In his opening salvo, Mitchison posits that despite marketers having to seriously get to grips with data protection legislation following the introduction of GDPR in 2018, it hasn’t done much to make the tangible rules around the subject clearer.
“When a marketer asks a question about Data Protection, the answer is often, ‘it depends’,” as he puts it.
The reason for this is because data protection is principle-based and often down to interpretation. If anyone’s in a position to make this claim, it’s Mitchison. Being the Director of Policy and Compliance for the Data & Marketing Association, he has a unique frontline insight.
According to Mitchison, one of the main roadblocks to data protection clarity for marketers are the Privacy and Electronic Communications Regulations – according to him, “it’s massively out of date and follows EU legislation which is no good for obvious reasons”.
And, although there’s been purported new legislation, it’s been “stuck in limbo for years, with the finalised text that makes up the legislation due to arrive in the next six months”.
As well as this, the ICO’s direct marketing code of practice was published in a draft state two years ago and remains just that, a draft. “This creates a lot of points of confusion, people don’t know whether to comply with what’s there as that’s what the ICO is intending, although it’s not law yet.”
As well as governmental codes, there are industry codes of practice to contend with, though these in general strive to be more helpful and offer guidelines to help with best practices.
Through industry codes, organisations like the DMA can work in tandem with government to bring industry codes to the ICO, meaning that certain aspects of data handling – with regards to marketing – can be delegated.
The lack of over-arching clarity on guidelines that reach every facet of advertising means there’s a constant flow of ongoing investigations and enforcement cases. These seriously affect people’s confidence in how data is handled.
On this, John says: “All of the large organisations that engage in large-form advertising find themselves under investigation but often, they don’t have guidance or frameworks from which to operate outside of legislative grey areas.”
One of the great marketing challenges of the day is centred around third party cookies. These have been getting phased out for some time but now we have a finalised date for their end, with them to be completed banned by the end of 2023.
On this, Mitchison says: “There have been various solutions in the offing but none of them have really taken hold meaning there’s something of an incoming void with regards to replacing third party cookies.”
From this, Mitchison moved on to the appointment of John Edwards as Information Commissioner and his comments since. Specifically, Mitchison highlighted the need for a strong data adequacy agreement as being paramount to the free flow of data.
Mitchison expressed some concerns over John Edwards’ comments about instigating a ‘bold new data regime’ and the impact that any wholesale changes could have on things adequacy.
Beyond this, reforms in the ICO strike John as “change for changes sake”.
Essentially, for all the positive steps in heralding a less opaque framework – Mitchison cites the Government’s proposed list of legitimate interests as “very positive”.
However, “there’s a lot of different things interacting that are causing confusion. A lot of marketers are at a loss of where to go for answers,” according to Mitchison.
Recommended
- Understanding cybercrime is key to defending against it
- Strathclyde Uni 5G project brings fans immersive sports experiences
- Scots tech employers asked to shape future of digital apprenticeships
His answer to this is to draw up a hierarchy to help guide best practice, this goes as follows:
The DMA Code – an aspirational agreement to which all DMA members and their businesses must adhere to. As a practical guide to what actually works, John feels this should be marketers’ first stop for tangible guidance as it’s coherent to an ethical approach to data that not only adheres to the law but serves as good practice as an ethical framework that “respects privacy, is honest and fair, is diligent with data and takes responsibility”.
GDPR/DPA 2018 – the legislation itself, as best as it can be taken on board and applied to your needs.
PECR/ePrivacy – the UK interpretation of EU ePrivacy directive.
ICO codes of practices – when this is published, it will have legal standing – the current draft has a lot of ‘do I, don’t I’, according to Mitchison, so looking further up the hierarchy might better serve your needs.
GDPR industry codes – though not many have been approved thus far, this is a good way to streamline guidelines specific to your industry.
DMA best practice guides – “these are excellent how to guides that focus on the practical uses of marketing,” according to Mitchison.
So, following all that, what is the current state of play for data protection legislation? Despite Mitchison’s best efforts to cut through the noise, his answer is, “uncertain”.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





