Data & Its Protection - Deal or No Deal

Data & Its Protection - Deal or No Deal


Pretty heavy week with a lot of people tiring of the political happening on the EU question! However, the basis on which the UK will leave the EU has still to be decided.

You may well have missed amongst this, some guidance around what we do in the meantime. The Government has made it clear all along that the General Data Protection Regulation (GDPR) will be absorbed into UK law at the point of exit, so there will be no substantive change to the rules that most organisations need to follow. However, organisations that rely on the transfers of personal data between the UK and the European Economic Area (EEA) may be affected.

Personal information has been able to flow freely between organisations in the UK and European Union without any specific measures. That’s because we have had a common set of rules with the GDPR.

But this two-way free flow of personal information will no longer be the case if the UK leaves the EU without a withdrawal agreement that specifically provides for the continued flow of personal data.

In this event, the Government has already made clear its intention to permit data to flow from the UK to EEA countries. But transfers of personal information from the EEA to the UK will be affected.

Help is at hand however. The ICO has issued guidance on this, they have published guidance and practical tools to help organisations understand the implications and to help you plan ahead. These comprise:

·      a â€˜Six Steps to Take’ guide;

·      broader guidance on the effects of leaving the EU without a withdrawal agreement, and

·      a general overview in the form of Frequently Asked Questions

They know that many organisations have already been making preparations in case the UK leaves the EU without a withdrawal agreement in place. This includes those that are involved in transfers of personal data to and from the EEA. If your organisation hasn’t yet seen it, their â€˜Six Steps to Take’ guide is a good place to start. It’s designed to help all organisations make the precautionary preparations that will help ensure these data flows continue.

Organisations will need to carefully consider alternative transfer mechanisms to maintain data flows and the guidance produced will help you weigh the options and take action if this proves necessary.

Standard Contractual Clauses

Many may decide that one potential solution is to put in place what are known as Standard Contractual Clauses between themselves and organisations outside the UK. Again, ICO have produced a straightforward, interactive guide to take you through that process. Particularly aimed at small and medium sized organisations, it will help you decide if Standard Contractual Clauses are relevant and will minimise the expense of putting them in place. It already includes help with completing the clauses, and the ICO will be making further developments in the next few weeks to incorporate an online tool to help organisations generate them automatically.

Transfers on the basis of a European Commission adequacy decision 

The Government has also made clear its intention to seek adequacy decisions for the UK. An adequacy agreement would recognise the UK’s data protection regime as essentially equivalent to those in the EU. It would allow data flows from the EEA and avoid the need for organisations to adopt any specific measures. But any such adequacy decisions will not be in place before the UK leaves the EU (and will take time to conclude). However, organisations need to consider their circumstances and what transfer mechanisms are appropriate.

Next steps

The guidance produced will help organisations plan ahead and ensure that personal data continues to flow. The ICO will be providing further information to the small number of organisations in the UK that rely on approved Binding Corporate Rules for their transfers to explain how they may be affected. 

Their website, ico.org.uk

Peter Smith

要查看或添加评论,请登录

Peter Smith的更多文章

  • Advisers, Consumer Duty & Agentic

    Advisers, Consumer Duty & Agentic

    Advisers, Consumer Duty & Agentic Think the current industry discussions around Agentic & indeed DeepSeek could well…

  • Advisers, Compliance, Consumer Duty & Agentic

    Advisers, Compliance, Consumer Duty & Agentic

    Advisers, Compliance, Consumer Duty & Agentic Interesting being involved in the latest AI discussions across Department…

    3 条评论
  • EU brings product liability rules in line with digital age and circular economy

    EU brings product liability rules in line with digital age and circular economy

    We've been talking about this for a long time on the "liability rules" especially with Fintech "products & services"…

  • Retail Investments Protection – Fund Groups take note…

    Retail Investments Protection – Fund Groups take note…

    Retail Investments Protection – Fund Groups take note… The Council today reached an agreement on strengthening the EU’s…

    1 条评论
  • Digital Identity for Financial Services moves on again.

    Digital Identity for Financial Services moves on again.

    European digital identity (eID): Council adopts legal framework on a secure and trustworthy digital wallet for all…

  • Is it a Wrap or is it a Platform?

    Is it a Wrap or is it a Platform?

    Is it a Wrap or is it a Platform? Way back in 2015 we were struggling with issues in the industry’s Wrap & Platform…

    1 条评论
  • Fintech at London Connect Tech Show

    Fintech at London Connect Tech Show

    Fintech & Big Data & AI Lots happening today at Big Data & AI World at Connect Tech Show London @ExCeLLondon…

  • Financial Services AI Boardroom Challenge

    Financial Services AI Boardroom Challenge

    Financial Services AI Boardroom Challenge Great session Monday at House of Commons - AI in the Boardroom with APPG AI &…

  • Advice – Guidance – Gamification

    Advice – Guidance – Gamification

    Advice – Guidance – Gamification When we started the industry wide Savings & Investment Project with the coalition…

  • Fintech CryptoCrash #DigitalAssets & Serendipity Week

    Fintech CryptoCrash #DigitalAssets & Serendipity Week

    Fintech CryptoCrash #DigitalAssets & Serendipity Week Lots of good stuff going on at the #DigitalAssetsWeek London…

    3 条评论

社区洞察

其他会员也浏览了