• Login
    • Advanced search
    • Title
    • Channel
    • Module
  • Home
  • Industry
    •  

      • Aerospace, Defense, and Government Services
      • Automotive and Mobility
      • Consumer
      • Manufacturing and Industrials
      • Education
      • Energy and Natural Resources
      • Financial Institutions
    •  

      • Insurance
      • Life Sciences and Health Care
      • Private Capital
      • Real Estate
      • Sports, Media and Entertainment
      • Technology and Telecoms
      • Transportation and Logistics
  • Practice
    • Corporate & Finance

      • Banking and Loan Finance
      • Business Restructuring and Insolvency
      • Capital Markets
      • Corporate Governance and Public Company Representation
      • Digital Assets and Blockchain
      • Infrastructure, Energy, Resources, and Projects
      • Leveraged and Acquisition Finance
      • Mergers and Acquisitions
      • Pensions
      • Private Equity, Venture Capital and Investment Funds
      • Real Estate
      • Real Estate Investment Trusts (REITs)
      • Tax
      • Transfer Pricing
    • Global Regulatory

      • Administrative and Public Law
      • Antitrust and Competition
      • Communications, Internet, and Media
      • Education
      • Energy Regulatory
      • Environment and Natural Resources
      • Financial Services
      • Food Law
      • Gaming Law
      • Government Contracts and Public Procurement
      • Government Relations and Public Affairs
      • Health
      • Immigration
      • International Trade and Investment
      • Medical Device and Technology Regulatory
      • New Nuclear
      • Pharmaceuticals and Biotechnology Regulatory
      • Privacy and Cybersecurity
      • Space and Satellite
      • Strategic Operations, Agreements and Regulation
      • Transportation Regulatory
    • Intellectual Property

      • Copyright
      • Designs
      • Domain Names
      • IP and Technology Transactions
      • IP Enforcement
      • Patents
      • Trade Secrets and Confidential Know-how
      • Trademarks and Brands
      • Unfair Competition
    • Litigation, Arbitration, and Employment

      • Business and Human Rights
      • Construction and Engineering
      • Corporate and Securities Litigation
      • Employment
      • International Arbitration
      • Investigations, White Collar, and Fraud
      • Products Law
      • Risks, Disputes, and Litigation
  • Comparative guides
  • Engage Premium
  • Login
  • Register
Hogan Lovells Engage 5.7.16
      • Title
      • Channel
      • Module
    • Hit ENTER to search in content
    • Advanced search
    • Login
  • Home
  • Industry
    •  

      • Aerospace, Defense, and Government Services
      • Automotive and Mobility
      • Consumer
      • Manufacturing and Industrials
      • Education
      • Energy and Natural Resources
      • Financial Institutions
    •  

      • Insurance
      • Life Sciences and Health Care
      • Private Capital
      • Real Estate
      • Sports, Media and Entertainment
      • Technology and Telecoms
      • Transportation and Logistics
  • Practice
    • Corporate & Finance

      • Banking and Loan Finance
      • Business Restructuring and Insolvency
      • Capital Markets
      • Corporate Governance and Public Company Representation
      • Digital Assets and Blockchain
      • Infrastructure, Energy, Resources, and Projects
      • Leveraged and Acquisition Finance
      • Mergers and Acquisitions
      • Pensions
      • Private Equity, Venture Capital and Investment Funds
      • Real Estate
      • Real Estate Investment Trusts (REITs)
      • Tax
      • Transfer Pricing
    • Global Regulatory

      • Administrative and Public Law
      • Antitrust and Competition
      • Communications, Internet, and Media
      • Education
      • Energy Regulatory
      • Environment and Natural Resources
      • Financial Services
      • Food Law
      • Gaming Law
      • Government Contracts and Public Procurement
      • Government Relations and Public Affairs
      • Health
      • Immigration
      • International Trade and Investment
      • Medical Device and Technology Regulatory
      • New Nuclear
      • Pharmaceuticals and Biotechnology Regulatory
      • Privacy and Cybersecurity
      • Space and Satellite
      • Strategic Operations, Agreements and Regulation
      • Transportation Regulatory
    • Intellectual Property

      • Copyright
      • Designs
      • Domain Names
      • IP and Technology Transactions
      • IP Enforcement
      • Patents
      • Trade Secrets and Confidential Know-how
      • Trademarks and Brands
      • Unfair Competition
    • Litigation, Arbitration, and Employment

      • Business and Human Rights
      • Construction and Engineering
      • Corporate and Securities Litigation
      • Employment
      • International Arbitration
      • Investigations, White Collar, and Fraud
      • Products Law
      • Risks, Disputes, and Litigation
  • Comparative guides
  • Engage Premium
  • Login
  • Register
  1. News
  2. UK data protection reform: A second bite of the cherry

UK data protection reform: A second bite of the cherry

10 March 2023
    • Share by email
    • Share on
    • Twitter
    • LinkedIn
    • Get link
    • Get QR Code
    • Download
    • Print

On 8 March 2023, the UK Department for Science, Information and Technology (DSIT) published the Data Protection and Digital Information (No.2) Bill (DPDI 2) which provides an update to the Government's reforms to the UK data protection framework, ending months of speculation as to what would be changed.

Index
  1. The changes
  2. The impact
  3. The future

In July last year the Government released their long awaited reforms to the UK's data protection framework, the Data Protection and Digital Information Bill (DPDI 1), which made amendments to a number of laws including the UK GDPR, Data Protection Act, and Privacy and Electronic Communications Regulations. The aim of the reforms was to simplify the data protection framework by reducing burdens on organizations while maintaining high data protection standards.

After the 2022 leadership changes within Government, the DPDI 1 was put on hold shortly after it entered its legislative journey, with a view to create a 'new data protection plan'. In the meantime, the Government engaged in further consultation with industry leaders, business groups, and consumers with a view to making UK law more aligned with the reality surrounding data processing activities and the objectives of the legislation.

With the DPDI 2, the Government aims to further lessen the compliance burdens on business by cutting 'pointless paperwork' whilst unlocking '£4.7 billion in savings for the UK economy'. Crucially, in addition to creating a new data protection framework that is better suited to the Government's needs and aims, the UK is also trying to make a contribution to the global debate about privacy regulation by putting forward a proposal of what may constitute a solid baseline for global compliance.

The changes

  • Commercial activities can fall under scientific research definition

The DPDI 2 amends the definition of scientific research so that it now includes research for the purposes of commercial activity.

  • Legitimate interests get clarification

The DPDI 2 introduces a non-exhaustive list of instances where organizations may rely on the 'legitimate interests' legal basis, including for the purposes of direct marketing, transferring data within the organization for administrative purposes and for the purposes of ensuring the security of network and information systems.

Direct marketing was already considered as a legitimate interest under the recitals of the UK GDPR, but intra-group administrative transfers and security are new additions to the list.

  • Clarifying the restrictions around automated decision making

The DPDI 2 clarifies the meaning of 'meaningful human involvement' in automated decision making by ensuring there is consideration of the extent to which profiling is involved. The secretary of state may also publish further guidance on the meaning of 'meaningful human involvement'.

  • Only keep records of processing personal data if high-risk

The DPDI 2 amends the obligation to maintain records of processing activities, so that records will only need to be kept where the personal data processing is likely to result in a high risk to the rights and freedoms of individuals.

  • Existing SCC will remain valid 

The DPDI 2 clarifies that existing safeguards for international personal data transfers will still be lawful once the new law takes effect.

The impact

The changes made to DPDI 1 are, on the whole, relatively minor. When the reforms were originally published last year, Hogan Lovells published an article-by-article analysis of the changes (which you can find here) and we concluded that none of the proposed changes represented a radical departure from the current law in the EU.

In the same way that DPDI 1 did not affect the essence of the UK data protection framework on the basis of which EU adequacy was granted, the revised version does not change that either. Therefore, the adequacy determination granted by the European Commission for restrictions-free transfers from the EU should not be affected.

The future

The DPDI 2 has been introduced as a new bill at the first reading stage. Its second reading is due to be scheduled within the next few weeks, which will be the first time these data protection reforms will be debated in the House of Commons. The DPDI 1 will fall away as the DPDI 2 proceeds through the houses.

The last data protection law to go through the domestic legislative process was the Data Protection Act 2018, and it was most the amended piece of legislation that session. However, DSIT expect the DPDI 2 to pass through in a form similar to the one now published.

In terms of timelines, it now seems likely that the reform of the current data protection framework will take effect during the course of this year. In practical terms, this means that organizations operating in the UK or targeting the UK market have a few months to consider their compliance strategy and decide whether to simply assume that their current level of compliance is acceptable or to explore the potential advantages of following the new regime.

 

Authored by Eduardo Ustaran, Dan Whitehead.

Kathleen McGrath, a Knowledge Paralegal in our London office, contributed to this post.

Contacts
Eduardo Ustaran
Partner
London
Nicola Fulford
Partner
London
Dan Whitehead
Counsel
London
Index
  1. The changes
  2. The impact
  3. The future
Additional Resources
  • Redline | Data Protection and Digital Information (No. 2) Bill
  • The UK Data Protection and Digital Information Bill | A practical comparative analysis with the EU GDPR and ePrivacy framework
Keywords UK, data protection, Data Protection and Digital Information Bill, UK GDPR, UK General Data Protection Regulation (UK GDPR), privacy, Cybersecurity, UK Government, DSIT, DPDI, DPDI 2, EU
Languages English
Topics Privacy, Cybersecurity
Countries United Kingdom
Delete Comment ?

Are you sure want to delete comment ?

Get link
Embed
Share by email
Get QR Code

Scan this QR Code to share this content

  • Contact us
  • Disclaimer
  • Privacy
  • Cookies
  • Legal Notices
  • Terms of Use

 

This website is operated by Hogan Lovells International LLP, whose registered office is at Atlantic House, Holborn Viaduct, London, EC1A 2FG. For further details of Hogan Lovells International LLP and the international legal practice that comprises Hogan Lovells International LLP, Hogan Lovells US LLP and their affiliated businesses ("Hogan Lovells"), please see our Legal Notices page. © 2022 Hogan Lovells.

Attorney advertising. Prior results do not guarantee a similar outcome.

Thomson Reuters HighQ Logo
© 2023 Hogan Lovells | Privacy Policy | Terms of Service