UK promises big data law shake-up... while also keeping the EU happy, of course. What could go wrong?
- Reference: 1629980649
- News link: https://www.theregister.co.uk/2021/08/26/uk_privacy_law_shakeup_information_commissioner/
- Source link:
Digital Secretary Oliver Dowden promised the UK would "seize the opportunity" offered by the UK's departure from the EU "by developing a world-leading data policy that will deliver a Brexit dividend for individuals and businesses across the UK."
The target of the new data shake-up will be cookie consent pop-ups, designed to help websites comply with EU law while allowing the traffic-tracking nuggets of code.
[1]
Speaking to The Telegraph newspaper, Dowden said he planned to do away with "endless" cookie banners and only apply them when cookies pose a high risk to individuals' privacy.
[2]
[3]
But any changes to UK law would have to maintain the EU adequacy ruling which allows data to be shared with non-member states. Otherwise, data transfers between the UK and EU would be hit with red tape.
Dowden said the UK would continue to align with the EU's General Data Protection Regulations and that Britain would set a "gold standard" in data regulation, "but do so in a way that is as light touch as possible."
[4]UK gains 'adequacy' status on data sharing with EU, but making that stick all depends on how much post-Brexit law diverges
[5]UK data watchdog sees its approach to government health tech during COVID-19 outbreak as 'pragmatic'
[6]Zoom incompatible with GDPR, claims data protection watchdog for the German city of Hamburg
[7]England's controversial extraction of personal medical histories from GP systems is delayed for a second time
In June, the EU [8]formally voted for proposals to give the UK "adequate" status in its data protection laws, allowing data sharing to continue post-Brexit. But at the time lawyers warned that there would be ongoing review of the UK's status and the European Commission reserved the right to revoke the adequacy decision if the UK went too far in liberalising its regime, particularly with respect to international transfers of data.
The UK is prioritising its own "data adequacy" partnerships with the United States, Australia, the Republic of Korea, Singapore, the Dubai International Finance Centre, and Colombia, with India, Brazil, Kenya, and Indonesia also on the list.
[9]
Dowden told The Telegraph there was "absolutely no reason why the EU needs to change that determination" and there are "no grounds whatsoever to say we've somehow watered down our privacy protections."
The UK is an "independent country and we will determine the way forward based on what is in our national interest," he added.
The government also said New Zealand Privacy Commissioner John Edwards was its preferred candidate to become the UK's next Information Commissioner, succeeding Elizabeth Denham.
[10]
As well as heading up the regulator responsible for enforcing data protection law, he would be empowered to "to take a balanced approach that promotes further innovation and economic growth."
In a pre-canned release, Dowden said the Information Commissioner would be able to "pursue a new era of data-driven growth and innovation." Exactly how far he can go will depend on the European Commission's view of the UK's new data protection plans, which are due to be published in detail in September.
Prospect trade union's research director Andrew Pakes commented on the news: “The UK has some of the highest data privacy standards in the world. Today’s announcements on the data strategy must build on these foundations rather than start a bonfire of the regulations.
“The public will rightly want reassurance that the UK will continue to strengthen data safeguards, in particular over the growth of remote work surveillance tools triggered by the pandemic.”®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YSe6up-g3mp08uefu7AIiAAAAII&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSe6up-g3mp08uefu7AIiAAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YSe6up-g3mp08uefu7AIiAAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2021/06/22/uk_eu_data_sharing_adequacy/
[5] https://www.theregister.com/2021/08/04/ico_annual_report/
[6] https://www.theregister.com/2021/08/17/zoom_incompatible_with_gdpr_hamburg_warning/
[7] https://www.theregister.com/2021/07/20/nhs_data_grab_delayed_again/
[8] https://www.theregister.com/2021/06/22/uk_eu_data_sharing_adequacy/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YSe6up-g3mp08uefu7AIiAAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YSe6up-g3mp08uefu7AIiAAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://whitepapers.theregister.com/
Re: Seems to be a recurring theme here ...
Remember, brexit means that we can tell them what to do! It means we can stick it to the EU man!
Oh, sorry, wrong forum...
Re: Seems to be a recurring theme here ...
Well since we were a founding member of and signatory to Luango (which include some non-EU states) up until we left the EU and nothings substantively changed so why shouldn't we apply to rejoin after Brexit? Oh, I remember, the EU commission has got to use every bureaucratic leave available to it, to be a right pain in the ass.
Re: Seems to be a recurring theme here ...
Considering the UK government has made a habit of breaking promises, violating treaties, reneging on agreements it has signed just months prior and is filled with people happily breaking international law nobody in their right mind would want to get them involved in anything formal. Imagine having to trust the UK government that it will do what it has signed up to. Ultimately 'Lugano' is all about trust.
Actions have consequences and I would rather sign an agreement with a crack addict than the UK government because at least with a crack addict there is a chance they will honour the agreement.
Re: Seems to be a recurring theme here ...
Well that goes for both sides.
Re: Seems to be a recurring theme here ...
But they need us more than we need them. So come on UK, what are you going to do about it?
Oh I see. They were all lies to con the old gullible voters. So we can do fuck all. Best rejoin then.
Re: Seems to be a recurring theme here ...
Ah, so you'll be one of those rabid rejoiners who feel the need for other people to do your thinking for you.
What could go wrong?
Given the record of the current incumbents, the list of possible things that are likely to go wrong is probably endless.
Re: What could go wrong?
You spelt "imbeciles" wrong.
More "Red Tape"
Have spent years getting on top of GPDR requirements, HMG wants to change it, at the risk of breaking international business processes - nothing new here then.
Re: More "Red Tape"
Aye, why have one law when you can have three, that's not at all going to be difficult to reliably implement.
Re: More "Red Tape"
For party donors that live off consulting on such matters, the more complexity the merrier, as this will bring boatloads of more money from companies having to comply with yet another set of rules.
Re: More "Red Tape"
This will be British* - Red, White and Blue tape
(* Manufactured in China)
GDPR
"Dowden said he planned to do away with endless cookie banners and only apply them when cookies pose a high risk to individuals' privacy.".
That's breaking the GDPR straightaway, no matter how many times the expression "light touch" is used.
In other breaking news, there's no "partly pregnant".
Re: GDPR
endless cookie banners
The only real problem with "cookie banners" is when (i.e. almost always) they obscure content or (at worst but commonly) prevent access to content until you've clicked on your choice.
Under the law, there's no compulsion on the potential data subject to make a choice, but the default by law in the absence of choice is essential cookies only (i.e. cookies without which the service to the user can not be delivered at all). The obtrusive cookie banner is designed to force people to choose, presumably with the hope that they'll choose to be snooped on.
Even El Reg is not entirely free of blame as its cookie banner is much larger than necessary for its content, obscures main page content, and can only be dismissed if javascript is enabled.
The ideal "cookie banner" should occupy a space otherwise not used for content, should be compact and clearly worded, and permit full unobscured access to all main content (minus all except essential cookies) even if it's ignored. It's a pity that nobody seems to have achieved this. If they had, there wouldn't be a perceived problem at all.
Re: GDPR
There really is such a thing but it is not something anyone would wish to be.
Probably typical Boris-style bluster and blather. There will be lots of noise about it, a few years of talking and then multinationals will kick up a big fuss if it endangers our "adequacy" status.
Performative Divergence
Sam Lowe, Senior Research Fellow at the Centre for European Reform, has coined the term ' Performative Divergence ' for some of the UK government's divergence proposals. They don't gain anything from such a divergence but it demonstrates that the UK can now diverge. Window dressing to convince the gullible.
The Daily Express [1]has removed 70 articles promoting promised Brexit benefits from its website so I think some people are getting quite nervous about the empty shelves and supermarket bosses talking about a cancelled Christmas. I saw some tweets from people saying they needed to show a return ticket and their hotel booking at the Schengen border when they went on their summer hols. People might start to see the Brexit consequences so there is a need for some smoke and mirrors.
I doubt this GDPR divergence is 'performative', though. It's quite clear that the people who paid for this government are the ones who call the shots. For them any consumer or privacy protection is just a nuisance.
[1] https://www.farrightwatch.net/2021/08/brexit-daily-express-curating-their.html
Rishi has cleaned the market from competition for his wife's Infosys. Now that the trade deal with India is in place, they will be shipping planes of Indian IT workers in. Just need to kick up the fuss about talent shortage a bit more. Then another gift of IR35 is that these workers won't have any employment rights (incl benefits, which is right up the Tory alley).
By the way, Google how many millions Rishi wife's stake in Infosys grew since the whole IR35 malarkey started. I wish I had more sense and bought in April 2020.
A BASE jumping error
Brexit was Boris's BASE jumping - He "got it done" and jumped from the EU but forgot to be prepared by wearing a parachute.
Brexit has been done, complaining about it doesn't fix anything. BASE jumping is fun and makes you feel fantastic when you get it done and land without loosing consciousness or breaking an arm or leg - but a lot of the time it needs a hell of a lot of hard work to get it done - just jumping off the wireless mast, or cliff isn't easy a lot of times - and the pandemic just means the wind was blowing.
So nothing that's happening is odd at all.
Re: A BASE jumping error
So Brexit means I should jump off a cliff, parachute optional? Sounds good to me.
Re: A BASE jumping error
No no. Boris has a parachute. Probably is made of gold. All the other people he persuaded to jump ... not.
It's quite telling that he needs to lie about this
The fact that the use of cookies is not an element of the GDPR but of the separate ePrivacy directive or his lie that the Church of England could not legally keep a record of people that wish to receive their emails suggests this is not about cookies or lists at all.
Prepare for more allowances for big businesses to sell and purchase data, fewer consumer protections (consumers don't pay The Party so their rights or opinions don't matter), fewer ways of recourse and redress and less strict requirements on disclosure. If it's good for the donors it must be good for the statute book.
I suspect the experts at the European Commission will go through these proposals with a fine tooth comb and will recommend a tear up of the adequacy decision if they see something that waters down protections in a way that conflicts with the GDPR or infringes on the rights of EU Citizens. I don't know what the notice period is for removing an adequacy status but it won't be very long. If you're a British tech business with lots of customers across the EU today is the start of Squeaky Bum Time.
Re: It's quite telling that he needs to lie about this
Wasn't the ICO position that sites don't have to show cookie banners anyway? Just the prominent link to privacy policy would suffice?
Re: It's quite telling that he needs to lie about this
The ICO themselves have form for breaking "cookie law" themselves:
https://www.itpro.co.uk/general-data-protection-regulation-gdpr/33850/ico-admits-its-own-cookie-policy-is-non-compliant-with
https://www.theregister.com/2019/11/07/ico_jobs_microsite_set_hundreds_of_cookies_without_consent/
Re: It's quite telling that he needs to lie about this
"The fact that the use of cookies is not an element of the GDPR but of the separate ePrivacy directive"
GDPR does have a bearing on cookies as, once the GDPR came into effect on 25/05/2018, the GDPR's definition of consent, rather than UK DPA 1998's definition, then applied with regard to PECR's requirements for "consent" for cookies from then onwards.
"or his lie that the Church of England could not legally keep a record of people that wish to receive their emails suggests this is not about cookies or lists at all."
Looking at the Telegraph article then yes, CoE *does* need relevant consent to keep people's email addresses for jumble sales mailings which CoE should have collected at whichever point individuals signed up to their email list. If they didn't do so then its CoE's fault, not the fault of PECR & GDPR.
Re: It's quite telling that he needs to lie about this
" I suspect the experts at the European Commission will go through these proposals with a fine tooth comb and will recommend a tear up of the adequacy decision
Unfortunately the adequacy decision itself tends to suggest that this is optimistic.
For example, para 49 (section 2.5.4 Transparency) states Data subjects should be informed of the main features of the processing of their personal data [emphasis added], which directly contravenes Article 5.1(b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes [emphasis added].
It seems that even the EU legislators are more interested in the free flow of personal data between Member States (Recital 3) than in the protection of fundamental rights and freedoms of natural persons (also Recital 3). I suppose it's not surprising - commercial pressure bears heavily on politicians, not only via financial contributions but also due to the need for ex-politicians to find lucrative work after their terms of office are ended.
"light touch as possible"
Oh, you should hire Ajit Pai then! He was a master in light touch regulations for screwing citizens to ensure his masters profits!
High-risk cookies? How they're going to define them? Good luck Britons, this looks another attempt to eat the cake and have it. Meanwhile even China is enacting stronger privacy laws - at least for businesses....
Re: "light touch as possible"
Yes but China's privacy laws mean "give us your government all the data"
Re: "light touch as possible"
Do not underestimate the access in all other countries. Remember cases involving NSA and GCHQ? We've only seen the tip of the iceberg. Don't think for a second that the governments of "free" societies are keeping themselves in the dark.
Re: "light touch as possible"
Definition below:
Beneficial to self or business interests = Low risk
Beneficial to consumers or competing business interests = High Risk.
HTH
A large number of UK sites that I visit have opaque or overly complicated opt outs for cookie invasion, I just close them and go elswhere.
What they need to decide is, which do they need more, to sell me their product and possibly gain repeat business or try to grab my data to make pennies from that? If the answer is my data, they make nothing because I go elsewhere.
They have that to deliberately get people to give up their privacy... make it awkward & lots of people give up.
That the Minister of State nominally responsible for Data Protection thinks that Cookies are covered by data protection law (they aren't, they fall under PECR) should be worrying but given the current crop of idiots in Whitehall its par for the course so I'm not surprised.
What is more worrying is the fact they don't seem to realise that any significant changes to UK GDPR increase the likelihood of the UK losing adequacy status and crippling any businesses that rely on any kind of personal data transfer to/from the EU.
Still as long as their donors make a few quid its all good
losing adequacy status and crippling any businesses that rely on any kind of personal data transfer to/from the EU.
They will have to commission the work to fix the mess, usually with one of the companies on party donor list. That's the whole point.
When he says "remove cookie banners" he means "remove data protection rights and free up NHS patient data". Easy slip to make, understandably.
And then the adequacy decision will be reversed, yet more businesses that have hosting in the UK will move it to the EU, and the bleating will start.
Piss
They are taking the piss aren't they.
They changed the law so now small IT businesses are taxed on revenue without being able to deduct legitimate business costs, while at the same time big corporations can continue to avoid paying taxes.
For SMEs this means the flexible IT workers have become 30-50% more expensive. Innovate with that.
Meanwhile they are faffing around with non-issues that companies spent good money to be compliant with and have to continue to be compliant regardless.
Elections can't come soon enough.
Re: Piss
They literally have no ideas, only dogma about reducing red tape which turns out to be yet another trade barrier with every other country in the same continent and will be ignored by every business which wants to trade with countries in the single market.
Re: Piss
"small IT businesses are taxed on revenue without being able to deduct legitimate business costs"
- the same applies to independent lorry drivers apparently.
Re: Piss
Weren't the IT people supposed to retrain as Ballet dancers ?
I'm sure there was some sort of official pronouncement
Re: Piss
All our current problems stem from too many lorry drivers retraining as ballet dancers.
An interesting set of countries
'United States, Australia, the Republic of Korea, Singapore, the Dubai International Finance Centre, and Colombia, with India, Brazil, Kenya, and Indonesia'
Doubtless all paragons of data protection. This is going to be selling out the rights of individuals in order to allow data to be exported far and wide. Still, it's an answer to those of us who wondered if Elizabeth Denham was about the least effective possible head of the ICO.
Re: An interesting set of countries
Amazing indeed. Set up a data broker in Singapore or Dubai, purchase NHS data on people with a gambling addiction and sell it to online betting firms in Gibraltar for better targeting. All under the legal cover of these new innovative agreements.
Another world-lead.
"seize the opportunity" offered by the UK's departure from the EU "by developing a world-leading data policy that will deliver a Brexit dividend"
Oh well, what could possibly go wrong?
"but do so in a way that is as light touch as possible."
Any new "touch" could hardly be lighter than the current one. Everyone, including the ICO, seems to have forgotten that the GDPR is there to protect the human rights of data subjects not their data per se. That requires two things: absolute transparency about processing and effective and affordable avenues for redress where infringements of those rights are identified. Neither has so far been manifest, at least in the UK. The ICO seems generally to have adopted a laissez faire approach to pretty much everything except:
[1] high profile cases against behemoths that are great publicity for the ICO but achieve no substantive change in behaviours;
[2] "data breaches", under an apparent assumption that a core purpose of the GDPR is IT security;
[3] breaches of PECR, which impinge on, but are a tiny percentage of, the remit of the GDPR.
Infringements of the rights of single individuals don't' appear to have a cat's chance in Hell of getting even considered, let alone acted on, despite the specific reference in several places to the fundamental rights and freedoms of the data subject and provision under the legislation for judicial remedies and compensation. However I have found these provisions to provide an apparent "get out clause" for the ICO, in that it may refuse to act, merely advising that a data subject can take the matter to court (inevitably at their own expense). How likely an action that has been rejected by the ICO is to succeed in court is an interesting but still open question.
[1]Research we conducted over the first two years under the GDPR showed that practically no business anywhere was taking transparency seriously, and thus all were effectively denying data subjects their statutory rights under the legislation, let alone the freedom to exercise their human rights where relevant. Such issues as this are where improvements should be concentrated in order to fulfil the ostensible purpose of the legislation: the protection of data subjects' rights.
As it stands, its purpose seems to be to specify what boxes a business has to tick in order to be free to abuse its data subjects.
[1] http://businessinforisk.co.uk/library/Awful_not_Lawful-final-BiR.pdf
Re: "but do so in a way that is as light touch as possible."
However I have found these provisions to provide an apparent "get out clause" for the ICO, in that it may refuse to act, merely advising that a data subject can take the matter to court
In my case I was told to just use a different service if I don't like how my data was handled by one of the big companies :-)
Some questions...and maybe some answers....
Quote: "....developing a world-leading data policy that will deliver a Brexit dividend for individuals and businesses across the UK...."
*
So.....which individuals? Which businesses?
*
So.....a "Brexit dividend" for Peter Thiel? ....for Palantir?
*
I think we should be told!
UK promises big data law shake-up... aka light touch
The Great British (glorious) public have spoken: they're fed up with clicking on cookie pop-up and SOMETHING MUST BE DONE! So, our Glorious Leadership have come up with a GREAT, GREAT plan: no pop-ups, opt-in by default. Brexit means brexit!
Doing away with "endless" cookie banners
Dowden said he planned to do away with "endless" cookie banners and only apply them when cookies pose a high risk to individuals' privacy.
And of course he has a simple, efficient, infallible, automated method of determining when a cookie poses "a high risk"?
In fact, before we get to that, he has a simple, workable, deterministic definition of "high risk"?
"a world-leading data policy"
So sick of this "world-leading", "world beating" bullshit.
Utterly delusional, no other country's interested in anything other than how much money they can make by exploiting this gullible bunch of braggarts.
Seems to be a recurring theme here ...
of the UK telling the EU what it's job is. Apparently the UK has decided that it's OK for the UK to (re)join the Lugano Convention although the EC don't quite see it that way.
Now the UK is telling the EU that the UKs data laws are OK with the EU. Surely that's for the EU to decide ?