UK Government to Introduce New Data Reform Bill

Rumours, gossip and all sorts around changes to Data Protection Law in the UK have been around since the 2021 consultation. But what is likely to happen? Well, we don’t know as the results of the consultation have yet to be published. So, any changes to data protection law in the UK are purely speculation. Here is what we do know and what the industry believes may happen.

The ICO launched a consultation on data transfers under the UK GDPR. This closed at the end of 2021. Following that consultation, on 28th January 2022 the Secretary of State laid the international data transfer agreement (“IDTA”) and UK addendum to the new EU Standard Contractual Clauses (“UK Addendum”) before Parliament. Also, a document setting out transitional provisions for the purposes of the UK GDPR and UK Data Protection Act regarding the use of the standard data protection clauses for international transfers was approved by the European Commission under the Data Protection Directive. 

The IDTA, UK Addendum and transitional provisions came into force on 21st March 2022.

The IDTA and UK Addendum will replace use of the previous EU Standard Contractual Clauses (approved by the European Commission) under the UK GDPR (“Directive SCCs”).

Timescales

Contracts concluded on or before 21 September 2022 on the basis that the Directive SCCs continue to provide appropriate safeguards. This will be until 21st March 2024 for the purposes of the UK GDPR. This is provided the processing operations and the subject matter of the contract remain unchanged. Also, the reliance on those Directive SCCs ensures that the transfer of personal data is subject to appropriate safeguards. Therefore, there is some time for organisations to update existing agreements based on the Directive SCCs. For new contracts for data transfers from the UK entered into after 21st September 2022, the UK Addendum to the new EU SCCs or the IDTA will need to be used. However, it can also be used for new contracts going forward once it comes into force on 21st March 2022.

Article 28

The IDTA uses the term “linked agreement”, which are agreements between the importer and exporter. For example, if the importer is a processor and there are Article 28 data processing terms in place in an existing or separate agreement. Therefore, the IDTA allows for the ability to cross refer to the relevant section of the linked agreement in certain circumstances.

An important difference between the new EU Standard Contractual Clauses and the IDTA is that the IDTA does not include Article 28 data processing terms. Instead, there is a provision which states if the importer is a processor or sub-processor, there is a linked agreement that includes those Article 28 obligations. In addition, the IDTA does not adopt the same “modular” approach as the new EU Standard Contractual Clauses.

In relation to the new EU Standard Contractual Clauses there is the option of a “UK Addendum”. This is a short template document which makes amendments or additions from a UK perspective. For example, referring to the UK rather than the EU, UK Data Protection Laws rather than EU GDPR, ICO rather than supervisory authority etc).

The use of the EU Standard Contractual Clauses with a UK Addendum will be the most practical solution for many organisations transferring personal data from both the EU and UK. This will help maintain consistency.

UK Data Protection Laws Consultation

The Department for Digital, Culture, Media and Sport published a consultation (“Data: a new direction”) on proposed amendments to UK data protection law. The consultation closed in November 2021. The outcome of that consultation is yet to be published. As a result, there is no draft legislation at this stage. This indicates that the current government is considering various changes to UK data protection laws in the future.

Potential Changes

Talking with industry colleagues and taking into account social media and plain old rumour, we believe the following is likely:

Legitimate interests:

Proposals to create a limited, exhaustive list of legitimate interests so that organisations can use personal data without applying the balancing of interests test. This could cover purposes such as:

Reporting criminal acts

safeguarding concerns to appropriate authorities

delivering statutory public communications

monitoring, detecting or correcting bias in relation to developing AI systems

audience measurement cookies or similar technologies to improve web pages that are frequently visited by users

Improving or reviewing the organisation’s network or system security

Improving the safety of a product or service

De-identifying personal data through pseudonymisation or anonymisation to improve data security

Personal data for internal research and development purposes

Business innovation purposes aimed at improving services to customers.

Flexible risk-based accountability framework:

The proposals include a requirement for a privacy management programme tailored to the organisation’s processing. We find this strange as we tailor privacy management to our clients’ needs whilst staying within the law. We are curious to understand what this means. We will update you when we know more about this.

Removal of requirements to designate a DPO:

This one concerns a great many in the industry. This involves replacing the requirement for a DPO with a new requirement to designate a suitable individual to be responsible for the privacy management programme. The individual will oversee the data protection compliance of the organisation. So, is this a responsible person? Again, we need to know more.

Removal of the requirement to conduct a DPIA:

We all love a DPIA…don’t we? Ok, maybe not but they perform an important role in data protection. The intention is to allow organisations to adopt different approaches to identifying and minimising data protection risks to better reflect their specific circumstances.

Removal of the requirement for prior consultation with the ICO:

It is suggested that it would no longer be mandatory to consult with the ICO in advance of carrying out processing identified as high risk. This data cannot be mitigated in light of the assessment under a DPIA. As this is not mandatory then fines cannot be applied for not doing so. This is probably good news but clear lawful guidance is needed to ensure rights of individuals are protected.

Removal of Article 30 record keeping requirement:

Ah, the much discussed ROPA. Love it or loath it, the Article 30 ROPA is a useful tool. Instead, new requirements under the privacy management programme would require certain records to be kept but organisations would have more flexibility. A Data Inventory can be kept. Hmmmm, does this sound familiar to anyone?

Change to the breach reporting threshold:

There is a suggestion that breaches would only be reportable to the ICO unless the risk to individuals are not “material”. Currently the threshold is “result in a risk” to individuals. The consultation suggests that the ICO would produce guidance and examples on what constitutes “non-material risk” in this context. Very interesting, and we wait.

Voluntary undertaking process:

This would involve providing the ICO with a remedial action plan if an infringement is discovered, This could be accepted as part of a voluntary undertaking process. This is a good idea if proper guidance is offered.

Data Subject Access Requests:

Oh, great news here. The proposal is to introduce a fee regime for data subject access requests, for example, by introducing a cost ceiling. This would operate as a cost limit to prevent organisations being overburdened by requests. In addition, there are proposals to change the threshold for response to a request. This would change the current threshold of “manifestly unfounded” to  “likely to cause a disproportionate or unjustifiable level of distress, disruption or irritation”. This would take into account the context and history of a request, including the identity of the requester and any previous contact with them.

The number of disruptive requests our clients are burdened with is too high. We decline many of them and then requestors run to the ICO who in turn back them. We are then required to fight our clients corner. The ICO will need to be very specific here! Charging a fee will stop many requests.

However, allowing the court access to previous claims activity will stop the serial claimers making a living from innocent businesses.

Cookies:

Whether cookies or essential cookies remain has been the subject of endless speculation for some time. Let’s wait and see.

Fines under PECR:

The alleged proposals also include increasing the levels of fines for breaches of the Privacy and Electronic Communications (EC Directive) Regulations (“PECR”). They contain the rules on electronic direct marketing and cookies, in line with the levels of fines under the UK GDPR. At present, the maximum amount of fines under PECR is £500,000. The Conservatives have already been fined under the PECR. Interesting…

Adequacy:

The consultation also sets out the Government’s intent to have an “ambitious programme of adequacy assessments” for third jurisdictions or groups of jurisdictions in relation to transferring personal data from the UK post-Brexit. Whether the new proposals meet with EU adequacy rules remains to be seen.

How does this affect you?

We are in no doubt every business will be affected by the suggested changes. If in doubt, get in touch here. We are always happy to help.