§ Lord Richardasked Her Majesty's Government:
What progress has been made by government departments in using BS7799 in order to implement the provisions of the Data Protection Act 1998; and what machinery exists to monitor the activities of individual government departments in this respect. [HL3366]
§ Lord Williams of MostynAlthough the Data Protection Act 1998 has not yet been brought into force, the Data Protection Act 1984, as well as the new Act, requires appropriate security measures to be taken to protect personal data held by data users or controllers. It is for each government department to decide, in the light of its own circumstances and personal data processing needs, what use to make of BS7799 in helping it to comply with its obligations under data protection legislation; and no central monitoring currently takes place.