Site navigation

ICO: UK Data Protection Bill ‘Creates Risks’

Andrew Hamilton

,

ICO data protection bill

The Information Commissioner’s Office has warned the Government that its proposed amendments to the Data Protection Bill overstep boundaries.

The Information Commissioner’s Office (ICO) has condemned last-minute changes made to the Data Protection Bill (2017) as ‘going beyond’ the Bill’s stated ambition.

The news comes just one week after it was reported that the Government was placing limits on the Investigatory Powers Act, curbing the amount of data that it would gather from sources not directly connected to criminal investigations.

But these latest changes, reported on Friday, allow the government to draw up its own framework on how departments will process personal data in the future, with only a need to ‘consult’ the Commissioner – there are no requirements to actually follow Commissioner Elizabeth Denham’s advice.

Even before these changes, The Register reported that data protection experts and the ICO itself had voiced concerns that the Data Protection Bill could make it difficult for the Commissioner to challenge the framework of the Government’s proposed collection policies. In effect, this could make it difficult to enforce rulings at all.

Now, the ICO has published a longer and more detailed criticism of the proposals.

The document states that the ICO and Information Commissioner, “understands the need for government departments and public bodies to be clear about their legal basis for undertaking their functions.”

However, the document adds: “The provisions as drafted appear to go beyond this limited ambition and create different risks that must also be considered.”

The ICO’s ‘most significant concerns’ centre on Clause 178(5) of the proposed DPB, which forces the Commissioner to consider government frameworks when questioning official data-gathering policies. The ICO has contested that it already considers relevant statutory guidance in its investigations, and added that if the Commissioner failed to do so, “she would be open to judicial review”.

According to the ICO, the provision, “runs a real risk of creating the impression that the Commissioner will not enjoy the full independence of action and freedom from external influence when deciding how to exercise her full range of functions”.

The ICO has also warned that the current wording of the bill allows the government to extend its framework to cover a specific person, “with functions of a public nature”, which the ICO claims could apply to private persons who perform some public actions. The ICO said: “The definition of this is very wide and could cover any aspect of data handling within government or other bodies to whom the measure is applied.

“A draft of the likely framework guidance should be published during the passage of the bill to allow parliamentarians and others to judge the extent and likely value of that guidance and how it fits with existing statutory guidance.”

Three peers have since written suggested amendments to the offending clauses to be considered in the bill’s report stage. These changes shift responsibility for writing a framework from the Secretary of State to the Commissioner, and removes the requirement for the ICO to take the framework into account.

Andrew Hamilton

Andrew Hamilton

PR & Content Executive at Hutchinson Networks

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data