Data Protection and Digital Information (No. 2) Bill

Written evidence submitted by DPN Associates (DPDB13)

DPDI No. 2 Bill – Call for Evidence

Role of Senior Responsible Individual

Introduction

 

Founded in 2014 , the Data Protection Network (DPN) publishes insight and in-depth guidance on data protection for organisations of all sectors and sizes. We also run regular webinars to share experiences and approaches to key data protection challenges facing businesses. We have 7, 5 00 subscribers to the DPN email updates.

The focus of our response to the Call for Evidence is on the appointment of a Senior Responsible Individual (SRI) , as set out in section 14 of the draft Bill. This response represents the collated views of the Data Protection Network’s independent Advisory Group ; a group of experienced data protection professionals from various industry sectors , and DPN Associate’s P artners who work as data protection consultants for large organisations , SMEs and not-for-profits .

The reason we have written this submission is our unanimous concern about the independent role of a Data Protection Officer, as prescribed under current law , being removed from future legislation , and outstanding questions about how the Senior Responsible Individual ( SRI ) role will work in practice.

Executive summary

§ It is not clear how the SRI role adds value for organisations who have already established the role of Data Protection Officer in their organisational structure.

§ For those organisations , who will remain under the scope of EU GDPR and mandatory DPO requirements, the new UK requirement to appoint an SRI appears to add additional complexit y and cost .

§ The removal of the DPO role from UK legislation concerns us, as this takes away the in-built independence and expertise this role provides .

§ The nature of the designation and appointment of a SRI , as part of senior management , will result in an inevitable and frequent conflict of interest vis-à-vis decisions relating to the compliant processing of personal data and commercial interests of the C ontroller or P rocessor.

§ Rather than replacing DPOs with SRIs in an attempt to relieve organisations of a perceived administrative burden, we propose allowing organisations the flexibility to retain a DPO or appoint an SRI.

§ Consideration could also be given to exempting small and micro sized organisations from compliance with data protection law generally, where the processing of personal data is incidental and/or lower risk. This approach is taken in other countries, such as Australia.

Points for consideration

The current DPDI draft raises a number of questions about how the Senior Responsible Individual (SRI) role would work in practice.

We call on the House of Commons Public Bill Committee to pay due regard to the following points.

1. Many organisations will be required to keep the DPO role to comply with EU GDPR

Draft Article 27(a) states the S enior R esponsible I ndividual must be a member of the organisation’s senior management . It states the role can be held jointly where two people are employed part-time and share a single senior management role.

Th e requirement for an SRI could place an additional burden on organisations which have already invested considerable time, money and resources into establishing the role of Data Protection Officer and in doing so have endeavoured to establish a high level of data protection maturity in their business .

Concern s :

§ It’s a fact m any businesses based in the UK which already have a DPO are also operating with in the EU (i.e. processing the data of EU-based individuals ) . T he se businesses will still be required to retain the role of DPO in their business to make sure they comply with the EU GDPR.

§ The differing requirements between DPDI and EU GDPR mean it is unlikely the same individual could fulfil both roles , as the DPO requirement specifically requires independence from those making decisions in senior management roles .

§ Therefore, the proposed requirement to appoint an SRI under the DPDI will actually become an additional burden . Organisations will need both an SRI and a DPO. While it may be envisaged the new SRI role could delegate all tasks to the DPO, the DPO would no longer have any legal status under UK law if the current draft remains unchanged.

§ The new requirements are likely to lead to:

o increased costs

o potential for difficulties should the two roles (SRI and DPO) disagree on compliance issues

o i nconsistency between how data protection is addressed and managed depending on whether it is UK or EU data

o increased administration

o potential confusion for staff

§ There is a real risk the need to have both roles would detract from the importan ce of having appropriate technical expertise in this complex and specialist area.

Proposed solution

§ Introduce the option to appoint a Senior Responsible Individual or a Data Protection Officer ( as an alternative ) . This added flexibility will be particularly helpful for UK organisations which operate in the EU or globally and do not wish to undermine all the hard work they have done over the past 5 years to establish the DPO as a key adviser in their business. This would also provide flexibility for businesses which only operate in the UK, but wish to retain their DPO.

§ It is our view that, were an existing DPO role to be retained, the incumbent shou l d enjoy a similar status in UK law as they do under EU GDPR . So , it would be important to explicitly confirm in DPDI the option for businesses to retain their DPO.

§ DPOs offer significant value to their organisations , not just in terms of compliance with the law but also with respect to championing the rights of individuals, maximising the value of data and fostering a positive culture which embraces good data governance. DPOs often facilitate the design and creation of products and services with privacy and data protection ‘baked-in’ , and take ownership and execution of vital tasks, such as handling privacy rights and conducting risk assessments .

§ We believe th e Government should be encouraging the appointment of DPOs. To that end, we suggest the requirement to appoint a DPO should be retained but that organisations may appoint a DPO on a voluntary basis.

2. Risk of the Senior Responsible Individual  (SRI) being appointed ‘in name only’

The intention of a Senior Responsible Individual being a "member of Senior Management" differentiates this role from that of a Data Protection Officer, who under current legislation must be independent. Organisational structures vary considerably . We would draw the Committee’s attention to the following points in this regard:

§ I t raises the question : who will be considered senior management’ ? Please confirm.

§ I t raises the very real prospect that some SRI s may lack the specialist expertise or even interest in data protection matters, but are ‘nominated’ for the role purely because they sit on the Board / Executive.

§ It is not clear in the current draft Bill if an SRI be allowed to act on behalf of a group of companies, or group of public sector organisations. Under current legislation a this is permitted for DPOs. Confirmation on this point would be welcomed.

3. Tasks performed by another person

Article 27(b) states the S enior R esponsible I ndividual must be responsible for specific tasks or for securing that they are performed by another person.

We have two q uestions requiring clarification in next draft .

§ Does this other person (or people) have to be employed by the organisation or could these tasks be outsourced? The draft is silent on this point. Currently some businesses outsource the role of the DPO to an external individual/company , or a DPO may act for a group of companies.

4. Conflicts of interest

Article 27(b) says where a conflict of interests may arise the senior responsible individual must secure the task i s performed by another person .

§ In our opinion, members of senior management team ( e.g. Head of Marketing, Chief Financial Office r , Head of Legal, Chief Operating Officer, Chief Executive Officer, etc) are ALL likely to face regular conflicts of interests when handling data protection matters .

A conflict of interests is specifically likely to arise when fulfilling the key task of ‘informing and advising the controller " ,
as their advice could be biased by the nature of their main role’s objectives .

§ The c urrent law calls out the requirement for a DPO to be independent . T he draft B ill doesn’t however mandat e for an SRI to act independently with regard to their data protection duties , however it does speak about conflicts of interest . T his is likely to create a n additional burden on organisations to assess where conflicts of interests may arise and where the SRI is judged to be conflicted, decide who else would be most suitable to take on specific tasks.

§ The draft Bill doesn’t say who should have decision-making powers regarding where an SRI is conflicted – are they expected to judge for themselves?

§ The draft also remains silent about who should carry out data protection duties where the SRI is conflicted . We ask you to consider that other members of senior management may also be conflicted and may not have the expertise ( n or enthusiasm) to tackle cer t ain data protection tasks to appropriate standards s uch as carrying out a risk assessment , a decision about lawfulness of processing , whether a data breach is notifiable or whether the technical and organisational measures in place are appropriate .

§ However , if the Bill were to allow an organisation to retain (or appoint) a DPO instead of an SRI, these concerns could be alleviated , due to the independence of the DPO role.

5. Advising processors

The current drafting of DPDI potentially places an obligation on the SRI to inform and advise the P rocessors engaged by the Controller, as well as the Controller themselves. This is inappropriate. Not only would it create contractual difficulties, but would place increased personal liability on the SRI , as well as potentially causing confusion where the C ontroller and P rocessor have differing risk profiles , or compliance policies and processes .

6. Micro businesses data protection exemption


Complying with data protection law can be onerous for small businesses and start-ups . W e suggest it is worth considering an explicit exemption for micro- business & start-ups which hold low volumes of non-sensitive data , rather than removing the requirement for a DPO.

Australia has an exemption for small businesses with a turnover of under $3 million, with specific caveats surrounding, for example, small businesses which process health data. This exemption is under some scrutiny, as small businesses could be doing very innovative activities with personal data. Therefore , such a n exemption would need to have clear limitation s , as we have suggested above.

Plain English

As a general comment, it would be welcomed if there could be a drive to make sure future legislation is written in plain English, avoiding unnecessary legalise. An approach adopted in Ireland, Singapore and Australia.


9 May 2023

 

Prepared 16th May 2023