United Kingdom

Image

On this topic page, you can find the IAPP’s collection of coverage, analysis and resources related to privacy in the United Kingdom. The IAPP Resource Center also includes a “Europe” topic page, which can be accessed here.

Featured Resources

UK data protection reform: An overview

On 8 March 2023, the U.K. government introduced the Data Protection and Digital Information (No. 2) Bill to Parliament. Its objective is to “update and simplify” the U.K.’s data protection laws and certain other legislation. This article sets out a comprehensive summary of the changes in comparison to the GDPR.
Read More

Ten takeaways from draft UK GDPR reform

IAPP Research and Insights Director Joe Jones, who previously worked as the deputy director of international data transfers at the Department for Digital, Culture, Media and Sport, parsed through the 212-page Data Protection and Digital Information Bill and offers his initial thoughts, along with the top takeaways.
Read More

Privacy Around the Globe: UK

In this session, IAPP Vice President and Chief Knowledge Officer Caitlin Fennessy, CIPP/US, connects with IAPP Research and Insights Director Joe Jones to take a close look at the changing privacy landscape in the United Kingdom.
Read More


Latest News and Resources

UK releases white paper on AI regulatory framework

The U.K. Department for Science, Innovation and Technology published a white paper with its approach to regulating artificial intelligence technologies. The regulatory framework seeks to "build public trust in cutting-edge technologies and make it easier for businesses to innovate, grow and create jobs." The approach consists of five AI principles: safety, transparency, fairness, accountability and governance, and redress. U.K. regulators will roll out guidance within the next 12 months to help ... Read More

ICO releases new UK GDPR certification scheme

The U.K. Information Commissioner’s Office approved the fourth set of U.K. General Data Protection Regulation certification scheme criteria for training and qualifying service providers. The scheme's intention will "enable … candidates to make informed choices when applying for training" programs so they can maintain confidence their personal data is being processed in accordance with the law. Other certification schemes released so far cover secure disposal and reuse of IT equipment, age assura... Read More

DPI: UK dispatch: Enforcement, data flows and UK reforms on the docket

Several significant figures in the privacy landscape shared their thoughts on the keynote stage at the IAPP Data Protection Intensive: U.K. here in London Thursday. The state of play and future of EU enforcement and international data transfers were the focus of a keynote panel moderated by IAPP Research and Insights Director Joe Jones and featuring former U.K. Information Commissioner and current Baker McKenzie International Advisor Elizabeth Denham and NOYB Honorary Chair Max Schrems.  Separa... Read More

UK introduces draft data protection reform

The U.K. released draft data protection reform of its General Data Protection Regulation. On Wednesday, U.K. Secretary of State for Science, Innovation and Technology Michelle Donelan introduced the Data Protection and Digital Information (No. 2) Bill to Parliament.  The first version of the reform bill was originally proposed by the government in July 2022 but was put on pause last September in the wake of Liz Truss's then-appointment as prime minister.  "Co-designed with business from the st... Read More

Edwards talks data reform, ‘deliberate,’ ‘approachable’ ICO

Amid the introduction of a new data protection reform bill Wednesday, U.K. Information Commissioner John Edwards said the goals within the ICO25 strategic plan "are not predicated or dependent on law reform." "We can still achieve everything we’ve set out to achieve regardless of the direction the law goes in, within certain limits, but I’m very confident of those limits," Edwards said in a keynote address at the IAPP Data Protection Intensive: U.K. in London, reflecting on his first year in of... Read More

UK PM overhauls government departments, including focus on innovation and tech
(IAPP, February 2023)
UK, DIFC commit to updated data partnership
(IAPP, December 2022)
Japan, UK reach digital partnership
(IAPP, December 2022)
DPC 2022: DCMS braces for fresh look at proposed data protection reform
(IAPP, November 2022)
DCMS announces plan for ‘business and consumer-friendly’ UK GDPR
(IAPP, October 2022)
UK-US data access agreement takes effect
(IAPP, October 2022)
The value of a UK representative: A response to the DPDI Bill
(IAPP, September 2022)
ICO: Freedom of information self-assessment toolkit
(UK ICO, August 2022)
UK DPDI Bill: Comparative analysis with the EU GDPR and ePrivacy framework
(IAPP, July 2022)
UK unveils data reform bill, proposes AI regulation
(IAPP, July 2022)
ICO rolls out strategic plan 2022-2025
(IAPP, July 2022)
South Korea, UK reach adequacy agreement ‘in principle’
(IAPP, July 2022)
UK Data Reform: Will the UK become a privacy island paradise?
(IAPP, June 2022)
UK issues response to data reform consultation
(IAPP, June 2022)
UK data protection reform: What is in the government’s proposals?
(IAPP, June 2022)
New U.K. health data strategy creates ‘secure,’ ‘privacy-preserving system’
(IAPP, June 2022)
Consent as legal basis for EU and UK employment
(IAPP, May 2022)
A conversation with UK Information Commissioner John Edwards
(IAPP, April 2022)
The UK data policy and possible divergences with the European Union
(IAPP, April 2022)
UK, German DPAs talk regulatory priorities, privacy complexities
(IAPP, April 2022)
U.K. Government National Data Strategy
(UK Government, April 2022)
UK Government: The Digital, Data and Technology Playbook
(UK Government, March 2022)
Data transfers, UK GDPR reform top of mind at DPI: UK
(IAPP, March 2022)
In first public speech as UK information commissioner, Edwards offers certainty in uncertain times
(IAPP, March 2022)
UK’s post-Brexit international data transfer agreement enters into force
(IAPP, March 2022)
UK government rolls out global AI standards initiative
(IAPP, January 2022)
Edwards discusses new beginning as UK commissioner
(IAPP, January 2022)
The way the third-party cookie crumbles: Part 1 – EU and UK developments
(IAPP, December 2021)
UK launches algorithmic transparency standard for government
(IAPP, December 2021)
Denham ‘deeply concerned’ with UK data reforms
(IAPP, November 2021)
UK Supreme Court halts billion-dollar privacy class action against Google
(IAPP, November 2021)
Changing direction? UK consults reforms to its data protection law
(IAPP, October 2021)
LinkedIn Live: “UK International Data Transfers Consultation”
(IAPP, October 2021)
ICO issues data protection guide for media, journalists
(IAPP, October 2021)
UK details plans for national AI strategy
(IAPP, September 2021)
The UK’s new plans for data transfers: An interview with Joe Jones
(IAPP, September 2021)
EU warns UK could lose adequacy by drifting away from GDPR
(IAPP, August 2021)
Denham discusses potential for global privacy standard
(IAPP, September 2021)
UK launches wide-ranging data reform initiative
(IAPP, September 2021)
Children’s Data Privacy Protections in the U.K.: What to Know and How to Comply
(Davis Wright Tremaine, September 2021)
UK announces independent adequacy decisions; Edwards named ICO top candidate
(IAPP, August 2021)
ICO publishes direct marketing guidance for public sector
(IAPP, August 2021)
ICO unveils AI and Data Protection Risk Toolkit
(IAPP, July 2021)
UK government publishes ‘Plan for Digital Regulation’
(IAPP, July 2021)
ICO Accountability Framework
(UK ICO, July 2021)
European Commission adopts UK adequacy decisions
(IAPP, June 2021)
UK CMA’s role in Privacy Sandbox ‘changes the dynamic’
(IAPP, June 2021)
UK health department, NHS publish draft health data strategy
(IAPP, June 2021)
Report: UK MPs suggest tossing GDPR, creating new standard
(IAPP, June 2021)
UK Court of Appeals deems Data Protection Act ‘immigration exemption’ unlawful
(IAPP, June 2021)
ICO addresses data protection in UK digital identity scheme
(IAPP, April 2021)
Elizabeth Denham reflects on the pandemic year and road ahead
(IAPP, April 2021)
ICO discusses common UK GDPR compliance issues
(IAPP, April 2021)
NIS representation in the EU and UK — Was the March 31 deadline a turning point?
(IAPP, April 2021)
GDPR representatives in EU and UK after Brexit
(IAPP, February 2021)
Draft UK adequacy decisions — A somewhat lukewarm embrace?
(IAPP, February 2021)
European Commission releases draft UK adequacy decisions
(IAPP, February 2021)
UK government publishes draft rules on use of digital identities
(IAPP, February 2021)
Government leaders discuss state of play for UK adequacy, data transfers
(IAPP, January 2021)
Data brokers under the spotlight: A commentary on the ICO vs. Experian case
(IAPP, January 2021)
UK, EU reach interim data flow agreement
(IAPP, January 2021)
Online Harms White Paper — UK Government
(UK Government, December 2020)
View More Resources

ICO Resources

The Information Commissioner’s Office is the UK’s independent data protection authority. Linked below are resources from the ICO.


ICO publishes guide for small businesses to respond to data protection complaints

The U.K. Information Commissioner’s Office issued a six-step guide for small businesses that receive data protection complaints. The steps are to acknowledge receipt of the complaint, find out the specific issue related to the complaint, provide updates to the data subject, record actions taken in response to complaint, formally respond to the individual with the outcome of the investigation, and review lessons observed.  Full Story... Read More

ICO updates guidance for BCRs

The U.K. Information Commissioner's Office published updated guidance for using binding corporate rules as a data transfer mechanism. The updates are geared toward a "simplified" approach for controllers and processors with the ICO noting it will "only request supporting documents and commitments once during the U.K. approval process." The regulator also called BCRs a "gold standard" transfer mechanism that "demonstrates your commitment to implementing appropriate safeguards."Full Story... Read More

ICO report reviews COVID-19 data protection challenges

The U.K. Information Commissioner's Office submitted a report to U.K. Parliament discussing observations on data protection challenges and practices during the peak of the COVID-19 pandemic. Former Information Commissioner Elizabeth Denham focused the paper on how the flexibility of the data protection legislation could enable the data use while maintaining protections. The paper also looks at best practices for maintaining user trust as organizations deployed more digital and technological solu... Read More

ICO Annual Track Survey

The U.K. Information Commissioner's Office released the findings of its 2021 Annual Track survey. The survey consists of data from the ICO polling individuals to gauge their awareness of their data protection rights and trust in organizations that use their information. Click To View (PDF) ... Read More

Brexit

Luxembourg DPA publishes Brexit data transfer guidance

The Luxembourg National Commission for Data Protection published guidance on how Brexit affects international data transfers. The guidance was created to help "companies, public bodies and associations" in Luxembourg transfer information to the U.K. following the European Commission's adequacy decision adoptions, recommending each entity respect the principles of the EU General Data Protection Regulation when sending data.Full Story ... Read More

Web Conference: ‘Brexit Means Brexit’ — Unpacking the Reality. UK Data Protection Law After 2020

Original broadcast date: 24 March 2021  The Brexit transition period has ended. How does that affect you? Join us to explore the impact on U.K., EU and non-European businesses. See what's happening with EU adequacy for the U.K. and learn how the U.K.'s new international transfers regime will impact data flows. We will discuss how the EU and U.K. can manage regulatory divergence and risks to data protection in a connected world. And, we will examine how businesses should prepare for different and potentially diverging regimes in the U.K. and the EU. Read More

Privacy Implications of Brexit

Original Broadcast Date: January 2021 In this Linkedin Live, Covington & Burling Senior Counsel Jetty Tielemans, European Commission Head of International Data Flows and Protection Bruno Gencarelli, and Department for Digital, Culture, Media & Sport Head of U.K. International Transfer Regime Joe Jones talk about the privacy implications of Brexit. Watch the full recording on LinkedIn. Access the IAPP's LinkedIn profile ... Read More

Government leaders discuss state of play for UK adequacy, data transfers

After years of uncertainty in the wake of the U.K.'s vote in 2016 to leave the EU, there are finally sign posts for privacy pros to look to as both regions aim to secure cross-border data transfers through U.K. adequacy. In a massive trade agreement signed last Christmas Eve, both regions secured a temporary transfer period that provides the U.K. government and European Commission time to complete an adequacy agreement.  But, of course, the clock is ticking.  "We don't see why the U.K. shouldn... Read More