The UK Government has relaunched its efforts to reform the UK’s data protection regime, with the Data Protection and Digital Information Bill (No. 2) (the “Bill“) being introduced to Parliament on Wednesday 8 March. The Bill supersedes a previous version that was originally published in July 2022 (see our previous legal update).
United Kingdom
UK Cybersecurity and Incident Response – The Outlook for 2023
Following on from our alert in relation to technology, data privacy, cybersecurity and IP legal developments to look out for in 2023, this update outlines some of the potential developments and trends in the UK cyber incident response landscape for 2023.
Increased litigation risk for cyber breach victims – the Information Commissioner’s Office begins naming …
ICO’s Updated Guidance on International Personal Data Transfers Offers an Alternative Approach to Carrying Out Transfer Risk Assessments
The UK Information Commissioner’s Office (the “ICO”) published new guidance on transfer risk assessments (“TRAs”) and a template for carrying out a TRA.
All businesses are required to carry out TRAs, also known as local law assessments or transfer impact assessments, when transferring personal data subject to the UK GDPR outside the United Kingdom using…
Ransomware Payments Under English Law: Key Considerations for Stakeholders
Ransomware attacks continue to surge from the levels seen just a few years ago and the threat such attacks present against companies and organisations remains very real – not least because the sums involved also continue to surge. According to a recent report by software company Acronis1, global ransomware damages are predicted to…
Deadline to Update Template Contracts to Address International Personal Data Transfers Outside the UK
Companies that rely on standard contractual clauses for transferring personal data from the United Kingdom to jurisdictions not considered to offer an adequate level of data protection under the UK General Data Protection Regulation can no longer use the old EU standard contractual clauses in new contracts as of today, Wednesday 21 September 2022.…
UK Government Sets Out its Plans for UK Data Protection Reform
The UK Government has published its response to the consultation on its proposed reform of the UK’s data protection regime (which we have provided further information on in our previous legal update available here.) Whilst the UK Government has proposed several incremental reforms to the UK’s data protection laws that will diverge from the…
Queen’s Speech Confirms UK Data Protection Reform
The Queen’s Speech 2022 (the “Speech”), given on 10 May 2022 (available here), details the UK Government’s priorities for the year. Although its focus was primarily on the cost of living crisis and proposed economic measures, the Speech confirmed that the UK’s data protection regime will be reformed by way of the ‘Data…
Standard contracts for transfers of personal data outside the UK enter into force
Today, 21 March 2022, the International Data Transfer Agreement (IDTA) and the UK Addendum to the EU standard contractual clauses have entered into force.
The IDTA and the UK Addendum can be used for transfers of personal data outside the UK to countries that are not considered “adequate” by the UK Government. You can read…
UK Government Launches Consultation on Adopting a New Comprehensive Framework Aimed at Enhancing Cyber Security of Businesses
In line with the government’s commitments in its 2022 National Cyber Strategy, the Department for Digital, Culture, Media & Sport (DCMS) launched a consultation on 19 January 2022 outlining its proposals for new measures to strengthen the cyber security of businesses in the UK.
The UK government acknowledges that a new legal framework needs…
Top Developments to look out for in 2022 in Intellectual Property, Information Technology and Data Protection
The UK Online Safety Bill was proposed by the UK government to establish a new regulatory framework to tackle harmful content online and usher in a new age of accountability for tech companies. The bill will impose a duty of care on companies that offer user-generated content, in addition to search engines, to protect users…