UK set for 'adequacy' status on data sharing with EU, but it all depends on how much post-Brexit law diverges
- Reference: 1624361432
- News link: https://www.theregister.co.uk/2021/06/22/uk_eu_data_sharing_adequacy/
- Source link:
But the move could prove temporary if the UK were to move too far from the principles of the General Data Protection Regulation (GDPR) in its ambition to be a global tech juggernaut.
Voting through the draft "Commission Implementing Decisions on the adequate protection of personal data by the United Kingdom", [1]the Committee on the Protection of Individuals with Regard to the Processing of Personal Data adopted the proposals for data sharing.
[2]
In February, [3]the European Commission said that EU law has shaped the UK's data protection regime for decades, unlike other countries with divergent systems. But it emphasised it would need to "future proof" the adequacy finding since the UK was no longer bound by EU privacy rules. Adoption of the draft decision was therefore proposed to be valid for four years.
[4]
[5]
The Confederation of British Industry (CBI) welcomed the decision. Russell Antram, head of EU negotiations, said: "Securing a positive decision on data adequacy from the EU was a priority for thousands of businesses across the UK. The free flow of data between the UK and the EU is essential for businesses across the economy – from automotive to logistics – playing an important role in everyday trade of goods and services."
[6]EU court rules in Telenet copyright case: ISPs can be forced to hand over some customer data use details
[7]Final guidance on Schrems II ruling: Data from EU could be held up if a third country lets authorities access it
[8]Gov.UK taskforce publishes post-Brexit wish-list: 'TIGRR' pounces on GDPR, metric measures
[9]UK government bows to pressure, agrees to delay NHS Digital grabbing the data of England's GP patients
Georgina Kon, technology and media partner at law firm Linklaters, said the adequacy decision was "quite unique" in that there was no specific end date or formal review.
She said: "There is an ongoing review of the UK's adequacy. What that means is that if the UK goes too far in liberalising its regime, particularly with respect to international transfers of data – which is something we know that the UK has been interested in doing – the Commission reserves the right to revoke the adequacy. Adequacy doesn't mean it's done and dusted. I think anything that the UK government does to try to make it a much more attractive destination for data would – if it goes too far — get some pushback from the EU."
Where would such an impetus to change UK law come from? Look no further than the [10]Taskforce on Innovation, Growth and Regulatory Reform (TIGRR), a Brexit goon-squad of Tory MPs that produced its report last week, complete with an [11]endorsement from Prime Minister Boris Johnson.
[12]
The TIGRR report is damning of Article 5 of GDPR, which states among other things that data should be "collected for specified, explicit and legitimate purposes" and be "adequate, relevant and limited to what is necessary."
"These restrictions limit AI because they prevent AI organisations from collecting new data before they understand its potential value and they also mean that existing data cannot be reused for novel purposes," the report said.
The 130-page document did not mention the phrase "data adequacy" even once, which might be troubling to those in the UK whose businesses depend on being able to access EU personal data.
[13]
Kon pointed out that any assault on the principles behind Article 5 in UK laws could spell trouble for the adequacy ruling. "Article 5 is fundamental; it tells you what the key principles for personal data ought to be within the EU. If the UK were to move far away from the existing Article 5 principle that could undermine the adequacy decision," she said.
It is possible the adequacy decision could be challenged in court, with data flows suspended while cases are ongoing.
A [14]blog from the German Federal Ministry of Justice and Consumer Protection has pointed out that a German Supervisory Authority could hold up the sharing of data with the UK and go to a federal court and then the European Court of Justice for a decision.
In any case, the ruling on the UK being an adequate jurisdiction to share data with would be reviewed on an ongoing basis as UK legislation diverges from EU law. ®
Get our [15]Tech Resources
[1] https://ec.europa.eu/transparency/comitology-register/screen/documents/074379/1/consult?lang=en
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YNIJIrbK47rfPH6kqsxBxgAAAIk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://ec.europa.eu/commission/presscorner/detail/en/ip_21_661
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNIJIrbK47rfPH6kqsxBxgAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNIJIrbK47rfPH6kqsxBxgAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/06/21/court_of_justice_telenet_bittorrent_ruling/
[7] https://www.theregister.com/2021/06/21/final_guidance_on_schrems_ii/
[8] https://www.theregister.com/2021/06/17/post_brexit_laws_mps_wishlist/
[9] https://www.theregister.com/2021/06/08/uk_gov_delays_gp_data_grab/
[10] https://www.theregister.com/2021/06/17/post_brexit_laws_mps_wishlist/
[11] https://www.gov.uk/government/news/prime-minister-welcomes-independent-report-on-re-imagining-regulation-in-the-uk
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YNIJIrbK47rfPH6kqsxBxgAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YNIJIrbK47rfPH6kqsxBxgAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://www.gesetze-im-internet.de/englisch_bdsg/englisch_bdsg.html#p0165
[15] https://whitepapers.theregister.com/
Re: It's a feature not a bug
Given the way NHS England are planning to use GP data I'm surprised this hasn't been a warning to the EU already.
Re: It's a feature not a bug
The Germans have good historical reason for being nervous about data being "re-used for novel purposes" - when the Nazis ransacked Magnus Hirschfeld's Institute for Sex Research, besides burning the books they made off with lists of addresses of gay men etc. That data was repurposed to hideous effect.
It couldn't happen here? Post-Brexit, nothing would surprise me.
Re: It's a feature not a bug
>If data can arbitrarily be re-used for any old purpose without getting further consent, then it's not really protected is it?
And unprotected is precisely the state those responsible for the TIGRR report want our data.
I give it less than three months
Before adequacy threatens to become inadequate.
a Brexit goon-squad of Tory MPs
Ah, nothing like a bit of unbiased reporting, is there?
Leaving aside the political cracks, " These restrictions limit AI because they prevent AI organisations from collecting new data before they understand its potential value and they also mean that existing data cannot be reused for novel purposes " is actually an interesting point. Much of scientific discovery has come from serendipity, those "I didn't expect that, I wonder why it happened" moments, and it would be unfortunate if this was prevented.
Instead of prescribing, in advance, the data as collected for specified, explicit and legitimate purposes , effectively trying to second-guess how it will be used, perhaps it would be better to define the things it MUST NOT be used for, and leave any grey issues to be decided by courts if necessary? It's that old difference between "everything not explicitly allowed is forbidden" and "anything not explicitly forbidden is allowed", which has always been a difference between European countries.
the ruling on the UK being an adequate jurisdiction to share data with would be reviewed on an ongoing basis as UK legislation diverges from EU law.
Which is exactly how it should be (and applies vice-versa if EU law diverges as well, of course).
None of the data that contributed to any serendipitous scientific discovery is personal data. And there are no restrictions on collecting non-personal data.
It isn't about whether the usage is "forbidden" it is about whether the collector has permission from the data subject. To put it in simple terms that even a Conservative politician can understand: I own data about me personally, and hence I can choose to whom I sell it, for what purposes, and for what price. Any attempt to retain or use personal data without permission of the subject is plain theft .
"Any attempt to retain or use personal data without permission of the subject is plain theft."
You were doing well up to here but however often theft is used in this context it isn't theft in legal terms because you haven't been deprived of it. Maybe a breach of copyright would be closer. We do need a legally defined simple term to use in this context, however.
Yikes
Actual sense from an EU body. Yes, the UK complies with EU data protection laws, No, it may not in the future. Recognising these things feels entirely appropriate.
Shame the Germans disagree. I guess they're still upset that we're not helping them fund that mess any more.
Re: Yikes
Perhaps the Germans are envious/annoyed by UK spies’ data slurping?
Re: Yikes
Perhaps the Germans are envious/annoyed by UK spies’ data slurping?
I suspect that they do it better, they just haven't been caught at it yet.
Re: Yikes
Do you remember the Japanese solder found on a Pacific island still fighting the Second World War? That's you, that is.
You will collect my personal data over my dead body
These restrictions limit AI because they prevent AI organisations from collecting new data before they understand its potential value and they also mean that existing data cannot be reused for novel purposes
This statement is absolutely false . 99.999% (or more) of data absolutely can be collected by AI organisations as they wish and can be reused for novel purposes. The only data that cannot be collected is personal data.
History of temperature changes in Nazeby by the minute can be collected with no restrictions and almost certainly has great value to some future AI. The AI developers just need to get smart about using the data they can collect and stay away from personal data. AI is not just about people.
Re: You will collect my personal data over my dead body
History of temperature changes in Nazeby by the minute can be collected with no restrictions
But what if that data is then used to determine where I was as I walked around? When does it become "personal"? It isn't black & white.
Re: You will collect my personal data over my dead body
I doubt it's a matter of getting smart, more a matter of not being greedy because a slurp of personal data will be much more valuable in their eyes then temperature records of Nazeby. What's needed is sufficient enforcement of the DPA to make such data a liability instead of an asset and that's just the opposite of what IDS & co want.
Realities v. politics
This decision is officially being made on the basis of compatibility of the legislation , so it's not totally surprising as the UK law actually pretty much replicates the GDPR, with the exception of a couple of [1]egregious and highly questionable departures that have, it appears, been conveniently overlooked.
However, in reality, [2]as our research has clearly established , practically nobody is actually complying with the legislation anyway, even on its most basics. So the whole exercise would seem to be pure political manoeuvring.
The purpose of the GDPR and its spin-offs was intended to be protection of data subject rights. That appears to have been entirely forgotten by all concerned.
[1] https://www.europarl.europa.eu/news/en/press-room/20210510IPR03816/data-protection-mepsurge-the-commission-to-amend-uk-adequacy-decisions
[2] http://businessinforisk.co.uk/library/Awful_not_Lawful-final-BiR.pdf
And another keyboard... gone
> its [UK's] ambition to be a global tech juggernaut
Note to self: must really stop reading El Reg while having a cuppa.
I'd like to think that a denial of adequacy would have been the better option here to act as a wake up call. Unfortunately the only actual result would be much frothing at the mouth by all the Brexiteers.
These restrictions limit AI because they prevent AI organisations from collecting new data
Well yeah, restrictions are generally created to prevent stuff, and if that is an amazing revelation to you, well let's just say that these companies probably already have you classified in the category "complete idiot".
It's like complaining that the restrictions on entering your house prevent criminal organisations from collecting new loot. Our information should not just be theirs to take, no matter how easily dazzled idiot lawmakers are by the magic two letters A & I.
It's a feature not a bug
> they also mean that existing data cannot be reused for novel purposes
They really are mistaking a feature for a bug.... If data can arbitrarily be re-used for any old purpose without getting further consent, then it's not really protected is it?
Good news on the adequacy, but I'm sure we'll find some way to screw it up (followed by politicians blaming the EU for being overly purist about the law or something)