Data Protection and Digital Information (No. 2) Bill

Written evidence submitted by Prighter Ltd (DPDIB03)

House of Commons Public Bill Committee considering the Data Protection and Digital Information (No.2) Bill

About Prighter

Prighter is a provider of Article 27 UK GDPR representative services, as well as data protection compliance software applications, which include solutions designed to ensure the effective handling of data subject rights, case management including communication with the ICO and tools enabling risk assessment, management, and reporting of data breaches. Prighter’s aim is to enable access to data protection compliance for organisations around the world.

This submission is drawn from our experience of providing UK representative services and our understanding of the detrimental impact that removal of Article 27 will have on a range of UK stakeholders, especially on the ability of individuals to exercise their rights.

1. Executive Summary

1.1. The UK GDPR has extra-territorial reach, meaning that it applies to organisations without an establishment in the UK whose processing activities relate to the offer of goods or services to individuals in the UK or the monitoring of UK individuals’ behaviour (Article 3(2)).

1.2. This is intended to give data subjects the same rights, protections and means of redress in respect of their personal information, regardless of the location of the relevant data controller or processor.

1.3. Problems with accessing overseas organisations may prevent data subjects from retaining control of their personal data. The same issues can also hinder the efforts of the ICO, risking the accountability of non-UK companies.

1.4. Article 27 of the UK GDPR, therefore, requires non-UK companies caught by Article 3(2) to appoint a representative to be their local addressee for the purpose of ensuring compliance with the UK data protection regime.

1.5. Clause 13 of the Bill proposes to remove Article 27 in its entirety.

1.6. The removal of a legal requirement to appoint a UK representative would mean the loss of an effective, reasonable, and proportionate means of enforcing the rights and protections given to UK stakeholders under the UK GDPR.

1.7. Based on our knowledge of the role and our understanding of the issues that may arise in the absence of a UK representative, we recommend that Article 27 of the UK GDPR should not be removed.

2. The relevant clause of the Bill

2.1. Clause 13(1):

"Omit Article 27 of the UK GDPR (representatives of controllers or processors not established in the United Kingdom)."

3. Potential consequences of the removal of Article 27

3.1. Prighter believes that the removal of the legal requirement to appoint a UK representative would be harmful to a range of UK stakeholders.

3.2. We are concerned that removal of Article 27 would:

3.2.1. significantly harm the fundamental rights of individuals by taking away access to overseas organisations. This would result in a loss of control by individuals over the use of their personal data. This is of particular concern for vulnerable groups, especially children, who are regularly the target of online digital services such as gaming, social media and many other applications, wearables and smart technologies.

3.2.2. frustrate the efforts of the ICO by increasing the time and resource spent on investigating complaints from UK data subjects against non-UK companies that cannot be contacted or that fail to respond to the ICO.

3.2.3. risk issues of non-compliance going unaddressed thereby diminishing the accountability of companies outside of the UK.

3.2.4. increase the existing frustrations of UK businesses in dealing with overseas organisations whose compliance efforts fail to take account of UK data protection laws. This situation will be exacerbated by the UK’s overall divergence from the retained version of the GDPR.

3.2.5. take away an ambassador of UK data protection legislation, reducing the promotion and therefore awareness of the extra-territorial reach of the UK GDPR. This could result in an overall drop in compliance levels amongst organisations outside of the UK.

3.2.6. in conjunction other proposed amendments to the UK GDPR, risk the legitimacy and adequacy of the UK data protection regime and jeopardise the EU adequacy decision.

4. Erosion of fundamental data subjects’ rights

4.1. A number of groups representing civil society [1] have openly criticised the Bill for its erosion of individual’s fundamental rights. The Public Law Project [2] , for example, has said that the Bill would "weaken important data protection rights and safeguards, making it more difficult for people to know how their data is being used" [3] .

4.2. The role of the representative was designed to remove barriers that might otherwise prevent individuals from exercising their rights. Obstacles such as language, time zone or lack of local contact information make it hard, sometimes even impossible, for people to make data subject requests in respect of non-UK controllers.

4.3. The UK representative acts as a local point of contact in the UK, keeping a permanent channel of communication open to companies without an office, branch or other stable arrangement in the UK. The representative therefore plays a pivotal role in preserving the ability for individuals to enforce their rights.

4.4. This is of particular importance in respect of vulnerable members of society who may require additional support when dealing with overseas companies. This includes children, who today have access to digital services in virtually all homes and schools via a variety of readily available personal devices, and who are often active online from a very early age [4] .

4.5. The online gaming industry is one such industry targeting digital services at children. Prighter conducted a survey of the top online gaming companies by market capitalisation [5] and found that of the 188 companies:

· only two are located in the UK;

· 80% are located in non-English speaking regions;

· Of that 80%, the majority (118) are headquartered in the Asia-Pacific region;

· Of these 118, fewer than 50% have a privacy notice available in English and only 39% have accessible contact details for privacy-related queries.

4.6. At a time when other regulatory initiatives including the ICO’s Children’s Code [6] and the Online Safety Bill [7] seek to increase the level of protection given to children’s data, the Bill threatens to reduce protection for individuals by removing a measure created specifically to safeguard individual’s rights.

4.7. Overseas data controllers must be more than just accessible. They must also be willing and able to respond to privacy-related requests. However, many companies outside the UK have a limited awareness of the obligations that the UK GDPR places on them. This includes knowing how to effectively manage data subject rights. Part of the role of the representative is to support overseas organisations through the process of handling data subject requests, thereby ensuring people’s rights are properly recognised and upheld.

4.8. Rather than empowering people as the Government has promised the Bill would do, removal of the legal requirement to appoint a UK representative puts the efficacy of the extra-territorial scope of the UK GDPR at risk and threatens to undermine privacy and data protection by endangering individuals’ rights.

4.9. Failure to preserve the public’s trust in the use of their data by overseas companies because of consumer’s inability to enforce their rights, or a lack of recognition of such rights, will ultimately result in an unwillingness to engage with such organisations. This will create a far greater barrier to trade with the UK than the proportionate requirement to appoint a UK representative.

5. Threatening Data Breach Reporting

5.1. The swift identification and reporting of a data breach is a crucial step in reducing the implications of that breach. The focus of any breach response plan must be on protecting individuals and their personal data. This may include communication of the breach to individuals to allow them to take steps to protect themselves from its potential consequences.

5.2. Where a controller or processor without an establishment in the UK that is subject to Article 3(2) of the UK GDPR experiences a data breach, it is bound by the notification obligations under Articles 33 and 34 of the UK GDPR.

5.3. A key part of the role of the UK representative is, therefore, to support overseas companies in the handling of data breaches. This includes assessing the possible adverse consequences for individuals and making the required notification to the ICO and/or those whose data is affected.

5.4. Removal of a legal requirement to appoint a representative may mean that some overseas organisations lack awareness of their data breach management and notification obligations, allowing breaches to go unreported, or delays in notification occurring. This creates the risk of greater harm to the individuals whose data has been compromised.

6. Increasing work for the Information Commissioner’s Office

6.1. All organisations caught by the UK GDPR are required to cooperate with the ICO and the ICO has the power to order controllers and processors to provide it with such information as it might request.

6.2. As with data subjects, the appointment of a UK representative is designed to enable access to overseas organisations by the ICO to ensure the effective enforcement of the UK GDPR.

6.3. Overseas companies can often be reticent about assisting a foreign regulator or may not recognise that they are obliged to do so. This can increase the workload of ICO case handlers and may ultimately frustrate an ICO investigation entirely.

6.4. Aggressive marketing practices example:

The ICO received a significant number of complaints from, or on behalf of, individuals that had been the recipients of intrusive and repetitive unsolicited cold calls. Many of the recipients were vulnerable individuals. The ICO served an investigatory letter on Prighter as the UK representative of a company under investigation in respect of such calls. Prighter’s client was initially very reluctant to provide any information to the ICO. In fact, the client’s brand had been the subject of passing off by a third party. Following discussions between Prighter and the client, the client agreed to engage with the ICO to provide evidence of the third party’s use of the client’s brand. The ICO were then quickly able to identify the true source of the offensive cold calls and proceed with their investigation against the correct overseas entity.

6.5. Difficulty in accessing overseas companies, and the loss of the representative as a mediator, may increase the time taken by the ICO to conclude an investigation, during which time further damage to individuals may occur, including to those in most need of protection. In some cases, these issues may frustrate an investigation entirely, meaning a lack of ability to enforce the UK GDPR against some non-UK companies.

6.6. The inability of the ICO to enforce the UK GDPR against overseas organisations renders the protections given to individuals under it completely worthless. The European Data Protection Board recently published the findings of a study on the enforcement of GDPR obligations against companies without an establishment in the country in which a relevant supervisory authority is located [8] . The independent study was conducted by researchers of the Centre de recherche, Information, Droit et Société (CRIDS) at University of Namur (Belgium).
The study analysed the practical and effective possibilities available to enforce Supervisory Authorities’ (SAs) investigative ad corrective powers against third-country controllers or processors that fall under the scope of Article 3(2) of the GDPR but are not willing to cooperate with Supervisory Authorities’ and did not appoint a representative. In respect of the role of an Article 27 representative the findings were clear: "the appointment of a controller/processor representative is crucial to the enforcement of SAs investigative and corrective powers". The study went on to conclude that non-compliance with Article 27 GDPR should be punished by administrative fines under Article 83(4)a of the GDPR.

6.7. In addition, providers of UK representative services have, by the nature of their business, an interest in the promotion of the extra-territorial scope, and therefore the requirements of the UK GDPR, to organisations around the world. To do so, they invest time and money in raising global awareness of the UK data protection regime, which ultimately engenders greater protection for individuals. This includes access to resources such as free webinars and open-sourced legal knowledge hubs.

6.8. These activities by the UK representative augment the efforts of the ICO and significantly extend the reach of the regulator beyond the borders of the UK in a way that the ICO does not have the time or resource to do by itself.

6.9. Removal of a legal requirement to appoint a UK representative, therefore, creates the inevitable concern of an overall drop in compliance levels amongst non-UK companies, especially if the loss of the role is interpreted by overseas organisations as a relaxation of the enforcement of the UK GDPR outside its borders.

7. Furthering frustration for UK Businesses

7.1. While the Bill will reportedly save UK businesses £4.7bn over the next decade [9] , removal of Article 27 of the UK GDPR will not produce a cost saving for UK businesses because the requirement only applies to those organisations without an establishment in the UK.

7.2. To the contrary, the loss of the UK representative will, if anything, increase the cost and frustration keenly felt by UK companies when engaging some non-UK suppliers. This is due to the time spent on explaining the requirements of the UK GDPR to those overseas organisations that approach the UK market without an understanding of UK data protection laws.

7.3. Supporting UK businesses example:

Prighter was recently approached by a higher education provider in the UK that had no existing relationship with Prighter, but which had identified that a potential supplier to the university had appointed Prighter as its UK representative. The university was very keen to engage the potential supplier in respect of a key research programme. However, it was struggling to obtain satisfactory responses from the potential supplier to its vendor assessment in relation to specific data protection concerns. Having been contacted directly by the university seeking assistance in explaining the underlying data protection issues to the potential supplier, Prighter was able to support its client in meeting the requirements of the university thereby enabling the university to appoint its chosen supplier and helping its client to secure the business of the UK.

7.4. The UK’s departure from the EU has already created a pain point for UK businesses who find themselves repeatedly having to explain to overseas organisations the UK’s requirements in relation to international data transfers and guide companies through the use of the UK’s International Data Transfer Agreement and addendum to the EU Standard Contractual Clauses.

7.5. Departure from the retained version of the GDPR will cause greater complexity for overseas organisations. This will in turn worsen the headache for UK businesses in dealing with overseas companies that need help to bring their products and services to the UK market in a UK GDPR compliant state.

Removal of the requirement to appoint a representative will only serve to increase the resource required by UK organisations when dealing with non-UK companies, ultimately increasing costs for UK businesses.

8. The true cost of reducing business regulation

8.1. The Government has emphasised that one of the aims of this Bill is to reduce burdens on businesses [10] . The requirement to appoint a UK representative is seen by the Government as an unnecessary compliance burden for overseas organisations and removal of the cost of retaining a representative is designed to boost trade with the UK [11] .

8.3. Prighter appreciates that, as with any compliance regime, the UK GDPR creates a burden on businesses. However, the UK representative is a proportionate and effective means of protecting the rights of individuals by ensuring the availability of non-UK companies. This must be given greater weight than the small cost to businesses associated with retaining a UK representative. In the words of Layla Moran MP during the Second Reading of the Bill in the House of Commons "if there is a conflict, it is absolutely the right of the individual that needs to be protected" [12] . And as summarised by Darren Jones MP during the Second Reading, "the challenge in reducing business regulation and co-designing legislation with stakeholders is knowing how much of an influence the largest, most wealthy voices have over the smallest, least influential voices. In this Bill - that means the difference between the voice of big tech and the voice of the people". 

8.3. While the voice of big tech companies may be most audible, their collective experience of working alongside a UK representative is likely limited as many will have a UK establishment and therefore not require a representative. The Department of Science, Innovation and Technology has, by its own admission, struggled to consult with businesses caught by Article 27 of the UK GDPR because it is a requirement that "applies exclusively to businesses and organisations outside of the UK which makes gathering evidence very challenging" [13] . As noted above in paragraph 6.6, independent research published by the EDPB has established that the role of the representative is crucial in preserving the enforcement of the GDPR. This poses important questions such as where pressure to remove the UK representative has come from, and why the Government is willing to put such a vital consumer right and means of enforcing the UK GDPR at the discretion of overseas organisations to implement rather than retaining a legal requirement to do so.

8.4. There is very little burden produced by the requirement to appoint a representative other than the payment of the fees for the representative’s service. The average cost to a large organisation (one with 250+ employees) of retaining a UK representative is £5,000 per annum [14] . The cost to small and medium sized businesses is significantly less with packages starting at around £400 per year. In addition, Article 27 already includes an exemption for organisations whose processing is occasional, does not include the large-scale processing of special category or criminal offence data and is unlikely to result in a risk to the rights and freedoms of individuals taking into account the nature, context, scope and purposes of the processing.

8.5. It is unlikely that removing the requirement to appoint a UK representative will boost trade with the UK. There is a much greater chance that a reduction in consumer confidence caused over time by the inability of individuals to keep control over the use of their personal data, and the frustration felt by UK businesses in dealing with companies that do not have a good grasp of the requirements of the UK GDPR, will instead have a detrimental effect on trade with the UK.

9. Summary of arguments against removing the role of the UK representative

9.1. The UK representative:

9.1.1. is a crucial consumer right designed to remove barriers that may otherwise prevent the protection and enforcement of the rights of individuals in respect of their personal information;

9.1.2. is an effective and proportionate measure that ensures access to, and accountability of, overseas organisations caught by the UK GDPR for UK stakeholders including data subject, the ICO and UK businesses;

9.1.3. raises awareness outside of the UK’s borders as to the requirements of the UK GDPR and in so doing increases the overall levels of data protection compliance of overseas organisations;

9.1.4. acts as an outward sign of an organisations willingness to comply with the UK GDPR and engendering public trust;

9.1.5. facilitates rather than hampers trade with the UK by increasing consumer confidence and enabling business to business transactions;

9.1.6. offers support to overseas organisations in navigating non-domestic legislation, which will be even more crucial as the UK diverges further from the retained version of the GDPR;

9.1.7. is not duplicative – while several other jurisdictions have implemented a requirement to appoint a representative, representatives covering another jurisdiction will not handle cases in respect of the UK; and

9.1.8. does not act as a genuine barrier to trade with the UK, nor will its removal boost trade.

10. Final words

10.1. The rights of UK individuals must not be at the discretion of overseas organisations to implement. As Mrs Justice Collins Rice put it when paraphrasing the words of the leading counsel for the defendant in the case of Sanso Rondon v. LexisNexis Risk Solutions U.K. Ltd [2021] EWHC 1427 (QB) [15] "the bad guys do not appoint Art. 27 representatives".

Andreas Mätzler

Founder and Attorney at Law

Charlotte Mason

UK Head of Legal and Regulatory

9 May 2023


[1] Stop the Data Discrimination Bill | Open Rights Group; Big Brother Watch responds to publication of the new Data Protection and Digital Information Bill - Big Brother Watch; DPDI-Bill-UK-civil-society-letter.pdf (openrightsgroup.org)

[2] Data Bill No.2 puts rights at risk. Again. - Public Law Project

[3] Data Protection and Digital Information (No. 2) Bill - Hansard - UK Parliament

[4] Online Nation 2021 report (ofcom.org.uk)

[5] https://companiesmarketcap.com/video-games/largest-video-game-companies-by-market-cap/

[6] Children's code: additional resources | ICO

[7] Online Safety Bill - Parliamentary Bills - UK Parliament

[8] Study on the enforcement of GDPR obligations against entities established outside the EEA but falling under Article 3(2) GDPR | European Data Protection Board (europa.eu)

[9] https://hansard.parliament.uk/commons/2023-03-08/debates/23030819000013/DataProtectionAndDigitalInformation(No2)Bill

[10] https://hansard.parliament.uk/commons/2023-03-08/debates/23030819000013/DataProtectionAndDigitalInformation(No2)Bill

[11] https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1140162/Data_Protection_and_Digital_Information_Bill_Impact_Assessment_-_June_2022.pdf

[12] Data Protection and Digital Information (No. 2) Bill - Hansard - UK Parliament

[13] https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1151358/data_protection_and_digital_information_bill_impact_assessment_march_2023.pdf

[14] https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1140162/Data_Protection_and_Digital_Information_Bill_Impact_Assessment_-_June_2022.pdf

[15] https://www.bailii.org/ew/cases/EWHC/QB/2021/1427.html

 

Prepared 10th May 2023