Call us on 0844 324 5840

NEWS & RESOURCES

Data Protection and Digital Information (No.2) Bill

This Bill aims to make changes to the UK General Data Protection Regulations (UK GDPR) and to introduce several significant data protection and ePrivacy reforms.

Key proposed changes:

  • removing the traditional role of Data Protection Officer and to replace it with ‘Senior Responsible Individual’ (SRI)
  • remove the requirement to complete a data protection impact assessment – although risks must still be identified and managed but on a risk based approach
  • require only controllers or processors of data that is likely to result in high risk to the rights and freedoms of individuals, to keep and maintain records
  • the Regulator, the Information Commissioner’s Office, will be replaced by the Information Commission and supported by a statutory Board, with a Chair and Chief Executive
  • remove the requirement for non-UK based controllers and processors to appoint a UK representative
  • remove the current test threshold “manifestly unfounded or excessive” when managing subject data access requests and replace with “vexatious or excessive”. Examples quoted in the Bill include requests that are intended to cause distress, not made in good faith or are an abuse of process.

WE’RE HERE TO HELP

SHARE THIS:

Instagram

GET IN TOUCH

Got questions? Looking for advice?

GET IN TOUCH

Got questions? Looking for advice?

RELATED RESOURCES

Explore our comprehensive library of related resources to gain valuable insights, expert tips, and helpful tools for optimising your HR practices.

01
Data Reform Bill
Insights
17 May 2022
02
Data and GDPR: Compliance and implications after Brexit
Insights
29 April 2021
03
Data and GDPR – Compliance and Implications after Brexit
Videos
15 April 2021