← LEADERSHIP TERMINAL

UK PARLIAMENT · SITTING

Sir John Whittingdale

MP for Maldon · Conservative · United Kingdom

IN THEIR OWN WORDS

I strongly welcome the Secretary of State’s confirmation of our continuing support for Ukraine. He has set out the sustained threat from Russia facing not just Ukraine, but this country and the whole of Europe, yet for too many people, it is still business as usual.

UKRAINE AND RUSSIA · 2026-09-10 · READ IN HANSARD

That is perhaps even more relevant to the second prong of the Government’s proposals, which is about social media. I will come to that point, but before I finish talking about local media, I want to mention that another of the Government’s flagship policies is devolution.

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

The hon. Member is completely right that this issue must be addressed before we proceed. There is also the question of cost, raised by my right hon. Friend the Member for Wetherby and Easingwold (Sir Alec Shelbrooke). There are people who probably do have access to broadband, if they choose to pay for it, but they cannot afford to do so.

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

I was the Minister responsible for the passage of the Media Act 2024, during the previous Parliament. It is a great delight to see some familiar faces with whom I have worked with in the past on the officials’ Bench.

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

Member for Hazel Grove (Lisa Smart) that young people are turning more and more to social media, but I do not think that this policy is the answer, because it looks to me like a very dangerous extension of Government interference in the freedom of the press and the right to free speech.

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

My right hon. Friend asks a perfectly valid question, and I want to acknowledge that there are concerns. We had a debate in Westminster Hall not that long ago, and a number of my colleagues—particularly from Scotland—turned up to express concern about the fact that the quality of reception via broadband in their constituencies is very poo…

MEDIA GREEN PAPER · 2026-09-08 · READ IN HANSARD

The complete record

Every one of 4,278 lines we hold for Sir John Whittingdale, in date order, each linked to its source. Free to read, in full, without an account. Page 30 of 86.

  1. We recognise that some people have raised concerns that giving organisations more flexibility in how they monitor and ensure compliance with the legislation could reduce standards of protection for individuals. We are confident that that will not be the effect of the clause. On the contrary, the clause provides an opportunity to elevate discussions about data protection risks to senior levels within organisations by requiring a senior responsible individual to take ownership of data protection risks and embed a culture of data protection. On that basis, I commend the clause to the Committee.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  2. That individual would be part of the organisation’s senior management and would be responsible for overseeing data protection matters within the organisation. In particular, the individual would be responsible for monitoring compliance with the legislation, ensuring the implementation of appropriate risk management procedures, responding to data protection breaches and co-operating with the information commissioner, or for ensuring that those tasks are performed by another suitably skilled person where appropriate. Senior responsible individuals may perform the tasks specified in clause 14 themselves, delegate them to suitably skilled members of staff or, if it is right for the company and its clients, seek advice from independent data protection experts.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  3. As I mentioned in our debate on clause 12, clauses 12 to 18 will give organisations greater flexibility about the policies, procedures or programmes that they put in place to ensure compliance with the legislation. As we have discussed, a criticism of the current legal framework is that many of the existing requirements are so prescriptive that they impose unnecessary burdens on businesses. Many organisations could manage data protection risks effectively without appointing an independent data protection officer, but they are forced to do so by the prescriptive rules that we inherited from the European Union. Clause 14 will therefore abolish existing requirements on data protection officers and replace them with new requirements for organisations to designate a senior responsible individual where appropriate.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  4. Clause 14 accordingly ordered to stand part of the Bill. Clause 15 Duty to keep records Question proposed, That the clause stand part of the Bill.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  5. The clause does not in any way represent a lessening of the requirement on organisations to comply with data protection law. It simply introduces a degree of flexibility. An organisation could not get rid of data protection officers without ensuring that processing activities likely to pose high risks to individuals are still managed properly. The senior responsible individual will be required to ensure that that is the case. At the moment, even small firms whose core activities do not involve the processing of sensitive data must have a data protection officer. We feel that that is an unnecessary burden on those small firms, and that allowing them to designate an individual will give them more flexibility without reducing the overall level of data protection that they require. Question put and agreed to.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  6. Other elements of the logs, such as the date and time of the consultation or disclosure and the identity of the person accessing them, are likely to be far more effective in protecting personal data against misuse; those elements remain in place. On that basis, I commend the clauses to the Committee.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  7. Recording a justification for accessing data was intended to help protect against unlawful access, but the reality is that someone is unlikely to record an honest reason if their access is unlawful. That undermines the purpose of this requirement, because appropriate and inappropriate uses would both produce essentially indistinguishable data. As officers often need to access large amounts of data quickly, especially in time-critical scenarios, the clause will facilitate the police’s ability to investigate and prevent crime more swiftly. We estimate that the change could save approximately 1.5 million policing hours.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  8. It will make it easier for data controllers to understand exactly what needs to be included in the record. Most importantly, organisations of any size will no longer have to keep records of processing, unless their activities are “likely to result in a high risk” to individuals. That should help small businesses in particular, which have found the current small business exemption difficult to understand and apply in practice. Clause 16 will make an important change to the logging requirements for law enforcement purposes in part 3 of the Data Protection Act. It will remove the ineffective requirement to record a justification when an officer consults or discloses personal data for the purposes of an investigation. The logging requirements are unique to the law enforcement regime and aim to assist in monitoring and auditing data use.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  9. Clauses 15 and 16 will improve the record-keeping requirements under article 30 of the UK GDPR and the logging requirements under part 3 of the Data Protection Act, which is concerned with records kept for law enforcement purposes. Article 30 of the UK GDPR requires most organisations to keep records of their processing activities and includes a list of requirements that should be included in the record. Those requirements can add to the paperwork that organisations have to keep to demonstrate compliance. Although there is an exemption from those requirements in the UK GDPR for some small organisations, it has a limited impact because it applies only where their processing of personal data is “occasional”. Clause 15 will replace the record-keeping requirements under article 30.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  10. Clause 16 ordered to stand part of the Bill. Clause 17 Assessment of high risk processing

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  11. The intention behind clause 15 is to reduce the burden on organisations by tying the record-keeping requirements to high-risk processing activities. If there is uncertainty about the nature of the risk, organisations will be able to refer to ICO guidance. The ICO has already published examples on its website of processing that is likely to be high-risk for the purposes of completing impact assessments; clause 17 will require it to apply the guidance to the new record-keeping requirements as well. It will continue to provide guidance on the matter, and we are happy to work with it on that. With respect to clause 16, I am most grateful for the Opposition’s welcome recognition of the benefits for crime prevention and law enforcement. Question put and agreed to. Clause 15 accordingly ordered to stand part of the Bill.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  12. Member for Barnsley East to withdraw her two amendments, and I commend clauses 17 and 18 to the Committee.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  13. The Opposition’s amendment 103 would mandate the publication of risk assessments by all public sector bodies. That requirement would, in our view, place a disproportionate burden on public authorities of all sizes. It would apply not just to Departments but to smaller public authorities such as schools, hospitals, independent pharmacies and so on. The amendment acknowledges that each public authority would have to spend time redacting sensitive details from risk assessments prior to publication. As those assessments can already be requested by the ICO as part of its investigations, or by members of the public via freedom of information requests, we do not think it is necessary to impose that significant new burden on all public bodies. I therefore invite the hon.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  14. Clause 18 will make optional the previous requirement for data controllers to consult the commissioner when a risk assessment indicates a potential high risk to individuals. The Information Commissioner will be able to consider any voluntary actions that organisations have taken to consult the ICO as a factor when imposing administrative fines on a data controller. Currently, compliance with the prior consultation requirement is low, likely due to a lack of clarity in the legislation and a reluctance for organisations to engage directly with the regulator on potential high-risk processing. The clause will encourage a more proactive, open and collaborative dialogue between the ICO and organisations, so that they can work together to better mitigate the risks.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  15. We think organisations are best placed to judge whether a particular activity poses a high risk to individuals in the context of the situation, taking account of any relevant guidance from the regulator. Secondly, we have also removed the mandatory requirement to consult individuals about the intended processing activity as part of a risk-assessment process, as that imposes unnecessary burdens. There are already requirements in the legislation to ensure that any new processing is fair, transparent and designed with the data protection principles in mind. It should be open to businesses to consult their clients about intended new processing operations if they wish, but that should not be dictated to them by the data protection legislation.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  16. The changes will apply to both the impact assessment provisions under the UK GDPR and the section of the Data Protection Act 2018 that deals with impact assessments for processing relating to law enforcement. Amendment 102 would reverse those changes to maintain the current data protection impact assessment requirements, but we feel that this would miss an important opportunity for reform. There are significant differences between the new provisions in the Bill and current provisions on data protection impact assessments. First, the new provisions are less prescriptive about the precise processing activities for which a risk assessment will be required.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  17. As we have discussed, one of the principal objectives of this part of the Bill is to remove some of the prescriptive unnecessary requirements on organisations to do things to demonstrate compliance. Clauses 17 and 18 reduce the unnecessary burdens placed on organisations by articles 35 and 36 of the UK GDPR in respect of data protection impact assessments and prior consultation with the ICO respectively. Clause 17 will replace the EU-derived notion of a data protection impact assessment with more streamline requirements for organisations to document how they intend to assess and mitigate risks associated with high-risk processing operations.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  18. I beg to move amendment 1, in clause 19, page 35, leave out lines 23 to 25 and insert— “(5) The Commissioner must encourage expert public bodies to submit codes of conduct described in subsection (1) to the Commissioner in draft.”. This amendment replaces a duty on expert public bodies to submit draft codes of conduct relating to compliance with Part 3 of the Data Protection Act 2018 to the Information Commissioner with a duty on the Information Commissioner to encourage such bodies to do so.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  19. Government amendment 1 replaces that requirement with a duty on the commissioner to instead encourage public bodies to do that. Government amendments 2 and 3 are consequential to that. Where a public body has submitted a code of conduct to the commissioner for review, Government amendment 4 removes the requirement for the commissioner to review any subsequent amendments made by the public body until the initial draft has been considered. This change will promote transparency, greater clarity and confidence in how police process personal data under the law enforcement regime. Codes of conduct are not a new concept. The clause mirrors what is already available under the UK GDPR.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  20. Clause 19 introduces an ability for public bodies with the appropriate knowledge and expertise to produce codes of conduct applicable to the law enforcement regime. The clause mirrors the equivalent provision in the UK GDPR. As with regular guidance, these codes of conduct will be drafted by law enforcement data protection experts and tailored to the specific data protection issues that affect law enforcement agencies, to help improve compliance with the legislation and encourage best practice. However, they are intended to carry more weight, because they will additionally have the formal approval of the Information Commissioner. When a code of conduct is produced, there is a requirement to submit a draft of it to the Information Commissioner. While that is good practice, we think it is unnecessary to mandate that.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  21. Clause 19, as amended, ordered to stand part of the Bill. Clause 20 Obligations of controllers and processors: consequential amendments Question proposed, That the clause stand part of the Bill.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  22. I welcome the Opposition’s support. Amendment 1 agreed to. Amendments made: 2, in clause 19, page 35, line 26, leave out from ‘body’ to ‘, the’ in line 27 and insert ‘does so’. This amendment is consequential on Amendment 1. Amendment 3, in clause 19, page 35, line 28, leave out ‘draft’. This amendment is consequential on Amendment 2. Amendment 4, in clause 19, page 35, line 33, leave out from ‘conduct’ to the end of line 34 and insert— ‘that is for the time being approved under this section as they apply in relation to a code’.—( Sir John Whittingdale .) This amendment makes clear that the Commissioner’s duty under new section 68A of the Data Protection Act 2018 to consider whether to approve amendments of codes of conduct relates only to amendments of codes that are for the time being approved under that section.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  23. Government amendment 40 will provide that the commissioner may refuse to deal with vexatious or excessive requests made by any person, not just those made by data protection officers or data subjects. Government amendments 41 to 43 make further minor and technical changes to the provisions in schedule 4 to reflect the changes we have made to the terminology.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  24. As clauses 12 to 18 remove terms such as data protection officers and data protection impact assessments from the legislation, some consequential changes are required to other parts of the legislation where the same terms are used. Clause 20 therefore introduces schedule 4, which sets out the details of the consequential changes required. An example of that is in article 13 of the UK GDPR, which currently requires controllers to provide individuals with the contact details of the data protection officer, where appropriate. In future, that provision will refer to the organisation’s senior responsible individual instead. Removal of the term data protection officer from the UK GDPR will have knock-on effects in other areas, including in relation to the types of people from whom the ICO receives requests and queries.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  25. It replaces the current list of considerations with a broader, non-exhaustive one. The schedule also clarifies the test found in new section 74AB that must be applied when regulations are made, giving greater clarity to the UK regulations decision-making process.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  26. The new power will help to future-proof the UK’s international transfers regime by allowing the Government to shape international developments and react quickly to global trends, helping UK businesses connect and trade with their partners around the world. Schedule 6 amends relevant parts of the Data Protection Act 2018 governing international transfers of personal data, which are governed by the law enforcement processing regime. Paragraph 4 omits the section governing transfers based on adequacy assessments and inserts a new provision to mirror the approach being adopted in schedule 5. As with the changes described in schedule 5, schedule 6 amends the power in new section 74AA for the Secretary of State to make regulations approving transfers of personal data to another jurisdiction.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  27. The new article 46 requirements are tailored for data exporters to transfer defined types of data in specific circumstances. They stipulate that the data exporter, acting reasonably and proportionately, must consider that the standard of protection provided for the data subject would be “not materially lower” than the standard of protection in the UK in the specific circumstances of the transfer. The new requirements accommodate disparities between data exporters, where what is right for a multinational organisation transferring lots of sensitive data may not be right for a small charity making ad hoc transfers. Schedule 5 also introduces article 47A, which provides a power for the Secretary of State to create or recognise new UK and non-UK alternative transfer mechanisms.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  28. The article also sets out a more concise and streamlined list of key factors that the Secretary of State must consider as part of their assessment. However, article 45B(2) is a non-exhaustive list, and the Secretary of State may also need to consider other matters in order to determine whether the required standard of protection exists. Article 45C amends the system for formally reviewing data bridge regulations, removing the requirement for them to be reviewed periodically. The Secretary of State will still be subject to the requirement to monitor developments in other countries on an ongoing basis. Schedule 5 also amends article 46, which sets out the rules for controllers and processors to make international transfers of personal data using alternative transfer mechanisms.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  29. Article 45B sets out the data protection test that the Secretary of State must consider is met in order to establish new data bridges. In order for a country or international organisation to meet the data protection test, the standard of protection for personal data in that country or international organisation must be “not materially lower” than the standard of protection under the UK’s data protection framework. The reformed law recognises that the Secretary of State must exercise their judgment when making a determination. Their assessment will be made with respect to the outcomes of data protection in a third country, instead of being prescriptive about the form and means of protection, recognising that no two data protection regimes are identical.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  30. Schedule 5 also introduces article 45A, which sets out the Secretary of State’s power to make regulations approving transfers of personal data to a third country or international organisation. The Government now use the term “data bridges” to refer to those regulations, which allow the free flow of personal data. Article 45A outlines that the Secretary of State may make such regulations only if they are satisfied that the data protection test is met. In addition to the requirement that the Secretary of State be satisfied that the data protection test is met, article 45A specifies that the Secretary of State may have regard to other matters that he or she considers relevant when making those regulations, including the desirability of facilitating transfers of personal data to and from the UK.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  31. Clause 21 refers to schedules 5 to 7, which introduce reforms to the provisions of the UK GDPR and the Data Protection Act 2018, which regulate the international transfers of personal data. Schedule 5 introduces changes to the UK’s general processing regime for transferring personal data internationally. In order to provide for a clearer structure than the current UK regime, schedule 5 will consolidate the existing provisions on international transfers. It replaces article 44 with article 44A, setting out in clearer terms the general principles for international transfers and listing the same bases under which personal data can be lawfully transferred overseas.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  32. Schedule 7 agreed to. Clause 22 Safeguards for processing for research etc purposes

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  33. New section 74AB(3)(c) of the Data Protection Act 2018 explains how references to processing of personal data in a third country should be read (in the data protection test for regulations approving international transfers of personal data). This amendment changes a reference to data transferred from the United Kingdom to include certain data transferred from outside the United Kingdom. Amendment 28, in schedule 6, page 156, line 6, leave out “the transfer of personal data” and insert “transfer”. This amendment and Amendment 29 simplify the wording in new section 74AB(4)(b) of the Data Protection Act 2018. Amendment 29, in schedule 6, page 156, line 8, leave out “the transfer of personal data” and insert “transfer”.— (Sir John Whittingdale.) See the explanatory statement for Amendment 28. Schedule 6, as amended, agreed to .

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  34. This amendment and Amendment 26 simplify the wording in new Article 45B(4)(b) of the UK GDPR. Amendment 26, in schedule 5, page 147, line 14, leave out “the transfer of personal data” and insert “transfer”.— (Sir John Whittingdale.) See the explanatory statement for Amendment 25. Schedule 5, as amended, agreed to. Schedule 6 Transfers of personal data to third countries etc: law enforcement processing Amendments made: 27, in schedule 6, page 155, line 39, leave out “from the United Kingdom” and insert— “to the country or organisation by means of processing to which this Act applies as described in section 207(2)”.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  35. Schedule 5 Transfers of personal data to third countries etc: general processing Amendments made: 24, in schedule 5, page 147, line 3, leave out “from the United Kingdom” and insert “to the country or organisation by means of processing to which this Regulation applies as described in Article 3”. New Article 45B(3)(c) of the UK GDPR explains how references to processing of personal data in a third country should be read (in the data protection test for regulations approving international transfers of personal data). This amendment changes a reference to data transferred from the United Kingdom to include certain data transferred from outside the United Kingdom. Amendment 25, in schedule 5, page 147, line 12, leave out “the transfer of personal data” and insert “transfer”.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  36. Government amendment 24 revises new article 45B(3)(c) of the UK GDPR, which is inserted by schedule 5 and which makes provision about the data protection test that must be satisfied for data bridge regulations to be made. An amendment to the Bill is required for the Secretary of State to retain the flexibility to make data bridge regulations covering transfers from the UK or elsewhere. The amendment will preserve the status quo under the current regime, in which the Secretary of State’s power is not limited to covering only transfers from the UK. In addition to these amendments, four other minor and technical Government amendments —25, 26, 28 and 29—were tabled on 10 May. Question put and agreed to. Clause 21 accordingly ordered to stand part of the Bill.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  37. At present, the legislative framework makes it difficult for organisations and others to understand what standard needs to be applied when transferring personal data internationally, with several terms used in the chapter and in case law. Our reforms ensure that a clear standard applies, which maintains protection for personal data. The hon. Lady raised the EU’s data adequacy assessment. That is something that featured earlier in our debates on the Bill, and, as we heard from a number of our witnesses, including the information commissioner, there is no reason to believe that this in any way jeopardises the EU’s assessment of the UK’s data adequacy.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  38. We completely agree with the hon. Lady that we would not wish to see data transferred to countries that have an inferior data protection regime. However, we do not think amendment 104 is required to achieve that, because the reforms in chapter 5 already provide for a clear and high standard of protection when transferring personal data overseas. It states that the standard of protection in that country must not be “materially lower” than the standard under the UK GDPR. That ensures that high standards of data protection are maintained. In addition, we feel that the amendment would return us to the confusion of the existing regime.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  39. I beg to move amendment 34, in clause 22, page 36, leave out lines 20 to 22. This amendment and Amendment 37 transpose the requirement for processing of personal data for research, archiving and statistical purposes to be carried out subject to appropriate safeguards from the beginning to the end of new Article 84B of the UK GDPR.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  40. Clause 23 sets out consequential changes to the UK GDPR and Data Protection Act 2018 required as a result of the changes being made in clause 22 to consolidate safeguards for research. Government amendments 34 to 39 are minor, technical amendments clarifying that, as part of the pre-existing additional requirement when processing for research, archiving and statistical purposes, a controller is to use anonymous—rather that personal—data, unless that means that those purposes cannot be fulfilled. It makes clear that processing to anonymise the personal data is permitted. On that basis, I commend the clauses, and indeed the Government amendments, to the Committee.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  41. Clause 22 creates a new chapter in the UK GDPR that provides safeguards for the processing of personal data for the purposes of scientific research or historical research, archiving in the public interest, and for statistical purposes. Currently, the provisions that provide safeguards for those purposes are spread across the UK GDPR and the Data Protection Act 2018. Clause 22 consolidates those safeguards in a new chapter 8A of the UK GDPR. Those safeguards ensure that the processing of personal data for research, archiving and statistical purposes does not cause substantial damage or substantial distress and that appropriate technical and organisational measures are in place to respect data minimisation.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  42. That change will assist closer working between organisations operating under the three distinct data protection regimes by providing greater confidence that data that, for example, may be of importance to a police investigation but also pertinent to a separate national security operation can be properly safeguarded by both organisations. I will allow the hon. Member for Barnsley East to speak to amendment 105, because I wish to respond to her.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  43. The change will align the national security exemption applicable to UK GDPR processing with the other national security exemptions in the Data Protection Act 2018, which do not permit the exemption to be applied in relation to an individual’s right to complain to the Commissioner. The ability of a Minister of the Crown to issue a certificate certifying the application of the exemption for the purposes of safeguarding national security, which previously existed, is retained; clause 24(8) simply updates that provision to reflect the new exemption.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  44. The processing of data by law enforcement authorities must always be lawful, and the protections surrounding sensitive processing remain. Subsection (2) amends the general processing regime of the Data Protection Act, regarding processing under UK GDPR, to remove the ability of organisations to exempt themselves, on the grounds of safeguarding national security, from article 77 of the UK GDPR, which provides the right for individuals to lodge a complaint with the Information Commissioner. That is because we do not consider exemption from that provision necessary.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  45. Clause 24 introduces an exemption that can be applied to the processing of personal data for law enforcement purposes under the law enforcement regime for the purposes of safeguarding national security. It will replace the current, more limited national security exemptions that exist in the law enforcement regime and mirror the existing exemptions in the UK GDPR and intelligence services regime. The clause will allow organisations to exempt themselves from specified provisions in the law enforcement regime of the Data Protection Act 2018, such as some of the data protection principles and the rights of the individual, but only where it is necessary to do so for the purposes of safeguarding national security. Like the other exemptions in the Act, it must be applied on a case-by-case basis. There are limits to what the exemption applies to.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  46. I assure the hon. Lady that clauses 25 and 26 are necessary for the improvement of national security. The reports on events such as the Manchester and Fishmongers’ Hall terrorist incidents have demonstrated that better joined-up working between the intelligence services and law enforcement is in the public interest to safeguard national security. A current barrier to such effective joint working is that only the intelligence services can operate under part 4 of the Data Protection Act, which is drafted to reflect the unique operational nature of their processing.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  47. I certainly accept that greater collaboration would have been beneficial as well, but there was a problem with data sharing and that is what the clause is designed to address. As the hon. Member for Barnsley East will know, law enforcement currently operates under part 3 of the Data Protection Act when processing data for law enforcement purposes. That means that even when they work together, law enforcement and the intelligence services must each undertake separate assessments regarding the same joint-working processing.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FOURTH SITTING) · 2023-05-16 · READ IN HANSARD

  48. It really does crystallise and clarify why we are here and how we will prioritise our efforts and resources.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FIRST SITTING) · 2023-05-10 · READ IN HANSARD

  49. To the previous question and answer, our role in trying to provide or maximise regulatory certainty means being able to invest as much resource as we can in that upstream advice, particularly in those novel, complex, finely balanced, context-specific areas. We are adding far more value if we can add that support upstream. The additional statutory objectives that are being added through the Bill overall will be a real asset to our accountability. Any regulator that welcomes independence also needs to welcome the accountability. It is the means through which we describe how we think, how we act and the outcomes that we achieve. Those extra statutory objectives will be a real aid to us and also an aid to Parliament and our stakeholders.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FIRST SITTING) · 2023-05-10 · READ IN HANSARD

  50. Q Thank you, Mr Hollobone. Good morning, Mr Edwards. Both the structure and powers of your office are going to change as a result of the Bill. Do you believe that the existing structure and the absence of the powers you will gain under the Bill have in any way impeded the carrying out of your functions? John Edwards : The obligation to investigate every complaint does consume quite a lot of our resources. Can I ask my colleague to make a contribution on this point? Paul Arnold : As the commissioner says, that duty to investigate all complaints can challenge us in terms of where we need to dedicate the majority of our resources.

    DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL (FIRST SITTING) · 2023-05-10 · READ IN HANSARD