Data Protection in 2024 – What You Need to Know

26th January 2024

As we move into 2024, it’s time to consider how data protection is going to look in the new year. From the UK’s upcoming Data Protection and Digital Information Bill to the new Data Privacy Framework enabling data transfers between the UK and US, as well as the EU’s new AI Act, there’s plenty to think about. Read the key highlights below in less time than it will take you to enjoy your favourite hot drink. 

Data Protection & Digital Information Bill

The new Data Protection & Digital Information Bill (DPDI) will bring some consistency to the UK’s distinct data protection and unsolicited electronic marketing laws. In other words, the DPDI Bill will update the UK General Data Protection Regulation (GDPR), the Data Protection Act 2018 (DPA 2018) and the Privacy and Electronic Communications Regulations 2003 (PECR).

What Will the DPDI Bill Do?

This bill intends to update and simplify data protection laws in the UK and improve data security overall. Here are some key points:

Clarify what is personal data

The definition of personal data has become very wide under the GDPR and the Bill will attempt to narrow the focus, especially where pseudonymised data is concerned.

Remove the need for a legitimate interest assessment in certain cases

A set of valid processing activities is to be provided which will automatically be classed as legitimate interests and an LIA will not need to be performed.

International data transfers

One of the aims of the Bill is to remove superfluous bureaucracy and replace adequacy decisions with a more flexible ‘data protection test’. Currently, to allow international flows to take place freely, the UK follows the EU framework of assessing a country’s legislative framework. Moving forward the data protection test will be met if the standard of data protection in a third country is “not materially lower” than that provided under UK law. This Data Privacy Framework (DPF), will be referred to as a Data Bridge. 

These changes may however interfere with the UK’s existing adequacy decision with the EU as it will prevent the onward transfer of EU citizens’ data to countries considered insecure by the EU.

Simpler rules on cookies

A long-awaited exemption will be provided for the often frustrating and onerous cookie consent banner. Under the Bill, consent will most likely not be needed for cookies not related to user privacy, for example, cookies used in analytics. 

An important point to note, however, is that these rules will only apply if targeting UK audiences.

No need for records of processing in low-risk situations

In an attempt to reduce the burden on small businesses, it will only be necessary to maintain records of processing activities when data processing is “likely to result in a high risk to the rights and freedoms of individuals”.

Tighter protections against spam marketing and nuisance calls

Nuisance calls and spam marketing activities such as unsolicited texts could incur heavier fines with the level of sanctions on unsolicited marketing increasing in line with those in the GDPR.

New powers to crack down on benefit fraud

The Bill intends to remove the confusion which was introduced with the GDPR limiting how and when data could be used for public interest purposes, such as sharing with government agencies and statutory bodies for fraud and crime detection purposes. For example, the DPDI will authorise banks and financial institutions to share account data with different entities to check on benefit claimants to ensure they do not have more in savings than is allowed, or that individuals aren’t spending too much time out of the UK.

Automated decision-making

Currently, data subjects have a right not to have decisions made on them based solely on automated decision-making processes, which include profiling, such as that used by social media firms. The bill will alter this provision and only apply if special category data is being used.

Refusing data subject rights

One of the unintended consequences of giving data subjects more rights has been that these rights have been used against controllers as a weapon and in ways which were not intended. For example, Data Subjects making unfounded or excessive requests for information under their Article 15 right of access. The new bill aims to address the imbalance and is replacing the ‘manifestly unfounded’ or ‘excessive’ threshold test, with the lower ‘vexatious’ or ‘excessive’ test. 

This will mean that where a Controller believes that a data subject is not acting in the purest sense the request can be narrowed or rejected. Controllers must however be very careful as they must treat these requests on a case-by-case basis.

 

When will the DPDI Bill come into law?

At the time of writing, the new DPDI Bill has just had its second reading in the House of Lords. Once this bill has passed through the House of Lords and Royal Assent, it will be passed officially into law. 

With an election on the horizon, how long this will take to come into law is a bit of a guessing game, but my gut tells me 12-18 months from now.

For more information on the Data Protection & Digital Information Bill, see the following resources: 

UK Government: Changes to Data Protection laws

Data Protection & Digital Information Bill

IAPP Data Protection reform overview


AI and Data Protection

As people learn more about AI and its potential impact on data protection, AI will likely come under increasing scrutiny in 2024.

The UK Information Commissioner, John Edwards, has warned that people will begin to lose trust in AI in 2024. As the keynote speaker at techUK’s Digital Ethics Summit 2023, Edwards goes on to say that non-compliance with data protection laws will ‘not be profitable’ and stresses the importance of privacy in the use of AI technology. The ICO is expected to issue more guidance on the use of AI by organisations later in 2024.

Read more about AI from the ICO here

The European Commission proposed the Artificial Intelligence Act back in 2021, which seems like a while ago now, especially since the rapid advancement of AI technology in the past year. The UK government will be publishing a white paper on AI in early 2024, and this is thought to intersect with the aforementioned DPDI Bill, especially regarding automated decision-making as covered by Article 22 of the UK GDPR. 

Technology has always advanced at a far quicker pace than the law can keep up, and it can be notoriously difficult to regulate. Whilst the task of lawmakers is daunting, let’s hope the new legislation is somewhat future-proofed. Whilst the AI Act is far from ready for implementation, we do know that it is highly likely to involve the following:

  • The use of AI for biometric categorisation systems that use protected characteristics, e.g. political beliefs, race, or sexual orientation, will be prohibited.
  • Content generated by AI will have to be disclosed, and AI models such as ChatGPT will have to be designed in a way that avoids the generation of illegal content
  • AI systems that are deemed ‘high risk’ will need to be assessed before going to market and throughout their lifecycle. This could include law enforcement, education, border control, and products subject to product safety laws, such as toys, cars and medical devices.
  • Consumer rights will be bolstered, including the right to complain and expect an explanation about AI systems that could affect them.

Find out more about the EU’s AI Act here.

Data Privacy Framework

The EU-US Data Privacy Framework (DPF) replaces the Privacy Shield, which broke down following the Schrems II case in which the CJEU ruled that the Privacy Shield did not provide adequate protections for EU data being processed within the US. 

Following a UK addendum to the EU-US DPF published in October 2023, Data can now be transferred to US organisations that have opted into the DPF. UK companies can still rely on SCCs (standard contractual clauses) for data transfers between the UK and the USA.

Additionally, Max Schrems and the non-profit organisation noyb are now challenging the EU-US DPF, asserting that the new framework has the same problems that the older Privacy Shield and Safe Harbour had, stating that:

“the US still takes the view that only US persons are worthy of constitutional rights”. – Source: noyb

 

Author: Paul Adams LLB (HONS)

Paul is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details