GovNet Events Fraud

From Silos to Prevention: What the Digital Economy Act Can Do - and Where It Is Going Next

Written by Jessica Kimbell, GovNet | Jul 30, 2026, 1:16:31 PM

Michael Sowerby, Head of DEA Debt and Fraud Data Secretariat, Jabeen Kamran, Head of Debt and Fraud Data Sharing, and Chantel Mathurin, Counter Fraud Business Development and Operations Manager - all from the Public Sector Fraud Authority - presented at Counter Fraud 2026 on the current state and future direction of the Digital Economy Act as a data sharing tool for fraud prevention.

Here is a summary of what they said:

What the Digital Economy Act is and what it has achieved

The Digital Economy Act provides a permissive legal gateway for data sharing between public bodies under Chapters 3 and 4, covering fraud and debt. Michael described it as intended to be quick and easy - and was honest that it does not always turn out that way, given the governance requirements involved. The safeguards are deliberate and, he noted, reassuring: as a private citizen whose own data appears in some of these shares, he wants to know it is being handled correctly.

The Digital Economy Act provides a permissive legal gateway for data sharing between public bodies under Chapters 3 and 4, covering debt and fraud. Michael described it as intended to be quick and easy - and was honest that it does not always turn out that way, given the governance requirements involved of the data sharing bodies. The safeguards are deliberate and, he noted, reassuring: as a private citizen whose own data appears in some of these shares, he wants to know it is being handled correctly.

As of this presentation, 25 departments and ALBs and 70 local authorities have used DEA powers. There are 123 registered data sharing pilots on gov.uk, of which 47 are fraud-related. The council tax debt recovery pilot - involving a significant number of local authorities working with HMRC and DWP - is among the largest. Across all fraud-related pilots, £202 million in audited benefits has been identified to the end of March 2024, delivered by a team that averaged 3 to 3.5 people over the past several years.

How a data share actually works

Jabeen set out the practical mechanics. Any data share requires a Data Protection Impact Assessment (DPIA) and a Data Sharing Agreement (DSA) - documents that would be needed in any data sharing arrangement. What the DEA adds is a simple business case. All documents require sign-off at senior level and from the Data Protection Officer. Final approval across all stakeholders is then required, and the Cabinet Office Minister must sign off every DEA data share before it proceeds.

Chantel led a session that included a practical illustration of the principle of proportionality. Given the task of verifying a blue badge application - eligibility being linked to receipt of PIP at the higher rate - what data would you request? A full benefit history? Medical reports? Or simply a yes/no confirmation of whether the applicant is currently in receipt of PIP at the higher rate? The answer is the last option. Data minimisation is not optional: you share only what is necessary for the specific purpose.

The NHS is a notable absence from the fraud schedules. Jabeen explained that there is an active policy debate about using NHS data for fraud purposes - specifically, the risk that if someone is obtaining medication or services through fraud because they cannot access them legitimately, stopping that fraud could have direct consequences for their health. That conversation is ongoing.

The direction of travel: From detection to prevention

The session's central argument was that most DEA fraud work to date has been retrospective - identifying fraud that has already entered a system - and that the direction of travel needs to move towards prevention, before payments are made. 

Jabeen described this ambition as a "future firewall" - a capability allowing real-time checks before an action is taken, rather than investigation after the fact. Discussions are  currently under way with a local authority on pre-issuing checks for penalty charge notices. Because cloned number plates mean that the registered keeper of a vehicle is often not the person who committed an offence, the team is building a real-time DVLA check into the PCN process, so the correct vehicle owner is identified before a notice is issued rather than after an appeal.

She was candid about the limits of purely pre-payment prevention. For Universal Credit, a student loan can be taken out at any point during a claim - not just at the beginning - so a single pre-claim check is not sufficient. Similarly, social care fraud often arises from changes in financial circumstances mid-claim. The answer is checking throughout the life of a claim, not just at the start. The DEA framework supports this: data shares can operate as ongoing checks rather than one-time verification exercises.

On the return-on-investment challenge, Jabeen acknowledged that prevention is harder to quantify than detection. When a fraud prevention check stops a payment going out, there is no headline figure of fraud found - only a payment correctly refused. Departments are developing methodologies to model what losses would have occurred without the check, but this remains an area where the profession needs to build its evidence base. Prevention pays for itself, she said - the work now is demonstrating that convincingly.

From pilot to business as usual

A recurring theme in the session was the journey from pilot to business as usual - and the barriers that prevent pilots from making that transition. The DEA process starts small, proves the concept, refines the data share design, and then looks to embed it as a standing capability. Pilots range from two weeks to six months to complete, depending on the governance complexity of the organisations involved. HMRC, for example, has multiple levels of governance to navigate - appropriately, given the sensitivity of the data it holds. Other departments move more quickly or slowly.

Local authorities present a particular challenge. Each operates as a mini-government with its own DPO, legal advice and risk appetite. The council tax pilot involving 53 local authorities, HMRC and DWP has taken around a year in its current iteration - longer than previous versions, but being built from the outset for rollout to all 360 local authorities. Jabeen's observation about local authority engagement was practical: for most contacts at a local authority, a DEA data share is not their day job. They are managing it alongside other responsibilities. The DEA team's role is to work at the customer's pace, remove barriers, and do a significant amount of myth-busting - including reassuring organisations that yes, you can share children's data under the DEA, provided it is handled correctly.

The bigger picture: National Data Library and what comes next

In response to a question from the floor about the relationship between the DEA and the National Data Library, Jabeen confirmed that the DEA team is actively feeding into those conversations. One of the persistent practical difficulties in setting up data shares is simply knowing what data exists and where. The National Data Library, once established, should make that significantly easier - and the DEA team is working to ensure its experience and the datasets it has identified are reflected in how that library is built.

Michael closed with a clear message for everyone in the room. The DEA is permissive - it gives organisations the legal power to share data for fraud purposes, on their own terms, starting as small as they need to. The call to action was direct: whenever fraud is identified as a risk, the first question should be whether the DEA can help. The team sits within the PSFA alongside the NFI team and the data analytics team, and can signpost to whichever part of that structure is most relevant. The barriers to data sharing are real but surmountable. The conversation has started.