← LEADERSHIP TERMINAL

UK PARLIAMENT · SITTING

Sir John Whittingdale

MP for Maldon · Conservative · United Kingdom

IN THEIR OWN WORDS

I strongly welcome the Secretary of State’s confirmation of our continuing support for Ukraine. He has set out the sustained threat from Russia facing not just Ukraine, but this country and the whole of Europe, yet for too many people, it is still business as usual.

UKRAINE AND RUSSIA · 2026-09-10 · READ IN HANSARD

That is perhaps even more relevant to the second prong of the Government’s proposals, which is about social media. I will come to that point, but before I finish talking about local media, I want to mention that another of the Government’s flagship policies is devolution.

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

The hon. Member is completely right that this issue must be addressed before we proceed. There is also the question of cost, raised by my right hon. Friend the Member for Wetherby and Easingwold (Sir Alec Shelbrooke). There are people who probably do have access to broadband, if they choose to pay for it, but they cannot afford to do so.

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

I was the Minister responsible for the passage of the Media Act 2024, during the previous Parliament. It is a great delight to see some familiar faces with whom I have worked with in the past on the officials’ Bench.

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

Member for Hazel Grove (Lisa Smart) that young people are turning more and more to social media, but I do not think that this policy is the answer, because it looks to me like a very dangerous extension of Government interference in the freedom of the press and the right to free speech.

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

My right hon. Friend asks a perfectly valid question, and I want to acknowledge that there are concerns. We had a debate in Westminster Hall not that long ago, and a number of my colleagues—particularly from Scotland—turned up to express concern about the fact that the quality of reception via broadband in their constituencies is very poo…

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

The complete record

Every one of 4,278 lines we hold for Sir John Whittingdale, in date order, each linked to its source. Free to read, in full, without an account. Page 29 of 86.

  1. As we have already discussed with clause 6, schedule 2 inserts a new annex into the UK GDPR. It sets out certain specific public interest circumstances in which personal data reuse is permitted regardless of the purpose for which the data was originally collected—for example, when the disclosure of personal data is necessary to safeguard vulnerable individuals. Taken together, clause 6 and schedule 2 will give controllers legal certainty on when they can reuse personal data and give individuals greater transparency. Amendment 70 concerns taxation purposes, which are included in the list in schedule 2. I reassure the hon. Member for Barnsley East that the exemption for taxation is not new: it has been moved from schedule 2 to the Data Protection Act 2018. Indeed, the specific language in question goes back as far as 1998.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  2. Let me start by recognising the importance of of subject access requests. I am aware that some have interpreted the change in the wording for grounds of refusal as a weakening. We do not believe that is the case. On amendment 72, in our view the new “vexatious or excessive” language in the Bill gives greater clarity than there has previously been. The Government have set out parameters and examples in the Bill that outline how the term “vexatious” should be interpreted within a personal data protection context, to ensure that controllers understand.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  3. The clause also includes examples of the types of request that may be vexatious, such as those intended to cause distress, those not made in good faith or those that are an abuse of process. We believe that the changes will give organisations much-needed clarity over when they can refuse or charge a reasonable fee for a request. That will ensure that controllers can focus on responding to reasonable requests, as well as other important data and organisational needs. I commend the clause to the Committee.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  4. The existing legislation enables organisations to refuse or charge a reasonable fee for a request when they deem it to be “manifestly unfounded or excessive”. Some organisations, however, struggle to rely on that in cases where it may be appropriate to do so, which as a consequence impacts their ability to respond to reasonable requests. The clause changes the legislation to allow controllers to refuse or charge a reasonable fee for a request that is “vexatious or excessive”. The clause adds parameters for controllers to consider when relying on the “vexatious or excessive” exemption, such as the nature of the request and the relationship between the data subject and the controller.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  5. Following the passage of the Bill, the Government will work with the ICO to update guidance on subject access requests, which we believe plays an important role and is the best way to achieve the intended effect of the amendments. For those reasons, I will not accept this group of amendments; I hope that the hon. Member for Barnsley East will be willing to withdraw them. I turn to clause 7 itself. As I said, the UK’s data protection framework sets out key data subject rights, including the right of access—the right for a person to obtain a copy of their personal data. A subject access request is used when an individual requests their personal data from an organisation. The Government absolutely recognise the importance of the right of access and do not want to restrict that right for reasonable requests.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  6. The current legislation sets out that any request from a data subject, including subject access requests, is to be responded to. The Government are retaining that approach and controllers will be expected to demonstrate why the provision applies each time it is relied on. The current ICO guidance sets out those obligations on controllers and the Government do not plan to suggest a move away from that approach. The clause also states that it is for the controller to show that a request is vexatious or excessive in circumstances where that might be in doubt. Thus, the Government believe that the existing legislation provides the necessary protections.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  7. The Government expect that the new parameters will be considered individually as well as in relation to one another, and a controller should consider which parameters may be relevant when deciding how to respond to a request. For example, when the resource impact of responding would be minimal even if a large amount of information was requested—such as for a large organisation—that should be taken into account. Additionally, the current rights of appeal allow a data subject to contest a refusal and ultimately raise a complaint with the ICO. Those rights will not change with regard to individual rights requests. Amendment 74 proposes adding more detail on the obligations of a controller who refuses or charges for a request from a data subject.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  8. I completely agree with my hon. Friend. That is an issue that both he and I regard as very serious, and is perhaps another example of the kind of legal tactic that SLAPPs—strategic lawsuits against public participation—represent, whereby oligarchs can frustrate genuine journalism or investigation. He is absolutely right to emphasise that. It is important to highlight that controllers can already consider resource when refusing or charging a reasonable fee for a request. The Government do not wish to change that situation. Current ICO guidance sets out that controllers can consider resources as a factor when determining if a request is excessive. The new parameters are not intended to be reasons for refusal.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  9. Clause 8 will rectify the disparity currently existing between processing regimes and put law enforcement and intelligence services organisations on an equal footing to UK GDPR organisations. That will also provide a consistent framework for organisations operating under more than one regime at the same time. The clause also brings clarity on how best to respond to a confusing or complex request, ensuring that organisations do not lose time while seeking this clarification and can instead focus on responding to a request. On that basis, I urge that clause 8 stand part of the Bill.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  10. The clause will also enable organisations to extend the period permitted for law enforcement and the intelligence services to respond to complex requests by two further months in certain circumstances. This replicates the existing provisions applicable to processing requests under the UK GDPR. Currently, all subject access requests received under the law enforcement and intelligence services regimes must be actioned within one month, irrespective of the complexity or number of requests received from an individual. Consequently, complex or confusing requests can disproportionately burden public bodies operating under those regimes, creating resource pressures.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  11. Clause 8 makes changes to the time requirements to which an organisation must adhere when responding to a subject access request. Currently, organisations must respond to a subject access request within a set period; in the majority of cases, that is one month from receipt of the request. This clause enables organisations to “stop the clock” on the response time when an organisation is unable to respond without further information or clarification from an individual. For example, when the controller has information on multiple data subjects with the same name, they may require further information to help to differentiate the data subject’s information from others’. Organisations must have a legitimate reason to pause the response time; once confirmation is received from the data subject, the original time obligations resume.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  12. Lady will be assured that there are safeguards to ensure that this power is not abused. Question put and agreed to. Clause 8 accordingly ordered to stand part of the Bill. Clause 9 Information to be provided to data subjects Question proposed, That the clause stand part of the Bill.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  13. May I briefly respond to the hon. Lady’s comments? I assure her that controllers will not be able to stop the clock for all subject access requests—only for those where they reasonably require further information to be able to proceed with responding. Once that information has been received from a data subject, the clock resumes and the controller must proceed with responding to the request within the applicable time period, which is usually one month from when the controller receives the request information. A data subject who has provided the requested information would also be able to complain to a controller, and ultimately to the Information Commissioner’s Office, if they feel that their request has not been processed within the appropriate time. I hope the hon.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  14. The reason is that we faithfully transposed the EU law enforcement directive, which did not contain such an exemption. Following our exit from the EU, we are taking this opportunity to align better the UK GDPR and the law enforcement regime, thereby simplifying the obligations for organisations and clarifying the rules for individuals.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  15. However, in the absence of an explicit exemption, organisations processing data under the law enforcement regime, for a law enforcement purpose rather than under the UK GDPR, must rely on ad hoc restrictions in the Data Protection Act. Those require them to evaluate and justify its use on a case-by-case basis, even where legal professional privilege is clearly applicable. The new exemption will make it simpler for organisations that process data for a law enforcement purpose to exempt legally privileged information, avoiding the need to justify the use of alternative exemptions. It will also clarify when such information can be withheld from the individual. Hon. Members might wonder why an exemption for legal professional privilege was not included under the law enforcement regime of the Data Protection Act in the first place.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  16. The exemption will help ensure that important research can continue unimpeded. The clause also makes some minor changes to article 14. Those do not amend the scope of the exemption or affect its operation, but make it easier to understand. I now turn to clause 10, which introduces an exemption relating to legally professionally privileged data into the law enforcement regime, mirroring the existing exemptions under the UK GDPR and the intelligence services regime. As a fundamental principle of our legal system, legal professional privilege protects confidential communications between professional legal advisers and their clients. The existing exemption in the UK GDPR restricts an individual’s right to access personal data that is being processed or held by an organisation, and to receive certain information about that processing.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  17. Articles 13 and 14 of the UK GDPR set out the information that must be provided to data subjects at the point of data collection: article 13 covers circumstances where data is directly collected from data subjects, and article 14 covers circumstances where personal data is collected indirectly—for example, via another organisation. The information that controllers must provide to individuals includes details such as the identity and contact details of the controller, the purposes of the processing and the lawful basis for processing the data. Given the long-term nature of research, it is not always possible to meaningfully recontact individuals. Therefore, applying a disproportionate effort exemption addresses the specific problem of researchers wishing to reuse data collected directly from an individual.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  18. Clause 9 provides researchers, archivists and those processing personal data for statistical purposes with a new exemption from providing certain information to individuals when they are reusing datasets for a different purpose, which will help to ensure that important research can continue unimpeded. The new exemption will apply when the data was collected directly from the individual, and can be used only when providing the additional information would involve a disproportionate effort. There is already an exemption from this requirement where the personal data was collected from a different source. The clause also adds a non-exhaustive list of examples of factors that may constitute a disproportionate effort. This list is added to both the new exemption in article 13 and the existing exemption found in article 14.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  19. These clauses relate to one of the fundamental purposes of the Bill, which is to facilitate genuine scientific research—obviously, that carries with it huge potential benefits in the areas of tackling disease or other scientific advances. We debated the definition of scientific research earlier in relation to clause 2. We believe that the definition is clear. In this particular case, the use of historical data can be very valuable. It is simply impractical for some organisations to reobtain consent when they may not even know where original data subjects are now located.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (THIRD SITTING) · 2023-05-16 · READ IN HANSARD

  20. On the basis of what I said earlier, and that assurance, I hope that the Committee will agree to the clause. Question put and agreed to. Clause 9 accordingly ordered to stand part of the Bill. Clause 10 ordered to stand part of the Bill. Clause 11 Automated decision-making

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  21. When the Committee adjourned this morning, I was nearly at my conclusion; I was responding to points made by the hon. Member for Barnsley East and by the hon. Member for Glasgow North West, who has not yet rejoined us. I was saying that the exemption applies where the data originally collected is historic, where to re-contact to obtain consent would require a disproportionate effort, and where that data could be of real value in scientific research. [Official Report, 23 May 2023, Vol. 733, c. 1MC.] We think that there is a benefit to research and we are satisfied that the protection is there. There was some debate about the definition of scientific research, which we covered earlier; that is a point that is appealable to the Information Commissioner’s Office.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  22. That is because even if an individual’s personal data is not used to inform the decision taken about them, the fact that they are identifiable through the personal data that is held makes them data subjects. The term “data subject” is broad and already captures the decision subjects described in the hon. Lady’s amendment, as the identification of a decision subject would make them a data subject. I will not, at this point, go on to set out the Government’s wider approach to the use of artificial intelligence, because that is somewhat outside the scope of the Bill and has already been set out in the White Paper, which is currently under consultation. Nevertheless, it is within that framework that we need to address all these issues.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  23. The intended effect is to extend the requirements associated with provisions related to decisions taken about an individual using personal data to those about whom decisions are taken, even though personal information about them is not held or used to take a decision. It would hence apply to the safeguards available to individuals where significant decisions are taken about them solely through automated means, as amendments 78 to 101 call for, and to the duties of the Information Commissioner to have due regard to decision subjects in addition to data subjects, as part of the obligations imposed under amendment 106. I suggest to the hon. Lady, however, that the existing reference to data subjects already covers decision subjects, which are, if you like, a sub-group of data subjects.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  24. I am very much aware of the concern about automated decision making. The Government share the wish of the hon. Member for Barnsley East for all those who may be affected to be given protection. Where I think we differ is that we do not recognise the distinction that she tries to make between data subjects and decision subjects, which forms the basis of her amendments. The hon. Lady’s amendments would introduce to the UK GDPR a definition of the term “decision subject”, which would refer to an identifiable individual subject to data- based and automated decision making, to be distinguished from the existing term “data subject”.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  25. Essentially, if anybody is affected by automated decision making on the basis of the characteristics of another person whose data is held—in other words, if the same data is used to take a decision that affects them, even if it does not personally apply to them—they are indeed within the broader definition of a data subject. With that reassurance, I hope that the hon. Member for Barnsley East will consider withdrawing her amendment.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  26. The Information Commissioner’s Office will play an important role in elaborating guidance on what that will entail in different circumstances.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  27. The Government absolutely share hon. Members’ view of the importance of transparency. We agree that individuals who are subject to automated decision making should be made aware of it and should have information about the available safeguards. However, we feel that those requirements are already built into the Bill via article 22C, which will ensure that individuals are provided with information as soon as is practicable after such decisions have been taken. This will need to include relevant information that an individual would require to contest such decisions and seek human review of them. The reforms that we propose take an outcome-focused approach to ensure that data subjects receive the right information at the right time.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  28. It is certainly our view that anybody who is affected by an automated decision made on the basis of data held about individuals themselves becomes a data subject, so I think the answer to the honourable Lady’s question is no. As I said, the Information Commissioner’s Office will provide guidance in this area. If such a situation does arise, obviously it will need to be considered.The hon. Members for Barnsley East and for Glasgow North West asked about making information available to all those affected, and about safeguards, which we think are contained within the requirements under article 22C.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  29. They would obviously have that right, and indeed they would ultimately have the right to appeal to the Information Commissioner if they felt that they had been subjected unfairly to a decision where they had not been properly informed of the fact. On the basis of what I have said, I hope the hon. Member for Barnsley East might withdraw her amendment.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  30. What constitutes a significant decision or meaningful human involvement is often highly context-specific, and the current wording allows for some inter-pretability to enable the appropriate application of this provision in different contexts, rather than introducing an absolute definition that risks excluding decisions that ought to fall within this provision and vice versa. For that reason, we are not minded to accept the amendments.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  31. On amendment 75, as we have already debated in relation to previous amendments, there are situations where non-statutory guidance, which can be produced without being requested under regulations made by the Secretary of State, may be more appropriate than a statutory code of practice. We believe that examples of the kinds of processing that do and do not fall within the definitions of the terms “meaningful human involvement” and “similarly significant” are best placed in non-statutory guidance produced by the ICO, as this will give the flexibility to amend and change the examples where necessary.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  32. On amendment 76, we feel that clause 44 already provides for an overarching requirement on the Secretary of State to consult the Information Commissioner and other persons that she or he considers appropriate before making regulations under UK GDPR, including the measures in article 22. When the new clause 44 powers are used in reference to article 22 provisions, they will be subject to the affirmative procedure in Parliament. I know that the hon. Lady is not wholly persuaded of the merits of using the affirmative procedure, but it does mean that parliamentary approval will be required. Given the level of that scrutiny, we do not think it is necessary for the Secretary of State to have to publish an assessment, as the hon. Lady would require through her amendment.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  33. The hon. Lady began her remarks on the broader question of the ambition to ensure that the UK benefits to the maximum extent from the use of artificial intelligence. We absolutely share that ambition, but also agree that it needs to be regulated. That is why we have published the AI regulation White Paper, which suggests that it is most appropriate that each individual regulator should develop its own rules on how that should apply. I think in the case that she was quoting of those who had lost their jobs, maybe through an automated process, the appropriate regulator—in that case, presumably, the special employment tribunal —would need to develop its own mechanism for adjudicating decisions. I will concentrate on the amendment.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  34. These safeguards ensure that individuals are made aware of and can seek human intervention on significant decisions that are taken about them through solely automated means. The reforms to article 22 would make clear employer obligations and employee rights in such scenarios, as we debated in the earlier amendments. On the wider question, we absolutely recognise that the kind of deployment of technology in the workplace shown in the examples that have already been given needs to be considered across a wide range of different regulatory frameworks in terms of not just data protection law, but human rights law, legal frameworks regarding health and safety and, of course, employment law.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  35. I am grateful to the hon. Members for Barnsley East and for Newcastle upon Tyne Central for setting out the thinking behind the amendment. We share the view, as the hon. Member for Newcastle upon Tyne Central has just said, that those who are subject to artificial intelligence and automated decision making need to have trust in the process, and there need to be principles underlying the way in which those decisions are taken. In each case, the contributions go above and beyond the provision in the Bill. On what we are proposing regarding data protection, the changes proposed in clause 11 will reinforce and provide further clarification, as I have said, in respect of the important safeguards for automated decision making, which may be used in some workplace technologies.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  36. As she knows, the White Paper is currently out to consultation, and I hope that she and others will take advantage of that to respond. They will have until 21 June to do so. I assure the hon. Lady and the hon. Member for Barnsley East that the Government are keenly aware of the need to move swiftly, but we want to do so in consultation with all those affected. The Bill looks at one relatively narrow aspect of the use of AI, but certainly the Government’s general approach is one that we are developing at pace, and we will obviously respond once the consultation has been completed.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  37. As I was Chair of the Culture, Media and Sport Committee in 2008 when we published a report calling for legislation on online safety, I recognise the hon. Lady’s point that these things take a long time—indeed, far too long—to come about. She calls for action now on governance and regulation of the use of artificial intelligence. She will know that last month the Government published the AI regulation White Paper, which set out the proposals for a proportionate outcomes-focused approach with a set of principles that she would recognise and welcome. They include fairness, transparency and explainability, and we feel that this has the potential to address the risks of possible bias and discrimination that concern us all.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  38. This exemption is available only where the decision taken by automated means is reconsidered by a human as soon as reasonably practicable. The subsections amending relevant sections of the Data Protection Act 2018, which apply to processing by or on behalf of the intelligence services, clarify that requirements apply to decisions that are entirely automated, rather than solely automated. They also define what constitutes a decision based on this processing. I have explained the provisions of the clause, and hope the Committee will feel able to accept it.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  39. The reformed section 50 of the Data Protection Act mirrors the changes in subsection (1) for solely automated decision making by law enforcement agencies for a law enforcement purpose, with a few differences. First, in contrast to article 22, the rules on automated decision making apply only where such decisions have an adverse legal or similarly significant effect on the individual. Secondly, the processing of sensitive personal data cannot be carried out for the purposes of entering into a contract with the data subject for law enforcement purposes. The final difference relates to the safeguards for processing. This clause replicates the UK GDPR safeguards for law enforcement processing but also allows a controller to apply an exemption to them where it is necessary for a particular reason, such as to avoid obstructing an inquiry.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  40. The clause makes it clear that solely automated decisions are those that do not involve any meaningful human involvement. It ensures that there are appropriate constraints on the use of sensitive personal data for solely automated decisions, and that such activities are carried out in a fair and transparent manner, providing individuals with key safeguards. The clause provides three powers to the Secretary of State. The first enables the Secretary of State to describe cases where there is or is not meaningful human involvement in the taking of a decision. The second enables the Secretary of State to further describe what is and is not to be taken as having a significant effect on an individual. The third enables the introduction of further safeguards, and allows those already set out in the reforms to be amended but not removed.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  41. We have, I think, covered a lot of ground already in the debates on the amendments. To recap, clause 11 reforms the rules relating to automated decision making in article 22 of the UK GDP and relevant sections of the Data Protection Act 2018. It expands the lawful grounds on which solely automated decision making that produces a legal or similarly significant effect on an individual may be carried out. Currently, article 22 of the UK GDPR restricts such activity to a narrow set of circumstances. By expanding the available lawful grounds and ensuring we are clear about the required safeguards, these reforms will boost confidence that the responsible use of this technology is lawful, and will reduce barriers to responsible data use.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  42. I beg to move amendment 17, in schedule 3, page 140, line 9, leave out sub-paragraph (3) and insert— “(3) In paragraph 2— (a) for “under Articles 15 to 22”, in the first place, substitute “arising under or by virtue of Articles 15 to 22D”, and (b) for “his or her rights under Articles 15 to 22” substitute “those rights”.”. This amendment adjusts consequential amendments of Article 12(2) of the UK GDPR for consistency with other amendments of the UK GDPR consequential on the insertion of new Articles 22A to 22D.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  43. That means that references to article 22 UK GDPR are updated to the reformed article 22A to 22D provisions, and references to sections 49 and 50 in the Data Protection Act are updated to the appropriate new sections 50A to 50D.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  44. I can be reasonably brief on these amendments. Schedule 3 sets out the consequential changes needed to reflect references to the rules on automated decision making in reformed article 22 and section 50 and other provisions in the UK GDPR and the Data Protection Act 2018. Schedule 3 also sets out that section 14 of the Data Protection Act is repealed. Instead, reformed article 22 sets out the safeguards that must apply, regardless of the lawful ground on which such activity is carried out. Government amendments 17 to 23 are minor technical amendments ensuring that references elsewhere in the UK GDPR and the Data Protection Act to the provisions on automated decision making are comprehensively updated to reflect the reforms related to such activity in this Bill.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  45. It will improve the terminology in the relevant articles of the UK GDPR by replacing the requirement to implement “appropriate technical and organisational measures”. In its place, data protection risks must be managed with “appropriate measures, including technical and organisational measures,”. That will give organisations greater flexibility to implement any measures that they consider appropriate to help them manage risks. A similar clarification is made to equivalent parts of the Data Protection Act. Clause 13 will remove article 27 of the UK GDPR, ending the requirement for overseas controllers or processors to appoint a representative in the UK where they offer goods or services to, or monitor the behaviour of, UK citizens—

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  46. The current framework provides some limited exemptions for small businesses and organisations that are carrying out low-risk processing activities, but they are not always as clear or as useful as they should be. We are therefore taking the opportunity to improve chapter 4 of the UK GDPR, and the equivalent provisions in part 3 of the Data Protection Act, in respect of law enforcement processing. Those provisions deal with the policies and procedures that organisations and law enforcement organisations must put in place to monitor and ensure compliance. Clauses 12 to 20 will give organisations greater flexibility to implement data protection management programmes that work for their organisations, while maintaining high standards of data protection for individuals. Clause 12 is technical in nature.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  47. One of the main criticisms that the Government have received of the current legislative framework is that it sets out a number of prescriptive requirements that organisations must satisfy to demonstrate compliance. They include appointing independent data protection officers, keeping records of processing, appointing UK representatives, carrying out impact assessments and consulting the ICO about intended processing activities in specified circumstances. Those rules can sometimes generate a significant and disproportionate administrative burden, particularly for small and medium-sized enterprises and for some third sector organisations.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  48. As I was saying, clause 13 will remove article 27 of the UK GDPR, ending the requirement for overseas controllers or processors to appoint a representative in the UK where they offer goods or services to, or monitor the behaviour of, UK citizens. By no longer mandating organisations to appoint a representative, we will be allowing organisations to decide for themselves the best way to comply with the requirements for effective communication. That may still include the appointment of a UK-based representative. The removal of this requirement is therefore in line with the Bill’s wider strategic aim of removing unnecessary prescriptive regulation.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  49. Clause 14 Senior responsible individual Question proposed, That the clause stand part of the Bill.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  50. If there are concerns that were not fed in during the consultation period, obviously we will consider them. However, it remains the case that even without the article 27 representative requirement, controllers will have to maintain contact with UK citizens and co-operate with the ICO under other provisions of the UK GDPR. For example, overseas controllers and processors must still co-operate with the ICO as a result of the specific requirements to do so under article 31 of the UK GDPR. To answer the hon. Lady’s question about where the benefit lies, the clause is part of a streamlining process to remove what we see as unnecessary administrative requirements and bureaucracy. Question put and agreed to. Clause 13 accordingly ordered to stand part of the Bill.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD