SlideShare a Scribd company logo
1 of 10
Professor David Erdos
Faculty of Law
University of Cambridge
Overview
1. Formal Framework
2. ICO, Tribunal & Parliamentary Actions
3. DPDI Bill Proposals
4. Possible Ways Forward
Timeline
 May 2018: General DP Regulation 2016/679 and DP Act 2018 applies;
Privacy & Elec Comms Regs (PECR) supervision system unchanged.
 Jan 2021: End of Brexit Implementation Period. EU GDPR One-Stop-
Shop ceases to apply to UK. UK GDPR.
 Jan 2022: DP & Digital Information Bill published.
Overview
GDPR/PECR Demarcation:
 GDPR: Most (private sector) processing of personal data
 PECR: Rules on (i) electronic direct marketing and (ii)
confidentiality of e-communications including re cookies
Key Commonalities:
 Requests for ICO Action
 Information Notices
 Enforcement Notices
 Fines for Breach
Key UK GDPR additions:
 Requests are Complaints
 Assessment Notices etc.
 Enforcement Obligatory
 Fines are Significant
 Some criminal offences
GDPR Fines: ≤£17.5M/4% & ≤£8.7M/2% (A. 83)
Personal
Data
Processing
DP Principles
• Fair, lawful,
transparent
• Purpose quality &
limits
• Information
quality & limits
• Integrity &
confidentiality
Legitimation
• Legitimating
Criteria
Sensitive Data
• Criminal data
• Other data
Transparency &
Control
• Proactive Direct
• Proactive Indirect
• Retroactive
• Control Rights
Discipline
• Demo compliance
• Security
• DP by design &
default
• Joint controllers
• Personal data
breaches
• Processor
engagement
• Recording keeping
• DP Officer
• Impact Assess
• Export Control
 ICO must impose “effective, proportionate & dissuasive” fines
ICO’s Main GDPR Responsibilities
 Enforcement = (In General) Fines/Formal Enforcement:
 Core ICO Duty = Enforcement (including after Complaint)
“the supervisory authorities’ primary responsibility is to monitor the
application of the GDPR and ensure its enforcement … must handle … a
complaint … with all due diligence … following an investigation … it is
required … to take appropriate action in order to remedy any findings of
inadequacy” (Court of Justice Grand Chamber in Schrems II (2020))
“penalties including administrative fines should be imposed for any
infringement of this Regulation, in addition to, or instead of appropriate
measures … In a case of a minor infringement or if the fine likely to be
imposed would constitute a disproportionate burden to a natural person, a
reprimand may be issued instead of a fine.” (GDPR recital 148)
 Annual Report Numbers:
 Cross-Cutting Analysis:
 ‘Complaints’ Average: GDPR/DP 37,279; PECR 109,254
 2019/20 Report stated c. 75% budget on “proactive engagement”
 Asserted great impact to soft approach e.g. California 2020 visit:
ICO: 5 Year Analysis (2018-23)
Year DP Fines (at £ 2022) DP Notices PECR Fines (at £ 2022) Income (at £ 2022)
18/19 22 (£3.5M) 0 23 £46M
19/20 15 2 7 (£2.6M) £56.1M
20/21 3 (£44.4M) 1 35 £59.8M
21/22 4 (£0.2M) 0 33 (£3.2M) £67.4M
22/23 2 or 3 (£7.6M or £13.4M) 1 19 (£1.88M) £67.4M
“The reception was universally warm and welcoming and helped us build strong
relationships with key stakeholders. The UK’s brand of pragmatic and proportionate
regulation was widely praised by businesses and lawmakers, as was our willingness to
find new regulatory solutions to problems.”
DP Scrutiny Record: Tribunal & Parliament
 Individual Scrutiny by Tribunal:
 Order to Progress Complaints remedy ruled non-substantive:
 Holistic Scrutiny by Parliamentary Committees:
 No systematic scrutiny of ICO track-record at all.
“The Commissioner is the expert regulator. She is in the best position to
consider the merits of a complaint and to reach a conclusion as to its
outcome. In so far as the Commissioner’s judgments would not and cannot be
matched by expertise in the Tribunal, it is readily comprehensible that
Parliament has not provided a remedy in the Tribunal in relation to the merits
of complaints.” (Upper Tribunal in Killock, Veale et. al. 2021)
“[I]n practice [the DCMS] committee has been focused on newsworthy
campaigns that accord with the particular interests of members, rather than
more prosaic scrutiny of the ICO’s performance against its statutory
functions and own stated objectives.” (Heuston & Tumbridge, 2020)
DPDI Bill: Decentering DP Supervision?
Structural Changes
 ICO to be reestablished as a Board.
 ICO’s PECR powers to be brought into line with GDPR.
Objectives and Priorities
 New public trust, innovation, competition, crime, security duties.
 SoS to set out Strategic Priorities; ICO must have regard to these.
Complaints and Scrutiny
 Complaints: No need to act where “vexatious” or where controller not had
45 days to act; must be guidance & right of appeal before Tribunal.
 (Wider) Scrutiny: Must publish forward-looking strategy,
Key Performance Indicators and annual regulatory action report.
DP Enforcement: New Ideas
 Improving Individual Scrutiny:
 Require Tribunal to oversee appropriateness of ICO’s substantive
response at least as regards “public interest” complaints.
 Enable NGOs to bring such complaints without specific mandate.
 Improving Holistic Scrutiny:
 Require EHRC to periodically scrutinize ICO from rights viewpoint.
 Report to be published & sent to scrutinizing Select Committee, as
well as Parliament generally and also Government.

More Related Content

Similar to Regulatory Enforcement of UK Data Protection

Virtual school of ig economic issues_2021
Virtual school of ig  economic issues_2021Virtual school of ig  economic issues_2021
Virtual school of ig economic issues_2021Desiree Miloshevic
 
S26: Techsauce | A New World of FinTech Regulation: What the Future Holds (23...
S26: Techsauce | A New World of FinTech Regulation: What the Future Holds (23...S26: Techsauce | A New World of FinTech Regulation: What the Future Holds (23...
S26: Techsauce | A New World of FinTech Regulation: What the Future Holds (23...Kullarat Phongsathaporn
 
Bloomberg Tax - Transfer Pricing Forum - The Netherlands
Bloomberg Tax - Transfer Pricing Forum - The NetherlandsBloomberg Tax - Transfer Pricing Forum - The Netherlands
Bloomberg Tax - Transfer Pricing Forum - The NetherlandsNavita Parwanda
 
Big data - FATCA to CRS
Big data - FATCA to CRSBig data - FATCA to CRS
Big data - FATCA to CRSAli Kazimi
 
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...Feroot
 
ITS 833 – INFORMATION GOVERNANCE[email pr.docx
ITS 833 – INFORMATION  GOVERNANCE[email pr.docxITS 833 – INFORMATION  GOVERNANCE[email pr.docx
ITS 833 – INFORMATION GOVERNANCE[email pr.docxvrickens
 
Proposal For Equalization Levy On Specified Transactions
Proposal For Equalization Levy On Specified TransactionsProposal For Equalization Levy On Specified Transactions
Proposal For Equalization Levy On Specified TransactionsKunal Gandhi
 
The real cost of KYC & AML compliance for the financial sector - Ondato
The real cost of KYC & AML compliance for the financial sector - OndatoThe real cost of KYC & AML compliance for the financial sector - Ondato
The real cost of KYC & AML compliance for the financial sector - OndatoOndato
 
The real cost of KYC & AML compliance for the financial sector - Ondato.pdf
The real cost of KYC & AML compliance for the financial sector - Ondato.pdfThe real cost of KYC & AML compliance for the financial sector - Ondato.pdf
The real cost of KYC & AML compliance for the financial sector - Ondato.pdfNehmeh Taouk elMeaaz
 
#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP...
#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP...#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP...
#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP...Emma Mirrington
 
UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?David Erdos
 
The Transfer pricing agreements in the Cooperative Compliance Environment
The Transfer pricing agreements in the Cooperative Compliance EnvironmentThe Transfer pricing agreements in the Cooperative Compliance Environment
The Transfer pricing agreements in the Cooperative Compliance EnvironmentUniversity of Ferrara
 
Newsletter on daily professional updates- 28/03/2020
Newsletter on daily professional updates- 28/03/2020Newsletter on daily professional updates- 28/03/2020
Newsletter on daily professional updates- 28/03/2020CA PRADEEP GOYAL
 
Dla piper data breach report 2020
Dla piper data breach report 2020Dla piper data breach report 2020
Dla piper data breach report 2020Paperjam_redaction
 
Data Privacy & The Golden Age of Security
Data Privacy & The Golden Age of Security Data Privacy & The Golden Age of Security
Data Privacy & The Golden Age of Security IDC Italy
 
Marsden CELPU 2021 platform law co-regulation
Marsden CELPU 2021 platform law co-regulationMarsden CELPU 2021 platform law co-regulation
Marsden CELPU 2021 platform law co-regulationChris Marsden
 
03 regulatory landscape&regtech
03 regulatory landscape&regtech03 regulatory landscape&regtech
03 regulatory landscape&regtechinnov-acts-ltd
 

Similar to Regulatory Enforcement of UK Data Protection (20)

Virtual school of ig economic issues_2021
Virtual school of ig  economic issues_2021Virtual school of ig  economic issues_2021
Virtual school of ig economic issues_2021
 
S26: Techsauce | A New World of FinTech Regulation: What the Future Holds (23...
S26: Techsauce | A New World of FinTech Regulation: What the Future Holds (23...S26: Techsauce | A New World of FinTech Regulation: What the Future Holds (23...
S26: Techsauce | A New World of FinTech Regulation: What the Future Holds (23...
 
Bloomberg Tax - Transfer Pricing Forum - The Netherlands
Bloomberg Tax - Transfer Pricing Forum - The NetherlandsBloomberg Tax - Transfer Pricing Forum - The Netherlands
Bloomberg Tax - Transfer Pricing Forum - The Netherlands
 
Big data - FATCA to CRS
Big data - FATCA to CRSBig data - FATCA to CRS
Big data - FATCA to CRS
 
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
 
ITS 833 – INFORMATION GOVERNANCE[email pr.docx
ITS 833 – INFORMATION  GOVERNANCE[email pr.docxITS 833 – INFORMATION  GOVERNANCE[email pr.docx
ITS 833 – INFORMATION GOVERNANCE[email pr.docx
 
Proposal For Equalization Levy On Specified Transactions
Proposal For Equalization Levy On Specified TransactionsProposal For Equalization Levy On Specified Transactions
Proposal For Equalization Levy On Specified Transactions
 
The real cost of KYC & AML compliance for the financial sector - Ondato
The real cost of KYC & AML compliance for the financial sector - OndatoThe real cost of KYC & AML compliance for the financial sector - Ondato
The real cost of KYC & AML compliance for the financial sector - Ondato
 
The real cost of KYC & AML compliance for the financial sector - Ondato.pdf
The real cost of KYC & AML compliance for the financial sector - Ondato.pdfThe real cost of KYC & AML compliance for the financial sector - Ondato.pdf
The real cost of KYC & AML compliance for the financial sector - Ondato.pdf
 
#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP...
#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP...#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP...
#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP...
 
UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?
 
Amla
AmlaAmla
Amla
 
The Transfer pricing agreements in the Cooperative Compliance Environment
The Transfer pricing agreements in the Cooperative Compliance EnvironmentThe Transfer pricing agreements in the Cooperative Compliance Environment
The Transfer pricing agreements in the Cooperative Compliance Environment
 
Newsletter on daily professional updates- 28/03/2020
Newsletter on daily professional updates- 28/03/2020Newsletter on daily professional updates- 28/03/2020
Newsletter on daily professional updates- 28/03/2020
 
Big data: Bringing competition policy to the digital era – Background note – ...
Big data: Bringing competition policy to the digital era – Background note – ...Big data: Bringing competition policy to the digital era – Background note – ...
Big data: Bringing competition policy to the digital era – Background note – ...
 
Dla piper data breach report 2020
Dla piper data breach report 2020Dla piper data breach report 2020
Dla piper data breach report 2020
 
Data Privacy & The Golden Age of Security
Data Privacy & The Golden Age of Security Data Privacy & The Golden Age of Security
Data Privacy & The Golden Age of Security
 
IDC on 10 myths regarding GDPR
IDC on 10 myths regarding GDPRIDC on 10 myths regarding GDPR
IDC on 10 myths regarding GDPR
 
Marsden CELPU 2021 platform law co-regulation
Marsden CELPU 2021 platform law co-regulationMarsden CELPU 2021 platform law co-regulation
Marsden CELPU 2021 platform law co-regulation
 
03 regulatory landscape&regtech
03 regulatory landscape&regtech03 regulatory landscape&regtech
03 regulatory landscape&regtech
 

More from David Erdos

Generative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPRGenerative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPRDavid Erdos
 
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An  EU and UK GDPR PerspectiveGoogle Spain and its Aftermath 2014-2023: An  EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR PerspectiveDavid Erdos
 
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49David Erdos
 
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?David Erdos
 
The GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and BeyondThe GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and BeyondDavid Erdos
 
Data Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing LandscapeData Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing LandscapeDavid Erdos
 
Constitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EUConstitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EUDavid Erdos
 
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?David Erdos
 
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection LawDead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection LawDavid Erdos
 
Disclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google SpainDisclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google SpainDavid Erdos
 
Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...David Erdos
 
Data Protection and "Intermediary" Responsibility: An Historical Perspective
Data Protection and "Intermediary" Responsibility:  An Historical PerspectiveData Protection and "Intermediary" Responsibility:  An Historical Perspective
Data Protection and "Intermediary" Responsibility: An Historical PerspectiveDavid Erdos
 
European Data Protection and Social Networking
European Data Protection and Social NetworkingEuropean Data Protection and Social Networking
European Data Protection and Social NetworkingDavid Erdos
 
UK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeUK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeDavid Erdos
 
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media:  Walking the Regulatory TightropeGDPR, DPAs and the Journalistic Media:  Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media: Walking the Regulatory TightropeDavid Erdos
 
Data Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in ConflictData Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in ConflictDavid Erdos
 
European Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search EnginesEuropean Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search EnginesDavid Erdos
 
Data Protection and Academic Research: The New GDPR Framework
Data Protection and Academic Research:  The New GDPR FrameworkData Protection and Academic Research:  The New GDPR Framework
Data Protection and Academic Research: The New GDPR FrameworkDavid Erdos
 
Reconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionReconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionDavid Erdos
 
Regulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data ProtectionRegulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data ProtectionDavid Erdos
 

More from David Erdos (20)

Generative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPRGenerative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPR
 
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An  EU and UK GDPR PerspectiveGoogle Spain and its Aftermath 2014-2023: An  EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR Perspective
 
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
 
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
 
The GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and BeyondThe GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and Beyond
 
Data Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing LandscapeData Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing Landscape
 
Constitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EUConstitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EU
 
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
 
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection LawDead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
 
Disclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google SpainDisclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google Spain
 
Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...
 
Data Protection and "Intermediary" Responsibility: An Historical Perspective
Data Protection and "Intermediary" Responsibility:  An Historical PerspectiveData Protection and "Intermediary" Responsibility:  An Historical Perspective
Data Protection and "Intermediary" Responsibility: An Historical Perspective
 
European Data Protection and Social Networking
European Data Protection and Social NetworkingEuropean Data Protection and Social Networking
European Data Protection and Social Networking
 
UK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeUK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & Change
 
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media:  Walking the Regulatory TightropeGDPR, DPAs and the Journalistic Media:  Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
 
Data Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in ConflictData Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in Conflict
 
European Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search EnginesEuropean Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search Engines
 
Data Protection and Academic Research: The New GDPR Framework
Data Protection and Academic Research:  The New GDPR FrameworkData Protection and Academic Research:  The New GDPR Framework
Data Protection and Academic Research: The New GDPR Framework
 
Reconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionReconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data Protection
 
Regulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data ProtectionRegulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data Protection
 

Recently uploaded

如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书Fs Las
 
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书SD DS
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书Fir L
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesritwikv20
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Dr. Oliver Massmann
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书Fs Las
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书Sir Lt
 
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书SD DS
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaNafiaNazim
 
POLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptxPOLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptxAbhishekchatterjee248859
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》o8wvnojp
 
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书SD DS
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书Fir L
 
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书SD DS
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书Fir L
 
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书SD DS
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionNilamPadekar1
 
如何办理美国波士顿大学(BU)毕业证学位证书
如何办理美国波士顿大学(BU)毕业证学位证书如何办理美国波士顿大学(BU)毕业证学位证书
如何办理美国波士顿大学(BU)毕业证学位证书Fir L
 

Recently uploaded (20)

如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
 
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use cases
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in India
 
POLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptxPOLICE ACT, 1861 the details about police system.pptx
POLICE ACT, 1861 the details about police system.pptx
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
 
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
 
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in  Pusa Road🔝 9953330565 🔝 escort Serviceyoung Call Girls in  Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
 
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
 
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
如何办理新加坡南洋理工大学毕业证(本硕)NTU学位证书
 
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书
 
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 sedition
 
如何办理美国波士顿大学(BU)毕业证学位证书
如何办理美国波士顿大学(BU)毕业证学位证书如何办理美国波士顿大学(BU)毕业证学位证书
如何办理美国波士顿大学(BU)毕业证学位证书
 

Regulatory Enforcement of UK Data Protection

  • 1. Professor David Erdos Faculty of Law University of Cambridge
  • 2. Overview 1. Formal Framework 2. ICO, Tribunal & Parliamentary Actions 3. DPDI Bill Proposals 4. Possible Ways Forward
  • 3. Timeline  May 2018: General DP Regulation 2016/679 and DP Act 2018 applies; Privacy & Elec Comms Regs (PECR) supervision system unchanged.  Jan 2021: End of Brexit Implementation Period. EU GDPR One-Stop- Shop ceases to apply to UK. UK GDPR.  Jan 2022: DP & Digital Information Bill published.
  • 4. Overview GDPR/PECR Demarcation:  GDPR: Most (private sector) processing of personal data  PECR: Rules on (i) electronic direct marketing and (ii) confidentiality of e-communications including re cookies Key Commonalities:  Requests for ICO Action  Information Notices  Enforcement Notices  Fines for Breach Key UK GDPR additions:  Requests are Complaints  Assessment Notices etc.  Enforcement Obligatory  Fines are Significant  Some criminal offences
  • 5. GDPR Fines: ≤£17.5M/4% & ≤£8.7M/2% (A. 83) Personal Data Processing DP Principles • Fair, lawful, transparent • Purpose quality & limits • Information quality & limits • Integrity & confidentiality Legitimation • Legitimating Criteria Sensitive Data • Criminal data • Other data Transparency & Control • Proactive Direct • Proactive Indirect • Retroactive • Control Rights Discipline • Demo compliance • Security • DP by design & default • Joint controllers • Personal data breaches • Processor engagement • Recording keeping • DP Officer • Impact Assess • Export Control  ICO must impose “effective, proportionate & dissuasive” fines
  • 6. ICO’s Main GDPR Responsibilities  Enforcement = (In General) Fines/Formal Enforcement:  Core ICO Duty = Enforcement (including after Complaint) “the supervisory authorities’ primary responsibility is to monitor the application of the GDPR and ensure its enforcement … must handle … a complaint … with all due diligence … following an investigation … it is required … to take appropriate action in order to remedy any findings of inadequacy” (Court of Justice Grand Chamber in Schrems II (2020)) “penalties including administrative fines should be imposed for any infringement of this Regulation, in addition to, or instead of appropriate measures … In a case of a minor infringement or if the fine likely to be imposed would constitute a disproportionate burden to a natural person, a reprimand may be issued instead of a fine.” (GDPR recital 148)
  • 7.  Annual Report Numbers:  Cross-Cutting Analysis:  ‘Complaints’ Average: GDPR/DP 37,279; PECR 109,254  2019/20 Report stated c. 75% budget on “proactive engagement”  Asserted great impact to soft approach e.g. California 2020 visit: ICO: 5 Year Analysis (2018-23) Year DP Fines (at £ 2022) DP Notices PECR Fines (at £ 2022) Income (at £ 2022) 18/19 22 (£3.5M) 0 23 £46M 19/20 15 2 7 (£2.6M) £56.1M 20/21 3 (£44.4M) 1 35 £59.8M 21/22 4 (£0.2M) 0 33 (£3.2M) £67.4M 22/23 2 or 3 (£7.6M or £13.4M) 1 19 (£1.88M) £67.4M “The reception was universally warm and welcoming and helped us build strong relationships with key stakeholders. The UK’s brand of pragmatic and proportionate regulation was widely praised by businesses and lawmakers, as was our willingness to find new regulatory solutions to problems.”
  • 8. DP Scrutiny Record: Tribunal & Parliament  Individual Scrutiny by Tribunal:  Order to Progress Complaints remedy ruled non-substantive:  Holistic Scrutiny by Parliamentary Committees:  No systematic scrutiny of ICO track-record at all. “The Commissioner is the expert regulator. She is in the best position to consider the merits of a complaint and to reach a conclusion as to its outcome. In so far as the Commissioner’s judgments would not and cannot be matched by expertise in the Tribunal, it is readily comprehensible that Parliament has not provided a remedy in the Tribunal in relation to the merits of complaints.” (Upper Tribunal in Killock, Veale et. al. 2021) “[I]n practice [the DCMS] committee has been focused on newsworthy campaigns that accord with the particular interests of members, rather than more prosaic scrutiny of the ICO’s performance against its statutory functions and own stated objectives.” (Heuston & Tumbridge, 2020)
  • 9. DPDI Bill: Decentering DP Supervision? Structural Changes  ICO to be reestablished as a Board.  ICO’s PECR powers to be brought into line with GDPR. Objectives and Priorities  New public trust, innovation, competition, crime, security duties.  SoS to set out Strategic Priorities; ICO must have regard to these. Complaints and Scrutiny  Complaints: No need to act where “vexatious” or where controller not had 45 days to act; must be guidance & right of appeal before Tribunal.  (Wider) Scrutiny: Must publish forward-looking strategy, Key Performance Indicators and annual regulatory action report.
  • 10. DP Enforcement: New Ideas  Improving Individual Scrutiny:  Require Tribunal to oversee appropriateness of ICO’s substantive response at least as regards “public interest” complaints.  Enable NGOs to bring such complaints without specific mandate.  Improving Holistic Scrutiny:  Require EHRC to periodically scrutinize ICO from rights viewpoint.  Report to be published & sent to scrutinizing Select Committee, as well as Parliament generally and also Government.