The laws governing use of data are set for a shake up as the UK looks to implement the General Data Protection Regulations (GDPR) and enshrine new protections into law with a Data Protection Bill.
The Government have announced new data protection laws with the aim of giving people more control over how others use their personal data including the right to be forgotten.
The Data Protection Bill will see existing European privacy rules subsumed into British Law and replace the 1998 Data Protection Act.
Here Matt Hancock, the Minister for Digital outlines the reason for change and why its important:
Under the plans individuals will have more control over their data by having the right to be forgotten and ask for their personal data to be erased. This will also mean that people can ask social media channels to delete information they posted in their childhood. The reliance on default opt-out or pre-selected ‘tick boxes’, which are largely ignored, to give consent for organisations to collect personal data will also become a thing of the past.
In summary, the Data Protection Bill will:
The data protection regulator, the Information Commissioner’s Office (ICO), will also be given more power to defend consumer interests and issue higher fines, of up to £17 million or 4 per cent of global turnover, in cases of the most serious data breaches. The current Data Protection Act allows for a £500,000 maximum fine so the new limits represent a significant change with large companies potentially in line for very significant fines.
Two new criminal offences are also to be created with potentially unlimited fines. These are re-identifying people from anonymous data and changing/tampering with data requested by an individual.
A new set of cross-EU data rules comes into force from 25 May 2018. The UK has an obligation to update existing data rules to match them so they are equivalent to the European Union's laws. This will allow organisations to freely send and receive data within Europe following Brexit.
The Government consulted on derogation (exemptions) contained within the General Data Protection Regulation (GDPR) in April/May this year. Responses from over 150 individuals and 170 organisations were received and can be viewed on the GOV.UK website.
The Government issued a statement of intent - New Data Protection Bill: Our planned reforms - on 7 August as a commitment to updating and strengthening data protection laws through a new Data Protection Bill.
The bill will see the government exercise the available derogations and reproduce the exemptions and safeguards currently evident in the Data Protection Act and extend protections in some areas. The Information Commissioner will provide guidance on the transition to the new law.
Businesses need to get up to speed with what the new rules will mean and what impact they are likely to have on existing data collation and use. We'll be exploring the changes in more detail in the coming months here on theNBS.com.
Note that this article is not intended to construe legal advice or offer comprehensive guidance.