New UK Data Protection Bill - here's what you need to know

New UK Data Protection Bill - here's what you need to know

Aug 8, 2017 |Richard McPartland |4 Minute Read

The laws governing use of data are set for a shake up as the UK looks to implement the General Data Protection Regulations (GDPR) and enshrine new protections into law with a Data Protection Bill.

The Government have announced new data protection laws with the aim of giving people more control over how others use their personal data including the right to be forgotten.

The Data Protection Bill will see existing European privacy rules subsumed into British Law and replace the 1998 Data Protection Act.  

Here Matt Hancock, the Minister for Digital outlines the reason for change and why its important:

What are the key changes? 

Under the plans individuals will have more control over their data by having the right to be forgotten and ask for their personal data to be erased. This will also mean that people can ask social media channels to delete information they posted in their childhood. The reliance on default opt-out or pre-selected ‘tick boxes’, which are largely ignored, to give consent for organisations to collect personal data will also become a thing of the past.

In summary, the Data Protection Bill will:

  • Make it simpler to withdraw consent for the use of personal data
  • Allow people to ask for their personal data held by companies to be erased
  • Enable parents and guardians to give consent for their child’s data to be used
  • Require ‘explicit’ consent to be necessary for processing sensitive personal data
  • Expand the definition of ‘personal data’ to include IP addresses, internet cookies and DNA
  • Update and strengthen data protection law to reflect the changing nature and scope of the digital economy
  • Make it easier and free for individuals to require an organisation to disclose the personal data it holds on them
  • Make it easier for customers to move data between service providers
  • Create new criminal offences to deter organisations from either intentionally or recklessly creating situations where someone could be identified from anonymised data.

What areas will need to be addressed?

  • Privacy. Opt out boxes hidden at the end of forms and information on data use buried in Privacy policies may no longer be acceptable. Organisations must make consent to opt in explicit and be aware of who will have access to the data and what they will do with it.
  • Personal data. An expanded definition will bring IP addresses, cookies (and information on web browsing habits) and even DNA into scope. Organisations need to audit the data they collect and determine what falls in scope and whether the burden of collection/maintenance outweighs any burden.
  • Automated processing. Where algorithmic technology is used to form a profile of an individual, the GDPR stipulates that individuals can demand this processing is undertaken by a human and not a machine. As insurance applications and job applications increasingly rely on this kind of processing this edict could have a big impact.
  • Portability. Consumers should be able to move data between providers if required without barriers being put in their way. For example, documents stored on a cloud storage site should be able to be ported to another quickly and easily.
  • The right to be forgotten. Organisations will need to provide access to the personal data they hold on others. Requests can also be made to wipe data (including all social media posts made by individuals when they were younger than 18). Companies will need to consider data storage and retrieval systems and processes.

What are the consequences for transgressions?

The data protection regulator, the Information Commissioner’s Office (ICO), will also be given more power to defend consumer interests and issue higher fines, of up to £17 million or 4 per cent of global turnover, in cases of the most serious data breaches. The current Data Protection Act allows for a £500,000 maximum fine so the new limits represent a significant change with large companies potentially in line for very significant fines.

Two new criminal offences are also to be created with potentially unlimited fines. These are re-identifying people from anonymous data and changing/tampering with data requested by an individual.

What's happened so far?

A new set of cross-EU data rules comes into force from 25 May 2018. The UK has an obligation to update existing data rules to match them so they are equivalent to the European Union's laws. This will allow organisations to freely send and receive data within Europe following Brexit.

The Government consulted on derogation (exemptions) contained within the General Data Protection Regulation (GDPR) in April/May this year. Responses from over 150 individuals and 170 organisations were received and can be viewed on the GOV.UK website.

The Government issued a statement of intent - New Data Protection Bill: Our planned reforms - on 7 August as a commitment to updating and strengthening data protection laws through a new Data Protection Bill.

The bill will see the government exercise the available derogations and reproduce the exemptions and safeguards currently evident in the Data Protection Act and extend protections in some areas. The Information Commissioner will provide guidance on the transition to the new law.

What does all this mean for businesses?

Businesses need to get up to speed with what the new rules will mean and what impact they are likely to have on existing data collation and use. We'll be exploring the changes in more detail in the coming months here on theNBS.com.

Note that this article is not intended to construe legal advice or offer comprehensive guidance.

Our latest news

Visqueen supports one of the first Gateway 2 approvals under the Building Safety Act

The Dyecoats development in Leeds marks a major milestone for the UK housing sector. The £100 million flagship Latimer Homes scheme being delivered by GRAHAM is one of the first high-rise new-build projects in the country to achieve Building Safety Act Gateway 2 approval, a crucial pre-construction sign-off confirming that the design meets all safety and regulatory requirements before work begins on site.

Building Safety ActSponsored

Five questions to ask when specifying insulated panels

Selecting an insulated panel system for an industrial building should start with the building and application requirements.

Design and SpecificationSponsored

NBS and BDP join forces to improve generic carbon data in construction

Today, NBS (part of Hubexo), the platform for connected construction information, announces a long-term strategic partnership with BDP, a major global multidisciplinary practice of architects, designers, engineers and urbanists. The partnership recognises BDP's integral role in the development of NBS LCA, a new life-cycle carbon assessment platform providing professionals with high-quality, reliable and easy-to-use carbon data to ensure accurate tracking as construction projects evolve. BDP's primary contribution to NBS LCA has been the development of more than 1,300 pre-calculated generic assemblies, covering the most commonly used building fabric elements alongside key concrete and steel structural elements. These assemblies provide whole-element carbon data, giving designers consistent, UK-relevant carbon benchmarks from the earliest stages of project design. Users can easily and instantly apply carbon rates to a range of pre-configured common building elements, including walls, floors, and roofs. Developed by BDP and NBS, the assemblies remove the need for designers to manually build up material layers or calculate individual components at the concept stage. This saves significant time and effort, enabling proportionate and responsible carbon evaluation early in the design process, when decisions have the greatest impact on a project's overall carbon footprint. BDP also participated in collaborative workshops that directly informed the development of NBS LCA, helping to shape a tool that is practical, accessible and aligned with real-world UK construction workflows. Dr Lee Jones, Head of Sustainability at Hubexo, said: “BDP's contribution to NBS LCA has been invaluable. Their depth of project experience and technical knowledge has directly shaped the generic assemblies at the heart of the platform. These assemblies give designers a reliable, UK-relevant starting point for carbon assessment, without the burden of building everything from scratch. This is exactly the kind of collaboration that moves the industry forward, and we're proud to be working with BDP on a long-term basis.” Julia Yao, Associate, Sustainability Consultant at BDP, said: “Carbon assessment needs to be embedded in design from day one, not bolted on at the end. Working with NBS to develop its LCA product has been a genuine opportunity to put that principle into practice. The generic assemblies we developed draw on real project data and are designed to give designers meaningful, actionable carbon information at the concept stage. We're delighted to see them at the core of a platform that will be used across the industry.” With the UK Government outlining its commitment to responsible carbon reporting through its Carbon Budget and Growth Delivery Plan, professionals need reliable, easy-to-use tools to assess and report embodied carbon. NBS LCA addresses this need by integrating carbon calculations with live design work, drawing on structured data from Circular Ecology's ICE Database and more than 12,500 verified, specification-ready construction products with Environmental Product Declarations (EPDs) from NBS Source and ECO Portal. Over the coming months, NBS and BDP will continue to develop their partnership, with a shared commitment to improving the quality and accessibility of carbon data for construction professionals across the UK. NBS LCA is available now, with flexible subscriptions designed for all professionals. For more information, visit the website here.

Product update