HomeSecurityBrexit: GDPR is expected to become more complex than ever

Brexit: GDPR is expected to become more complicated than ever

Brexit day is approaching, but there is no certainty as to whether or not the UK’s departure from the EU will be accompanied by a so-called “withdrawal agreement” – or not. Data protection is a major area that will be affected by Brexit. And under a no-deal scenario, the impact of the UK’s departure from the EU becomes even more dramatic. There are a number of questions that customers are asking about the applicable data protection regime (GDPR) for the day after Brexit, and the specific answers depend on the size of businesses, the location of stores and offices, the volume of international data transfers and where their customers are based.

Brexit GDPR

Continue reading if you want to learn more about the three most frequently asked questions about Brexit.

  1. If the UK leaves the EU without a deal, can UK businesses stop worrying about GDPR? Technically, when the UK leaves the EU, the EU General Data Protection Regulation (GDPR) will no longer be law in the UK. However, the UK government has already planned to adopt the “UK GDPR”. As the name suggests, this set of rules will be closely aligned with the EU GDPR and will accompany the existing UK Data Protection Act 2018. The combination of these two bills could potentially have a stricter impact on the overall data protection regime than in the UK today. In addition, UK-based businesses with customers in the EU will need to comply with the EU GDPR. There are also areas where there may not be clear rules, but UK businesses will need to make adjustments, which will result in additional compliance measures. These are, for example, measures on international data transfers, liability, new regulatory oversight requirements, the establishment of an EU representative, etc. In short, the GDPR will cease to apply in the UK, but what is being considered is a regulatory environment that is set to become much more complex for UK businesses.
  2. If the UK leaves the European Union, the UK becomes a “third party” for data protection. What does this mean? Yes, on the day the UK leaves the EU, the UK becomes a third party for data protection and a number of restrictions will apply to international data transfers involving the flow of personal data to and from the UK. This issue is, in fact, one of the most affected by Brexit. Businesses need to consider a range of possible scenarios depending on the direction and details of their data flows. For example, transfers of personal data from the UK to EU countries will be largely unaffected. For data transfers from the UK to non-EU countries, businesses in the UK need to consider the rules contained in both the forthcoming UK GDPR and the decisions to be adopted soon. One of the most complex issues, however, is the transfer of personal data from the EU to the UK that is indirect – for example, those involving a third party such as a cloud. Generally, on Brexit day, businesses must stop such transfers unless certain safeguards or exemptions are in place. For example, the transfer may be based on the European Commission’s standard contractual clauses or be subject to an exemption where the transfer is necessary for the performance of a contract. Binding corporate rules are also an option. However, businesses may also decide that storing or processing EU personal data in the UK is not a viable strategy, particularly in the absence of an EU decision recognizing the UK as “adequate” for data protection. These businesses may decide to invest in setting up EU-based data centres or work with providers that offer this as an option. They could also consider technical measures to secure these transfers: Anonymizing data before it is sent to the UK could be one way to do this.
  3. What should businesses do today? The best thing to do today is to ensure that businesses comply with existing data protection rules – specifically the GDPR and the UK Data Protection Act 2018. While the regulatory environment will undoubtedly be more complex, it will remain largely consistent with the current one. However, our data shows that only half of UK organisations are GDPR compliant. Businesses should therefore accelerate the execution of their compliance strategies. In light of Brexit, businesses need to understand the international flows of personal data. Key transfers to track will be from the EU to the UK. They should prioritise the remediation of transfers involving large volumes of data, transfers of special category data or criminal convictions and evidence of criminal offences, and critical business transfers. Investing in appropriate measures to ensure the lawfulness of these transfers is essential. They should also consider existing privacy policies, data protection impact assessments, data subject rights and measures to demonstrate accountability as areas that will require further adjustments
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS