← LEADERSHIP TERMINAL

UK PARLIAMENT · SITTING

Sir John Whittingdale

MP for Maldon · Conservative · United Kingdom

IN THEIR OWN WORDS

I strongly welcome the Secretary of State’s confirmation of our continuing support for Ukraine. He has set out the sustained threat from Russia facing not just Ukraine, but this country and the whole of Europe, yet for too many people, it is still business as usual.

UKRAINE AND RUSSIA · 2026-09-10 · READ IN HANSARD

That is perhaps even more relevant to the second prong of the Government’s proposals, which is about social media. I will come to that point, but before I finish talking about local media, I want to mention that another of the Government’s flagship policies is devolution.

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

The hon. Member is completely right that this issue must be addressed before we proceed. There is also the question of cost, raised by my right hon. Friend the Member for Wetherby and Easingwold (Sir Alec Shelbrooke). There are people who probably do have access to broadband, if they choose to pay for it, but they cannot afford to do so.

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

I was the Minister responsible for the passage of the Media Act 2024, during the previous Parliament. It is a great delight to see some familiar faces with whom I have worked with in the past on the officials’ Bench.

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

Member for Hazel Grove (Lisa Smart) that young people are turning more and more to social media, but I do not think that this policy is the answer, because it looks to me like a very dangerous extension of Government interference in the freedom of the press and the right to free speech.

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

My right hon. Friend asks a perfectly valid question, and I want to acknowledge that there are concerns. We had a debate in Westminster Hall not that long ago, and a number of my colleagues—particularly from Scotland—turned up to express concern about the fact that the quality of reception via broadband in their constituencies is very poo…

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

The complete record

Every one of 4,278 lines we hold for Sir John Whittingdale, in date order, each linked to its source. Free to read, in full, without an account. Page 27 of 86.

  1. Let me address the point of the hon. Member for Glasgow North West first. The intention of the clause is to ensure that complainants go first to the data controller, and the data controller makes available a process whereby complaints can be considered. I certainly fully understand the concern of the hon. Lady that it should not prove burdensome, particularly for small firms, and I do not believe that it would necessarily require an electronic means to do so. If that is not the case, I will tell her, but it seems to me that the sensible approach would be for data controllers to have a process that the Information Commissioner will accept is available to complainants first, before a complaint is possibly escalated to the next stage. With regard to the point of the hon.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FIFTH SITTING) · 2023-05-18 · READ IN HANSARD

  2. Clause 43 is a technical measure that creates a presumption that our data protection laws should not be overridden by future laws that relate to the processing of personal data, but it respects parliamentary sovereignty by ensuring that Parliament can depart from this presumption in particular cases if it deems it appropriate to do so. For example, if new legislation permitted or required an organisation to share personal data with another for a particular purpose, the default position in the absence of any specific indication to the contrary would be that the data protection legislation would apply to the new arrangement.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FIFTH SITTING) · 2023-05-18 · READ IN HANSARD

  3. General rules of interpretation can be open to different interpretations by courts, particularly in the light of legal challenges following our exit from the European Union. This can create the potential for legal uncertainty and as a result could lead to a less effective and comprehensive data protection legislative framework. Clause 43 creates a presumption that any future legislation permitting the processing of personal data will be subject to the key requirements of the UK’s data protection legislation unless clear provisions are made to the contrary. This is a technical but necessary measure and I commend it to the Committee.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FIFTH SITTING) · 2023-05-18 · READ IN HANSARD

  4. That would certainly be my interpretation. I do not see that a trade agreement could possibly overturn an Act of Parliament unless Parliament specifically sets out that it intends that that should be the case. This is a general protection, essentially saying that in all future cases data protection legislation applies unless Parliament specifically indicates that that should not be the case. Until now, ensuring that any new data protection measures are read consistently with the data protection legislation has relied either on inclusion of express provision to that effect in new data processing measures, or on general rules of interpretation. There are risks to that situation. Including relevant provisions in each and every new data processing provision is onerous and could be inadvertently omitted.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FIFTH SITTING) · 2023-05-18 · READ IN HANSARD

  5. The clause outlines the process and procedure for making regulations under powers in the UK GDPR. Such provision is needed because the Bill introduces regulation-making powers into the GDPR. There is an equivalent provision in section 182 of the Data Protection Act. Among other things, the clause makes it clear that, before making regulations, the Secretary of State must consult the Information Commissioner and such other persons as they consider appropriate, other than when the made affirmative procedure applies. In such cases, the regulations can be made before Parliament has considered them, but cannot remain as law unless approved by Parliament within a 120-day period.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FIFTH SITTING) · 2023-05-18 · READ IN HANSARD

  6. The Secretary of State must consult the Information Commissioner and other appropriate persons when preparing the trust framework; that consultation requirement can be satisfied ahead of the clause coming into force. The Secretary of State must review the trust framework every 12 months and must consult the Information Commissioner and other appropriate persons when carrying out the review. I commend both clauses to the Committee.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FIFTH SITTING) · 2023-05-18 · READ IN HANSARD

  7. I am sure that the Committee will be pleased to learn that we have now completed part 1 of the Bill. [Hon. Members: “Hear, hear!”] Clause 46 provides an overview of the provisions in part 2 that are aimed at securing the reliability of digital verification services through a trust framework, a public register, an information gateway and a trust mark. Clause 47 will require the Secretary of State to prepare and publish the digital verification services trust framework, a set of rules, principles, policies, procedures and standards that an organisation that wishes to become a certified and registered digital verification service provider must follow.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FIFTH SITTING) · 2023-05-18 · READ IN HANSARD

  8. Member for Newcastle upon Tyne Central have both set out detailed questions about the operation of the new office and the work alongside other Government Departments. I would like to respond to their points but, given that we are about to break, we could accept the general principle of this clause and then discuss them, no doubt in greater detail, in the debate on subsequent clauses. Will the Committee accept this clause with the assurance that we will address a lot of the issues just raised as we come to subsequent clauses in this part of the Bill? Question put and agreed to. Clause 46 accordingly ordered to stand part of the Bill. Ordered, That further consideration be now adjourned . —(Steve Double.)

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FIFTH SITTING) · 2023-05-18 · READ IN HANSARD

  9. I am grateful to the hon. Member for Barnsley East for setting out the Opposition’s general support for the principle of moving towards the facilitation of digital verification services. She set out some of the benefits that such services can provide, and I completely echo her points on that score. I reiterate the central point that none of this is mandatory: people can choose to use digital verification services, but there is no intention to make them compulsory. The trust framework has been set out with a wide number of principles and standards, to which privacy is central. The hon. Member for Barnsley East is right that that will be necessary to obtain trust from people seeking to use the services. She and the hon.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FIFTH SITTING) · 2023-05-18 · READ IN HANSARD

  10. Clauses 48 to 52 provide the Secretary of State with powers and duties relating to the governance and oversight of digital identities in the UK. Those functions will be carried out by the office for digital identities and attributes. I can tell the hon. Member for Newcastle upon Tyne Central that the office is a team of civil servants in the Department for Science, Innovation and Technology. The office will oversee certified organisations that provide trusted digital verification services, to ensure that the purpose of the legislation is being upheld as the market develops.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  11. As the office is an internal body, within the Department, I do not think that it would necessarily be specifically identified in the legislation in that way. If there is any more information on that, I will be happy to provide it to the hon. Lady in a letter, but the office is not a separate body to the Department.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  12. Clause 52 provides a power to the Secretary of State to remove a provider from the register if the Secretary of State is satisfied that the provider is failing to provide services in accordance with the trust framework, or if it has failed to provide the Secretary of State with information as required by a notice issued under clause 58. Clause 52 also contains safeguards in respect of the use of that power. Clause 53 applies where the Secretary of State revises and republishes the DVS trust framework to include a new rule or to change an existing rule and specifies in the trust framework that a top-up certificate will be required to show compliance with the new rule from a specified date. I hope that what I have set out is reasonably clear, and on that basis I ask that clauses 48 to 53 stand part of the Bill.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  13. The amount and timing of those fees are to be determined by the Secretary of State. Clauses 51 and 52 confer powers and duties on the Secretary of State in relation to the removal of persons from the register. Clause 51 places a duty on the Secretary of State to remove a provider from the register if certain conditions are met. That will keep the register up to date and ensure that only providers that hold a certificate to prove that they adhere to the standards set in the framework are included in the register.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  14. Clause 48(7) provides definitions for “accredited conformity assessment body”, “the Accreditation Regulation”, “conformity assessment body” and “the UK national accreditation body”. Clause 49 makes provision for the Secretary of State to determine the form of an application for registration in the digital verification services register, the information that an application needs to contain, the documents to be provided with an application and the manner in which an application is to be submitted. Clause 50 allows the Secretary of State to charge providers a fee on application to be registered in the DVS register. The fee amount is to be determined by the Secretary of State. The clause also allows the Secretary of State to charge already registered providers ongoing fees.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  15. Assessment is by independent audits, and successful DVS providers are issued with a certificate. The Secretary of State is prohibited from registering a provider if it has not complied with the registration requirements. An application must be rejected if it is based on a certificate that has expired, has been withdrawn by the issuing body, or is required to be ignored under clause 53 because the trust framework rules have been amended and the provider has not obtained a top-up certificate in time. The Secretary of State must also refuse to register a DVS provider if the provider was removed from the register through enforcement powers under clause 52 and reapplies for registration while still within the specified removal period.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  16. The Secretary of State is required to add a digital verification service provider to the register, provided that it has met certain requirements. To gain a place on the register, the provider must first be certified against the trust framework by an accredited conformity assessment body. Secondly, the provider must have applied to be registered in line with the Secretary of State’s application requirements under clause 49. Thirdly, the provider must pay any fee set by the Secretary of State under the power in clause 50. The United Kingdom Accreditation Service accredits conformity assessment bodies as competent to assess whether a digital verification service meets the requirements set out in the trust framework. That, of course, is an arm’s length body.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  17. This is a function that will operate within Government. I do not think that it is one where there is any specific need for particular independence, but as I said, I am happy to supply further details about precisely how it will operate if that is helpful to the hon. Lady. Let me move on from the precise operation of the body. Clause 53 sets out requirements for certified digital verification service providers in relation to obtaining top-up certificates where the Secretary of State revises and republishes the DVS trust framework. Clause 48 provides that the Secretary of State must establish and maintain a register of digital verification service providers. The register must be made publicly available.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  18. Further down the line, as the market develops, it may be decided that it should be housed permanently in an independent body or as an arm’s length body, but that is for consideration in due course. It will start off within the Department. I will come back to the hon. Member for Newcastle upon Tyne Central with more detail about dispute resolution. I take her point; I am not sure how often what she describes is likely to happen, but clearly it is sensible at least to take account of it.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  19. I look forward to debating the detail of the framework with the hon. Member for Barnsley East when it comes forward, but the hon. Member for Newcastle upon Tyne Central raised a couple of specific points. As I said, the new office for digital identities and attributes will be in the Department for Science, Innovation and Technology, and it will work on a similar basis to that of the office for product safety and standards, which operates within the Department for Business and Trade. However, I should make it clear that the office for digital identities and attributes is not a regulator, because the use of digital identities is not mandatory, so it does not have investigatory or enforcement powers. It is not our intention for it to be able to levy fines or resolve individual complaints.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  20. Under these provisions, registered DVS providers may not further disclose information provided by Revenue Scotland or the Welsh Revenue Authority unless they have the consent of that revenue authority to do so. The addition of these provisions will provide an equivalent level of protection for information shared by all three tax authorities in the context of part 2 of the Bill, avoiding any disparity in the treatment of information held by different tax authorities in this context. A similar provision is not required for Northern Irish tax data, as HMRC is responsible for the collection of devolved taxes in Northern Ireland.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  21. Public authorities must have regard to the code when disclosing information under this power. Publication of the first version of the code is subject to the affirmative resolution procedure. Publication of subsequent versions of the code is subject to the negative resolution procedure. We will work with the commissioners for HMRC to ensure that the code meets the needs of the tax system. New clauses 3 and 4 and Government amendments 6 and 7 establish safeguards for information that reflect those already in the Bill under clause 55 for HMRC. Information held by tax authorities in Scotland and Wales—Revenue Scotland and the Welsh Revenue Authority—is subject to similar statutory safeguards relating to confidentiality. These safeguards ensure that confidence and trust in the tax system is maintained.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  22. All information held by His Majesty’s Revenue and Customs is subject to particular statutory safeguards relating to confidentiality. Clause 55 establishes particular safeguards for information disclosed to registered digital verification service providers by His Majesty’s Revenue and Customs under clause 54. The Government will not commence measures to enable the disclosure of information held by HMRC until the commissioners for HMRC are satisfied that the technology and processes for information sharing uphold the particular safeguards relating to taxpayer confidentiality and therefore allow information sharing by HMRC to occur without adverse effect on the tax system or any other functions of HMRC. Clause 56 obliges the Secretary of State to produce and publish a code of practice about the disclosure of information under clause 54.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  23. Clause 54 creates a permissive power to enable public authorities to share information relating to an individual with registered digital verification service providers. That the power is permissive means that public authorities are not under any obligation to disclose information. The power applies only where a digital verification service provider is registered in the DVS register and the individual has requested the digital verification service from that provider. Information disclosed using the power does not breach any duty of confidentiality or other restrictions relating to the disclosure of information, but the power does not enable the disclosure of information if disclosure would breach data protection legislation. The clause also gives public authorities the power to charge fees for disclosing information.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  24. Clause 57 makes provision for the Secretary of State to designate a trust mark to a DVS provider. The trust mark is essentially a kitemark that shows that the provider complies with the rules and standards set out in the trust framework, and has been certified by an approved conformity assessment body. The trust mark must be published by the Secretary of State and can only be used by registered digital verification service providers. The clause gives the Secretary of State powers to enforce that restriction in civil proceedings.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  25. Amendment 7, in clause 58, page 84, line 5, after “55” insert “or (Information disclosed by Revenue Scotland)”— (Sir John Whittingdale.) This amendment prevents the Secretary of State requesting a disclosure of information which would contravene the new clause inserted by NC4. Question proposed, That the clause, as amended, stand part of the Bill.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  26. I am grateful to the hon. Lady for her support. I entirely take her point that a trust mark only really works if people know what it is and can look for it when seeking a DVS provider. Regarding potential abuse, obviously that is something we will monitor and potentially publicise in due course. All I would say at this stage is that she raises valid points that I am sure we will consider as the new system is implemented. Question put and agreed to. Clause 57 accordingly ordered to stand part of the Bill. Clause 58 Power of Secretary of State to require information Amendments made: amendment 6, in clause 58, page 84, line 5, after “55” insert “or (Information disclosed by the Welsh Revenue Authority)” This amendment prevents the Secretary of State requesting a disclosure of information which would contravene the new clause inserted by NC3.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  27. Information does not have to be disclosed if to do so would breach clause 55 in relation to HMRC data or data protection legislation, or if disclosure is prohibited by the relevant parts of the Investigatory Powers Act 2016. Information does not need to be disclosed if doing so would reveal an offence that would expose a person to criminal proceedings. That does not apply to offences mentioned relating to false statements. Clause 59 gives the Secretary of State the power to make regulations specifying that another person is able to exercise her functions under part 2. This clause enables us to move the governance and oversight functions of the Secretary of State to a third party if appropriate.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  28. Clauses 58 to 60 set out powers and duties conferred upon the Secretary of State in relation to the exercise of her governance and oversight functions under part 2. Clause 58 enables the Secretary of State to issue a written notice that requires accredited conformity assessment bodies or registered DVS providers to provide information reasonably required by the Secretary of State to exercise functions under part 2. The notice must state why the information is required. It may also state what information is required, the form in which it should be provided, when it should be provided and the place to which it should be provided. Any notice given to a provider must also inform the provider that they may be removed from the DVS register if they fail to comply with the notice. The power is subject to certain safeguards.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  29. We are obviously at a very early stage in the development of this market. At the moment, it is felt right that oversight should rest with the Secretary of State, but it may be that as the market grows and develops there will need to be the oversight via a separate body. The clause keeps the power available to the Secretary of State to delegate the function if he or she chooses to do so. Clause 60 requires the Secretary of State to publish an annual report on the functioning of this part. The first report must be published within 12 months of clause 47, the DVS trust framework clause, coming into force. The reports will help to ensure that the market continues to meet the needs of DVS providers, public authorities, regulators, civil society and individuals. I commend the clauses to the Committee.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  30. I beg to move amendment 46, in clause 61, page 85, line 24, after “supplied” insert “or provided”. The definition of “business data” in clause 61 refers to the supply or provision of goods, services and digital content. For consistency with that, this amendment amends an example given in the definition so that it refers to what is provided, as well as what is supplied.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  31. Government amendment 46 clarifies that a specific example of business data—information about location—refers to the supply or provision of goods or services. It corrects a minor inconsistency in the list of examples of business data in subsection (2)(b). Subsection (3) concerns who is a customer of the supplying trader, and who can therefore benefit from smart data. Customers may include both consumers and businesses. Subsection (4) enables customers to exercise smart data rights in relation to contracts they have already entered into, and subsection (5) allows the schemes to function through provision of access to data, as opposed to sending data as a one-off transfer.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  32. The definitions of data holder and trader in subsection (2) explain who may be required to provide data under the regulations. The definitions of customer data and business data deal with the two kinds of data that suppliers may be required to provide. Customer data is information relating to the transactions between the customer and supplier, such as a customer’s consumption of the relevant good or service and how much the customer has paid. Business data is wider contextual data relating to the goods or services supplied or provided by the relevant supplier. Business data may include standard prices, charges or tariffs and information relating to service performance. That information may allow customers to understand their customer data.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  33. Smart data schemes establish the secure sharing of customer data and contextual information with authorised third parties on the customer’s request. The third parties can then be authorised by the customer to act on their behalf. The authorised third parties can therefore provide innovative services for the customer, such as analysing spending to identify cost savings or displaying data from multiple accounts in a single portal. The clauses replace existing regulation-making powers relating to the supply of customer data in sections 89 to 91 of the Enterprise and Regulatory Reform Act 2013; those powers are not sufficient for new smart data schemes to be effective. Clause 61 defines the key terms and concepts for the powers in part 3. We have tabled a minor Government amendment to the clause, which I will explain.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  34. The rest of the clauses in this part permit the Secretary of State or the Treasury to include in the regulations the measures that will underpin these data sharing schemes and ensure that they are subject to proper safeguards—for example, relating to the enforcement of regulations; the accreditation of third party businesses wanting to facilitate data sharing; and how these schemes can be funded through levies and charging. Regulations that introduce schemes, or significantly amend existing schemes, will be subject to prior consultation and parliamentary approval through the affirmative procedure. The policy intention behind the clauses is to allow for the creation of new smart data schemes, building on the success of open banking in the UK.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  35. We move on to part 3 of the Bill, concerning smart data usage, which I know is of interest to a number of Members. Before I discuss the detail of clause 61 and amendment 46, I will give a brief overview of this part and the policy intention behind it. The provisions in part 3 allow the Secretary of State or the Treasury to make regulations that introduce what we term “schemes” that compel businesses to share data that they hold on customers with the customer or authorised third parties upon the customer’s request, and to share or publish data that they hold about the services or products that they provide. Regulations under this part will specify what data is in scope within the parameters set out by the clauses, and how it should be shared.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  36. I share my hon. Friend’s general view. Customers can authorise that their data be shared through devices with other providers, so they should equally have the right to take back that data if they so wish. He invites me to come back to him with greater detail on that point, and we would be very happy to do so. Amendment 46 agreed to. Clause 61, as amended, ordered to stand part of the Bill. Clause 62 Power to make provision in connection with customer data

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  37. We are committed to that, and there is a risk that a statutory deadline for making the regulations would jeopardise our due diligence. I assure her that all her concerns are ones that we share, so I hope that she will accept that the amendments are unnecessary.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  38. Lady’s attention to the commitments made last month by the Economic Secretary to the Treasury, who set out the Treasury’s plans to use the smart data powers to provide open banking with a sustainable regulatory framework, while the Under-Secretary of State for Business and Trade, my hon. Friend the Member for Thirsk and Malton (Kevin Hollinrake), chaired the inaugural meeting of the Smart Data Council last month. That council has been established to support and co-ordinate the development of smart data schemes in a timely manner. With respect to having a deadline for schemes, we should recognise that implementation of the regulations requires careful consideration. The hon. Member for Barnsley East clearly recognises the importance of consultation and of properly considering the impacts of any new scheme.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  39. On amendment 114, we absolutely share the view of the importance of Government consulting businesses before making regulations. That is why, under clause 74(6), the Secretary of State or the Treasury must, when introducing a smart data scheme, consult such persons as are likely to be affected by the regulations and such sectoral regulators as they consider appropriate. Those persons will include businesses relevant to the envisaged scheme. On amendment 115, we absolutely share the ambition to grab whatever opportunities smart data offers. In particular, I draw the hon.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  40. Moreover, the clauses require the Government to consider the effect of the regulations on matters including customers, businesses and competition. An impact assessment would be an effective approach to meeting those requirements. However, there is a risk that prescribing exactly how a Department should approach the requirements could unnecessarily constrain the policymaking process. I turn to amendment 113. Clause 74(5) already requires the Secretary of State or the Treasury to consult with relevant sector regulators as they consider appropriate. As part of the process, sector regulators may be asked to contribute to the development of regulatory impact assessments, so we do not believe the amendment is necessary.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  41. I assure the hon. Lady that I and, no doubt, the whole Committee share her excitement about the potential offered by smart data, and I have sympathy for the intention behind her amendments. However, taking each one in turn, we feel amendment 112 is unnecessary because the requirements are already set by the better regulation framework, the Small Business, Enterprise and Employment Act 2015 and, indeed, these clauses. Departments will conduct an impact assessment in line with the better regulation framework and Green Book guidance when setting up a new smart data scheme, and must demonstrate consideration of their requirements under the Equality Act 2010. That will address the proportionality, targeting and necessity of the scheme.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  42. Subsection (3) could allow the authorised third party to update the customer’s contact details across the associated accounts, for example if an email address changes. Clause 63 outlines the provisions that smart data scheme regulations may contain when relating to customer data. The clause establishes much of the critical framework that smart data schemes will be built on. On that basis, I commend clauses 62 and 63 to the Committee.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  43. Clause 62 provides the principal regulation-making power to establish smart data schemes in relation to customer data. The clause enables the Secretary of State or the Treasury to make regulations that require data holders to provide customer data either directly to a customer, or to a person they have authorised, at their request. Subsection (3) of the clause also allows for an authorised person who receives the customer data, to exercise the customer’s rights in relation to their data on their behalf. We call that “action initiation”. An illustrative example could be in open banking, where customers can give authorised third parties access to their data to compare the consumer’s current bank account with similar offers, or to group the contracts within a household together for parents or guardians to better manage children’s accounts.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  44. Clause 65 outlines provisions that regulations relating to business data may contain. Those provisions are non-exhaustive. The clause largely mirrors clause 63, extending the same protections and benefits to schemes that make use of businesses data exclusively or in tandem with customer data. The clause differs from clause 63 in subsection (2), where an additional consideration is made as to who may make a request for business data. As action initiation relates only to an authorised person exercising a customer’s rights relating to their data, clause 65 does not include the references to that that are made in subsections (7) and (8) of clause 63.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  45. Clause 64 provides the principal regulation-making power for the creation of smart data schemes relating to business data. Regulations created through this clause allow for business data to be provided to the customer of a trader or a third-party recipient. Business data may also be published to be more widely available. These regulations relating to business data will increase the transparency around the pricing of goods and services, which will increase competition and benefit both consumers and smaller businesses. To give just one example, the Competition and Markets Authority recently highlighted the potential of an open data scheme that compared the prices of fuel at roadside stations, increasing competition and better informing consumers. It is that kind of market intervention that the powers provide for.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  46. I think it is probably sensible if I come back to the hon. Lady on that point. I am sure we would be happy to provide examples if there are ones that we can identify. Question put and agreed to. Clause 64 accordingly ordered to stand part of the Bill. Clause 65 ordered to stand part of the Bill. Clause 66 Decision-makers

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  47. Subsection (2) provides that the assistance may be given on terms and conditions that are deemed appropriate by the regulation maker. Financial assistance is defined to include both actual or contingent assistance, such as a grant, loan, guarantee or indemnity. It does not include the purchase of shares. I commend clauses 66 to 72 to the Committee.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  48. Clause 71 will enable the regulations to impose a levy on data holders or allow a specified public body to do so. That is to allow arrangements similar to those in section 38 of the Communications Act 2003, which enables the fixing of charges by Ofcom. Together with the provision on fees, the purpose of the levy is to meet all or part of the costs incurred by enforcers and accrediting bodies, or persons acting on their behalf. The intention is to ensure that expenses can be met without incurring a cost to the taxpayer. Levies may be imposed only in respect of data holders that appear to be capable of being directly affected by the exercise of the functions. Clause 72 provides statutory authority for the Secretary of State or the Treasury to give financial assistance, including to accrediting bodies or enforcers.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  49. The purpose of the clause, along with clause 71, is to seek to ensure that the costs of smart data schemes, and of bodies exercising functions under them, can be met by the relevant sector. It is intended that fees may be charged by accrediting bodies and enforcers. For example, regulations could specify that an accrediting body may charge third parties to cover the cost of an accreditation process and ongoing monitoring. Enforcers may also be able to charge to cover or contribute to the cost of any relevant enforcement activities. The regulations may provide for payment of fees only by persons who are directly affected by the performance of duties, or exercise of powers, under the regulations. That includes data holders, customers and those accessing customer and business data.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD

  50. Clause 69 contains provisions relating to financial penalties and the relevant safeguards. It sets out what regulations must provide for if enabling the use of financial penalties. Subsection (2) requires that the amount of a financial penalty is specified in, or determined in accordance with, the regulations. For example, the regulations may set a maximum financial penalty that an enforcer can impose and they may specify the methodology to be used to determine a specific financial penalty. Clause 70 enables actors in smart data schemes to require the payment of fees. The circumstances and conditions of the fee charging process will be specified in the regulations.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (SIXTH SITTING) · 2023-05-18 · READ IN HANSARD