Site navigation

UK Data Protection Bill Falls Short

Andrew Hamilton

,

UK Data Protection Bill

Several organisations including Which? and the Open Rights Group have demanded Digital Minister Matt Hancock improves the UK Data Protection Bill 2017.

The embattled UK Data Protection Bill has come in for further criticism, this time from a group of consumer rights and privacy organisations. Several UK groups have written to demand the UK’s Minister for Digital, Matt Hancock, improves the Data Protection Bill (2017), which they claim will allow companies to get away with major data breaches unscathed.

The privacy collective – composed of Which?, the Open Rights Group, Age UK, the Financial Services Consumer Panel and Privacy International are supporting ‘collective redress’ in instances of mass breaches. This would allow nominated organisations to pursue offending companies on behalf of consumers as a whole, rather than requiring individual consumers to pursue a complaint.

This new approach could enforce a far stricter approach to reporting breaches. It could also circumvent  situations where consumers are not pursuing a company, thanks to ‘data breach fatigue’ – where customers become apathetic to a breach because it happened in the past, or where it involves very young, or very old consumers.

As an example, a major criticism surrounding Equifax’s handling of its colossal data breach during the summer was the firm’s delay in admitting its failure – customers were only informed in September, five weeks after the breach incident on July 29th.

The Open Rights Group’s Scotland director, Matthew Rice, wrote about this very issue in DIGIT in October 2017.

The organisations have co-signed a letter to Mr Hancock, which reads: “Under the current system individuals have the right to seek redress from organisations when their data has been lost or misused.

“Whilst we wholly support the provisions in Article 80(1), which reflects the existing system, it is inadequate on its own in holding organisations to account. Further, given the potential scale of data breaches and the breach notification duty, a mechanism under Article 80(2) would save significant administrative and court time, in that it will avoid a myriad of individual claims.”

Super Complainants

Jim Killock, Executive Director of the Open Rights Group, told Banking Technology that the process would be enforced through the creation of ‘super complainants’ – a select few organisations that have the power to raise the issue with the offending company: “Currently a human face has to be attached to a complaint before it can be taken forward, but the letter urges for action against bad practice, not necessarily the harm of consumers.”

Being a super complainant would come with certain qualifications, the organisations assert. For example, only certain institutions would be allowed to become super complainants. Also, these organisations would have to demonstrate accreditation, and would risk losing this if they flooded the Information Commissioner’s Office with too many irrelevant cases.

There would be no financial reward attached to these cases in order to deter the ‘ambulance chasers’ and cowboys who could seek to gain from legal action. Instead the cases would be pursued from a security and privacy point of view.

The new proposals would directly affect the Data Protection Bill (2017), currently in its report stage at Parliament where amendments can be made. This Bill was also criticised by the ICO for allegedly ‘going beyond’ its remit, and permitting the Government to collect too much information from the people, without needing to consult the ICO.

Andrew Hamilton

Andrew Hamilton

PR & Content Executive at Hutchinson Networks

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data