During her presentation, she caught listeners up on some key definitions and developments in data protection, which can be a nightmare for organisations to navigate as they continue their digital transformation journeys.
When we think about the cloud, we have to think about data – cloud is just a mechanism for data storage that has quickly been adopted across industries in a bid to digitise and safely store their data.
But while cloud implementation has grown at pace, an understanding of how it works has not necessarily translated as well.
“I ask my clients: where is your data,” Irvine said, “and they say: the cloud. And then I ask: where is the cloud?”
This is where things start to get a little murky, and regulatory discrepancies occur.
Throughout her talk, Irvine skillfully breaks down the major data protection laws affecting firms in the UK, some of the integral definitions, and how data regulations have changed over time.
Data protection: Definitions and Regulations
Firstly, GDPR is the EU data protection legislation that was established prior to Brexit, which strictly required most online platforms to explicitly ask before collecting non-essential user data, and requires a legal basis for the collection of user data.
After Brexit, the UK set up it’s own GDPR law, which was then supplemented by the Data Protection Act 2018 – this essentially means that the UK has almost the same framework as the European GDPR, but with UK regulatory bodies, namely the Information Commissioner’s Office, keeping track of compliance and issuing fines.
The UK is currently drafting a new regulatory framework, titled the Data Protection and Digital Information Bill, which the UK government claims will be more business-friendly and less cumbersome than the current GDPR, while maintaining user’s digital rights.
Now, onto definitions.
Data protection regulations typically deal with data controllers and data processors.
Data controllers are those that collect and use personal data. Data processors are those that process and store that data, at the request and upon the instruction of the data controller.
Meta, for instance, would be a data controller – they collect data from their users for a certain purpose. A cloud service provider, like Microsoft Azure, Amazon Web Services (AWS), and Google Cloud, would be a data processor, since they store and transfer data at the whim of their data controller.
It is typically the responsibility of the data controller to create contracts keeping their data processor compliant with the relevant data laws.
Most laws have to do with data transfers, which can be defined surprisingly broadly: “It’s not just sending it physically, obviously, that’s not a thing that you can, some individual can access that data – not even just download it – but just access that data, then that counts as a transfer.”
This can even apply for employees of the same companies accessing data if they are in different places, particularly if they are across international borders.
And it is across these international channels that the regulatory nightmares begin.
International Data Regulations
According to Irvine, most UK cloud data is stored in the EU, and from a regulatory perspective, this is a very good thing.
After Brexit, the UK and EU decided upon an ‘adequacy agreement,’ meaning that the EU found the UK to have an adequate enough data protection law as to more freely transfer data between the two nations without further regulatory frameworks.
However, most cloud companies are based in the US, and data will sometimes be passed through digital borders and end up as ‘transferred’ to US parties of the same companies.
This requires firms in the UK to fill out contracts stipulating the acceptance of users to have their data transferred across the border and potentially subject to US law.
“In the US, there is no overarching data privacy, it’s not enshrined in the Constitution,” Irvine explained. Further, law enforcement agencies can access data in the US without a subpoena, as was exposed by Edward Snowden in 2013. This affected not just the data of US citizens and residents, but any global data held or transferred within the US.
This alerted digital rights activists in the EU, with Max Schrems taking the helm to push the EU to reconsider its data sharing regulations with the US.
Now, companies need to fill out extensive contracts with US-based companies to legally transfer data.
For international data transfers, companies must put in place additional safeguards: “The one that is used most regularly are standard contractual clauses – or in the UK we call them international data transfer agreements. And in addition to that, we are also obliged to carry out a transparent risk assessment.”
These legal hurdles can result in stringent fines if not done properly – data controllers need to make sure their processors, and any third party handlers, are held to GDPR standards
In one of the most high-profile GDPR cases, Meta was found to have not used a specific contract-basis to transfer EU data to the US, and the company was found in breach of GDPR, recurring a record £1 billion fine.
All of these legal requirements can make businesses with the US – home to some of the biggest names in technology – a legislative quagmire for companies large and small to reckon with.
But according to Irvine, this “goes back to the risk of us not having had rights in another country, we have not been able to do compensation in our country, and assets by law enforcement bodies.”
Still, the EU and UK have ambitions to make this entire process easier.
The EU is attempting to set up a Data Protection Framework with the US, “but this keeps being challenged,” according to Irvine.
The DPF would allow a more streamlined process for data transfer between the US and EU, which would make cloud transfer less legally challenging.
Recommended
- Roundtable | What Can Be Learned From Estonia’s Tech Success?
- The UK Government Publishes Renewed Geospatial Strategy
- Zühlke Plans to Scale Scottish Operation and Announces Senior Hire
Currently, the framework has yet to be accepted as the EU is still unimpressed with the US’s general lack of privacy guarantees. However, a new executive order would make it more difficult – but not outright impossible – for US law enforcement agencies to access EU data transferred to the US. The order introduced “concepts of necessity and proportionality” to allow US intelligence agencies to access the data of EU citizens.
At London tech Week, UK Prime Minister Rishi Sunak and US President Joe Biden met, and announced their intention to form a US-UK Data Bridge.
This would allow the US and UK to freely transfer data without specific contracts currently required by UK GDPR. While this is only and intention, and not a formal law, it does intend to “piggyback” as Irvine says, off of the EU-US DPF so the UK can retain their ‘adequacy agreement’ with the EU.
Currently, the UK is investigating US data protection laws so see if they will align with the UK’s current and future data privacy concerns.
The Data Protection and Digital Information Bill will likely fall under international scrutiny as countries and the EU decide if it offers enough protection to continue easy data transfers with the UK.





