What are the proposed changes in the Data Protection and Digital Information Bill 2?

31st March 2023Houses of Parliament

What are the proposed changes in the Data Protection and Digital Information Bill 2?

The Data Protection and Digital Information Bill 2 was read in Parliament on 8 March, with the second reading planned for 17 April with the ambitious goal of saving UK businesses £4.7billion over the next 10 years.

You may recall that the original Bill was introduced back in July 2022; however, it was put on hold in September last year due to the election of Liz Truss to allow Ministers to give the Bill further consideration.

The Data Protection and Digital Information Bill 2 is the replacement proposed by Michelle Donelan, Secretary of State for Science, Innovation and Technology.

In the press release that accompanied the reading of the Bill, under the headline of the billions of pounds to be saved was the way the Bill intended to do this:

‘New data laws to cut down pointless paperwork for business and reduce annoying cookie pop-us’ Government Press Release

Bear in mind that this is still just a draft; here are a few of the key changes we have noted for you:-

  • Legitimate interest made easier

The idea here is that there will be a list of ‘recognised legitimate interests’; if your processing falls on this list, you won’t need to conduct the balancing test. Controversially, to some extent, direct marketing is currently in the draft list. Once we have the final version of the Bill we will explain in more detail what the Government have signed off on.

  • Higher fines for direct marketing

However, if you abuse the system, the maximum fines for direct marketing are drafted to increase considerably.

  • Cookie banner requirement relaxed

The draft legislation proposes that cookie pop-ups will NOT be required for websites that only use basic cookies for collecting statistics, security and location information (in many cases, this refers to people who have Google Analytics and nothing else).

  • Less onerous record keeping

Currently, all businesses with over 250 employees (and all those carrying out ‘high risk’ processing) must maintain a Record of Processing Activities (often referred to as a RoPA).  A RoPA is an incredibly useful document for keeping tabs on your data.  It acts as a central record and is often referred back to. The draft legislation does away with the RoPA in most cases (unless you fall under ‘high risk’ activities).

You still need to maintain records, but not via a RoPA, which many organisations did find meant they were duplicating effort.

  • Your own method for Risk assessments

It is a similar story here.  You still need to conduct an assessment for any processing that is deemed ‘high risk’ but you won’t need to use the format of the current Data Protection Impact Assessment. This will give you more flexibility and a bit of room to streamline the process if need be – but if your current system is working, you may decide it makes sense to continue with the DPIA template that you are used to using.

  • Role of Data Protection Officer replaced by Senior Responsible Individual

You could argue that this is semantics. As before, it applies only to public authorities or those carrying out high-risk processing.  If this applies to you, you still need an individual who is part of the senior management to be accountable for data protection compliance.

  • More leeway to refuse inappropriate Data Subject Access Requests

The draft bill proposes changing the wording from ‘vexatious or excessive’ to manifestly unfounded or excessive’ regarding when a Controller can turn down the request.  This is to give organisations a defence against people who make the request primarily as a means of causing inconvenience to an organisation rather than genuinely wanting a copy of their personal data (if they hold a grudge against them for example).

  • UK Comissioner’s Office to become the Information Commission

John Edwards, the UK Information Commissioner, said in response to the Draft Bill:

“We look forward to continuing to work constructively with the Government to monitor how these reforms are expressed in the Bill as it continues its journey through Parliament”.

There is a lot to balance here.  Privacy and commerciality.  Ensuring we keep our adequacy agreement with Europe.

The proposed changes in the Data Protection and Digital Information Bill 2

We will follow the Bill through Parliament and keep you posted on future developments  – don’t forget the above is just the draft. If you would like to contact us in the meantime, please take advantage of your complimentary thirty minute consultation.

 

 

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details