Data Protection Digital Information Bill

The new Data Protection Digital Information Bill is making its way through parliament. The first volume was introduced on 18 July 2022 but was put on hold two months later and was subsequently withdrawn.

New proposed changes to the legislation, which was introduced on March 8, 2023, are supposed to help businesses cut down on unnecessary red tape, reduce cookie-pop ups and increase fines for spam texts and nuisance marketing calls, among others. 

Considering compliance with the legislation is currently clunky and onerous, the reforms should make data protection legislation a lot easier and help businesses navigate this tricky area. We are yet to see whether the final bill will indeed meet these expectations.

The government is looking at ways to help businesses by changing the current legislation whilst ensuring the changes are to the same high standard that we currently have. The prediction is that British firms will save £4.7 billion over 10 years from the new Bill.

Things they are looking to change are going to affect Scientific Research, Cookie Popups, Legitimate Interests, Record Keeping, Automated Decision Making and AI and Direct Marketing. 

Are the new reforms going to shake up the data protection legislation in the UK? We are yet to find out. 

The key takeaways of the Bill

The Government hopes it will help organisations navigate U.K. laws and rules easily and lessen the burden for small and mid-sized businesses.  

Most reforms remain the same or similar to the first Bill laid out in July last year. However, there are differences in how personal data is used in commercial research and easing up organisations’ record-keeping requirements.

Out of 200 pages of provisions, we pulled the more relevant proposals. Here are some of the key elements of the Bill:

  • Increased fines for direct marketing. The new proposals announce an increase in fines for nuisance marketing and sales calls and spam text. The penalty is up to 4% of global turnover or 17.5 million GBP, or whichever is greater.
  • Changes in website cookies. Reduction in the amount of consent pop-up cookies on websites.
  • Changes in consent. Reduction of the number of consent notices. This makes it easier for businesses to see what personal data they can process without needing consent.
  • Business-friendly framework. An easier and simpler system that allows businesses more flexibility on the new data compliance. Reduction of paperwork required to prove compliance.
  • Reforms in scientific research. An easier approach to reuse data for scientific and research purposes
  • Reforms to the Information Commissioner’s Office. The Information Commissioner’s Office will have its statutory board with a chair and chief executive. 
  • Safeguards on automated decision-making. Businesses will find it easier to use technologies like artificial intelligence (AI) systems in a way that supports automated decision-making. 

Wrapping up

It took the Parliament a year to enact the Data Protection Act 2018. We will therefore have to wait to find out what the new Bill will actually look like.  

But the main question on everyone’s lips is whether it will have an impact on the UK’s adequacy decision granted by the EU following Brexit?! 

If you are still confused about how it impacts you contact us today.  We offer Power Hours on data protection and can also assist in policy drafting. This includes drafting website policies such as privacy and cookies policies – all of which come with a legal website compliance check to ensure your website is how it should be.