Category: Other Information Law

KC’s legal advice supports Hawktalk’s claims of inadequate standards set by DPDI Bill

This is my contribution to the Second Reading (Lords) of the Data Protection and Digital Information (DPDI) Bill which is tomorrow. First there is a legal opinion, just published by defenddigitalme from Stephen Cragg KC of Doughty Street Chambers. This is accessible from https://defenddigitalme.org/2023/11/28/new-legal-opinion-on-the-data-protection-and-digital-information-bill/  This legal opinion reinforces the major concerns raised in my previous blogs on the DPDI Bill.  Collectively these concerns weaken data subjects rights and the privacy protection afforded by the current UK_GDPR. They concern the definition

Read article

DPDI Bill undermines transparency of Artificial Intelligence development and training

Last week, Prime Minister asked  “how can we write laws [to regulate AI] that make sense for something we don’t yet fully understand?”.  The PM does not appreciate that his Government has already drafted a law that applies to the processing of personal data for AI purposes but which has the objective of diminishing the protection afforded to data subjects. In this blog, I show, in the context of scientific research, how the proposed DPDI No 2 Bill” (the “Bill”

Read article

Serious questions arising from ICO v Clearview Tribunal Decision

I was surprised by the recent Tribunal Decision (the “Decision”) which quashed Clearview’s £7.5 million fine on the grounds the UK_GDPR did not apply.   My puzzlement has given rise to several important questions about the Decision. These questions need an urgent answer; hence this blog. Clearview is a USA company which has scraped billions of photos and personal data from the Internet and used them to sell services to law enforcement/national security agencies and similar agencies in other countries (e.g.

Read article

Cronyism at the Information Commission can undermine its regulatory independence

I have atoned for not delivering a blog for two months by reading Schedule 13 of the Data Protection and Digital Information No 2 Bill (the “Bill”).  As readers know, the Information Commissioner (ICO) is to be replaced by an Information Commission, and Schedule 13 outlines the procedural arrangements for the operation of the Commission. Schedule 13 is not “a gripping read”.  With all its provisions about voting, quorums, Committees, Board Members, Chairs and Chief Executives, the text can be described in two words:

Read article

DPDI Bill’s Codes of Practice are institutionally biased in favour of controllers

Who should prepare Codes of Practice that describe good practice in data protection? Should a Code’s final content be the responsibility of the data protection regulator or a government minister? I can sense your reaction to these two questions.  A longish blog on Codes of Practice–oh dear.  On the standard scale found on most data protection “Yawnometers”,  the topic of “Codes of Practice” is usually found on the far right of the scale, just before “Registration fees”. However, this view

Read article

If “guard-rails” are needed to control Artificial Intelligence, why does the DPDI No.2 Bill remove them?

Last week, the Prime Minister was quoted concerning the need to ensure Artificial Intelligence (AI)  is “introduced safely and securely with guard-rails in place”.  Strange to find that he appears to be unaware that several of these urgently needed guard-rails are being dismantled by the DPDI No.2 Bill (the “Bill”). On June 6th, I delivered a presentation to the Data Protection Forum where there was lively discussion concerning the weakening of data protection within several identified issues of the Bill.

Read article

DPDI No.2 Bill dumps all data subject consent requirements for Third Party marketing

The DPDI No.2 Bill (the “Bill”) overturns the Third Party direct marketing rules in relation to data subject’s consent that have applied for 40 years, ever since the DPA1984.  This blog illustrates how Third Party marketeers will be able to lawfully rely on legitimate interest for such marketing. For the purposes of this blog, the old ICO DPA1988 Guidance on the processing of personal data for a direct marketing purpose had a useful summary concerning the use of data subject’s

Read article

The “Seven deadly privacy sins” associated with the DPDI No.2 Bill

The blog provides a summary of seven areas where the proposed Data Protection and Digital Information No. 2 Bill (“No.2 Bill”) undermines privacy issues; these should be debated by Parliament. Some area, such as ICO independence and research, are left unexplored in this Blog. 1.   Absence of Keeling Schedules It is difficult to comment on legislation that significantly modifies existing legislation if the relevant Keeling Schedules, which detail the proposed legislative changes, are unavailable (perhaps deliberately so).  The No.2 Bill

Read article

Facial recognition CCTV excluded from new data protection law by definition of “personal data”

I have come to the conclusion that the new definition of personal data in the Data Protection and Digital Information No.2 Bill (“No.2 Bill”) only applies to facial recognition CCTV if the data subject is on a watch-list. If the individual is not on a watch-list, and the camera images are deleted immediately after checking the watch-list, then personal data are not processed and there are no data protection obligations (e.g. no transparency) It then follows that if the watch-list,

Read article

Definition of “personal data” in DPDI No 2 Bill results in non-compliance with CoE Convention No.108

The press release associated with the DPDI No.2 Bill proudly states that the Bill ensures “that the new regime [is] built on the UK’s high standards for data protection and privacy”. These new “high standards”, evidently, includes adopting a definition of “personal data” that fails to meet the data protection standards established by the text of the Council of Europe (CoE) Convention No. 108, as published in January 1981. In other words, the most enduring international binding agreement on data

Read article
Search Hawktalk blogs by month :
Select Date
View blogs by category:
Hawktalk Taxonomy