The data adequacy decision, announced yesterday, will prevent any disruption to the flow of data between Britain and the EU, an issue of lingering concern in the wake of Britain leaving the union.
According to the European Commission, the decision will limit the duration of adequacy to four years.
Commenting on the announcement, EC Vice-President for Values and Transparency VÄ›ra Jourová said: “The UK has left the EU, but today its legal regime of protecting personal data is as it was. Because of this, we are adopting these adequacy decisions today.”
Despite marking a positive step for post-Brexit cooperation, Jourová warned that Britain’s status could be withdrawn if the Commission believes UK regulations are no longer fit to protect EU citizens’ data.
According to the European Commission, a key factor in reaching this adequacy decision was the fact that Britain’s data protection framework will still be based on rules and regulations that were applicable when the country was an EU member state.
“The UK has fully incorporated the principles, rights and obligations of the GDPR and the Law Enforcement Directive into its post-Brexit legal system,” the European Commission said in a statement.
Jourová commented: “We are talking here about a fundamental right of EU citizens that we have a duty to protect. This is why we have significant safeguards and if anything changes on the UK side, we will intervene.”
Didier Reynders, Commissioner for Justice, added: “The EU has the highest standards when it comes to personal data protection, and these must not be compromised when personal data is transferred abroad.”
Concerns over British data protection standards have been expressed by the European Parliament, the European Data Protection board and EU member states, Jourová noted, and these have, to some extent, been justified.
UK Government backbenchers have repeatedly expressed their desire to diverge from EU data protection regulations, including GDPR.
Additionally, government-backed research into Britain’s post-Brexit data options recommended that GDPR be scrapped and replaced with a UK-drafted data protection framework.
According to the study, conducted by Iain Duncan Smith and George Freeman, GDPR restricts the use of data for “worthwhile purposes” and “overwhelms” citizens due to its complexity.
While unlikely, had the EU chosen not to grant adequate status the impact on British business would have been significant; prompting UK industries to establish more complex – and costly – methods by which to share data.
Recommended
- Binance cryptocurrency exchange banned by UK financial regulator
- Sturgeon grilled by Greens MSP over Amazon spend after ‘dumping’ reveal
- OGTC becomes Net Zero Technology Centre in renewable pivot
Research published last year by the New Economics Foundation suggested that the cost of no adequacy to British businesses could be as high as £1.6 billion.
The extra cost, the study said, would be largely due to the additional compliance obligations firms faced post-Brexit.
Other nations, including Canada, New Zealand and Switzerland, have all secured ‘adequate’ status with the EU. However, the United States has encountered trouble in this regard.
The US has previously been granted partial status, but two separate decisions by the European court of justice saw its status rescinded.
Chris Combemale, CEO of the Data & Marketing Association, welcomed the decision as a “significant boost after a challenging year”.
He said: “A positive decision on data adequacy is a huge relief for thousands of businesses across the UK – over half of businesses surveyed by the DMA just before Brexit stated this was important for the future of their business.
“The UK can now progress new data legislation, such as the crucial National Data Strategy, knowing that a high-standards and innovation-focussed approach rests in harmony with the European perspective.”





