Showing posts with label Information Commissioner. Show all posts
Showing posts with label Information Commissioner. Show all posts

Saturday, 25 June 2022

The Proposed Data Reform Bill


 








Jane Lambert

In my article Consultation on Changing the Data Protection Laws (12 Sept 2021), I discussed the consultation on changing the data protection laws. According to the consultation outcome, Data: a new direction - government response to consultation of 23 June 2022, the government received 2,924 responses, 684 by email and 2,240 via a survey platform. It also attended over 40 round tables with academia, tech and industry bodies, and consumer rights groups.  The consultation outcome lists the organizations in Annex B, summarized the responses in the consultation outcome and set out the government's legislative intentions in the light of the responses on each issue in Annex A.

In a recent press release, the Department for Digital, Culture, Media and Sport outlined a new Data Reform Bill.  That Bill is intended to reduce the administrative burden on businesses in order to encourage more innovative uses of personal data for research, facilitate trade and save businesses up to £10 billion over the next 10 years. An example given by the press release is that an independent pharmacist will no longer have to recruit an independent data protection officer to comply with the data protection legislation provided that it can manage risks effectively.  The Bill will also increase penalties for nuisance calls and other serious breaches of the Privacy and Electronic Communications (EC Directive) Regulations 2003 and reorganize the Information Commissioner's Office. 

The proposals have been welcomed by John Edwards, the recently appointed Information Commissioner, in a Statement in response to the government’s announcement on the upcoming Data Reform Bill which was published on 16 June 2022.   His predecessor contributed to the consultation (see Response to DCMSconsultation “Data: anew direction” 6 Oct 2021).

I shall return to this topic once the bill is published.  Anyone wishing to discuss this article or its subject matter may call me on 020 7404 5252 during office hours or send me a message through my contact form.

Tuesday, 11 January 2022

Information Rights - Driver v Information Commissioner

Ramsgate Sands in 1854
Artist William Frith 

 













First Tier Tribunal (General Regulatory Chamber) (Upper Tribunal Judge Rintoul, J Randall and Raz Edwards) Driver v Information Commissioner and another [2021] UKFTT 2017-0218 (GRC)

In his preface to the white paper Your Right to Know (Cm 3818), the then Prime Minister, Tony Blair, introduced his government's proposals for a Freedom of Information Bill as one of several important constitutional reforms.  Others included the Human Rights Bill,  devolution statutes for Scotland and Wales and the Data Protection Act 1998.  The government's intention was to redefine its relationship with the governed.

S.1 (1) of the Freedom of Information Act 2000 states that:
"Any person making a request for information to a public authority is entitled—
(a) to be informed in writing by the public authority whether it holds information of the description specified in the request, and
(b) if that is the case, to have that information communicated to him."

However, those rights are subject to several exceptions pursuant to s.1 (2) and s.2 (1), (2) and (3) (g) of the Act. One of those exceptions is s.41:

"(1) Information is exempt information if—
(a) it was obtained by the public authority from any other person (including another public authority), and
(b) the disclosure of the information to the public (otherwise than under this Act) by the public authority holding it would constitute a breach of confidence actionable by that or any other person.
(2)  The duty to confirm or deny does not arise if, or to the extent that, the confirmation or denial that would have to be given to comply with section 1 (1) (a) would (apart from this Act) constitute an actionable breach of confidence."
In Higher Education Funding Council for England v Information Commissioner and another (unreported, 13 Jan 2010). the Information Tribunal held that a public authority seeking to rely on that exception would have to show that the disclosure would be likely to give rise to a successful action for breach of confidence:
“Our conclusion on this part of the case, therefore, is that the HEFCE must establish that disclosure would expose it to the risk of a breach of confidence claim which, on a balance of probabilities, would succeed. This includes considering whether the public authority would have a defence to the claim.  Establishing that such a claim would be arguable is not sufficient to bring the exemption into play.”

An example of such a claim was  Driver v Information Commissioner and another   [2021] UKFTT 2017_0218 (GRC).

The information in question was the identity of certain claimants and the amounts paid to each of them in an out of court settlement with a local authority that had banned the transport of live animals through its port in contravention of EU law.  Those claimants had successfully challenged the ban in the Chancery Division on the grounds that it breached art 35 of the Treaty on the Functioning of the European Union.  They subsequently claimed damages for losses occasioned by the ban.  

 A local resident who had opposed live animal exports asked the authority for the above information under s.1 (1) of the Freedom of Information Act 2000. The authority declined on the ground that disclosure of that information would be an actionable breach of confidence. The resident asked the Information Commissioner to intervene.  The Commissioner sided with the local authority.  The resident appealed successfully against the Commissioner's decision to the General Regulatory Tribunal.  The Tribunal held that s.41 did not apply because the withheld information had not been obtained by the local authority (see Driver v Information Commissioner and another [2017] UKFTT 2017_0040 (GRC)).  The Information Commissioner appealed to the Upper Tribunal which allowed the appeal and remitted the case to a differently constituted first instance tribunal (see Information Commissioner v Driver and another [2020] UKUT 333 (AAC)). The Upper Tribunal directed the new tribunal to proceed on the basis that the threshold condition in s.41 (1) (a) of the Act had been satisfied.  That is to say, the claimants’ names constituted information obtained by the public authority from another person.

In the remitted proceedings the tribunal took as its starting point the following passage from the judgment of Mr Justice Megarry (as he then was) in Coco v A N Clark (Engineers) Ltd [1968] FSR 415:

"In my judgment, three elements are normally required if, apart from contract, a case of breach of confidence is to succeed. First, the information itself, in the words of Lord Greene, M.R. in the Saltman case on page 215, must “have the necessary quality of confidence about it”. Secondly, that information must have been imparted in circumstances importing an obligation of confidence. Thirdly, there must be an unauthorised use of that information to the detriment of the party communicating it. I must briefly examine each of these requirements in turn."

The tribunal was satisfied that the information in question was passed to the local authority in the course of negotiations for compensation. The object of those negotiations was to achieve an out of court settlement.  At para [33] of its decision it said:

"There are good reasons of public policy why such negotiations are conducted with an expectation of confidentiality, not least of which is to encourage parties to settle disputes without the need to go to court. These negotiations were, we accept, carried out on a without prejudice basis. That, in turn, prevents the parties from revealing later what was discussed. The corollary of that is to impose a duty of confidentiality as, otherwise, the basis of without prejudice communications would be undermined. We find that is so irrespective of the fact that there was no express agreement to keep matters confidential; that was not necessary given the nature of the negotiations."

The resident had submitted that the information was not confidential because the identities of the claimants were well known.  They may have been witnesses in previous litigation.  Their names, photographs and videos had been circulated over the internet. That was true but what that evidence did not do was "identify with any certainty any entity, real or corporate, as having been in receipt of compensation or, importantly, the amount paid to each."  Accordingly, the confidential nature of the information had been retained and the obligation of confidence had not been waived.  The tribunal was satisfied that the information had "the necessary quality of confidence about it" and had been "transmitted in circumstances importing an obligation of confidence."

Turning to the question of detriment, the tribunal said at [42]:

"We consider that there is a detriment in the disclosure of withheld material in that the material was supplied on the basis that it was to be kept confidential. The parties clearly proceeded on that basis. The fact that they had done so, and had suffered loss, is something that they wished not to be known."

The tribunal reminded itself that its role was to consider only if it was more likely than not that a court would find a breach of confidence. Given the particular circumstances in which the information had been imparted and the relationship of trust that that would have been created, the disclosure of the information to the resident would have met the detriment requirement.

The tribunal acknowledged that there are circumstances in which the public interest outeights the obligation of confidence.  In this case, there was a significant weight to be attached to the public interest in keeping confidential negotiations undertaken on a without prejudice basis. All the parties who had entered into those negotiations did so on the assumption that they would be kept confidential. It was an assumption they were rightly entitled to hold.  The tribunal accepted that the public was entitled to know how its money was spent and to whom, but the amount of the settlement and the reason for entering it was already in the public domain.  There was no need to disclose more.  The tribunal concluded at [51] that the withheld material was exempted information by operation of s.41.

Anyone wishing to discuss this article may call me on 020 7404 5252 or send me a message through my contact form.

Sunday, 14 October 2018

Privacy Sandbox

Author Hyena
Reproduced with kind permission of the author
Source Wikipedia





















Jane Lambert

The Information Commissioner's Office has just carried out a consultation on creating a regulatory sandbox "to develop innovative products and services using personal data in innovative ways" (see ICO call for views on creating a regulatory sandbox on the ICO website).  The idea of a sandbox was pioneered by the Financial Conduct Authority which described it as  "a ‘safe space’ in which businesses can test innovative products, services, business models and delivery mechanisms without immediately incurring all the normal regulatory consequences of engaging in the activity in question" (see FCA Regulatory Sandbox Nov 2015). 

The FCA's idea of a sandbox for new products, services and business models proved not only feasible but popular and has been imitated by other financial services regulators around the world.  The Information Commissioner announced her intention of extending the idea to data protection in her Information Rights Strategic Plan 2017 - 2021:
"Technology goal #8: To engage with organisations in a safe and controlled environment to understand and explore innovative technology. 
  • We will establish a ‘regulatory sandbox’, drawing on the successful sandbox process that the Financial Conduct Authority has developed. The ICO sandbox will enable organisations to develop innovative digital products and services, whilst engaging with the regulator, ensuring that appropriate protections and safeguards are in place. As part of the sandbox process the ICO would provide advice on mitigating risks and data protection by design. 
  • In 2018 we will consult and engage with organisations about implementation of a sandbox."
The consultation closed on Friday but the Call for Evidence makes clear that that was only the first stage of the consultation process. There will be a more detailed proposal for consultation later in the year.

In his blog post Your views will help us build our regulatory sandbox, Chris Taylor, Head of Assurance at the ICO, set out the topics upon which he wants to hear from the public:
  • "what you think the scope of any such sandbox should be - should we focus on particular innovations, sectors or types of organisations?
  • what you think the benefits might be to working in a sandbox, whether that’s our expert input or increased reassurance for your customers or clients.
  • what mechanisms you might find most helpful in a sandbox – from adaptations to our approach, to informal steers or the provision of technical guidance – what are the tools that a sandbox might contain?
  • at what stage in the design and development process a sandbox would be most useful to you?"
Mr Taylor also made a point that applies to innovation generally and not just to data protection law.  It is often said in the USA and in some quarters in this country that red tape (which is a derogatory term for regulation) hobbles innovation and enterprise.   If that were so the USA would be the most innovative nation on earth but a glance of the Global Innovation Index  shows that it lies behind four European nations including the UK. 

The author explains that 
"privacy and innovation go hand in hand. It’s not privacy or innovation, it’s privacy and innovation – because organisations that use our sandbox won’t be exempt from data protection law."
A regulatory sandbox enables regulators to anticipate and make provision for difficulties before they arise thus rescuing sparing new technologies and businesses from the legal quagmires that dogged earlier technologies.  In those days the law reacted to new technologies often imperfectly. 

The proposed sandbox should mitigate the privacy uncertainties affecting new products, services and business models but they won't remove all. There will remain other issues such as patenting or other IP protection, licensing, competition and so firth.  I am well placed and should be glad to help fintech and other entrepreneurs or the patent and trade mark attorneys, solicitors, accountants and other professional advisers who may assist them.  Should any of them wish to discuss this article or data protection generally, they are welcome to call me on +44 (0)20 7404 5252 during office houses or send me a message through my contact form.   

Tuesday, 27 March 2018

Information Commissioner's Charges after GDPR

Bank of England
Author Adrian Pingstone
Licence Copyright waived by owner
Source Wikipedia























Jane Lambert

The General Data Protection Regulation ("GDPR") imposes a number of new obligations on data controllers but it does not require them to pay any money unlike the Data Protection Act 1984 and the Data Protection Act 1998.  A small but very welcome concession in exchange for responsibilities that will increase the costs of compliance one might have thought.

Fat chance! Our own Parliament has passed the Digital Economy Act 2017 section 108 (1) of which enables the Secretary of State to make regulations that "require data controllers to pay charges of an amount specified in the regulations to the Information Commissioner." The government has now published draft regulations under that provision known as The Data Protection (Charges and Information) Regulations 2018 which will come into effect on 25 May 2018. The Explanatory Note  states that they will replace The Data Protection (Notification and Notification Fees) Regulations 2000 SI 2000 No 188.

According to the Information Commissioner;s press release, this legislation has been enacted because the government has a statutory duty to ensure that the Information Commissioner's Office is adequately funded (see New model announced for funding the data protection work of the Information Commissioner’s Office 21 Feb 2018 ICO's News and Blogs). They have a point there.  I for one was heartened by photos of ICO investigators doing their job in relation to recent personal data misuse allegations (see Investigators complete seven-hour Cambridge Analytica HQ search 24 March 2018 The Guardian).

The amount of the new charges is set out in reg 3 (1):
"For the purposes of regulation 2 (2), the charge payable by a data controller in—
(a) tier 1 (micro organisations), is £40;
(b) tier 2 (small and medium organisations), is £60
(c) tier 3 (large organisations), is £2,900."
To qualify as a "micro organisation" a business must:
(i)  have a turnover of less than or equal to £632,000 for the data controller’s financial year,
(ii) no more that 10 members of staff;
(iii) be a charity, or
(iv) be a small occupational pension scheme.
As micro organizations will be offered a £5 discount if they pay by direct debit, the new rules will not increase their payments at all if they take advantage of the concession.   For businesses in tier 3 there will be a massive increase from £500 to £2,900 per year.   The new rates are intended to reflect the relative risk for each category of data controller.

Anyone wishing to discuss these rules or data protection in general should call me on 020 7404 5252 during office hours or send me a message through my contact form.

Sunday, 14 January 2018

Information Commissioner fines The Carphone Warehouse £400,000 for breaching the Seventh Data Protection Principle










Jane Lambert

In GDPR - Fines 7 Dec 2017 I outlined the Information Commissioner's existing powers under s.55A of the Data Protection Act 1998 and The Data Protection (Monetary Penalties) (Maximum Penalty and Notices) Regulations 2010 to impose monetary penalties on data controllers who contravene s.4 (4) of the Act. As I noted in that article, the maximum penalty that the Commissioner can impose is limited to £500,000 by reg 2 of those Regulations.

By a monetary penalty notice dated 8 Jan 2018 the Information Commissioner fined the Carphone Warehouse £400,000 (80% of the maximum under reg 2) for failing to prevent unauthorized access to the personal data of over 3 million of its customers and some 1,000 of its employees. 

Paragraph 7 of Sched. 1 of the Act provides:
"Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data."
Paragraphs 9 to 12 of the schedule add:
"The seventh principle
9. Having regard to the state of technological development and the cost of implementing any measures, the measures must ensure a level of security appropriate to—
(a)   the harm that might result from such unauthorised or unlawful processing or accidental loss, destruction or damage as are mentioned in the seventh principle, and
(b)   the nature of the data to be protected.
10. The data controller must take reasonable steps to ensure the reliability of any employees of his who have access to the personal data.
11. Where processing of personal data is carried out by a data processor on behalf of a data controller, the data controller must in order to comply with the seventh principle—
(a)   choose a data processor providing sufficient guarantees in respect of the technical and organisational security measures governing the processing to be carried out, and
(b)   take reasonable steps to ensure compliance with those measures.
12. Where processing of personal data is carried out by a data processor on behalf of a data controller, the data controller is not to be regarded as complying with the seventh principle unless—
(a) the processing is carried out under a contract—
(i)      which is made or evidenced in writing, and
(ii)     under which the data processor is to act only on instructions from the data controller, and
(b) the contract requires the data processor to comply with obligations equivalent to those imposed on a data controller by the seventh principle."
Based on evidence that had been submitted by the Carphone Warehouse which included reports by forensic specialists, the Commissioner found at paragraph 22 that the data controller had contravened the above data protection principle in 11 respects ranging from the use of out of date software to inadequate vulnerability scanning.  Having regard to the state of technological development, the cost of implementing any measures, the nature of the relevant personal data and the harm that might ensue from its misuse, the Commissioner's held was that there were multiple inadequacies in Carphone Warehouse's technical and organisational measures for ensuring the security of personal data on the System.

The Commissioner concluded that the requirements of s.55A (1) had been met. After considering both aggravating and mitigating factors she fixed the penalty at £400,000 to be paid by the 8 Feb 2018.  She offered the data controller a 20% discount if it pays the fine in full by 7 Feb 2018 and does not appeal. If it exercises its right of appeal it will forego the £80,000 discount. That leaves a very difficult decision for The Carphone Warehouse and its lawyers. If the company accepts the Commissioner's finding it risks claims for compensation in the civil courts by any one or more of its 3 million customers and 1,000 employees. On the other hand it will not be easy to appeal and the costs could well exceed £320,000.

Should anyone wish to discuss this note or data protection generally, he or she should call me on 020 7404 5252 during normal business hours or send me a message through my contact form.

Friday, 5 January 2018

Claims by Data Subjects against Data Controllers and Processors under the GDPR

Royal Courts of Justice
Author Rafa Esteve
Licence Creative Commons Attribution Share Alike 4.0 International
Source Wikipedia


















Jane Lambert

In my article How the GDPR works 3 Dec 2017 I wrote that the General Data Protection Regulation ("GDPR") establishes a set of principles for processing personal data (data by which living human beings can be identified) and machinery for monitoring and enforcing compliance.  I added that "that machinery takes the form of rights for data subjects (the individuals who can be identified from the data) and obligations upon data controllers (those who control the processing of personal data) and processors (those who carry out the processing) to take reasonable steps to minimize the risk or effect of non-compliance."

Previous legislation required EU member states to establish supervisory authorities to regulate the processing of personal data in their respective territories and the supervisory authority for the United Kingdom is the Information Commissioner in Wilmslow near Manchester.  If a data subject believes that his or her rights under the GDPR have been infringed, he or she will be able to complain to the Information Commissioner or the supervisory authority of some other member state or sue the data controller or processor in the courts of the United Kingdom or some other member state.

This article considers the circumstances in which a data subject might wish to bring an action against a data controller or processor in the courts of England and Wales and how he or she might do so.

What is the GDPR?

In my Introduction to the GDPR 2 Dec 2017 I wrote that "the initials GDPR stand for the words “General Data Protection Regulation” which is "the short title for a law officially known as Regulation (EU) 2016/679 of the European Parliament and Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC." I added:
"The GDPR is thus a law to protect the interests of living individuals throughout the EU with regard to the processing of data by which they may be identified while safeguarding the free flow of information throughout the EU. It will come into being with equal effect in every member state without further intervention of the governments of those states."
It will come into force on 25 May 2018 and remain for as long as the United Kingdom remains in the European Union. However, many of its provisions will be preserved in a new Data Protection Bill which is now proceeding through Parliament (see my article Introduction to the Data Protection Bill  16 Sept 2017).

Right of Action

Art 79 (1) of the GDPR provides:
"Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation."
Such a right of action is not new.  EU member states are already required to provide a judicial remedy for any breach of the rights guaranteed by the national law applicable to the processing in question under art 22 of the Data Protection Directive (Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data). In the United Kingdom, the judicial remedy mentioned in art 22 is implemented by s.15 (1) of the Data Protection Act 1998.

In what Circumstances could a Data Subject sue?

A data subject might wish to go to law to seek compensation under art 82 (1) of the GDPR for any material or non-material damage that he or she may have suffered as a result of an infringement of the regulation or for an order for the rectification or erasure of data, the restriction of data processing or any other relief that can only be granted by a court.

In which Court?

Art 79 (2) of the CDPR allow proceedings for compensation or other remedy to be brought in any member state in which the controller or processor.  Alternatively, they may be brought before the courts of the member state where the data subject has his or her habitual residence unless the controller or processor is a public authority of a member state acting in the exercise of its public powers. In that case the authority must be sued in the member state where it is located.  Clause 92 (13) of the Data Protection Bill provides that the jurisdiction to compel subject access requests may be exercised by the High Court in England and Wales, the High of Northern Ireland or the Court of Session in Scotland. Similarly, those courts have jurisdiction to hear objections to process under clause 97 (7) and to make orders for the rectification or erasure of personal data under clause 98 (6).  There is no equivalent provision for compliance orders under clause 158 or compensation under clause 159. By contrast, s.15 (1) of the Data Protection Act 1998 provides that claims under the Act may be brought before the High Court or the County Court in England and Wales or the Court of Session or a sheriff's court in Scotland.

How to bring Proceedings under the GDPR

It would appear that a claimant must prove:
  • the existence of a right under the GDPR;
  • an actual or threatened infringement of that right; and
  • damage resulting from the infringement.
The right may be express such as those that arise under Chapter III of the regulation or implied such as the right to object to the transfer of personal data abroad without the safeguards provided by Chapter V. The damage may be material or non-material and it must have resulted or be likely to result from an infringement of the data subject's right. A controller or processor has a complete defence under art 82 (3) of the GDPR if he or she can prove that he or she is not in any way responsible for the event giving rise to the damage.

Liability of Processors

One of the changes brought about by the GDPR is that processors can be sued for damage caused by non-compliance with the regulation or acts outside or contrary to the lawful instructions of the controller. This change is probably more apparent than real because processors that have failed to comply with relevant data protection legislation can usually be joined as Part 20 defendants either for breach of express or implied terms of their service level agreements or a common law duty of care.

Procedure

In the absence of a pre-action protocol for data protection complaints, data subjects, controllers and processors will be expected to comply with paragraph 6 of the Practice Direction - Pre-action Conduct and Protocols. Wherever possible, disputes should be settled through direct negotiations, arbitration, mediation or some other form of alternative dispute resolution. Those that cannot be resolved through negotiation or ADR may be brought in either the Queen's Bench Division or the Chancery Division. Claims for compensation are more likely to be brought in the Queen's Bench Division whereas those for compliance orders are more likely in the Chancery Division

Alternative Dispute Resolution

Parties seeking the appointment of a neutral to resolve a dispute under the GDPR or other data protection legislation may wish to consider one of the arbitrators or mediators of 4-5 Gray's Inn Square as James Bridgeman SC, the Hon Louis Harms, Caroline Kenny QC, Anthony Connerty, several other members of chambers and I have relevant knowledge and experience.

Further Information

Anyone wishing to discuss this article, the GDPR or data protection in general is invited to call me on +44 (0)20 7404 5252 during office hours or send me a message through my contact form.

Sunday, 3 December 2017

How the GDPR works

Author Mauro Cateb
Licence Creative Commons Attribution-Share Alike 3.0 unported

















Jane Lambert

In my introduction to the GDPR 2 Dec 2017 I wrote that the regulation sought to balance two conflicting imperatives, namely the need to protect the public from the harm that can result from malicious, negligent or even careless processing of data that identifies living individuals and the need to safeguard free flows of such data for legitimate purposes.  As I also wrote in that article, there is nothing new about any of that. That policy is exactly the same as that of the Data Protection Directive, the Data Protection Act 1998, the Data Protection Act 1984, the Council of Europe Convention and the OECD Guidelines.

The GDPR also seeks to achieve that objective in much the same way as previous legislation.  It establishes a set of principles for processing personal data (data by which living human beings can be identified) and machinery for monitoring and enforcing compliance.  That machinery takes the form of rights for data subjects (the individuals who can be identified from the data) and obligations upon data controllers (those who control the processing of personal data) and processors (those who carry out the processing) to take reasonable steps to minimize the risk or effect of non-compliance.

The GDPR's data processing principles require personal data to be:
(a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);
(b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89 (1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);
(c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);
(d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);
(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89 (1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);
(f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’)."
It is the data controller's duty to be responsible for and demonstrate compliance with those principles.

So long as data controllers and processors process personal data in accordance with those principles they are unlikely to go far wrong. However, if they stray from them, whether intentionally or not, they risk legal action in the civil courts or fines or other sanctions by the Information Commissioner or the equivalent supervisory authority of another EU member state.

As an obvious way round the legislation would be to export the data to a country that does not regulate the processing of personal data either at all or to the same extent and in the same way, the regulation restricts transfers of data abroad unless Commission is satisfied with the legal protection of personal data processing that is available in the recipient country or enforceable contractual arrangements are in place for the protection of such data. The GDPR makes clear that the regulation applies not just to data controllers and processors that are in the EU, but also to data controllers outside the EU which offer goods or services to data subjects in the EU or monitor the behaviour of such data subjects within the EU.

In the next few articles I shall drill down into each of those topics in more detail.  Should anyone wish to discuss this article, the GDPR or data protection generally, he or she should call me on +44 (0)20 7404 5252 during office hours or send me a message through my contact form.

Further Reading


Date
Author and Title
Publication
2 Dec 2017
NIPC Data Protection
1 Dec 2017
NIPC Data Protection
11 Aug 2017
NIPC Data Protection