
Changes to UK Data Protection Legislation

Currently, the Data Protection and Digital Information Bill (the “DPDI”) is making its way through parliament and at present sits at the committee stage. Barring any unforeseen circumstances, the Bill should become law in May-June 2024.
Given that the DPDI is still making its way through Parliament, and therefore subject to change, with outlined what are currently the most notable changes.
The DPDI makes some important changes to domestic data protection legislation and some more minor ones. The most notable changes include:
- The way that international data transfers are regulated will change. The Secretary of State will have the discretion to create ‘data bridges’ with countries where they are satisfied that there are ’not materially lower data protection standards’ in those countries. This change is in many ways the most interesting and potentially disruptive. All eyes will be on the EU to see how they react to this change and whether they consider it consistent with their data protection measures regarding third countries.
- Data Protection Impact Assessments will change to ‘Assessments for High-Risk Processing’ with more control given to the data processor to determine what are high-risk activities. The Information Commissioner’s Office (‘ICO’) will also be rebranded as the Information Commissioner (‘IC’) and will now be legally obligated to produce official guidance containing examples of the types of processing activities which are likely to result in high-risk to the rights and freedoms of individuals.
- Instead of Data Protection Officers, businesses will be required to appoint a ‘Senior Responsible Individual’ (SRI). The requirement to appoint an SRI and their responsibilities will be more wide ranging.
We will of course keep you updated on the DPDI’s progress.
