Breach of confidentiality in the disclosure of data for technical processing or technical storage
Translated from Swedish by AI; the translation may contain errors. The Swedish text is the original.
Summary AI, written in advance
S motions for approval of the committee's proposal so that authorities can better outsource or coordinate their IT operations, which can become more cost-effective and provide more robust protection 1. S emphasizes that the authorities have a great responsibility in the suitability assessment and that the restriction of the freedom of information strengthens the protection for sensitive information 1. V welcomes the purpose but motions for approval of its reservation because they believe there are major security challenges and risks with outsourcing, especially to private service providers abroad 2. V argues that the authorities' information security must be improved before the proposal is implemented 2. M motions for approval of the committee's proposal and argues that outsourcing can provide more secure data protection than in-house management 3.
Written by AI in advance and may contain errors. The numbers lead to the speech a statement builds on; check against the text below.
Peter Hedberg (S)
Mr. Speaker! Today we are debating the Committee on the Constitution's report 2022/23:35 Breach of confidentiality when handing over for technical processing or technical storage of data. I would first like to move for approval of the committee's proposal in the report.
Mr. Speaker! The purpose of this proposal is for authorities to be able to better outsource or coordinate their IT operations. Furthermore, one of the purposes is also to strengthen the protection for the data that is disclosed during such a procedure.
The proposition submitted proposes that confidentiality shall not prevent an authority from providing information to an individual or another authority if these have been tasked to only technically process or technically store the information. The possibility of outsourcing the storage can mean a more cost-effective operation for the individual authority, but also that one gains access to a more robust protection.
I know that several concerns have been raised about this, both during previous referral processes and now after the bill has been submitted to the Riksdag and processed. At an earlier stage, the investigation suggested that an authority wishing to outsource or coordinate its IT operations should not do so if the interest that the secrecy is to protect takes precedence over the interest of disclosure. Several referral bodies objected to this, and instead, the government has proposed that information shall not be disclosed if it is inappropriate in view of the circumstances.
This is a change that we Social Democrats welcome, and I note that this is also highlighted in the reservation found in the committee report. Here, I really want to emphasize the authorities' responsibility and what we actually say in the committee report. The suitability assessment shall "take into account all circumstances that are relevant in a specific outsourcing or coordination situation. These may be circumstances linked to the authority providing the information, to the recipient of the information, or to the information being disclosed. The circumstances may also refer to the current IT operation service, the contractual relationship between the commissioning authority and the recipient of the information, or the general security situation, nationally or internationally."
This means that an authority that wants to outsource or coordinate its IT operations, therefore has a great responsibility based on this suitability assessment.
Mr. Speaker! There are not many of us registered for this debate; there are three of us. We Social Democrats have noted the concerns found in the Left Party's reservation and do not intend to minimize the risks in any way. But we have also highlighted such parts in the committee's position and therefore have come to the conclusion that we stand behind the proposal.
It is also important here to emphasize the restriction of the freedom of information for those covered by a duty of confidentiality and who handle sensitive information in a situation involving outsourcing. We believe this strengthens the protection for sensitive information.
Mr. Speaker! In conclusion, IT security is crucial for our citizens' privacy. This applies regardless of whether the authority handles all parts itself or whether IT operations are outsourced or coordinated. It must be emphasized that it is probably difficult to protect against all forms of intrusion, both due to technical developments, security policy risks, and unfortunately also the human factor. On the other hand, I believe we all in the committee agree that we as legislators expect active work from the authorities to ensure adequate security for the tasks they have to handle, as well as that the authorities signal to us what needs they have regarding both resources and other forms of challenges.
Jessica Wetterling (V)
Mr. Speaker! I thank the previous speaker for having, in several ways, usefully mentioned the objections that the Left Party has in this matter.
Mr. Speaker! Every day, the public handles vast amounts of information. Much of what is handled and stored is both important and sensitive, both for the individual and for our society as a whole. Certain pieces of information are classified as protected, and some also concern national security. If information is lost, stolen, manipulated, or disseminated to unauthorized persons, it can easily have serious consequences. Many still remember and associate the Transport Agency primarily with the scandal in 2017 – which, among other things, caused the Committee on the Constitution to be convened in the middle of the summer – when it was revealed that non-security-cleared persons abroad had gained access to protected personal data.
A high use of IT services in society often leads to many good things that facilitate our everyday lives, but it also entails digital security risks. In recent years, there has been increasingly frequent warnings about cyberattacks against various authorities, which have subsequently received media attention. There has been a clear increase in incidents related to the internet, for example, data breaches, fraud, and the spread of malicious code.
It is clear that a lack of security protection and deficient information security risk having devastating consequences for our society. Incidents or disruptions attacking the digital infrastructure can, for example, lead to extensive problems for financial systems, healthcare, food supply, or our national security. When the handling of important information fails, it also risks leading to a diminished trust in our authorities and societal functions.
Mr. Speaker! The Government's proposal in this matter concerns the creation of a new confidentiality-breaking provision whose purpose is to create opportunities for authorities to hand over data covered by confidentiality to an individual or another authority whose mission is to technically process or store the data on behalf of the requesting authority, so-called outsourcing.
The government's purpose is good; it is to create better conditions for agencies to outsource or coordinate their IT operations as well as to strengthen the protection for the tasks that are handed over in an outsourcing of the IT operations. This in itself is, of course, something the Left Party welcomes. We can, however, unfortunately still not stand behind this proposal from the government.
Mr. Speaker! Sweden's ambition has long been to be at the forefront within the EU when it comes to digitalization. As a country, Sweden has also had great success in developing digital solutions in almost all areas of society. But when it comes to the work with and awareness of cybersecurity, Sweden does not rank nearly as high. Just yesterday, I listened to representatives from the Swedish Authority for Privacy Protection who raised this problem. Furthermore, many others within the industry testify that there is a major shortage of competence and that it is difficult to hire people who are experts in cybersecurity.
The Swedish Security Service testifies that Sweden is subjected to cyberattacks daily that are increasingly sophisticated, and that the effects of cyberattacks can not only have major consequences for society-critical functions and critical IT systems, but also that the direct and indirect costs of these attacks are estimated to be in the billions.
The Swedish National Audit Office has also repeatedly audited the agencies' information security work and reported on deficiencies in, among other things, the follow-up work.
Mr. Speaker! It is quite clear that today's order is not functioning satisfactorily, and in that case, one could also think that the Left Party should welcome this proposal from the government. One could also assume that the purpose is to help, above all, small agencies with few employees, where it should reasonably be a bit more difficult to establish effective protection for various tasks, to be able to subcontract the work to another larger agency that has more resources and that the protection could thereby be strengthened.
It sounds both reasonable and wise. But last week, the Swedish Police Authority, which is one of our largest agencies, was forced to send emails to over 60,000 people who have applied for jobs at the agency, because their personal data may have been compromised following a breach.
Mr. Speaker! I mean therefore that there are major security challenges when data is stored digitally and outsourced, but also when authorities handle the data themselves. I mentioned the Transportstyrelsen scandal earlier as an example, but it is unfortunately only one of many.
Due to these deficiencies, Vänsterpartiet has previously submitted a motion that the government should develop state cloud services which could also help authorities, regardless of size, to maintain good information security. We consider it a risk factor in itself to outsource tasks involving the handling of security-sensitive information, and that outsourcing of protected tasks should only occur in exceptional cases. We particularly question whether sensitive information can be outsourced to private service providers abroad, something that occurred in the Transportstyrelsen scandal.
The Government has, in its proposal, partially listened to the referral bodies' criticism regarding which balance of interests should be made before an authority outsources certain tasks or not. Unfortunately, however, the fundamental problem of lack of information security at the agencies remains. The Government writes in its proposition that access to secure and efficient IT operations is a fundamental prerequisite for a state or municipal agency to be able to conduct a purposeful operation, but the Government does not elaborate on whether the agencies' IT operations are sufficiently secure today or how they can become so in the future.
Mr. Speaker! For example, the Prosecution Authority writes in its referral response that an implementation of these proposals would entail a significant risk that authorities, municipalities, and regions could come to make decisions that conflict with EU law and the requirements for personal data processing, and that information subject to secrecy is incorrectly disclosed. They also write that if clear and mandatory security requirements are not established and the authorities' knowledge of and work with information security classification are not given greater focus, an implementation would simply entail a risk to Sweden's digital sovereignty.
The Swedish Police Authority and several other referral bodies share the same criticism and therefore reject the proposal.
We in Vänsterpartiet agree that the authorities' work regarding information security and security protection must improve before a proposal like this can be implemented.
I would like to conclude by moving for approval of our reservation in the matter.
Lars Engsund (M)
Mr. Speaker! We are debating the government's proposal for amendments to the Public Access to Information and Secrecy Act. I agree with much of what Member Peter Hedberg mentioned in his speech and therefore intend to shorten my speech a bit to save some time.
In short, the proposal is about facilitating for authorities to manage their IT operations in a more cost-effective way, which can also lead to more robust and secure information management than what can be achieved with IT operations managed in-house. It can, for example, involve that adequate competence and adequate resources are lacking to manage the IT operations, especially in smaller authorities.
This can occur, for example, by smaller agencies collaborating in a joint IT operation, alternatively that an agency subcontracts, or outsources as it is also called, its IT operation to service companies that are specialized in the task. The proposal also means that the protection will be strengthened for the tasks that are handed over to an individual when the IT operation is subcontracted.
It is important to emphasize in this context the importance of the information handled by our agencies having a purpose-specific protection. Deficiencies in the handling of protected information at an agency can have very serious consequences. Outsourcing or coordination of IT operations can involve risks. At the same time, an outsourcing or coordination of IT operations can result in the agency achieving a more secure and robust task protection than can be achieved with IT operations managed internally.
Breach of confidentiality in the disclosure of data for technical processing or technical storage
Mr. Speaker! The follow-up motion to the report states that security challenges exist and that they are of a significant nature. Among other things, comparisons are made with the so-called Transport Agency scandal in 2017, where non-security-cleared persons were given access to classified information. This is, of course, a serious and unacceptable incident. Requirement setting, control, and follow-up are thus particularly important parameters for an authority's IT operations, especially in areas such as those concerning secrecy and the handling of sensitive information.
Naturally, this applies regardless of whether the IT operations are managed internally by the agency, coordinated, or outsourced. It is not who manages the operations that is decisive, but rather how they are managed, that is, that there are adequate routines, how requirements are set, how they are controlled, and how they are followed up that guarantee security and robustness.
Mr. Speaker! I vote in favor of the committee's proposal in the report and therefore against the follow-up motion.
The deliberation was hereby concluded.
Source: The Swedish Parliament. The speeches come from the open data of the Riksdag, translated into English by AI, which may contain errors.