...

Over 20 Years of Legal Expertise – Trusted by UK Businesses. Secure Your Peace of Mind Today!

What is the UK Data Protection and Information Bill

Following Brexit, the United Kingdom enacted the General Data Protection Regulation (GDPR), known as the UK GDPR, aligning it with domestic legislation. The Data Protection Act (DPA) of 2018 and the Privacy and Electronic Communications Regulations (PECR) of 2003 complement the UK GDPR.

The government of the United Kingdom recognised the necessity for new regulations to govern some areas that had been neglected in the past. The primary objectives were:

Advance the research and innovation of the UK;

Decrease operational expenses for British companies;

Appropriately safeguard the development of AI technologies while promoting their advancement.

With this in consideration, the United Kingdom Government has put forth a revised iteration of the UK Data Protection and Digital Information Bill, an early draft at present. If enacted, the new legislation will amend the UK GDPR, the DPA, and the PECR, thereby providing businesses that handle data from UK residents with an updated privacy framework.

In this article, we will discuss the implications of the key changes introduced by the new UK legislation on businesses, draw comparisons to the previous regulation, and outline the changes themselves.

Table of contents

  1. What is the UK Data Protection and Information Bill
  2. Comparison between the previous Bill and its new version
    1. Personal data
    2. Legitimate interest
    3. Cookies
    4. Direct marketing
    5. International data transfers
    6. Automated decision-making and profiling
    7. The role of ICO and DPO
  3. New concepts included in the second version of the Bill
    1. Digital identity
    2. Smart data
  4. What does the new UK Data Protection and Digital Information Bill mean for your business
  5. What’s next?

What is the UK Data Protection and Information Bill

Introduced on July 18, 2022, the first Data Protection and Digital Information Bill, currently known as “the No. 1 Bill,” was paused in September 2022. Then on March 2023 the new version of the Bill, known as “the No. 2 Bill” was introduced by the Government to be reviewed by the UK Parliament

Currently, the Bill is due to pass the report and third reading stages, but the dates have not yet been announced. Despite the possibility of amendments at these stages, the bill is anticipated to pass in 2024.

The second version of the UK Data Protection and Information Bill will cover:

Organisations that process personal data as part of their activities in the UK, including but not limited to organisations located there;
Third-party organisations that process personal data of UK residents to offer them services or monitor their behaviour.

Comparison between the previous Bill and its new version

The new law has changed numerous definitions compared to the previous regulation. The majority of the amendments provide additional context for each specification or clarify the meaning of particular terms.

The Bill revises the definitions of legitimate interests, personal data, and purpose limitation. Additionally, the regulations encompass data transfers, data processing of scientific research, and the role of the data protection officer (DPO) and information commissioner’s office (ICO). Furthermore, it specifies which organisations will be governed by the new law.

It also provides more flexibility in compliance matters through its simple, clear, and business-friendly framework.

Personal data

The updated version of the Bill amends the definition of personal data to facilitate the determination of whether information relates to an “identifiable” individual.
The assessment is limited in two ways:

  • Identification remains with the controller, processor, or other third party receiving the information;
  • Identification is made only by “reasonable means.”.

This has both advantages and disadvantages, depending on the companies’ focus on privacy.

Legitimate interest

Legitimate interest – is one of the main “lawful bases” that make data processing legal.

Legitimate interest-based processing of data may encompass:

  1. Processing essential for sending direct marketing communications, such as advertising materials tailored to specific individuals.
  2. Processing essential for internal administrative purposes.
  3. Processing essential for ensuring the security of the network and information system.

Before applying any of the legal grounds, you must first go through legitimate interest assessment (LIA).

It includes:

  • The purpose test to identify and assess the objective qualifies as a legitimate interest;
  • The necessity test to consider necessary for your identified purpose;
  • The balancing test to consider equilibrium between the interests/fundamental rights and identified legitimate interests.

The revised UK Bill will establish a legal framework known as “recognised legitimate interests” to safeguard critical public interests, including but not limited to defence, data processing for the public interest, protection of vulnerable individuals, democratic engagement, national security, public safety, and crime detection and investigation.

Cookies

Unless their use is strictly necessary, consent is always required for the implementation of cookies and similar technologies. Cookie usage is a frequent instance of:

  • Memorise a user wishes to buy;
  • Compliance with the UK GDPR;
  • Quick and effective page loads;
  • analytics purposes;
  • recognition a user when they return to a website.

Under PECR, consent is necessary unless eligible for the “soft opt-in” exemption, which applies only to commercial and non-profit entities, excluding charities for donation collections.

The new Bill extends the soft opt-in exemption to non-commercial organisations, allowing consent for objectives like charity, politics, and other non-commercial purposes. It applies when contact details are obtained during an expression of interest, and recipients can easily object.

In relation to cookies, the following are now exempt from the consent requirement:

  • installing the necessary security updates.
  • ensuring compliance with user preferences.
  • collecting statistical information for website improvement purposes.

Significantly benefiting organisations, particularly those that utilise analytics cookies, these exemptions mitigate concerns regarding data loss and may even reduce enforcement risks. Nevertheless, the specific execution of these exceptions is not yet known.

Direct marketing

The updated Bill mandates electronic communication providers to report suspected breaches of direct marketing rules to the Information Commission. Penalties may apply for non-compliance.

IC guidance will detail the definition of “reasonable grounds,” emphasizing that providers are not required to intercept or examine communications. This measure aims to enhance awareness and enforcement against non-compliant direct marketing practices.

International data transfers

The Bill harmonises the principles of international data transfer with the UK GDPR. Transfers require that the recipient be located in an adequate country with safeguards or derogations. Amendments offer the UK government flexibility in adequacy decisions.

If provisions for onward transfers do not meet the standards of the GDPR, the EU might express concerns regarding the sufficiency of the UK. The EU Commission monitors equal data protection and has the authority to amend or revoke decisions. The EU Court of Justice renders a verdict regarding the sufficiency of the United Kingdom with regard to EU data subjects.

An adequacy decision facilitates data transfers between the EU and the UK, but loose UK data transfer standards could risk this decision.

The change allows proportionality in transfer risk assessments, offering a light-touch review for minimal or non-sensitive personal data.

Standard contractual clauses that were present prior to the Bill continue to be valid. For UK data transfers, the UK International Data Transfer Agreement and Addendum remain in effect.

Automated decision-making and profiling

According to the UK GDPR, automated decision-making refers to choices made using factual or inferred data without the need for human intervention. Profiling assesses personal life aspects to make data-driven choices.

The amended Bill clarifies the meaning of removing any possibility of human involvement in automated decision-making. Human intervention rights only cover important decisions, excluding decisions with legal ramifications for data subjects.

When making decisions based on profiling, automated decision-making takes into account meaningful human involvement.

The Bill is applicable when there is no human involvement in the marketing that is customised for each individual, and it forbids the use of automated decision-making or profiling that has a substantial or legal impact on an individual.

The role of ICO and DPO

The new Bill rebrands the ICO as the Information Commission (IC) and transforms it into a corporate body. It proposes changes in governance, duties, and enforcement powers. The IC’s primary objectives include ensuring personal data protection, promoting public trust in data processing, and considering general public interests.

Concerns about the IC’s independence arise, addressed by the Secretary of State, who publishes reasons for approving or rejecting statutory codes or guidance produced by the IC.

The new Bill replaces the role of a data protection officer (DPO) with that of a senior responsible individual (SRI) within an organisation’s senior management. The SRI takes on responsibilities for data protection matters, including addressing data breaches and handling complaints related to data processing.

New concepts included in the second version of the Bill

The new Bill also introduces updated and novel concepts and definitions listed below.

Digital identity

Digital verification services (DVS) involve online services for verifying and confirming individual information, such as establishing or verifying data not provided by the individual. Users can apply to use these services, creating a reusable digital identity to share with organisations needing the information.

Smart data

The Bill proposes smart data schemes in consumer markets to let customers request specific data from businesses. This resembles open banking. The Bill empowers the Secretary of State and HM Treasury to create new schemes to expand the open data economy for consumers and businesses. However, the targeted industries and application of these provisions need clarification.

What does the new UK Data Protection and Digital Information Bill mean for your business

The Bill simplifies business data protection while upholding UK GDPR principles. UK GDPR-compliant businesses won’t need to change, but the bill clarifies the framework and addresses issues from five years of GDPR experience.

However, global organisations with EU operations may need to update their data protection frameworks to comply with the Bill. Business-friendly legislation promotes international trade and reduces compliance paperwork. It simplifies data rules for scientific research, boosting UK innovation and AI trust.

What’s next?

The UK Parliament is currently looking over the draft Bill. The draft Bill may undergo changes before the final version is released.

The law puts the responsibility for data privacy on organisations. The goal is to make things easier and lower the cost of compliance for UK businesses. Over time, it will become clearer what the real effects are, but for now, businesses should share and keep sensitive information safe.

Some people are against the Bill because they say it violates the privacy rights of data subjects, limits their rights, and could hurt the UK-EU data adequacy agreement. Concerns include not being able to review decisions made automatically and the idea that the government will take over the ICO. There is a chance that the EU will cancel the adequacy agreement if it thinks that the new laws don’t have enough protections.

 

More From Stay Legal

Share this with your network