News: 1658744105

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Browsers could face two regimes in Europe as UK law set to diverge from EU

(2022/07/25)


Browsers will need to satisfy two different data regimes in Europe under UK legislation proposed to replace EU laws.

The British government has promoted its approach as a way of [1]easing the burden of cookie consent on website users, but the new law could be challenging for browser builders wanting to comply with both EU and UK regimes, which currently come under the General Data Protection Regulation (GDPR).

The [2]UK Bill , set to be debated in Parliament, says that websites won't need to require users to consent to "collect information for statistical purposes" about how a website or service is used "with a view to making improvements to the website".

[3]

However, it also offers web users the right to opt in or out of cookie tracking at a browser level.

[4]

[5]

Jonathan Kirsop, partner and head of information law with Pinsent Masons, said: "It could help users to rid themselves of the countless consent requests they receive while browsing the internet. Implementing such an approach would not be straightforward, however, as it would be hard to argue that any general consent given by users satisfies the EU GDPR's requirements. Businesses providing browsers or publishing websites across Europe would need to grapple with two very different regimes."

The Conservative government says it wants to make data protection law more flexible and allow data sharing with other nations while maintaining its data-sharing deals with the EU, the so-called adequacy arrangement with the UK's largest trading partner.

[6]

"We now have the opportunity to seize the benefits of Brexit and transform the UK’s independent data laws. We have designed these new updates to our data protection framework so it works in our interests, protects our citizens, and unburdens our businesses," said Matt Warman, minister for media, data and digital infrastructure, introducing the Bill.

"Through this Bill we will realise the opportunities of responsible data use whilst maintaining the UK's high data protection standards. The EU does not require countries to have the same rules to grant adequacy, so it is our belief that these reforms are compatible with maintaining a free flow of personal data from the European Economic Area."

But Kirsop said the proposals could put adequacy at risk, making life harder for businesses sharing personal data between the UK and the EU.

[7]

"The proposals could be viewed as diverging sufficiently from the EU GDPR to threaten the UK's adequacy status, something which could potentially plunge global companies back into expensive and cumbersome remediation programmes less than five years after they conducted extensive work to comply with the GDPR before it took effect," he said.

[8]UK Info Commissioner slams use of WhatsApp by health officials during pandemic

[9]Boris Johnson set to step down with tech legacy in tatters

[10]UK, South Korea strike data-sharing pact

[11]Cookie consent crumbles under fresh UK data law proposals

On the other hand, "those seeking a substantial streamlining of requirements and the removal of obstacles to innovation and business, whether perceived or real, may feel the Bill does not go far enough," he said in [12]a blog .

The Bill follows the government consultation, " [13]Data: a new direction " [PDF], which provoked concern when it opened debate on removing the right for individuals to challenge automated decisions made about them.

As AI-based decision making becomes more popular in applications for healthcare to financial services, [14]campaigners challenged proposals to remove these rights , set in EU law, given the potential flaws in AI including biased training data.

The Bill set before Parliament reframes the argument around challenges to automated decisions. It creates a right to "human intervention" in decision making, but it is set only to apply to "significant" decisions, rather than decisions that produce legal effects or similarly significant effects, Kirsop said.

The proposed laws also get rid of the requirement for businesses to carry out a Data Protection Impact Assessment and substitute it with the need to carry out an assessment of high-risk processing, the details of which are yet to be defined.

The Bill also proposes changes to how the government works with the Information Commissioner's Office (ICO), the data protection watchdog. Open Rights Group executive director Jim Killock said the changes would put ministers in charge of the ICO and unleash a new wave of police surveillance powers.

"British businesses will be sweating as they try to get their heads around another costly and expensive change to the regulatory regime," he said. "This Bill will scrap important protections from prejudice and bias afforded to women, workers, patients, migrants, ethnic minorities, and vulnerable people and communities, and everyone else."

MPs will next consider the Bill at Second Reading, which is likely to take place in September. ®

Get our [15]Tech Resources



[1] https://www.theregister.com/2022/06/17/cookies_crumble_in_uk_data/

[2] https://bills.parliament.uk/bills/3322/publications

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yt6@JyghPibGjKDwjHb42QAAANc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yt6@JyghPibGjKDwjHb42QAAANc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yt6@JyghPibGjKDwjHb42QAAANc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yt6@JyghPibGjKDwjHb42QAAANc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yt6@JyghPibGjKDwjHb42QAAANc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/07/12/uk_department_of_health_and/

[9] https://www.theregister.com/2022/07/07/boris_johnson_tech_legacy/

[10] https://www.theregister.com/2022/07/06/uk_south_korea_data_agreement/

[11] https://www.theregister.com/2022/06/17/cookies_crumble_in_uk_data/

[12] https://www.pinsentmasons.com/out-law/analysis/uk-data-protection-digital-information-bill

[13] https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1022315/Data_Reform_Consultation_Document__Accessible_.pdf

[14] https://www.theregister.com/2021/09/10/right_to_contest_automated_ai_uk_consult/

[15] https://whitepapers.theregister.com/



Disgusted Of Tunbridge Wells

Different countries have different laws. Sometimes inside the EU too. See Belgium's ban on video game loot boxes necessitating changes in FIFA Ultimate Team.

just another employee

..and some EU countries don't even have data protection laws compatible with EU GDPR yet..... Slovenia being case in point.

Doctor Syntax

If they're in the EU they do have laws campatible with GDPR. They have GDPR.

David Nash

I was going to comment but Lars has just clarified...so ignore this.

Peter2

This is where we get into the difference between "in theory" and "in fact". In theory, there is no difference between theory and fact. In fact, there is a difference.

Likewise, in theory when the EU parliament makes a regulation (as opposed to a directive) then it automatically takes effect across the entire EU.

In actual fact, most countries have their own parliaments and their own courts who feel that they, and not the EU council run their countries, and they don't implement things that don't meet the requirement of their laws.

Slovenia, as one of the countries who "enjoyed" the Russian secret services vanishing people guaranteed privacy as part of their constitution, and I think they feel that key parts of things directly attached to their constitution get written by them. The end result is that they have gone through several drafts, but the GDPR is still not enforceable in Slovenia.

So they don't in fact have the GDPR.

Doctor Syntax

"Likewise, in theory when the EU parliament makes a regulation (as opposed to a directive) then it automatically takes effect across the entire EU.

In actual fact, most countries have their own parliaments and their own courts who feel that they, and not the EU council run their countries, and they don't implement things that don't meet the requirement of their laws."

Let me draw your attention to the fact that the Idiot Tendency in UK politics were concerned by the fact that Parliament and courts really were constrained by the EU council and didn't like it. Hence we've now got to where we are now - a government operating without adult supervision coming out with just such a mess.

I haven't looked at the Slovenia situation but I'd expect that the EU is - I recall reading about the EU leaning on Poland for political interference with the courts. The ultimate sanction would, I suppose, be suspension of those countries from the EU as punishment.

I think that last remark has just enlightened me as to why the UK has opted for what would otherwise be regarded as a punishment - a government run by public schoolboys.

jmch

"The ultimate sanction would, I suppose, be suspension of those countries from the EU as punishment."

The actual sanction that would make them pay attention is to be cut off from the EU budget, particularly for countries that are net recipients of funding. Typically speaking, the democratic laggards are net recipients.

Lars

@Doctor Syntax

I agree with the "a government run by public schoolboys".

The use of "public" in this respect in Britain is confusing for everyone else as a publicly funded school is called a "state" school. And a state school is of course publicly funded by the state.

And in other parts of the world schools are called private schools when they publicly are not funded by the state (to 100%).

But about countries who don't live up to what was demanded (and expected) joining the EU the EU doesn't have the "power" to just kick out a country, such laws where not included.

In a way I think that is a bit sad but it's a lot sadder that such reasons can occure.

As for schools, what does it tell you about a country where state schools perform less well or are assumed to perform less well than private schools.

To me it will indicate that the country is run by an elite for the elite.

But it could be even worse than that. In Sweden there was some enthusiasm for private schools until it become obvious that the quality and the reasons why was like with Trump

University. There was not the quality expected.

What if that happened in Britain too long ago.

And you don't have this or that any more. Would that surprise me.

Lars

@just another employee

"The GDPR was adopted on 14 April 2016 and became enforceable beginning 25 May 2018. As the GDPR is a regulation, not a directive, it is directly binding and applicable, and provides flexibility for certain aspects of the regulation to be adjusted by individual member states.

The regulation became a model for many other laws across the world, including in Turkey, Mauritius, Chile, Japan, Brazil, South Korea, South Africa, Argentina and Kenya. As of 2021 the United Kingdom retains the law in identical form despite no longer being an EU member state. The California Consumer Privacy Act (CCPA), adopted on 28 June 2018, has many similarities with the GDPR.".

https://en.wikipedia.org/wiki/General_Data_Protection_Regulation

So it's for all EU countries but with some flexibility.

wolfetone

" See Belgium's ban on video game loot boxes necessitating changes in FIFA Ultimate Team. "

Fair play to Belgium. It's disgusting that this form of gambling is promoted in a game where a good size of it's user base are children.

Yet Another Anonymous coward

OK so I haven't played video games since Attack Of The Mutant Camels, but how do you have a loot box in a soccer game?

Can you buy a chest that has an invisibility cloak, healing spells and David Beckham's left foot ?

Anonymous Coward

They contain additional players, apparently.

wolfetone

It ranges from things like new players that are available to your team, historic players, unique kits, power ups etc.

Nothing physically real, although of course it takes real money to purchase them.

Yet Another Anonymous coward

Could they argue that since it's FIFA world soccer, the bribes are for extra realism?

Quo Bono?

Paul Smith

Exactly who is this change supposed to benefit? Lose the adequacy agreement and the UK loses access to easy data exchange with the EU, on the other hand, it means the likes of Facebook can do whatever they want with data about UK people. Cambridge Analytics MkII?

I would suggest that someone takes a very serious look at who is lobbying whom and how much they are paying, because this stinks.

Re: Quo Bono?

Doctor Syntax

"Lose the adequacy agreement and the UK loses access to easy data exchange with the EU"

In this respect it's interesting to look at the impact assessment (you can find in linked on https://bills.parliament.uk/bills/3322/publications )

From that:

"17. EU Adequacy decisions are adopted through a unilateral, autonomous EU process controlled and managed by the European Commission. As the UK diverges from EU GDPR, the risk that the EU revokes its Adequacy decision increases. EU Adequacy decisions do not require an ‘adequate’ country to have the same rules, and the Government’s view is that reform of UK legislation on personal data is compatible with the EU maintaining free flow of personal data from Europe. "

My emphasis; Rice-Davies applies. But it's not HMG that makes the adequacy statement, it's the EU.

It gets wilder in para 18 which estimates the potential costs:

"we estimate the impact of Adequacy with the EU being discontinued on top of these measures to be between £190 and £460 million in one-off SCC costs and an annual cost of between £210 and £410 million in lost export revenue when taking a micro approach to modelling. The analysis does not attempt to assign probabilities but simply estimates the impact in the event of loss of Adequacy. The trade impacts are the direct reduction in UK-EU trade and the impact may be larger when accounting for interactions with onward supply chains with trade with third countries."

It continues with the remarkable statement:

"As there is uncertainty in both the likelihood and timing of any decision, the impact is not included in the net present value or other measures in the summary of the IA."

In other words we think we're OK (17) so we'll just ignore it (18).

Re: Quo Bono?

Jason Bloomberg

I would suggest that someone takes a very serious look at who is lobbying whom and how much they are paying

There is no need for lobbying when the government and minister's ideology is "profit before people".

Brexit was a dream of those who wanted to escape the clutches of EU regulation which limited the abuses they could indulge in, constrained their pursuit of profit. Gullible and stupid people voted "please screw us over" and that's what this government intends to deliver, claims a mandate for doing.

Re: Quo Bono?

Doctor Syntax

Gullible and stupid people

They were voting for "we'll take back control" and thought that "we" included themselves.

Re: Quo Bono?

Mike 137

" Lose the adequacy agreement and the UK loses access to easy data exchange with the EU "

The US formally lost Privacy Shield but that made zero difference to the transfer of personal data from the EU and the UK to the US. Furthermore, Privacy Shield was grossly inadequate while it was recognised, and that mde no difference either.

Non-compliance with the GDPR is widespread, the problem being that it's not formally enforced by the regulators but relies on complaints. It's a perfectly adequate (if not perfect) piece of legislation in principle, but as [1]practically everyone has ignored it since day one , it has no effective teeth.

[1] http://www.businessinforisk.co.uk/library/BiR-Awful_not_Lawful-final.pdf

Re: Quo Bono?

Anonymous Coward

"Non-compliance with the GDPR is widespread, the problem being that it's not formally enforced by the regulators but relies on complaints."

In general if you open a complaint case with the ICO then they will only investigate the use/misuse of *your* personal data, even if your complaint also highlights the misuse of the personal data of a large percentage of the population they will not look into the wider aspect.

ICO will only investigate large scale misuse of personal data when they receive "sufficient" complaints regarding it, where "sufficient" is something they decide (likely based on whether ICO could be bothered to do anything about it).

Re: Quo Bono?

Warm Braw

Exactly who is this change supposed to benefit?

You need to focus on that word "supposed".

It will not benefit anyone, no-one (outside government) has lobbied for it and no-one in government can construct a case for it in its own terms.

However, this is merely the start of "performative divergence" - a fantastic fog obscuring the reality that the road to the sunlit uplands is jammed with parked lorries. It doesn't matter that nobody benefits. What matters is that the "supposed" benefits are through the fog, over the rainbow and beyond the horizon so the cultists are content to continue waiting for the rapture replacement bus service.

Finally

wolfetone

This is the brexshit I voted for.

I found the current cookie law far to simple and one dimensional, and I was craving more bureaucracy in my work life. This, finally, scratches that itch.

Who do I have to thank for this? I bet it's Nadine, she's a good 'un. Finger on the pulse etc.

Re: Finally

Will Godfrey

You forgot the /s

Re: Finally

wolfetone

As with most of what brexshit has become, I have chosen to ignore convention and break long held rules about how to conduct business.

Re: Finally

Doctor Syntax

Become?

Re: Finally

Doctor Syntax

"I bet it's Nadine"

It does indeed emanate from the Department of Culture media.

Re: Finally

Yet Another Anonymous coward

I'm torn between wanting more government and businesses tracking me online in order to protect me from from the children - but I'm British and so want to be tracked by biscuits not American 'cookies' - preferably hobnobs

Re: Finally

The Bobster

"and for some reason, also sport" #W1A

The essence of this is to treat the public like crap

VoiceOfTruth

Businesses, no matter how rotten and dirty they are, = good. The public, the great unwashed who didn't go to the right schools, = bad.

The ICO is a joke anyway, and not a very funny one. It grabs a small headline about data being transferred using WhatsApp to pretend that it is doing something other than polishing chairs, but is completely silent about medical records being sold to who knows who?

Re: The essence of this is to treat the public like crap

ITMA

No it isn't.

It is so that businesses can get back to treating us how they would like to treat us - a cash crop to be harvested and sold.

Re: The essence of this is to treat the public like crap

GNU SedGawk

The Charter City idea is going to be "interesting".

AFAIU we go to bed with rights, and wake up without them.

I'm hopeful to have got the wrong end of the stick https://medium.com/@cormack.lawson/charter-cities-the-real-reason-for-brexit-and-the-bigger-picture-4de80dbb69fb

Everybodies favourite dodgy group https://www.taxpayersalliance.com/charter_cities_f1_qrrrebspo_1e_acnz6xzb7l0 seems quite keen.

The Scottish press don't seem so keen https://www.thenational.scot/politics/20267661.rishi-sunaks-beloved-charter-cities-pose-huge-threat-democracy/

Re: The essence of this is to treat the public like crap

Greybearded old scrote

They weren't completely silent, they said, [1]"Slapped wristies, don't do it again."

[1] https://www.theregister.com/2017/07/03/google_deepmind_trial_failed_to_comply_with_data_protection_law/

Re: The essence of this is to treat the public like crap

Anonymous Coward

> but is completely silent about medical records being sold to who knows who?

There is no real way to hold ICO to account.

Complaints to the Parliamentary and Health Service Ombudsman only cover whether ICO followed ICO's documented procedures, you cannot complain about any decisions ICO reached.

The only route regarding case decisions that ICO make is to take personal legal action against ICO, something that the majority of people cannot afford.

Re: The essence of this is to treat the public like crap

VoiceOfTruth

-> There is no real way to hold ICO to account.

As I wrote above, they are chair polishers. Jobs for some friends of politicians. Make a noise once in a while, then go back to polishing chairs.

Re: The essence of this is to treat the public like crap

Anonymous Coward

"Make a noise once in a while, then go back to polishing chairs."

Rather than polishing chairs they are actually complicit in covering up/enabling Data Protection law breaking:

https://forums.theregister.com/forum/all/2022/07/21/amazon_one_medical/#c_4499249

Re: The essence of this is to treat the public like crap

Anonymous Coward

Just noticed this ICO25 bad-taste joke:

https://ico.org.uk/media/about-the-ico/documents/4020926/ico25-plan-for-consultation-20221407-v1_0.pdf

Quote:

"...showing that it can be a ‘how to’, not a ‘don’t do’."

That'll be "showing how to break DP Law in a way that ICO will do nothing about" rather than "don't break DP Law" I assume...

Re: The essence of this is to treat the public like crap

ITMA

Also the ICO will not uphold anything which appears to be a breach of privcy under GDPR if it goes against government policy.

A case to illustrate this - I complained to them about my energy supplier, EON (and their "agents"), keep pestering me about when I want an appointment to have a "so-called" smart meter installed. My answer always been "NO - FUCK Off and DO NOT CONTACT ME AGAIN. You DO NOT have permission to conctact me about anything other than meter readings and my bill. I do NOT give you permission for my details to be used to contact me about anything else, especially smart meters".

However, according to the ICO, because the roll out of "so-called" smart meters is government policy, energy companies are obliged to keep pestering me until I give in and can ignore my wishes and GDPR.

In other GDPR and the ICO are utter shite.

Re: The essence of this is to treat the public like crap

Anonymous Coward

and the procedure for accessing the documented procedures is available only the 29th of February, when the Moon rises, in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard.”

Re: The essence of this is to treat the public like crap

ITMA

They've been moved - I've looked there LOL

And nothing of value was achieved …

Detective Emil

[W]ebsites won't need to require users to consent to "collect information for statistical purposes" about how a website or service is used "with a view to making improvements to the website".

Since most sites want to drop cookies associated with advertising and tracking, if the law really is written this narrowly, all those sites will still have to present consent dialogs.

Re: And nothing of value was achieved …

Doctor Syntax

"Since most sites want to drop cookies associated with advertising and tracking"

Why should sites be wanting to do this instead of just doing it?

Re: And nothing of value was achieved …

Anonymous Coward

"Since most sites want to drop cookies associated with advertising and tracking"

I believe you are misusing English here and you intended to say "want to set cookies".

"to drop" implies throwaway, which is the complete opposite of what most sites intend to do.

Re: And nothing of value was achieved …

Yet Another Anonymous coward

"to drop" implies throwaway

Not when it comes to bombs

Re: And nothing of value was achieved …

Greybearded old scrote

Yeah, you throw them away. You don't want them exploding where you are.

Expat-Cat

Love articles like this. Trouble is the value is immediately devalued due to a major inaccuracy. GDPR does not mandate any sort of cookie behaviour; this is covered by the ePrivacy Directive from 2002.

If this basic point is not known, how good is the rest of the information?

David Nash

If that's the case, why did all the cookie-permission-popups only start appearing after GDPR rather than after 2002?

Ben Tasker

They didn't.

What did change after GDPR was they became much more detailed - prior to it, a lot of sites (particularly UK side) chanced it with a small banner/notification that said "This site uses cookies, if you continue you consent", which was never technically compliant, but the ICO had largely signed off on it.

GDPR made it explicitly clear that that was not sufficient.

Zippy´s Sausage Factory

Because the GDPR raised the prospect of rather large fines, the 2002 directive was toothless by comparison.

Lars

@Expat-Cat

Yes you find it here:

https://en.wikipedia.org/wiki/Privacy_and_Electronic_Communications_Directive_2002

"There are some interplays between the ePrivacy Regulation (ePR) and the General Data Protection Regulation (GDPR).Some EU lawmakers had hoped the ePrivacy Regulation (ePR) could come into force at the same time as the General Data Protection Regulation (GDPR) in May 2018.[3] In this way, it would repeal the ePrivacy Directive 2002/58/EC and accompany the GDPR in regulating the requirements for consent to the use of cookies and opt-out options."

Expat-Cat

How the 2 sets of Directives and Regulations interact is a full and complex subject. My point was that when I see an "expert" making a number of statements but with a large factual error in the basic explanation I am not inclined to look at those statements with much belief.

GDPR makes only one short mention of cookies, and that is to clarify that where cookies may contain private data OR may be used in any way that allows an individual to be identified, then this is private data as covered by GDPR.

user to computer ratio too high.