GDPR has had numerous complaints which have alleged that major companies such as Google, WhatsApp and Facebook have forced people to give up their private data without obtaining proper consent.
The Data Protection Act 2018 (DPA) establishes a legal framework of rights that provides the safeguard of individuals personal data, whilst businesses can use said data for other purposes. Following the UK’s departure from the EU, UK GDPR no longer applies directly to UK law but is still retained through the Withdrawal Act 2018. Currently, the DPA sits alongside UK GDPR to represent primary data protection in the UK.
The European Commission (EC) made an adequacy decision in favour of the UK. This means that EU and the UK have essentially an equivalent level of data protection which means that personal data can flow freely between the UK and EU countries without additional safeguards.
However, the UK government have published its proposals for a new data protection plan within the UK. One of the key talking points in relation to this new bill is the cookies consent notification – the pop up that appears on when you attempt to access any website. If you accept cookies, then small bits of text can be used to track certain things about you including:
- What you do on the site
- Your location
- What device you are using
The Data Reform Bill is an attempt by the government to move away from Europe’s GDPR legislation. GDPR heavily supports the principle of protecting the privacy and data of individuals alongside steep penalties for non-compliance, however cookies are not covered.
The Data Reform Bill proposes:
- The requirement for small and medium sized businesses to employ data-protection officers and conduct for data-gathering activities is removed. This will reduce unnecessary strain on businesses as smaller businesses can manage GDPR risks independently, if they can manage the risk themselves.
- Allowing the Information Commissioner’s Office, which currently must investigate every data-protection complaint it receives, to be more flexible and target action in relation to the greatest harms
- The government’s new opt out model for users will heavily reduce the need for users to click through consent banners and other frustrating pop ups.
From the perspective of the U.S., there is no single data protection legislation. Instead, there are hundreds of laws enacted on both federal and state level to protect the personal data of U.S. residents. For example, the federal Computer Fraud and Abuse Act has been used to assert legal claims against the use of cookies for behavioural advertising.
It is important to determine if Bill and the proposed reforms achieve the government’s aims of balancing the protection of the individuals in a way that satisfies the EC and reduce the burden that is placed on businesses with the current data protection regimen. It can be suggested that the UK could lose its adequacy rating by seeking to ease the administrative burdens of compliance placed on businesses. If this occurs, then it will lead to a big expense for businesses if they want to transfer business across borders.
By Abhiraj Aujla, an LLM student at Solent University


