Session 2022-23
Data Protection and Digital Information (No. 2) Bill
Written evidence submitted by DPN Associates (DPDB13)
DPDI No. 2 Bill – Call for Evidence
Role of Senior Responsible Individual
Introduction
Founded in 2014 , the Data Protection Network (DPN) publishes insight and in-depth guidance on data protection for organisations of all sectors and sizes. We also run regular webinars to share experiences and approaches to key data protection challenges facing businesses. We have 7, 5 00 subscribers to the DPN email updates.
The focus of our response to the Call for Evidence is on the appointment of a Senior Responsible Individual (SRI) , as set out in section 14 of the draft Bill. This response represents the collated views of the Data Protection Network’s independent Advisory Group ; a group of experienced data protection professionals from various industry sectors , and DPN Associate’s P artners who work as data protection consultants for large organisations , SMEs and not-for-profits .
The reason we have written this submission is our unanimous concern about the independent role of a Data Protection Officer, as prescribed under current law , being removed from future legislation , and outstanding questions about how the Senior Responsible Individual ( SRI ) role will work in practice.
Executive summary
§ It is not clear how the SRI role adds value for organisations who have already established the role of Data Protection Officer in their organisational structure.
§ For those organisations , who will remain under the scope of EU GDPR and mandatory DPO requirements, the new UK requirement to appoint an SRI appears to add additional complexit y and cost .
§ The removal of the DPO role from UK legislation concerns us, as this takes away the in-built independence and expertise this role provides .
§ The nature of the designation and appointment of a SRI , as part of ‘ senior management ’ , will result in an inevitable and frequent conflict of interest vis-à-vis decisions relating to the compliant processing of personal data and commercial interests of the C ontroller or P rocessor.
§ Rather than replacing DPOs with SRIs in an attempt to relieve organisations of a perceived administrative burden, we propose allowing organisations the flexibility to retain a DPO or appoint an SRI.
§ Consideration could also be given to exempting small and micro sized organisations from compliance with data protection law generally, where the processing of personal data is incidental and/or lower risk. This approach is taken in other countries, such as Australia.
Points for consideration
The current DPDI draft raises a number of questions about how the Senior Responsible Individual (SRI) role would work in practice.
We call on the House of Commons Public Bill Committee to pay due regard to the following points.
1. Many organisations will be required to keep the DPO role to comply with EU GDPR
Draft Article 27(a) states the S enior R esponsible I ndividual must be a member of the organisation’s senior management . It states the role can be held jointly where two people are employed part-time and share a single senior management role.
Th e requirement for an SRI could place an additional burden on organisations which have already invested considerable time, money and resources into establishing the role of Data Protection Officer and in doing so have endeavoured to establish a high level of data protection maturity in their business .
Concern s :
§ It’s a fact m any businesses based in the UK which already have a DPO are also operating with in the EU (i.e. processing the data of EU-based individuals ) . T he se businesses will still be required to retain the role of DPO in their business to make sure they comply with the EU GDPR.
§ The differing requirements between DPDI and EU GDPR mean it is unlikely the same individual could fulfil both roles , as the DPO requirement specifically requires independence from those making decisions in senior management roles .
§ Therefore, the proposed requirement to appoint an SRI under the DPDI will actually become an additional burden . Organisations will need both an SRI and a DPO. While it may be envisaged the new SRI role could delegate all tasks to the DPO, the DPO would no longer have any legal status under UK law if the current draft remains unchanged.
§ The new requirements are likely to lead to:
o increased costs
o potential for difficulties should the two roles (SRI and DPO) disagree on compliance issues
o i nconsistency between how data protection is addressed and managed depending on whether it is UK or EU data
o increased administration
o potential confusion for staff
§ There is a real risk the need to have both roles would detract from the importan ce of having appropriate technical expertise in this complex and specialist area.
Proposed solution
§
Introduce the
option
to appoint a Senior Responsible Individual
or
a Data Protection Officer
(
as an alternative
)
. This
added flexibility will
be particularly helpful for UK organisations which operate in the EU
or globally
and
do
not wish to undermine all the hard work they have done over the past 5 years to establish the DPO
as a key
adviser
in their business.
This would also provide
flexibility for businesses which only operate in
the UK, but
wish to retain their
DPO.
§ It is our view that, were an existing DPO role to be retained, the incumbent shou l d enjoy a similar status in UK law as they do under EU GDPR . So , it would be important to explicitly confirm in DPDI the option for businesses to retain their DPO.
§ DPOs offer significant value to their organisations , not just in terms of compliance with the law but also with respect to championing the rights of individuals, maximising the value of data and fostering a positive culture which embraces good data governance. DPOs often facilitate the design and creation of products and services with privacy and data protection ‘baked-in’ , and take ownership and execution of vital tasks, such as handling privacy rights and conducting risk assessments .
§ We believe th e Government should be encouraging the appointment of DPOs. To that end, we suggest the requirement to appoint a DPO should be retained but that organisations may appoint a DPO on a voluntary basis.
2. Risk of the Senior Responsible Individual (SRI) being appointed ‘in name only’
The intention of a Senior Responsible Individual being a "member of Senior Management" differentiates this role from that of a Data Protection Officer, who under current legislation must be independent. Organisational structures vary considerably . We would draw the Committee’s attention to the following points in this regard:
§ I t raises the question : ‘ who will be considered senior management’ ? Please confirm.
§ I t raises the very real prospect that some SRI s may lack the specialist expertise or even interest in data protection matters, but are ‘nominated’ for the role purely because they sit on the Board / Executive.
§ It is not clear in the current draft Bill if an SRI be allowed to act on behalf of a group of companies, or group of public sector organisations. Under current legislation a this is permitted for DPOs. Confirmation on this point would be welcomed.
3. Tasks performed by another person
Article 27(b) states the S enior R esponsible I ndividual must be responsible for specific tasks or for securing that they are performed by another person.
We have two q uestions requiring clarification in next draft .
§
Does this other person
(or people)
have to be employed by the organisation or could these tasks be outsourced?
The draft is silent on this point.
Currently
some
businesses outsource the role of the DPO
to an external individual/company
, or
a DPO may act for a group of companies.
4. Conflicts of interest
Article 27(b) says ‘ where a conflict of interests may arise the senior responsible individual must secure the task i s performed by another person . ’
§
In our opinion,
members of
senior management team
(
e.g.
Head of Marketing, Chief Financial Office
r
, Head of Legal, Chief Operating Officer,
Chief Executive Officer,
etc)
are
ALL
likely to
face regular conflicts of interests
when handling
data protection matters
.
A conflict of interests is specifically likely to arise when fulfilling the
key
task of
‘informing and advising the controller
"
,
as their advice could be biased by the nature of
their
main role’s objectives
.
§ The c urrent law calls out the requirement for a DPO to be independent . T he draft B ill doesn’t however mandat e for an SRI to act independently with regard to their data protection duties , however it does speak about conflicts of interest . T his is likely to create a n additional burden on organisations to assess where conflicts of interests may arise and where the SRI is judged to be conflicted, decide who else would be most suitable to take on specific tasks.
§ The draft Bill doesn’t say who should have decision-making powers regarding where an SRI is conflicted – are they expected to judge for themselves?
§
The draft also remains silent about
who should carry out
data protection
duties where
the SRI is
conflicted
.
We ask you to consider that
other members of senior management may
also be conflicted and may
not have the expertise
(
n
or enthusiasm)
to tackle cer
t
ain
data protection
tasks
to appropriate standards
s
uch as
carrying out a
risk assessment
, a decision about lawfulness
of processing
,
whether a data breach is notifiable
or whether
the
technical and organisational measures
in place
are
appropriate
.
§ However , if the Bill were to allow an organisation to retain (or appoint) a DPO instead of an SRI, these concerns could be alleviated , due to the independence of the DPO role.
5. Advising processors
The current drafting of DPDI potentially places an obligation on the SRI to inform and advise the P rocessors engaged by the Controller, as well as the Controller themselves. This is inappropriate. Not only would it create contractual difficulties, but would place increased personal liability on the SRI , as well as potentially causing confusion where the C ontroller and P rocessor have differing risk profiles , or compliance policies and processes .
6. Micro businesses data protection exemption
Complying with data protection law can be onerous for small businesses and start-ups
. W
e suggest it is worth considering
an
explicit
exemption for micro-
business
& start-ups which
hold
low
volumes of non-sensitive data
, rather than removing the requirement for a DPO.
Australia
has
an exemption for small businesses with a turnover of under
$3 million, with specific caveats surrounding, for example, small businesses
which
process health data.
This
exemption is under some scrutiny, as small businesses could be doing very innovative activities with personal data.
Therefore
,
such a
n exemption
would need to
have clear limitation
s
, as we have suggested above.
Plain English
As a general comment, it would be welcomed if there could be a drive to make sure future legislation is written in plain English, avoiding unnecessary legalise. An approach adopted in Ireland, Singapore and Australia.
9 May 2023
