Category: Data Protection

TIGRR, Eeyore and Pooh Bear decide to destroy the GDPR

Yesterday, the Taskforce on Innovation, Growth and Regulatory Reform (TIGRR) reported to the Prime Minister on how the UK could, in general,  reshape its approach to regulation and seize new opportunities from Brexit with its newfound regulatory freedom.  Unsurprisingly, changes to the UK_GDPR are high on TIGRR’s list. In summary, under the heading “Replace GDPR with a new UK framework for data protection”,  perhaps with a “UK Framework for Citizen Data Rights”, TIGRR propose:  a Common Law approach towards enforcement;

Read article

Missing data protection safeguards with respect to NHS Digital’s national database of medical records

Like many, I did not know about the Ministerial Directions that require NHS Digital to create a national database of GP medical records until the indefatigable “Med Confidentiality” NGO raised its profile.  In this blog, I will make some comments about data protection safeguards, most of them statutory,  which appear to me to be missing. NHS Digital, at the behest of the Secretary of State for Health, has been given Directions to take copies of medical records from all GP surgeries in

Read article

Judgement in immigration exemption case could cause chaos and threaten any adequacy determination for the UK

The Court of Appeal’s conclusion that the ‘Immigration Exemption’ in Schedule 2 to the DPA 2018 is not compliant with the GDPR creates two data protection headaches for Government. First, the Court’s method of determining the illegality of the immigration exemption (i.e. that the safeguards in Article 23(2) of the GDPR were missing from the UK’s DPA2018),  applies to ALL exemptions in Schedules 2 to 5.  So does this mean ALL exemptions in the DPA2018 are equally unlawful? Second, if

Read article

ICO’s criticism of National Fraud Initiative on data matching raises serious concerns over proportionality and necessity

When I posted the blog on the return of the database state via the National Fraud Initiative (NFI), I knew I was going out on a limb.  Afterall, if one criticises a key Government initiative for being incredibly invasive of privacy, one hardly expects to be awarded two or three “back-of-the-hand” COVID contracts as a “thank you”. So it is a relief that the ICO’s response to NFI consultation on data matching (just published) has come to similar conclusions (see

Read article

UK’s “world class” data protection regime had 20 faults

Since the Brexit Vote in 2016, the Government has described the UK’s data protection regime (e.g. the DPA1998) as “world class”.  This description has stuck in my craw because, since 2005,  I have unsuccessfully tried to “liberate” official information, held by Government, concerning several deficiencies in this “world class” regime. Nearly two decades of Freedom of Information (FOI) requests later, last month (March 31st), I “ZOOMed” into another “Groundhog Day” FOI Tribunal to make the latest round of arguments.  This

Read article

A divided Isle of Man is the answer to UK’s data transfer woes

Oliver Dowden’s blue skies “data protection” think tank at the Department of Culture, Media and Sport (DCMS) has come up with an interesting idea to resolve all UK’s problems with respect to overseas transfers and adequacy determination, once and for ever. According to a confidential DCMS “Departmental Information Paper” (amusingly called “DIPers” by DCMS insiders) found abandoned in Costa Coffee at Watford Gap Service station on the M11 last week,  the think tank’s idea  “neuters all those lefty-lawyers, privacy fanatics

Read article

The next Information Commissioner likely to dance to the Government’s tune and thereby lack credibility

A brief blog on two recent publications in the press that herald the appointment of a malleable Information Commissioner to replace Ms. Denham in October.  According to these documents, the replacement Commissioner could well be expected to make decisions that favour Government policy (e.g. in data sharing; with respect to the National Data Strategy). The first publication is the column that appeared in the Financial Times (FT) on February 27th; it is written by Oliver Dowden,  Secretary of State for

Read article

The return of the database state: mandatory data matching and expansive data sharing

The Government propose to expand the data matching capability of the Cabinet Office as legitimised by the Local Audit and Accountability Act 2014.  Data matching (and the associated data sharing) is to be extended from its current anti-fraud base to include any other criminal activity, debt recovery and data quality (e.g. improving accuracy of personal data). The proposals are described in a document entitled “Consultation on the expansion of the National Fraud Initiative Data Matching Powers” which also includes a

Read article

Does the UK-EU Trade Deal provide for adequacy and kill off the “soft opt-in”?

Can I wish blog readers a belated “Happy New Lockdown”. This blog considers two issues (a) the adequacy arrangements in the EU-UK Trade Agreement (the “Agreement”) and (b) electronic marketing provisions in the Agreement which might sink the “soft opt-in”. But first a reminder for readers to refer to the UK_GDPR and EU_GDPR from now on.  These two GDPR variants are established by the “Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019” (the “Brexit DP Regs”)

Read article

Seasonal Book Offer: Data Protection Law & Practice (5th Edition)

It’s with great pleasure that I write to promote the best book on Data Protection in the UK; it is “Data Protection: Law and Practice (5th Edition)” by my ex-boss, Rosemary Jay (with a few chapters written by a collection of well-known and authoritative  DP experts). The book contains 1500 pages of solid Data Protection commentary (with a further 250 pages devoted to cross references to relevant case law and index). It is an invaluable reference work. If ever you

Read article
Search Hawktalk blogs by month :
Select Date
View blogs by category:
Hawktalk Taxonomy