DPDI II
Not another GDPR, surely?
The government recently brought an updated version of the Data Protection and Digital Information (DPDI) Bill to parliament. It is currently in the Lords and will make the statute book very soon. This much anticipated sequel will reportedly save British businesses billions of pounds in unnecessary paperwork. Folks on the web will apparently no longer be bothered by so many annoying cookie popups when browsing the web. Is it an enhanced GDPR? This seems unlikely. It is likely to be another framework.

What is this bill trying to achieve?
The Data Protection and Digital Information Bill is an important evolution of the UK’s data protection framework.
The Bill strikes a delicate balance between reform and upholding high data protection standards. It is designed to make the UK’s data protection regime clearer and easier to comply with for low-risk scenarios, to support data-driven research and innovation, and provide clarity to organisations on how they can process data for clear public interest reasons such as for crime prevention, safeguarding and to support the Government and public services to respond to serious incidents.
These reforms will clarify and enhance the flexibility of the UK’s data protection system, benefitting researchers, innovators, and smaller companies as well as citizens and public authorities.
The DPDI Bill will amend the UK’s General Data Protection Regulation (GDPR) in ways that support the use of data to solve some of the UK’s most pressing challenges. This will provide clearer bases for using data in research and development to giving companies more certainty to process data to prevent crime, respond to emergencies and to safeguard children or vulnerable adults.
However, the aims of this are great, but what else lurks within this bill?
Valuable House Time
When the government introduces a new bill to Parliament, it can often contain extra elements not originally part of the bill. This can happen because an idea dropped from a previous bill can be added to another bill, if closely related.
The reason is that officials and ministers look to do deals and add dropped components from failed legislation or elements removed at committee stage. Therefore, a successful deal can mean you get a greater return for your parliamentary time. However, if not all goes well, a bill can be scuppered with some great polices, never making it into law.
It now seems that the DPDI has suffered a similar fate. The GDPR introduced permission based cookie consent. We all loathe this, let’s be honest. And businesses want less paperwork in order to be compliant. Can this be done in a meaningful and safe way? The DPDI II promises this. But, will it deliver?
New Frameworks
There will also be new frameworks for digital ID verification and new schemes for increased data portability. The regulator (the ICO) will see governance changes. Its management of the GDPR has been questionable and its inability to levy appropriate fines, woeful.
Finally, new frameworks for artificial intelligence will be in place, but the EU AI Act is also in place. Will this new act comply with it and where is the jurisdiction? The scaremongers are saying this could lead to higher fines than the GDPR. The ICO should look away now.
These are all challenging and potentially emotive issues to combine in a single story. This means an inevitably slightly confused narrative. Through its amendments, the government appears to have responded to feedback in good faith, but by charting the middle course you can risk upsetting everyone.
Government response
The government’s announcements have referred to vast cost savings to businesses and a reduction in annoying cookie banners. Are these just headline-grabbing statements? No doubt designed to win votes. Of course they are. But, what is the truth?
There have been criticisms of the EU’s ‘top-down’ and ‘one-size-fits-all’ approach to regulation. The DPDI II will be based on common sense, it is claimed. Therefore aiming criticism at the GDPR. But are the wonderful benefits of the DPDI II being overstated?
Number Ten is keen to tell us that we will be diverging in some senses from EU law. However, importantly not so much that we lose our Adequacy status with the EU. But as companies that trade within the EU will still need to meet EU standards for that market, they may just stick with what they are doing to avoid running two different processes. In other words, the GDPR.
The Wider Market
This is very tricky for UK companies working in both markets. In particular, websites, which aim to serve potential customers all around the world. Therefore the headline-grabbing, EU bashing benefits might be a bit of a red herring.
Inflating benefits and spinning headlines that land well with the supporter base are unsurprisingly standard fare in Westminster. In truth, the main crime the government has committed through this Bill is its paradoxical approach to data portability.
Data Portability
The DPDI offers new powers for the government to introduce Smart Data schemes. In practice, this could lead to new schemes in a range of sectors such as finance, communications, and energy that unlock the flow of consumers’ personal data from their providers to trusted third parties. This could be a major benefit. However, suitable controls must be in place.
I foresee that one of the most powerful candidates for such a scheme would be Open Digital, through which consumers could (if they wish) seamlessly provide continuous real-time access for accredited third parties to their online data generated by web browsing, app downloads, online shopping, music and video streaming, travel etc.
Personal Information Management Services (PIMS) have for decades been an ambition. However, Smart Data schemes like this can make them a reality. We are observing rapid advancement of AI capability and its potential ability to learn and add value from large volumes of information. Therefore, the case for releasing data from controllers has never been stronger. But the lack of AI controls and legislation is frightening.
Smart Data for all?
The government has been working on Smart Data for some time. Initial consulting on proposals took place in 2019. It has subsequently run workshops with regulators and conducted various pieces of research. In its final impact assessment, it championed the potential benefits of ‘new innovative services, stronger competition in the affected markets, and better prices and choice for consumers and small businesses. This includes reduced bureaucracy. Competitive data-driven markets can reduce friction for established market players. It can also drive start-ups, investment, and job creation’.
Final Thoughts
The Government elected to introduce late number of amendments on the bill’s last day in the Commons.
I believe this is good policy making with no political agenda. However, after many years of discussion, thinking and consideration, where are we? The real truth is we are miles away from a new scheme being implemented. For now, we must hope that the newly created Smart Data Council can get things moving. I won’t be holding my breath and I don’t think you should either.
The UK’s DPDI Bill creates another regulatory framework.
For instance, on cookies ,”The Bill proposes to permit organisations to use cookies without consent (on an opt-out basis) in a limited set of circumstances, namely if the purpose of the processing is:
- to collect statistical information in order to bring improvements;
- to enable the way the website appears or functions when displayed on the terminal equipment to adapt to the preferences of the user, or to enhance the appearance or functionality;
- for the installation of necessary security updates to a device; and
- to locate an individual in an emergency.”
If you want to know more, please contact us.
Leave a Reply