2023 saw a slurry of lawsuits and ground-breaking cases for data regulation.
The EU’s GDPR challenged Meta’s main business model surrounding behavioural advertising.
Creative communities, both home and away, pushed back against LLMs being trained on copyrighted material as we witness a grapple to retroactively regulate a technology that, arguably, we should have better prepared for.
These two in cases in particular have drawn battle lines in the wider data handling discourse, as the UK continues its Brexit process by finalising its new Data Protection and Digital Information Bill, deviating from the EU’s strict legislation.
Further, third party cookies – the snippets of data used to track users from website to website, often leveraged by behavioural advertisers – are on their deathbed, as Google moves to promote its new sandbox, leaving advertisers scrambling to move away from a marketing model that’s proved so effective since the late 90s.
Throw the live grenade that is AI’s continued advancement and proliferation, what do all of these changes mean, for businesses, for the public, for governments, consumers, and users? What can we expect for data privacy in the coming year?
To try and answer that, we spoke to Laura Irivne, a partner and head of regulatory law at Davidson Chalmers Stewart LLP, and an accredited specialist in data protection law, as well as Nader Henein, a VP analyst for Gartner specialising in Data Protection.
Data Protection and Digital Information Bill
The Data Protection and Digital Information Bill (DPDI) promises to be business friendly and remove some of the EU’s oft-maligned legislative red tape, but what does the bill actually entail with regards to data privacy for businesses and consumers?
Essentially, it’s the UK’s first true departure from the EU’s GDPR, with the 2018 Data Protection Act only changing the regulations so that its adherence call fall under the scrutiny of the Information Commissioner’s Office, an independent regulator set to create guidelines and issue fines to data handlers.
Since then, the UK has had to maintain an adequacy agreement with the EU in order to maintain regular data transfers.
While the DPDI does make some changes and allows businesses to update their compliance, most changes appear minor, and both Irvine and Henein expect most businesses will not adopt these changes.
Unless a business only operates in the UK, they will still have to comply with other global data protection regulations, including GDPR. To operate in the rest of Europe, UK businesses will have to comply with the EU’s GDPR.
So, why would the UK government introduce a new regulation if businesses are unlikely to adopt it?
“We know the government does want to be seen to be reducing red tape: that was part of the driver for leaving the EU,” Larua Irvine, Partner and Head of Regulatory Law at Davidson Chalmers Stewart LLP Accredited Specialist in Data Protection Law, told DIGIT.
Nader Henein, a VP analyst for Gartner specialising in Data Protection, was less guarded in his words: “It’s because of Brexit. They committed to changing 600 EU era bills,” he explained. “Data protection is just next on the list.”
Only organisations purely operating within the UK may take advantage of the new framework’s more centralised approach, but these requirements are not dramatic enough to risk EU adequacy, both Irvine and Henein clarified.
However, the DPDI does make certain changes that puts consumers, and the UK’s EU adequacy agreement, at potential risk.
One of the major changes underpinning the bill is the dissolution of the independent powers of the ICO – the new bill will give ultimate oversight to the Secretary of State, allowing a political figure to overrule and override guidance from the Commissioner’s Office.
This will provide the Secretary of State the potential to influence the rulings and guidelines for automated decision making, the use of legitimate interests to collect data, and other regulations under the remit of the bill.
“I think that’s going to be the biggest loss that we’re going to have. We need independent regulators,” Henein said. “They cannot be government appointed.”
Irvine worries that the political alignment of the Secretary of State could interfere with data privacy rulings, making data governance a political question rather than one of privacy.
“It feels like there’s a lot more scope for political interference in relation to the ICOs functions,” Irvine said. “Some of the provisions in the bill allow the agenda to be fixed by a politician rather than by an independent regulator.”
The new law represents the UK’s struggle to align with the business interests of Big Tech companies, while maintaining enough data protections to keep their EU adequacy agreement.
“It’s a delicate balance, trying not to deviate too far away from Europe, and at the same time to remain close to the US, and serve the British public at large,” Henein said.
In 2023, the EU ruled that Meta could no longer rely on legitimate interest as a legal basis to collect user data for behavioural advertisement. The UK’s ICO made no move to match the EU’s ruling on this, meaning that Meta’s new compliance standards will not be rolled out to UK consumers.
“That is quite a significant divergence in the approach in the EU and in the UK,” Irvine said. “I think that’s the sort of concern that I would have for us as data subjects and as consumers, that these protections are going to be watered down in the UK.”
The Secretary of State could allow for further divergence from the EU regarding data protection regulations.
The big fear from this, Irvine says, is that big tech may get to have their way in the UK if decisions surrounding data protection are left to political officials rather than independent regulators.
Depending on who is selected as Secretary of State, the UK could see a data privacy renaissance, or they could see rights being stripped away to create a more ‘business friendly’ environment.
Beyond what’s already there, we need to be cognisant as nascent and emerging technologies begin to have more practical implications in things like data handling – , in this regard, regulations to protect consumers will become ever more critical.
Recommended reading
- Data Privacy Week: Skills Gap, Budget Constraints Mar Privacy
- Data Protection Reforms Must Not Put UK and EU Data Flow at Risk
- ICO and EU Enter MoU for Data Protection and Privacy Laws
“This is a crucial time amidst the development of all these technologies. As a society, we need to be able to understand what’s happening to our data, particularly biometric data because it’s so useful,” Irvine said.
“Allowing certain technologies to be used here more easily than in the EU, it’s definitely the wrong approach, in my view, if you are really interested in protecting individual rights.”
AI and Data Protection – Has the Train Left the Station?
Central to AI is data – large language models, like ChatGPT and GPT-4, require “insane amounts of information” to operate, Henein says.
ChatGPT scraped and continues to scrape the internet for data to train itself on – that’s how it can write a limerick about the fall of Constantinople, write a dissertation introduction on the effects of the industrial revolution on feminist theory, generate code for a first year computer programming course, and break down the difference between an IPO and a market value at the drop of a hat.
Public data has been, and continues to be, scraped and not even the EU’s landmark AI Act has anything to say about it.
“The AI Act has sidestepped that particular landmine, and it is a landmine because there’s really no way around it, because they {LLMs] will hoover up whatever they want,” Henein said.
GDPR may have something to say about that hoovering, however. Under the regulations, public data can only be used for its intended purpose – using someone’s email available on LinkedIn to subscribe them to advertising would be considered stealing under GDPR, Henein explained.
The same argument could be made for the information being hoovered up across the internet to power LLMs.
“That’s the intersection of potentially the AI Act and GDPR – that’s going to be fun to watch next year,” Henein said.
The Cookie Crumbles, But Tracking is Alive and Well
Third party cookies – the packaged morsels of user data bought and sold between sites for targeted behavioural advertising and statistical analysis – are being phased out , and the $600bn adtech industry is set to face a “seismic shift”, according to Henein.
The end of cookies, however, should not be regarded as the end of tracking altogether.
“The death of the cookie does not necessarily somehow herald a new age of privacy on the internet; tracking will continue to be there,” he assured.
Henein reassures that while Google pushes its new Privacy sandbox, which will transform how advertising businesses collect user data, platforms are already experimenting with different tracking methods.
“Until we come up with a model that is equitable, to a certain extent, it’s going to continue to be clumsy and messy,” Henein warned.
But what are these cookie-less options?
For one, many platforms are now prompting visitors to provide their email for a 10% discount –
“They’re looking to identify who you are,” Henein warns, “because they know that the cookies are going away. And their capacity to identify you is going away as well. So they need to start linking the data.”
While companies may be saying the effect won’t be dramatic, Henein calls their bluff.
“It’s the old saying ‘this is nothing but a flesh wound’. Some companies will be saying ‘we haven’t used cookies in ages’,” he said. “Yeah, that’s not true. It’s going to impact the industry in a very resounding way.”
Google, which has a 70% share in the adtech industry, is steering this massive transformation, but what this will look like for the adtech industry, consumers, and privacy rights, remains to be seen.
The company has already begun rolling out its privacy sandbox on Chrome to 1% of users – the privacy sandbox essentially uses Google data rather than cookies to sell to advertisers for targeted, personalised adverts.
“It’s going to be a very messy year, very beautifully messy,” Henein mused.
“It’s really one of those, grab the popcorn, sit back and watch companies that have previously been billion dollar darlings of the ad tech industry implode.”





