Share this article
The ICO has expressed “strong concerns” about proposed changes to the data protection regulations
Changes to GDPR are on the horizon, thanks to a government consultation introducing proposed changes to data protection in the UK. However, the UK’s data regulator – the Information Commissioner’s Office (ICO) – has cited strong concerns about the new plans in their official response to the consultation, stating that this new direction could infringe on the regulator’s future independence.
The ‘Data: a new direction’ consultation was published last month by the Department for Culture, Media and Sport (DCMS), proposing a new regulatory framework for data protection in the wake of the UK leaving the European Union.
Responses to the consultation have been mixed, with many expressing doubts at its viability given that the UK has been granted adequacy status by the EU for data transfers precisely because they are so closely aligned on GDPR.
So is there method to the madness, or is the future of UK GDPR in jeopardy?
Justifying their reasoning behind the proposed changes to data protection, the government has stated that the current one size fits all approach used in GDPR disproportionately impacts smaller businesses, especially those who may not have the same proportionate levels of risk associated with protecting data. These new changes would move GDPR away from its current box-ticking approach to a more proactive system, according to the government.
UK Information Commission’s, Elizabeth Denham, has approved of this aspect of the consultation, stating that she supports “the intention of the proposals to make innovation easier for organisations” and efforts to “make it simpler for companies to do the right thing when it comes to our data.”
What’s more, the government has also estimated that this proposed reform will lead to a net direct benefit of £1.04 billion over 10 years, and that’s after accounting for potential costs incurred through any changes to the UK’s EU adequacy status.
However, these potential benefits do not erase the areas of concern highlighted by the ICO. As stated by Denham, “the devil is in the detail”, and the government is being pressured to ensure that the final package clearly maintains rights for individuals.
“It is crucial we continue to see the opportunities of digital innovation and the maintaining of high data protection standards as joint drivers of economic growth. Innovation is enabled, not threatened, by high data protection standards,” states Denham.
In particular, concerns have been raised regarding the consultation’s calls for the ICO itself to be reformed, which could threaten ICO’s independence as a regulator. On behalf of the regulator, Denham has said:
“For the future ICO to be able to hold government to account, it is vital its governance model preserves its independence and is workable, within the context of the framework set by Parliament and with effective accountability.
“The current proposals for the Secretary of State to approve ICO guidance and to appoint the CEO do not sufficiently safeguard this independence.”
As such, the ICO has urged the government to reconsider the proposals outlined in the consultation.
It’s impossible to say with certainty at this stage how these proposed changes would impact businesses, but one thing is clear: uncertainty surrounding data protection leaves you vulnerable.
Data protection is more important than ever before, yet it’s all too easy for businesses to misstep or overlook an area of risk. With regulations set to change, it’s now even more vital that you take control of your cybersecurity and protect your business against common threats.