The UK slowly but surely, cements its position post-Brexit, using all of the benefits that came from it. In May, the government announced that there would be changes to UK Data protection law. These changes were a long time coming. But the government has finally announced it’s plans for the upcoming data protection reform bill. The complex General Data Protection Regulation (GDPR) which the UK adopted in 2018, prevented many organisations (mainly small businesses and startups) from using data as dynamically as they could.
Even though the same high standard data protection standards will stay in place. With the new Data Reform Bill, the businesses that were most affected will now have a more flexible approach to meet these standards.
The new Data Reform Bill aims to reduce the burden placed upon businesses concerning their data protection obligations, facilitate the use of personal data for analytical and scientific research and improve people’s everyday life. The government claims that these reforms could save British businesses £1 billion over a period of ten years.
Just how, we are yet to find out how.
How will the planned changes to the data protection reform bill help your business?
The new Data Reform Bill will have a significant impact on small businesses. There will no longer be a requirement to appoint a Data Protection Officer (DPO). Or undertake time-consuming data protection impact assessments (DPIAs) or maintain records of processing activities (ROPAs).
However, businesses still have to manage the risks effectively and will have to implement “privacy management programmes”. The programmes will be tailored to the size of organisations and the risks presented by their processing activities.
Those businesses who are obligated to have a Data Protection Office will be pleased to know that the . Whilst the records of processing activities (ROPAs) will be replaced with “personal data inventories”. Instead of data protection impact assessments (DPIAs), organisations will now implement “risk assessment tools”.
This means that small businesses won’t have to hire a DPO to become GDPR compliant. Instead, they can manage risks effectively themselves and not waste time filling out unnecessary forms where there is no or low risk.
The new UK GDPR will also reduce the amount of pointless paperwork and red tape.
In addition, the Data Protection Reform Bill will increase the penalties for companies pestering people with nuisance calls. Or, in general, contacting customers without their consent. The fines are hefty, with a penalty of £17.5million or four per cent global turnover, whichever is greater.
Bye Bye Cookies!
Besides penalties for breaching the UK’s privacy and electronic communications regulations (PECR). The Bill will also cut down on cookie pop-ups and banners people see on the internet – at last! The idea is to allow users to set their online cookie preferences to automatically opt out of annoying pop-up banners or cookies.
One of the key elements of the Data Reform Bill is lowering the barrier to legal requirements for companies to collect or use data for research purposes. This means that scientists and researchers can collect and use data without obtaining explicit consent for that data to be processed for a specified reason. For example, with the new reforms, researchers will only need to specify they are using data in cancer research, as opposed to a specific cancer study.
Final thoughts on the data protection reform bill
It is important to note that businesses that are already UK GDPR compliant and operate in the UK will remain compliant with the new regime with a minimal impact.
Whilst we do not know yet when the changes will take effect. We do know that most reforms are business-friendly. This is great news for UK businesses who have to deal with onerous processes when handling personal data.
If you’re intereted to read the ICO’s statement in response to the government’s announcement take a look here.
