The New Government and Data Protection
Where does the Labour government stand on data protection, cyber security and AI?
Of all the Bills announced in the King’s Speech, some are relevant for those working in the data protection, digital information and data security space. The Government has appointed a Minister of State for Data Protection and Telecoms. His name is Sir Chris Bryant, MP.

The full scope of the Government’s plans is not yet known. However, the background briefing notes to the King’s Speech do offer a few clues about what we can expect.
The DPDI is dead
As the General Election was called, the DPDI was abandoned. The bill was at the Committee stage in the Lords when this happened. It was always going to be a difficult bill to get into law. This was due to the large number of amendments added, prior to it leaving the Commons.
We now have the DISD Bill which appears to resurrect some of the provisions in previous Government’s Data Protection and Digital Information Bill (DPDI). However, don’t get too excited thinking that major reform of the UK GDPR is on its way. In other words, there isn’t going to be less onerous data protection obligations, as the Government is taking a different approach. A contrast changing the focus to enable the sharing of data to aid economic growth.
The background briefing notes stated that the Bill “will enable new innovative uses of data to be safely developed and deployed and will improve people’s lives by making public services work better by reforming data sharing and standards; help scientists and researchers make more life enhancing discoveries by improving our data laws; and ensure your data is well protected by giving the regulator (the ICO) new, stronger powers and a more modern structure”.
Focus of the Bill
Digital identity verification
Better known as Digital ID Cards, the aim of such identities is to make processes involving identities easier. Accordingly, this might be for ID verification for pre-employment and when buying age-restricted products. The new bill will make life much easier for ID checks.
‘Smart data’ measures
These measures will allow the sharing of personal data across platforms and with third parties. Consequently, the success of Open Banking has proven this approach works. Life is much easier for bank customers as they can now provide account information, which makes facilitating payments easier.
ICO Reform
This is a move away from a single commissioner to a national Information Commission. All the powers and functions would no longer rest with one commissioner. The current commissioner, John Edwards, supports this change. Furthermore, this will help with data protection enforcement.
Consent provisions for scientific research
The scientific sector will be able to request broad consent rather than specific consent. This is for legitimate scientific research.
We hope that we and other industry businesses will be allowed to help shape the new bill. The Data & Marketing Association (DMA) is advocating for twelve reforms which it says will make a difference to businesses and charities. These include greater certainty around the use of the legitimate interests and lawful bases. Likewise, it is hoped that this will reduce bureaucracy for small businesses. This will reduce the consent requirements for non-intrusive cookies. They want to extend the use of the email soft opt-in for non-commercial organisations.
Cyber Security and Resilience Bill
Better known as the ‘Cyber Bill’, this new bill aims to introduce measures to strengthen the UK’s cyber defences. It’s likely to give regulators more powers to push organisations to bolster their cyber defence measures. We might see some form of mandatory cyber incident reporting. It will be interesting to see how this ties in with the Cyber Essentials scheme. Furthermore, we will wait and see whether the Cyber Essentials scheme would be expanded to ensure cyber defences are in place. Data protection will remain at the core of the Government’s strategy.
Network and Information Systems Regulations
Expansion of the Network and Information Systems Regulations 2018 is long overdue. This will mean new rules being introduced in other words. These will include digital services and supply chains. The EU has already updated its NIS regulations. So, it is likely the UK will follow.
Artificial Intelligence
The EU AI Law is now in force and there is some debate as to how far its territorial reach extends. From a data protection perspective, it is often unclear where AI data processing actually takes place. Then perhaps this is why there wasn’t any official announcement of an AI bill. The alternative argument is that we don’t need an AI bill as we could simply adopt the EU bill.
In conclusion, the future of data protection looks bright.
However, I am concerned that without a mandatory standard for cyber security and data protection, all these well-meaning efforts could fall flat. Cyber Essentials can evolve to a mandatory standard.
Leave a Reply