Site navigation

What Could Change Under the New UK Data Protection Bill?

Michael Behr

,

UK data protection bill
A billion pounds of savings weighed against a billion in additional costs if the UK loses its adequacy status – and that needs to be weighed against eroding people’s data rights.

With the Data Protection and Digital Information Bill introduced in the House of Commons on the 19th of July, many of the details of the proposed updates to UK legislation and GDPR were revealed.

At the heart of the Government’s claim is that the new changes will promote innovation by removing some of the regulatory burdens facing organisations.

The big questions surrounding the bill are whether it goes far enough in its purported aims to streamline requirements, whether it will erode people’s data rights and protections, and perhaps crucially from a business perspective, diverge so far from European GDPR that they put the UK’s adequacy status at risk?

“Through this bill we will realise the opportunities of responsible data use whilst maintaining the UK’s high data protection standards,” said Minister for Media, Data and Digital Infrastructure Matt Warman.

According to Warman, the bill offers UK businesses around £1bn of savings over the next decade.


What Will the Data Protection Bill Change?

A large part of what the new legislation aims to do is clarify, and also potentially limit, the data that counts as personal data.

Under proposals currently being explored is limiting the definition of personal information. This would be defined by whether the controller or processor could identify its owner by reasonable means at the time of the processing, or where the controller or processor should know that another person will likely obtain the information through the processing and the individual will likely be identifiable as result.

It is this “time of the processing” that is an important point, as it removes the liability around future identification.

Legitimate interests will undergo an overhaul – currently, organisations have to perform a ‘balancing exercise’ to decide if they have a legitimate reason to process personal data. However, the new bill will scrap the current balancing test, with a new list of recognised reasons replacing it.

Elected representatives will also be allowed to process general personal data where necessary for the purposes of democratic engagement activities, such as opinion surveys of local residents, and targeted letters to constituents.

Furthermore, under the new rules, the fines for offending nuisance calls and texts will increase and telecoms network providers will need to notify the ICO if they believe unsolicited direct marketing is occurring on their networks.

The requirements on cookie banner pop ups will be eased for low-risk activities, such as audience measurement. In addition, the groundwork will be laid to remove banners for other types of cookies once new solutions are developed.

Government data sharing will also be improved and support built for digital identities. And law enforcement and national security partners will receive greater clarity on their obligations concerning how data is processed.

Some things will remain largely unchanged – cybersecurity, for example. Organisations will still have to respond and report data breaches.


Adequate for UK Adequacy?

When announced, the new data protection reforms aimed to remove administrative burdens from GDPR, as well as enshrine flexibility and risk-based ‘privacy management’. The new bill comes following a consultation, which started last year.

There were concerns about what the UK’s data protection legislation could create a rift with the EU should it deviate from GDPR.

From a compliance perspective, the Department of Culture, Media and Sport has said that “organisations currently compliant with the GDPR would not need to significantly change their approach”.

Under GDPR, European data protection standards must be adhered to even if the data processor is based outside the EU.

For third country transfers to take place, the country where the processor is based must ensure equivalent protections are in place. Countries deemed by the EU to offer these protections are on an adequacy list, which currently includes the UK.

While there are some concerns about the UK’s close relationship with the US, mass surveillance and bulk collection of communications data, the UK ultimately received adequacy status in June 2021 as it had followed GDPR for several years before leaving the EU.

However, it came with the caveat that it would be reviewed every four years.

The concern is should UK data protection legislation begin to diverge from its European equivalent, this could threaten the UK’s adequacy status.

For example, under the bill the Secretary of State will be able to amend the text by statutory instrument, bypassing parliament, with minimal scrutiny. This concentration of power may cause concern for the EU.

Also included in the bill is a framework for the DCMS to make adequacy decisions about data transfers to third countries, with the US already announced as a priority destination.

Should the UK lose its adequacy status, it would put data transfers between the two jurisdictions at risk, costing British over £1bn in reduced trading revenue and £420m in extra compliance costs over five years, according to UK Government estimates.

“The EU does not require countries to have the same rules to grant adequacy, so it is our belief that these reforms are compatible with maintaining a free flow of personal data from the European Economic Area,” Warman noted.


Data Rights

However, there are concerns that the move to streamline rules have come at the expense of people’s data rights.

For example, individuals have the right to make data subject access requests (DSARs), where they can request a copy of an organisation’s data on them, have been weakened. Organisations will be able to refuse to respond to requests or charge fees should they determine the requests to be “vexatious or excessive”.

In addition, while Warman claimed that the ICO will “remain operationally independent,” there are concerns that ministerial oversight of the body will erode its independence.

With the Secretary of State gaining power over it, this opens the risk that the ICO could be subject to political manipulation and the Government will be unsupervised when working with personal data.


Recommended


The Open Rights Group (ORG) has accused the data protection bill of turning the UK into a “global data laundering hub,” as it meant organisations could potentially evade the rules by transferring data overseas without meaningful protections.

In addition, it warned that mass data sharing will be allowed from law enforcement agencies without proper checks and balances.

Executive Director of the Open Rights Group Jim Killock said: “The Data Protection and Digital Information Bill turns up the heat on attacks on UK citizens’ fundamental rights and liberties. Undermining the rule of law, placing Ministers in charge of the regulator ICO (The Information Commissioner’s Office) and unleashing a new wave of police surveillance powers.”

He added: “This data oligarchs charter will cheat workers out of their rights, increase regulatory costs for business, and will only benefit global tech companies. This bill will scrap important projection from prejudice and bias afforded women, workers, patients, migrants, ethnic minorities, and vulnerable people and communities, and everyone else.

“This bill will enshrine discrimination, bias and prejudice into UK law.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Michael Behr

Senior Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data