European Data Protection Board's opinion on UK data adequacy
The European Data Protection Board has adopted two positive opinions on the draft UK adequacy decisions issued by the European Commission, bringing the bloc closer to maintaining the free flow of personal data between the UK and the European Economic Area post-Brexit.
During its 48th plenary session on the 14 April , the European Data Protection Board (EDPB) adopted two opinions on the European Commission draft Implementing Decisions, published on 19 February, on the adequate protection of personal data in the UK.
The EDPB broadly welcomes the Commission’s draft decision to grant UK data adequacy, finding many aspects of the UK data protection framework to be “essentially equivalent” to the safeguards under the GDPR. These include:
- concepts (e.g. “personal data”; “processing of personal data”; “data controller”);
- grounds for lawful and fair processing for legitimate purposes;
- purpose limitation;
- data quality and proportionality;
- data retention, security and confidentiality;
- transparency; special categories of data;
- direct marketing;
- automated decision making and profiling.
The EDPB even goes a step further to state that UK data protection law includes principles that go beyond than what is required for a country to be granted adequacy by the EU; therefore, elevating the level of protection provided for in the UK.
While the EDPB does not expect the UK legal framework to replicate European data protection law, as a former Member State, there is significant mirroring of EU law in the UK GDPR and the DPA 2018 (aka. the UK data protection framework). Such content principles include the ones related to personal data breach notifications, the data protection officer, data protection impact assessments and data protection by design and by default.
However, despite finding “strong alignment” between the GDPR and the UK data protection framework, the EDPB’s tone is hesitant and cautious, urging the Commission to subject the UK’s framework to more detailed scrutiny with regards to:
- The UK’s intention to develop separate and independent policies in data protection, which may lead to significant divergence from EU data protection law.
- Safeguards of personal data under the “broadly formulated” immigration exemption.
- Onward transfers of personal data to other jurisdictions outside of the EEA.
- The interplay between the UK data protection framework and its international commitments, such as the UK-US Cloud Act Agreement, or other information sharing agreements which are inaccessible by the public such as the UK-US Communication Intelligence Agreement.
- The effectiveness of the UK’s practice on procedural and enforcement mechanisms through the Information Commissioner’s Office.
- Access by public authorities to data transferred to the UK under national security and surveillance laws.
Aside from calling on the Commission to keep a close eye on developments in the UK that may affect the level of protection of personal data, the EDPB consistently reminds the Commission of the powers it has at its disposal to suspend, amend or even repeal the adequacy decision. The EDPB has also welcomed the Commission’s decision to introduce a sunset clause of four years for the draft decision. This would be the first EU adequacy decision to include a sunset clause where adequacy is not renewed without a reassessment.
The bridging mechanism, as agreed under the Trade and Cooperation Agreement, allows for the unrestricted transfers of personal data from the EEA to the UK until 1 May 2021. However, this deadline may be extended to 1 July 2021 upon agreement from both sides, until the final UK data adequacy decision is formally adopted by the European Commission after seeking approval from the European Council via the Comitology process. Should the Commission not adopt the data adequacy decision for the UK, businesses will need to use alternative tools and safeguards such as Standard Contractual Clauses to transfer personal data from the EEA to the UK. More on techUK's brexit hub.
Latest News from
The AI adoption paradox: can cautious adoption reap maximal benefits?14/05/2021 16:25:00
Joanna Crown, Product Strategist at Mind Foundry, describes how human-AI collaboration is the transformation needed for organisational success with AI. #AIWeek2021.
Foreign Secretary Dominic Raab at CyberUK 202114/05/2021 11:25:00
techUK has summarised the key points from Rt Hon Dominic Raab's speech at CyberUK 2021.
Delivering AI to Support Parkinson’s UK During the Coronavirus Pandemic14/05/2021 08:05:00
Parkinson’s UK is Europe’s leading Parkinson’s support and research charity. The organisation raises around £35m p.a. to drive better care, treatments and quality of life for those with Parkinson’s, their friends, family and their carers.
How AI is cleaning up our Oceans13/05/2021 16:25:00
AI has been at the heart of change for many industries. Right now, it is the responsibility of every industry to become more sustainable and AI technologies can help to do this.
Home Secretary announces Computer Misuse Act Review13/05/2021 13:33:00
Review into 31 year old legislation to start this year.
AI as co-creator: building better software and better businesses13/05/2021 12:33:00
Learn how computer vision and wider access to cloud-based AI capabilities is driving adoption at the most innovative companies. Guest Blog: Jaspar Casey, Product Marketing Manager at Eggplant.
Ofcom’s strategic review of its approach to markets that deliver mobile services12/05/2021 15:25:00
The UK’s telecoms regulator Ofcom has published a Terms of Reference document, setting out how it will approach its strategic review of the UK’s mobile market.
Home Secretary announces Computer Misuse Act Review12/05/2021 14:25:00
Review into 31 year old legislation to start this year.
‘Cyber Security is a Team Sport’ - CYBERUK 2021 begins11/05/2021 16:25:00
This morning, the National Centre for Cyber Security’s CEO, Lindy Cameron, kicked off the first ever virtual CYBERUK event, which is currently streaming across the world, enabling the conference to reach more people than ever before.