As 2024 gets into full swing, David Goobrand, head of data privacy, and Andrew Macqueen, a trainee soliceter, of Technology and Commercial at Burness Paull have revealed some top data trends for the new year as regulation continues to change to keep pace with emerging technology and cyber risks.
Just after Data Privacy Day, it is important to freshen up on data compliance best practice as new laws and regulations come into view on the horizon
As data only expands in volume, the value placed on data increases on a complex scale, as do the risks associated with processing the data.
While firms are encouraged to stick to proper procedures, offer effecting training and awareness, and maintain accountability and governance, Burness Paull have delved deeper into what firms should keep an eye on in 2024.
New Year, New Laws?
2023 already saw the introduction of some major new regulatory laws in the European Union, with the introduction of the EU AI Act, the new Data Governance Act, the EU Data Act, the Digital Services Act, and the Digital Markets Act.
In the UK, the Online Safety Act was finally ratified after several legislative hurdles, aiming to dramatically change how the internet is regulated.
2024 will see the Data Protection and Digital Information bill introduced into the UK, their first major departure from GDPR.
The bill claims to be ‘business-friendly’, but experts are wary about the changes in the bill being friendly to anyone operating in the UK.
Burness Paul expects that the increasing number of regulations revolving data and the potential inter-relationship (or conflict) between these in the UK, Europe, and further afield can make compliance complex.
Artificial IntelligenceÂ
AI, especially generative AI, has captured the attention and investment of organisations across different sectors, with many rushing to embrace the benefits the emerging technology could bring.
The legal, regulatory and security risks, however, are starting to catch up, and need to be considered and managed carefully to ensure that AI remains an asset, rather than a liability.
Even as the ICO warns about a decline of trust in AI in 2024, adoption and reliance has not waned.
Burness Paull therefore urged a cautious approach to AI adoption, with risk management central to responsible adoption.
Considering and managing any data protection, discrimination, and bias related risks should also be a top priority for AI adoption.
Cyber Risks are Here to Stay
Cybersecurity continues to be the top risk of impacting all organisations in 2024. Cyber risk will continue to evolve in 2024, especially with the emergence of new and increasingly sophisticated threats with the use of AI and quantum computing.
Regulatory frameworks are looking to address this, in the UK and in Europe.
The Europe of the Critical Entities Resilience (CER) Directive has been adopted focused on resilience and incident response.
Recommended reading
- Data Privacy Week: Skills Gap, Budget Constraints Mar Privacy
- Data Protection Reforms Must Not Put UK and EU Data Flow at Risk
- Data Privacy Day: Where are We and How Did We Get Here?
2024 will also see the UK’s Product Security and Telecommunications Act 2022 come into affect, setting out minimum security standards that consumer networks must follow.
With these new laws and more regulatory scrutiny, it has become more important than ever to ensure an organisation is prepared with appropriate procedures in place.
Data Transfers
2023 saw a dramatic new data transfer regime, with the EU and the US finalising another attempt to simply data transfers between the two regions.
The EU and US have radically different approaches to data protection and regulation, and the EU-US Data Privacy Framework (DPF) is already expecting challenges from privacy advocates including Max Shrems of None of Your Business (NOYB), which broke down the last attempt to simply data transfers.
In fact, Nader Henien, VP analyst in data protection at Gartner, Inc, in an interview with DIGIT, confessed that he is on the record telling organisations to not rely on the DPF for data transfers as he is expecting the law to get challenged soon.
As the UK has essentially piggy-backed onto the EU-US framework, it will remain to be seen if the UK-US data bridge will also be challenged, and if it will be upheld.
Separately, the EU-UK Adequacy Decision is set to be reviewed this year. The agreement simplifies the data transfer process between the EU and UK, but may be scrutinised as the UK’s new DPDI bill is approved and changes some laws and regulations.
While Laura Irvine, partner and head of regulatory law at Davidson Chalmers Stewart LLP, and an accredited specialist in data protection law, says the agreement may be at risk, Henien says the agreement is likely to stay based on the other countries the EU has adequacy agreements with.
Further, towards the end of 2023, the ICO issued new guidance for organisations completing transfer risk assessments for transfers of personal data from the UK to the US – Burness Paull expects further guidance to come in 2024.
Burness Paull also expects a focussed effort from a number of organisations to implement the new EU standard contractual clauses (SCCs) and the UK Addendum or the UK standalone international data transfer agreement ahead of the March 2024 deadline.





