The Data (Use and Access) Bill

The UK Government has reintroduced a bill (The Data (Use and Access) Bill) to amend the UK GDPR. This Bill is based on the previous government’s proposals, but omits some key changes.

The Data (Use and Access) Bill introduces several amendments to the UK’s data protection framework. These amend the UK General Data Protection Regulation and the Data Protection Act 2018.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

 

GDPR

 

Key Changes

Recognised Legitimate Interests: The Bill amends Article 6 of the UK GDPR to permit data controllers to process personal data based on “recognised legitimate interests” without the need for a detailed legitimate interest assessment. These interests are specified in Schedule 4 of the Bill. They include activities such as ensuring network and information security, preventing fraud, and safeguarding the rights of individuals.

The Bill also sets out explicitly that direct marketing can be undertaken on the basis of legitimate interests, although the legitimate interests assessment would still need to be done in that case.

Automated Decision-Making: The Bill expands the lawful basis for solely automated decision-making processes. It outlines specific conditions under which such processing is permissible, aiming to provide clearer guidelines for organisations leveraging automated systems.

Information Commissioner’s Office Restructuring: The governance structure of the ICO is revised to enhance its regulatory capabilities. The Bill proposes changes to its oversight mechanisms, aiming to improve accountability and efficiency in enforcing data protection laws.

Data Breach Reporting Alignment: The Bill brings improvements to the personal data breach reporting regime under the Privacy and Electronic Communications Regulations, aligning it more closely with the UK GDPR. This aims to streamline reporting processes and ensure consistency across regulatory frameworks.

Health and Care Data Protection: Specific provisions are introduced to strengthen data security and protection within the health and care sectors. The Bill seeks to enable the safe and lawful use of personal data in these sectors, balancing the need for data accessibility with effective privacy controls.

These amendments reflect an evolutionary approach to data protection reform. The aim is to modernise existing laws while maintaining robust safeguards for individual privacy rights. However, other proposals such as removing the need for a data protection officer have not been taken forward.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

What’s Next?

The Data (Use and Access) Bill is currently making its way through Parliament. Be sure to come back to check for further updates.

Listen to This Article Here

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial