A cross-party House of Lords committee is warning the UK government of the huge financial costs it risks if it fails to maintain its data transfer agreement with the EU.
The warning comes shortly after the new government introduced its proposed Digital Information and Smart Data (DISD) bill, following the scrapping of the conservative’s Data Protection and Digital Information (DPDI) bill.
Introduced as the Data Use and Access bill on 23 October, the bill will change the UK’s implementation of the GDPR, as well as the Law Enforcement Directive (LED), which are both transfixed in UK law under the Data Protection Act 2018.
In 2021, UK was granted data adequacy with the EU, allowing it to maintain free flow data transfers between the two entities. However, changes in data laws could mean the EU would revoke this allowance.
Essentially, the EU investigates other country’s data protection laws to ensure EU citizens would have equal data rights if their data is transferred to an outside country. The EU revoked its data agreement with the US back in 2020 after it found that the US’s laws would not ensure “essentially equivalent protection.”
Now, the House of Lords European Affairs Committee has written a letter to digital secretary Peter Kyle raising the issue with government, urging them to enter into early talks with the European Commission to ensure the UK can maintain its data adequacy agreement.
The European Commission is set to make two different adequacy determinations under the GDPR and LED.
The letter warned that losing EU data adequacy would increase costs and administrative burdens for the private and public sector, and could make the UK a less-attractive location for businesses because it would lose its free data movement with its closest market.
Recommended reading
- UK Gov Introduces New Data Use and Access Bill
- NHS Data Sharing Raises Domestic Abuse Charities’ Alarm Bells
- “Common Sense” Changes Coming to Data Protection & Digital Information Bill
“The Government should therefore pursue data protection policies that are aimed at retaining the UK’s data adequacy status with the EU, under both the General Data Protection Regulation (GDPR) and the Law Enforcement Directive (LED),” Lords wrote.
“Securing adequacy renewal decisions from the European Commission in the first half of 2025 should be the Government’s immediate data protection policy priority.”
The letter also encouraged the UK government to take this opportunity to strengthen its international reputation as a “trusted and responsible data bridge.”
“The Government should be fully engaged in the international debate about future data
protection arrangements with the aim of ensuring that the outcome serves UK interests, in enabling digital innovation, and rights and protections the public expect to be in place.”





