risks.
The UK has an adequacy decision for certain transfers to the US under the UK Extension to the EU-US Data Privacy Framework. This decision assessed US laws and practices relating to government access to data, including the US CLOUD Act. This analysis is published and available on GOV.UK. Where adequacy is not relied upon, organisations must use alternative safeguards in line with Article 46 of the UK GDPR, such as standard contractual clauses.
Departments’ assessments enable them to identify and implement proportionate mitigations. These may include technical controls, such as encryption and strict access restrictions, contractual safeguards with service providers, and organisational measures governing data handling and oversight. Where relevant, departments must also assess the application of UK international data transfer provisions and ensure appropriate safeguards are in place.
Asked by: Anna Sabine (Liberal Democrat - Frome and East Somerset)
Question to the Department for Science, Innovation & Technology:
To ask the Secretary of State for Science, Innovation and Technology, what safeguards are in place to protect UK data held by US cloud providers from access requests made on US national security grounds outside the scope of the UK–US Data Access Agreement.
Answered by Ian Murray - Minister of State (Department for Digital, Culture, Media and Sport)
Under UK data protection laws, organisations must ensure personal data is appropriately protected when transferred internationally.
The UK has an adequacy decision for the US, which included an assessment of US national security safeguards. Where adequacy is not relied upon, organisations must rely on alternative safeguards, such as standard contractual clauses.
The UK has been designated a ‘qualifying state’ by the US under Executive Order 14086 allowing individuals whose personal data has been transferred to the US access to redress mechanisms if they believe their personal data has been accessed or handled unlawfully by US authorities for national security purposes.
Asked by: Anna Sabine (Liberal Democrat - Frome and East Somerset)
Question to the Department for Science, Innovation & Technology:
To ask the Secretary of State for Science, Innovation and Technology, what assessment he has made of the adequacy of rural broadband coverage.
Answered by Chris Bryant - Secretary of State for Northern Ireland
Our assessment is that rural coverage is not good enough which is why we are committed to improving it.
We are committed to delivering nationwide gigabit coverage by 2030. More than £2 billion of contracts have been signed to provide access to gigabit-capable broadband to over a million more premises.The vast majority of the premises to be covered by these contracts will be in rural areas.