SlideShare a Scribd company logo
1 of 14
Dr David Erdos
Faculty of Law
University of Cambridge
Pathway to the Proposals
 31 January 2020: UK leaves EU; enters implementation period
 31 December 2020: EU-UK Trade & Cooperation Agreement;
start of ≥ six month transition for personal data transfers
 1 January 2021 : UK mirrors EU secondary DP law & data
adequacy agreements; full adequacy to EEA & Switzerland
 28 June 2021: EU grants UK full adequacy (excluding data
subject to “immigration exception”)
 10 September 2021: Data: A New Direction consultation start
Directions of Change
Change
Promote
Innovation
Reduce
Burdens
Boost
Trade
Improve
Public
Services
Reform
ICO
Regulation
Change: How Radical?
 Controllers would gain
more legal flexibility
(& certainty)
 Data subjects fewer
legal rights to challenge
 ICO less legally focused
on data rights & duties
 Most substantive changes
could be plausible
implementation of GDPR
 Integrity duty changes well
within Council of Europe DP
Convention 108+
 De facto ICO upholding of
data rights & duties limited
“The UK’s data protection standards will remain fully aligned with
the revised Convention 108.” (HM Government, 2017)
GDPR Building Blocks (with Restrictions)
Scope
(Personal
Data
Processing)
DP Principles
• Fair, lawful,
transparent
• Purpose quality
& compatibility
• Information
quality & limits
Legality
• Legal grounds
Sensitive Data
• Categorical
definition
• Default
prohibition
absent waiver
Integrity
• Demo compliance
• Security
• DP by design &
default
• Joint controllers
• Personal data
breaches
• Processor
engagement
• Recording keeping
• DP Officer
• Impact Assessment
• Export Control
Supervision
Transparency &
Control
• Proactive
• Reactive
GDPR Permitted Restrictions: Green = full; Amber = interpretative (see A. 6(4), 9(2)(1)(g), 10 & 23)
(UK) GPDR Scope
 International Background:
 Little obvious scope to restrict even under DP Convention
 But Japan has GDPR adequacy with limits based on systematic
organisation etc.
 Main Possible UK Changes:
 Put anonymisation on statutory footing stressing unreasonable time,
effort or resources constraint.
 State identifiability threshold is relative to each controller.
 Verdict: Limited change only.
DP Principles & Legality
 International Background:
 DP Convention similar to GDPR but with less specificity especially re:
necessity of processing and purpose compatibility
 Main Possible UK Changes:
 Clarify compatibility: law safeguarding important public interest,
where different controllers & where original ground consent
 Clarify legitimate interests: exhaustive list where no “balancing”
needed; remove “impediments” re AI & democratic engagement
 PECR: Limit/remove consent for cookies & non-commercial marketing
 Verdict: PECR change may be far-reaching; otherwise limited change.
Sensitive Data General Prohibition
 International Background:
 DP Convention: Narrower definition; Appropriate safeguards only
 Main Possible UK Changes:
 Limit/remove “substantial public interest” threshold uncertainties
 Secure legal grounds for health data processing in emergency, AI anti-bias
training and testing & democratic engagement of political parties etc.
 Consider new sensitive legal bases
 Verdict: Limited change only

Transparency and Control Rights
 International Background:
 DP Convention: Similar structure but much more limited default
 GDPR: may allow for far-reaching case-by-case limits (A 23)
 Main Possible UK Changes:
 Privacy notices: No change except limit recontact for research repurpose
 Subject Access: Nominal fee; disproportionality threshold; cost limit
 AI significant decision-making: Clarity or even remove all further rights
 Verdict:
 Generally quite limited
 But subject access & AI proposals in tension even with DP Convention
Integrity Duties
 International Background:
 DP Convention: High-level accountability framework
 GDPR: More detail than on substantive; complex and prescriptive
 Main Possible UK Changes:
 Privacy management programmes to replace impact assessment, prior
consultation, documentation and statutory DP officer requirements
 Breach notification to ICO only when risk “material”
 Data transfers: relax 4-yearly review of adequacy; allow controller
appropriate safeguards; state redress may be judicial only; state repetitive
derogation use okay; exempt “reverse transfers”
 Verdict: Significant change
 However, most proposals in principle within DP Convention
(DP Authority) Supervision
 International Background:
 DP Convention: Much looser than GDPR (which de jure is largely
peremptory) but still focus on DPA upholding data subject rights
 Main Possible UK Changes:
 Reestablish ICO as transparent Board; PECR powers to mirror GDPR
 ICO data use, growth, innovation, competition & public safety duties
 Government role & impact assessment re ICO priorities, codes of practice
& (complex) guidance
 Complaints – require process starts with controller first & legal criteria on
when ICO will pursue
 Verdict: Significant changes, squaring with DP Convention questionable
 But de facto ICO upholding of data rights & duties anyway limited.
Conclusions
 GDPR (not PECR) proposals evolutionary not revolutionary
 Many of these changes are sensible and clearly within at least
DP Convention framework
 But overall package is tilted to controllers not data subjects
 Entrenchment & acceleration of ICO agenda away from
upholding data rights & duties of particular concern.

More Related Content

What's hot

The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
SaimaRafiq
 

What's hot (20)

General Data Protection Regulation (GDPR) - Cross-Border Data Transfers
General Data Protection Regulation (GDPR) - Cross-Border Data TransfersGeneral Data Protection Regulation (GDPR) - Cross-Border Data Transfers
General Data Protection Regulation (GDPR) - Cross-Border Data Transfers
 
“Privacy Today” Slide Presentation
“Privacy Today” Slide Presentation “Privacy Today” Slide Presentation
“Privacy Today” Slide Presentation
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Data Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethicsData Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethics
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
 
Privacy and Data Protection
Privacy and Data ProtectionPrivacy and Data Protection
Privacy and Data Protection
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018
 
Personal privacy and computer technologies
Personal privacy and computer technologiesPersonal privacy and computer technologies
Personal privacy and computer technologies
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
Trade Secrets: Presentation on Trade Secret Protection in India - BananaIP
Trade Secrets: Presentation on Trade Secret Protection in India - BananaIPTrade Secrets: Presentation on Trade Secret Protection in India - BananaIP
Trade Secrets: Presentation on Trade Secret Protection in India - BananaIP
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
 
Privacy in simple
Privacy in simplePrivacy in simple
Privacy in simple
 
Privacy & Data Protection
Privacy & Data ProtectionPrivacy & Data Protection
Privacy & Data Protection
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
GDPR and Security.pdf
GDPR and Security.pdfGDPR and Security.pdf
GDPR and Security.pdf
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Overview on data privacy
Overview on data privacy Overview on data privacy
Overview on data privacy
 
Data Privacy & Security
Data Privacy & SecurityData Privacy & Security
Data Privacy & Security
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 

Similar to UK GDPR: What New Direction?

DMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberDMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 december
Rachel Aldighieri
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
Jim Wilson
 

Similar to UK GDPR: What New Direction? (20)

"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
 
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
 
TrustArc Webinar: UK's Post-Brexit GDPR Reforms
TrustArc Webinar: UK's Post-Brexit GDPR ReformsTrustArc Webinar: UK's Post-Brexit GDPR Reforms
TrustArc Webinar: UK's Post-Brexit GDPR Reforms
 
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
 
DMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberDMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 december
 
The GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacyThe GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacy
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Rollits Education Focus Summer 2017
Rollits Education Focus Summer 2017Rollits Education Focus Summer 2017
Rollits Education Focus Summer 2017
 
Practical Guide to GDPR 2017
Practical Guide to GDPR 2017Practical Guide to GDPR 2017
Practical Guide to GDPR 2017
 
[REPORT PREVIEW] GDPR Beyond May 25, 2018
[REPORT PREVIEW] GDPR Beyond May 25, 2018[REPORT PREVIEW] GDPR Beyond May 25, 2018
[REPORT PREVIEW] GDPR Beyond May 25, 2018
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
Draft data protection regn 2012
Draft data protection regn 2012Draft data protection regn 2012
Draft data protection regn 2012
 
GDPR - A practical guide
GDPR - A practical guideGDPR - A practical guide
GDPR - A practical guide
 
Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data Privacy
 
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
What does the Proposed EU General Data Protection Regulation (GDPR) mean for ...
 

More from David Erdos

Regulatory Enforcement of UK Data Protection
Regulatory Enforcement of UK Data ProtectionRegulatory Enforcement of UK Data Protection
Regulatory Enforcement of UK Data Protection
David Erdos
 
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection LawDead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
David Erdos
 
Disclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google SpainDisclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google Spain
David Erdos
 
European Data Protection and Social Networking
European Data Protection and Social NetworkingEuropean Data Protection and Social Networking
European Data Protection and Social Networking
David Erdos
 
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media:  Walking the Regulatory TightropeGDPR, DPAs and the Journalistic Media:  Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
David Erdos
 
Reconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionReconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data Protection
David Erdos
 

More from David Erdos (19)

Regulatory Enforcement of UK Data Protection
Regulatory Enforcement of UK Data ProtectionRegulatory Enforcement of UK Data Protection
Regulatory Enforcement of UK Data Protection
 
Generative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPRGenerative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPR
 
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An  EU and UK GDPR PerspectiveGoogle Spain and its Aftermath 2014-2023: An  EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR Perspective
 
The GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and BeyondThe GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and Beyond
 
Data Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing LandscapeData Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing Landscape
 
Constitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EUConstitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EU
 
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection LawDead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
 
Disclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google SpainDisclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google Spain
 
Data Protection and "Intermediary" Responsibility: An Historical Perspective
Data Protection and "Intermediary" Responsibility:  An Historical PerspectiveData Protection and "Intermediary" Responsibility:  An Historical Perspective
Data Protection and "Intermediary" Responsibility: An Historical Perspective
 
European Data Protection and Social Networking
European Data Protection and Social NetworkingEuropean Data Protection and Social Networking
European Data Protection and Social Networking
 
UK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeUK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & Change
 
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media:  Walking the Regulatory TightropeGDPR, DPAs and the Journalistic Media:  Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
 
Data Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in ConflictData Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in Conflict
 
European Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search EnginesEuropean Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search Engines
 
Data Protection and Academic Research: The New GDPR Framework
Data Protection and Academic Research:  The New GDPR FrameworkData Protection and Academic Research:  The New GDPR Framework
Data Protection and Academic Research: The New GDPR Framework
 
Reconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionReconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data Protection
 
Regulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data ProtectionRegulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data Protection
 
New Media Internet Expression and European Data Protection
New Media Internet Expression and European Data ProtectionNew Media Internet Expression and European Data Protection
New Media Internet Expression and European Data Protection
 
EU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information FlowEU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information Flow
 

Recently uploaded

Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.ppt
JosephCanama
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
Airst S
 
一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书
irst
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
Airst S
 
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSSASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
CssSpamx
 
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
F La
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
ss
 
一比一原版(MelbourneU毕业证书)墨尔本大学毕业证学位证书
一比一原版(MelbourneU毕业证书)墨尔本大学毕业证学位证书一比一原版(MelbourneU毕业证书)墨尔本大学毕业证学位证书
一比一原版(MelbourneU毕业证书)墨尔本大学毕业证学位证书
irst
 
一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理
e9733fc35af6
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理
Airst S
 
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
A AA
 
一比一原版(UWA毕业证书)西澳大学毕业证如何办理
一比一原版(UWA毕业证书)西澳大学毕业证如何办理一比一原版(UWA毕业证书)西澳大学毕业证如何办理
一比一原版(UWA毕业证书)西澳大学毕业证如何办理
bd2c5966a56d
 
一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理
Airst S
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
Airst S
 

Recently uploaded (20)

Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation StrategySmarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
 
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam TakersPhilippine FIRE CODE REVIEWER for Architecture Board Exam Takers
Philippine FIRE CODE REVIEWER for Architecture Board Exam Takers
 
Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.ppt
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
 
Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?
 
一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
 
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSSASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
 
Elective Course on Forensic Science in Law
Elective Course on Forensic Science  in LawElective Course on Forensic Science  in Law
Elective Course on Forensic Science in Law
 
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
 
5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdf5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdf
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
 
一比一原版(MelbourneU毕业证书)墨尔本大学毕业证学位证书
一比一原版(MelbourneU毕业证书)墨尔本大学毕业证学位证书一比一原版(MelbourneU毕业证书)墨尔本大学毕业证学位证书
一比一原版(MelbourneU毕业证书)墨尔本大学毕业证学位证书
 
一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理一比一原版悉尼科技大学毕业证如何办理
一比一原版悉尼科技大学毕业证如何办理
 
It’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy Novices
It’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy NovicesIt’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy Novices
It’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy Novices
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理
 
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
 
一比一原版(UWA毕业证书)西澳大学毕业证如何办理
一比一原版(UWA毕业证书)西澳大学毕业证如何办理一比一原版(UWA毕业证书)西澳大学毕业证如何办理
一比一原版(UWA毕业证书)西澳大学毕业证如何办理
 
一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
 

UK GDPR: What New Direction?

  • 1. Dr David Erdos Faculty of Law University of Cambridge
  • 2.
  • 3. Pathway to the Proposals  31 January 2020: UK leaves EU; enters implementation period  31 December 2020: EU-UK Trade & Cooperation Agreement; start of ≥ six month transition for personal data transfers  1 January 2021 : UK mirrors EU secondary DP law & data adequacy agreements; full adequacy to EEA & Switzerland  28 June 2021: EU grants UK full adequacy (excluding data subject to “immigration exception”)  10 September 2021: Data: A New Direction consultation start
  • 5. Change: How Radical?  Controllers would gain more legal flexibility (& certainty)  Data subjects fewer legal rights to challenge  ICO less legally focused on data rights & duties  Most substantive changes could be plausible implementation of GDPR  Integrity duty changes well within Council of Europe DP Convention 108+  De facto ICO upholding of data rights & duties limited
  • 6. “The UK’s data protection standards will remain fully aligned with the revised Convention 108.” (HM Government, 2017)
  • 7. GDPR Building Blocks (with Restrictions) Scope (Personal Data Processing) DP Principles • Fair, lawful, transparent • Purpose quality & compatibility • Information quality & limits Legality • Legal grounds Sensitive Data • Categorical definition • Default prohibition absent waiver Integrity • Demo compliance • Security • DP by design & default • Joint controllers • Personal data breaches • Processor engagement • Recording keeping • DP Officer • Impact Assessment • Export Control Supervision Transparency & Control • Proactive • Reactive GDPR Permitted Restrictions: Green = full; Amber = interpretative (see A. 6(4), 9(2)(1)(g), 10 & 23)
  • 8. (UK) GPDR Scope  International Background:  Little obvious scope to restrict even under DP Convention  But Japan has GDPR adequacy with limits based on systematic organisation etc.  Main Possible UK Changes:  Put anonymisation on statutory footing stressing unreasonable time, effort or resources constraint.  State identifiability threshold is relative to each controller.  Verdict: Limited change only.
  • 9. DP Principles & Legality  International Background:  DP Convention similar to GDPR but with less specificity especially re: necessity of processing and purpose compatibility  Main Possible UK Changes:  Clarify compatibility: law safeguarding important public interest, where different controllers & where original ground consent  Clarify legitimate interests: exhaustive list where no “balancing” needed; remove “impediments” re AI & democratic engagement  PECR: Limit/remove consent for cookies & non-commercial marketing  Verdict: PECR change may be far-reaching; otherwise limited change.
  • 10. Sensitive Data General Prohibition  International Background:  DP Convention: Narrower definition; Appropriate safeguards only  Main Possible UK Changes:  Limit/remove “substantial public interest” threshold uncertainties  Secure legal grounds for health data processing in emergency, AI anti-bias training and testing & democratic engagement of political parties etc.  Consider new sensitive legal bases  Verdict: Limited change only 
  • 11. Transparency and Control Rights  International Background:  DP Convention: Similar structure but much more limited default  GDPR: may allow for far-reaching case-by-case limits (A 23)  Main Possible UK Changes:  Privacy notices: No change except limit recontact for research repurpose  Subject Access: Nominal fee; disproportionality threshold; cost limit  AI significant decision-making: Clarity or even remove all further rights  Verdict:  Generally quite limited  But subject access & AI proposals in tension even with DP Convention
  • 12. Integrity Duties  International Background:  DP Convention: High-level accountability framework  GDPR: More detail than on substantive; complex and prescriptive  Main Possible UK Changes:  Privacy management programmes to replace impact assessment, prior consultation, documentation and statutory DP officer requirements  Breach notification to ICO only when risk “material”  Data transfers: relax 4-yearly review of adequacy; allow controller appropriate safeguards; state redress may be judicial only; state repetitive derogation use okay; exempt “reverse transfers”  Verdict: Significant change  However, most proposals in principle within DP Convention
  • 13. (DP Authority) Supervision  International Background:  DP Convention: Much looser than GDPR (which de jure is largely peremptory) but still focus on DPA upholding data subject rights  Main Possible UK Changes:  Reestablish ICO as transparent Board; PECR powers to mirror GDPR  ICO data use, growth, innovation, competition & public safety duties  Government role & impact assessment re ICO priorities, codes of practice & (complex) guidance  Complaints – require process starts with controller first & legal criteria on when ICO will pursue  Verdict: Significant changes, squaring with DP Convention questionable  But de facto ICO upholding of data rights & duties anyway limited.
  • 14. Conclusions  GDPR (not PECR) proposals evolutionary not revolutionary  Many of these changes are sensible and clearly within at least DP Convention framework  But overall package is tilted to controllers not data subjects  Entrenchment & acceleration of ICO agenda away from upholding data rights & duties of particular concern.