News: 1652782206

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Tech pros warn EU 'data adequacy' at risk if Brexit Britain goes its own way

(2022/05/17)


BCS, The Chartered Institute for IT, has warned that proposed changes to Britain's data protection rules must not put the flow of data between the EU and the UK at risk.

The professional body said the supposed benefits of a leaner data protection regime – something the government [1]promised last week – should not come at the expense of the UK's current "data adequacy" arrangement with the EU.

The UK remained compliant with the EU's General Data Protection Regulation (GDPR) when it formally left the EU at the end of 2020. Its interpretation of EU law meant that the trading bloc [2]gave the UK an "adequacy" ruling , permitting data sharing across the border.

[3]

However, in the Queen's Speech [4]setting out policy plans for the next Parliament, the government promised the data protection regime would be reformed to "take advantage of the benefits of Brexit to create a world-class data rights regime that will allow us to create a new pro-growth and trusted UK data protection framework that reduces burdens on businesses, boosts the economy, helps scientists to innovate and improves the lives of people in the UK."

[5]

[6]

Last week [7]legal experts warned the government could be determined to create laws diverging from the principles underscoring GDPR to make a political point about the UK's independence from the EU following Brexit.

Today, Dr Sam De Silva, chair of BCS's Law Specialist Group and a technology and data partner at international law firm CMS, said: "Any material deviation the UK adopts in relation to data protection does risk its adequacy status so I hope there will be a detailed and objective analysis undertaken to assess whether the benefits from UK's data reform outweigh the risks of not continuing to have an adequacy status.

[8]Lawyers say changes to UK data law will make life harder for international businesses

[9]Ad-tech firms grab email addresses from forms before they're even submitted

[10]Europe's GDPR coincides with dramatic drop in Android apps

[11]Bank for International Settlements calls for reform of data governance

"What was in the Queen's Speech in relation to the reform of data protection was not surprising because it generally follows the principles outlined in the Government's Consultation Paper on Reforms to the UK Data Protection Regime – 'Data: A New Direction'.

"However, the devil will be in the detail – which we do not have sight of yet."

[12]

Earlier this year, one legal expert warned that the UK's approach outlined in the consultation paper would risk the adequacy ruling.

Data protection training firm [13]Amberhawk published details of an analysis by Rosemary Jay, senior consultant attorney at law firm Hunton Andrews Kurk, in response to the government's consultation.

In her view, it was an error for the consultation not to deal with the impact of the proposals on the UK's adequacy determination.

[14]

"The consultation includes a number of helpful and practical proposals," she said. "However, the wide scope means that it can be difficult to tease out the useful and/or significant elements. In some cases the impact of the proposals is not clear and in some places it is difficult to work out how different aspects of the proposals fit together.

"In addition, there are some regrettable omissions... The most striking omission is the absence of any assessment of the proposals on the UK’s adequacy finding from the EU." ®

Get our [15]Tech Resources



[1] https://www.theregister.com/2022/05/16/brexit_data_law/

[2] https://www.theregister.com/2021/06/22/uk_eu_data_sharing_adequacy/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YoPGp9HTGBFc@buKP-i6BAAAAMk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.gov.uk/government/publications/queens-speech-2022-background-briefing-notes

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YoPGp9HTGBFc@buKP-i6BAAAAMk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YoPGp9HTGBFc@buKP-i6BAAAAMk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/05/16/brexit_data_law/

[8] https://www.theregister.com/2022/05/16/brexit_data_law/

[9] https://www.theregister.com/2022/05/16/ad_companies_data/

[10] https://www.theregister.com/2022/05/09/gdpr_europe_apps/

[11] https://www.theregister.com/2022/05/06/bis_data_governance_design/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YoPGp9HTGBFc@buKP-i6BAAAAMk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://amberhawk.typepad.com/amberhawk/2022/01/independent-evidence-that-the-dcms-data-proposals-could-undermine-adequacy.html

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YoPGp9HTGBFc@buKP-i6BAAAAMk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://whitepapers.theregister.com/



Funny..

Andy 73

How all the invested parties never, ever see value in there being less regulation...

Re: Funny..

codejunky

@Andy 73

How else can they justify growing their departments

Snapper

There is a big difference between 'less' and cutting to the point of causing serious issues with other groups requirements.

I strongly suspect this gubmint will do whatever it pleases and f**k business.

"The way forward"

Mike 137

" ... create a world-class data rights regime that will allow us to create a new pro-growth and trusted UK data protection framework that reduces burdens on businesses, boosts the economy, helps scientists to innovate and improves the lives of people in the UK "

In practice, this means dismantling most of the protections offered to data subjects by removing from them much of the control over processing of their personal data that was formally enshrined in the GDPR.

Pretty much all the proposals submitted for 'consultation' removed or watered down responsibilities of data controllers to data subjects, and it seems that, despite a significant body of objections and cautions submitted in response by experts, HMG is going to implement what it originally proposed, regardless of any emergent consequences - as happened in the case of the Northern Ireland Protocol, except that they probably won't attempt to backtrack to correct emergent data protection issues because nobody in business or government really cares about personal privacy unless it's their own. The public is a commodity, just like everything else.

Re: "The way forward"

SW10

...create a world-class data rights regime that will allow us to create a new pro-growth and trusted UK data protection framework that reduces burdens on businesses, boosts the economy, helps scientists to innovate and improves the lives of people in the UK...

Let me FTFY:

...create a world-class tail that will allow us to wag the dog, reduce burdens on pigs such that they drift aloft, boost magic bean production, help tailors to innovate the finest silks visible to all but fools, and improve the lives of hedge-fund owning Ministers

Too late

Anonymous Coward

The UKs course for the next decade has been set. A low-regulation (for foreigners), low quality, low protection pariah state. Unable to secure any meaningful trade (because nobody wants to trade with countries that struggle to obey their own fucking treaties) it's a plummet to the bottom.

Re: Too late

Anonymous Coward

Exactly. Look at the mess likely to be caused as a result of the current government's attitude towards the NI agreement *they* themselves signed.

The Brexiteers mouthed off about getting a trade deal with the US as if the UK would swan in and get whatever it wanted. Back in the real world, as many opposed to Brexit foresaw, it has put Britain in the weak position of *needing* that deal, adding to the existing weakness of dealing with a partner many times its size that doesn't need to rush and has the UK over a barrel.

No-one in the Leave camp that dominates the current UK government cared about the consequences for NI (or much else beyond English nationalist puffery) at the time of the vote- because they never cared about NI in the first place- and it's an issue now because they didn't pay attention to that. The DUP supported Brexit as a wrecking tactic because they assumed any hard border would be across the island of Ireland and not across the North Sea.

Both shot themselves in the foot, and we're all going to suffer the consequences. (Especially here in Scotland where we voted against this mess).

The Obama era US (pre-Brexit, pre-Trump) made clear that any post-Brexit UK would *not* be rushed to the front of the queue for a trade deal. Biden (i.e. post-Brexit, post-Trump) is pro-Irish and pro-EU and has made clear that anything damaging to the Good Friday peace agreement (including a hard border on the island of Ireland) is likely to wreck the UK's chances of getting that deal.

The US has made clear that it expects the Good Friday peace agreement to be maintained.

It'd be ironic if it was the threat of that trade deal being killed off that stopped the UK government reneging on the NI agreement which it clearly signed in bad faith, purely as a short-termist ruse to back itself out of a corner it painted itself into.

But given that they're quite happy to risk trade with the EU and the UK's economic future, there's a chance they'd ignore that anyway.

Re: Too late

Phil O'Sophical

the current government's attitude towards the NI agreement *they* themselves signed

Both the UK and EU signed it, unfortunately the EU has been particularly over-zealous about checking it. "Trust but verify" is all very well, but when 60% of the EU's external border checks were happing in 12 miles of Irish sea there was clearly some imbalance. The UK still follows the same standards & rules as it did when it was an EU member, there is no reason (apart from pique) for the EU to attempt to block goods shipments.

Fortunately both sides seem willing to continue discussions, hopefully with a pragmatic outcome.

Re: Too late

Cederic

Given the UK has historically provided plenty of protections and has secured multiple trade deals I fear I must disagree strongly with your deeply pessimistic view.

You haven't incidentally provided any references to the UK failing to meet its own treaties. There are sadly many for the EU and its members failing to meet its - e.g. allowing Greece into the Euro despite it failing to meet the criteria, trying to use Article 16 of the Northern Ireland Protocol because the EU messed up its vaccine procurement, the multiple countries establishing internal borders in contravention of their Schengen obligations.

The UK is lucky to have escaped that expensive anti-democratic treaty ignoring organisation.

Inadequate approach to data adequacy

Flak

I shudder to think what GB's new data protection legislation will look like based on previous form, particularly the 'oven ready' Brexit deal with the NI Protocol signed in what can only be described as bad faith and the finger of blame now pointed at the EU rather than the UK government.

Any substantive divergence from current (EU aligned) GDPR carries the risk of organisations having to continue to comply with EU legislation if they want to do business with organisations and individuals in the EU.

Having then to comply with two sets of requirements means more rather than less red tape for UK businesses.

A new industry will spring up helping businesses to be able to demonstrate compliance with EU legislation and validate an organisation's data protection adequacy.

Plus the UK is no longer part of the club that makes the rules, but is still subjected to them. This was crystal clear from the beginning of this sorry process.

Re: Inadequate approach to data adequacy

Phil O'Sophical

GB's new data protection legislation will look like based on previous form

That would be the "previous form" where the UK had some of the strongest DP rules in Europe, well ahead of EU minima and better than France and Germany?

Re: Inadequate approach to data adequacy

Mike 137

" the "previous form" where the UK had some of the strongest DP rules in Europe "

When was that? The 1998 DPA implementation of the European Directive was [1]so awful that the European Commission would not even divulge the issues to avoid “prejudice to international relations” " [ref amberhawk as linked above].

And it was far from alone in being deficient, which is precisely why the Regulation was created to replace the Directive - to eliminate the ambiguity resulting from divergent interpretations across member states.

[1] https://amberhawk.typepad.com/amberhawk/2017/03/uks-gdpr-law-will-not-be-judged-adequate-if-it-contains-provisions-that-made-the-dpa-inadequate.html

Re: Inadequate approach to data adequacy

Phil O'Sophical

When was that?

The UK's original DP act was 1984 (under a Tory government).

The 1998 DPA implementation of the European Directive was so awful

Yes, the Blair government's attempt at implementing the new EU rules in 1998 seemed to be poorly worded and unclear in terms of the EU legislation.

eliminate the ambiguity resulting from divergent interpretations across member states.

Always a problem with EU law. In an attempt to create regulations that can be agreed to by an increasing number of very different countries, EU rules tend to become complex, ambiguous, and very hard to implement. There's always a fine line between using the ambiguities to make it acceptable at home, without stretching them so far the the European Comission gets upset. Labour failed.

I'm less familiar with the details of the 1998 act, when I was involved in DP it was around the time of the 1984 act, and then more recently with GDPR.

Still, the UK has generally been willing to try and strengthen DP rules above & beyond those in force in other European countries.

Re: Inadequate approach to data adequacy

Mike 137

" The UK's original DP act was 1984

Yes. One of my businesses was registered under it, and I'd hardly call it a high quality piece of legislation - it in many ways provided opportiunities for undetectable 'box ticking' as is now under discussion. For example, the statement of processing that was lodged with the ICO was templated very loosely and did not require or allow detailed specification of actual processing - just selection among broad pre-defined categories of purpose.

Admittedly the GDPR doesn't prescribe presentation (which is a major weakness), but the Article 13/14 requirements for content go a long way towards the right answer.

Re: Inadequate approach to data adequacy

Mike 137

" Having then to comply with two sets of requirements "

As, courtesy of BREXIT, we now have to strike trade deals with lots of other countries outside Europe, there's going to be many more than two sets of requirements - indeed there always have been for businesses with international markets. Way back before the GDPR was even thought of I helped coordinate data protection for an organisation operating in around 90 countries. It needed to maintain compliance with a few more than that number of different regimes (courtesy of state v. federal legislations).

So whether or not the UK retains notional adequacy, it will still have to comply with the GDPR when processing the personal data of persons in the EU (EEA), but bearing in mind that a lot of upcoming data protection legislation world wide is being modelled on the GDPR, our 'softening up' is unlikely to inspire the confidence of potential new trade partners.

But the big problem for the UK is not so much this, but that our own internal data protection regime will not respect the privacy of our own citizens. I suspect that will be pretty unpopular once it's recognised.

Re: Inadequate approach to data adequacy

Cederic

The NI Protocol was indeed signed in bad faith - the EU had no intention of negotiating, the Surrender Bill prevented the Government from refusing it and the EU has since refused to allow it to work to the benefit of both parties.

The sooner we ditch that travesty the better.

Re: Inadequate approach to data adequacy

Lars

"The sooner we ditch that travesty the better."

Why haven't you done it then with all the time you have had.

Re: Inadequate approach to data adequacy

BOFH in Training

It may be impossible to comply with two sets of requirements if they contradict each other.

Hopefully they don't but the devil is in the details (which noone seems to knows of yet).

diverging to make a political point about the UK's independence

Howard Sway

So they're choosing the tech industry, and all digital business activity, as the plaything they're going to sacrifice to make their debating society point about being different just for the sake of it. Well done. Just add this to the trade war they're spoiling for, and all the other global economic problems, and the Sunlit Uplands of Brexit will surely soon be arrived at.

I'm sure it's lots of fun to play this game if you're rich enough that it won't cause you that much pain.

Re: diverging to make a political point about the UK's independence

JimmyPage

So they're choosing the tech industry, and all digital business activity, as the plaything they're going to sacrifice to make their debating society point about being different just for the sake of it

Why not ? They've already fucked the farmers and fishermen - who actually voted for this clusterfuck.

How much care do you think they will show a tech sector that was 100% opposed to Brexit from the off ?

Misdirection Again...And Funding Opportunities For Certain Well Known Political Parties......

Anonymous Coward

Quote: "... in the Queen's Speech setting out policy plans for the next Parliament, the government promised the data protection regime would be reformed..."

Translation: The Conservative government will, for example, sell all the personal NHS records they can find to Peter Thiel and Palantir.

....of course, FOR A PRICE!!

Take a look:

PALANTIR

Link: https://www.bloomberg.com/features/2018-palantir-peter-thiel

Link: https://www.theregister.com/2022/05/05/palantir_leaps_from_covid_role/

OTHER SELL OUT OPPORTUNITIES

Link: https://www.theregister.com/2021/10/11/data_guardian_police_bill/

Link: https://www.theregister.com/2021/09/30/royal_free_deepmind_representative_action_uk/

Link: https://www.theregister.com/2021/10/11/data_guardian_police_bill/

So......the Conservative approach to "data protection" and "privacy" is simple...and in two parts:

(1) We will sell anything to anyone.....as long as the price is in millions or billions (you know...dollars, pounds stirling....)

(2) We know nothing (nothing I tell you) about the concerns of individual citizens (you know...the taxpayers funding this charade...)

A friend of mine won't get a divorce, because he hates lawyers more than he
hates his wife.