Share this article
Over the last few years there has been uncertainty about exactly how the UK would forge a new relationship with Europe post-Brexit. Amidst this uncertainty there was, however, always something the experts agreed on: the continued importance of the EU General Data Protection Regulation (GDPR). So, as the dust settles on the Trade Agreement the UK Government negotiated with Europe, it is no surprise to anyone that, when it comes to data privacy, very little has changed.
In fact, the Information Commissioner’s Office (ICO) welcomed the data protection provisions of the Trade Agreement with the EU, saying that it means that “organisations can be confident in the free flow of personal data from 1 January, without having to make any changes to their data protection practices”.
This is, of course, true for all organisations that have already embedded the principles of GDPR into their business systems. Those who have been hesitating, or who have not yet fully embraced GDPR, will have more to do over the coming months.
Currently, the UK Data Protection Act 2018 enshrines GDPR’s requirements into UK law. In addition, the Government issued a statutory instrument “The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019”, the outcome of which will be a new data protection framework known as “UK GDPR”.
In short the principles of GDPR are here to stay and adhering to best practice will continue to be a requirement for anyone who doesn’t wish to fall foul of the law. Despite this, there are still a few areas of uncertainty.
Here’s my take on what we know is changing and what may become clearer further downstream.
In the short term, there are a couple of buzz words that refer to the detail of the transition period. The first is “bridge”. This is the four-month period (which can be extended to six months) during which data can still flow freely from the UK to the European Economic Area (EEA). The second is “adequacy” which refers to a decision by the EU Commission as to whether UK law is equivalent to the terms of its EU counterpart. If and when an adequacy decision is made, the transfer of data will continue. If this decision is not made, the free transfer of data will end when the bridge period expires.
The UK Government has stressed that it is committed to securing an adequacy agreement under both GDPR and the Law Enforcement Directive (LED). Yet, whatever the outcome, building the principles of GDPR into all aspects of an organisation’s data privacy policy is essential to best practice. It will not only proactively protect your customer data – which is, after all, the motivation behind the regulation – but it will also ensure you are on the right side of the UK GDPR standard once it is released and it will stand you in good stead for fast-tracking the process of exchanging data with EU counterparts.
As mentioned, if you have already taken steps to adhere to the principles of GDPR, you have little to worry about. Having said that, however, GDPR is not static and needs to be constantly reviewed and updated. Those who have rolled out remote working over the last year will need to ensure that this element of the business is included in the GDPR policy. This should also include any changes to systems – even very small ones – which may affect adherence.
Those who have not fully embraced GDPR in its previous incarnation need to make it a priority. Whatever the size of organisation, it applies to you. In the event of a breach, in addition to the actual cost of the breach itself, you will be held accountable by the ICO who can impose fines and penalties.
For full info see ICO guidance on GDPR.
Given the complexity of the transition process and the actual lack of a recognised compliance process for GDPR, professional help is invaluable. Whether you are a large organisation looking at transferring significant volumes of international data, considering whether to engage EU representation or streamlining and updating your process; whether you are an SME struggling to work out how best your particular business can adhere to the principles of the regulation or even an organisation which has very few EU customers or partners; there are multiple factors to consider.
Engaging with specialist GDPR consultants will bring immense benefits. With a thorough knowledge of the process in a range of sectors and sizes of organisation, a data protection expert can help you identify the processes, procedures and broader business improvements that will improve the security and management of valuable data.
At SRM, we always stress that our service is not intended to replace your existing information security office holders; instead we can provide support and resource to assist them; much like a specialist tax accountant would assist your financial team.
If the time has come for you to improve your data protection policies and procedures, or you just want to check how you should be handling GDPR after Brexit, why not get in touch with the SRM team today?