Data Protection and Digital Information (No. 2) Bill

Further written evidence submitted by Judith Ratcliffe, Privacy Professional (DPDIB18)

Dear Scrutiny Committee,

The Information Commissioner's Office - ICO - has posted this on Linked In:

https://www.linkedin.com/company/information-commissioner's-office/

ICO support > >

We support these reforms because we have been able to shape them. We believe they will protect people’s rights and support organisations to innovate with confidence.

Working with Government >
We’ve been involved with the Bill from the outset - the result is that it maintains our already high standards of data protection and will bring benefits for the people of the UK .

ICO independence >>

With greater independence comes greater accountability and as a regulator we welcome that.

From this, it would appear that the ICO has misunderstood many aspects of the Data Protection and Digital Information Bill - in particular in relation to the 'bold' statements I have highlighted above.

It appears that the ICO believes the Bill will 'protect people's rights' - I would ask why the Information Commissioner believes this, since much of the Bill appears, in fact to take away people's Rights and /or make it harder to get Rights actioned.

Schedules 1 and 2 which create a new lawful basis of 'recognised legitimate interests' to take one example, the amendments to Article 22 GDPR, to remove protections and also Section 7, which reduces the threshold for rejecting Rights Requests to 'vexatious' which may mean organisations reject Rights Requests, simply because the complainant/ requestor has annoyed the organisation, coupled with S.24 on National Security amongst others (which I have pointed to in my bundle of evidence to yourselves), all appear to serve to undermine people's Rights and also go against the overarching Article 8 Right to Respect for a Person's Private Life, as set out in the European Convention on Human Rights and Human Rights Act, 1998, in my understanding.

A number of Privacy Professionals and Civil Rights Group- the Open Rights Group, have sounded the alarm on this front and continue to do so.

The changes in the DPDI Bill also appear to go against known Precedents sent out in UK Case-Law:

The changes set out at P14 and 15 of the Data Protection and Digital Information Bill (DPDI Bill), Section 7 - go even further than the DCMS Consultation, which only
referenced Data Subject Access Requests/ DSARs (Requests that allow You to Access a copy of your data and information about how/why/where/when it is
collected, used and stored).

Under the DPDI Bill, a Data Controller may designate ANY and ALL Data Protection Rights Requests as vexatious and they have even added another part of the Bill in
relation to 'vexatious' or excessive requests to the Information Commissioner, which arguably makes everything considerably worse and puts up yet more barriers for you to
get your Rights actioned.

Changing ‘The ‘manifestly unfounded’ threshold to refuse ANY Data Protection Rights Request to the lower threshold ‘vexatious’ is, arguably, fundamentally flawed and will,
arguably unjustly deny people their Rights and cause widespread harm.To take just one example - The Right to Access (Right to Access Request/Data Subject Access Request = DSAR)

In Magnacrest ,

https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2019/02/housing-developer-fined-for-ignoring-data-request/


 Mike Shaw, the ICO’s Criminal Enforcement Manager, said, in 2019:
"The right to access your own personal information is a fundamental and long-standing principle of data protection law."


Two further cases back up the fundamental principle and right: The first is Dawson- Damer , https://www.bailii.org/ew/cases/EWCA/Civ/2017/74.html in which the Court

held that it would be "odd" to conclude that the sole purpose of a DSAR must be to verify the accuracy of the data subject’s personal data.

Such a "no other purpose" rule may have undesirable consequences, such as non-compliance by Data Controllers on the basis that the data subject (may have) an ulterior motive for making the DSAR".

And indeed Data Controllers can find themselves the subject of complaints escalations and even costly litigation where they unfairly refuse DSARs on the basis of such supposed ulterior motives. Data Controllers shouldn’t be permitted to presume such ‘guilt’.

The UK Government is arguably highly likely to expose itself to legal challenges if it continues with its proposal and, by so-doing , exposes organisations to a huge rise in complaints that those organisations will not thank the UK Government for imposing upon them.

The second case, that backs up my assertions, is Ittihadieh v Cheyne Gardens & Ors and Deer v University of Oxford [2017] EWCA Civ 121

In this case, the Court held that ‘although the underlying purpose of a DSAR is to check the accuracy of their data and to see if it is being processed lawfully, the right of access is not subject to "any express purpose or motive test". It was also held that "the fact that a data subject may have "collateral purposes" such as litigation, when making the DSAR, will neither invalidate it, nor relieve data controllers of their obligation to respond’.

It is, arguably, vitally important to pay heed to these cases and delete the parts of the Data Protection and Digital Information Bill that undermine people’s fundamental rights. The Bill may cause people, and their ability to get action on their fundamental rights, serious harm.

The term ‘vexatious’ is highly subjective and would be an unfair barrier. The impact on people, who are trying to get their Rights upheld, would be, in some cases devastating.

I remember several cases, where organisations at first glance would have happily used such an excuse to shut down individuals’ requests. However, on further investigation by
the Data Protection Team, the individuals were all proven correct in their allegations and their complaints and Rights Requests were, ultimately, upheld.

They, arguably, shouldn’t have had to ‘make a fuss’ or write in multiple times for someone to treat them reasonably and listen to what they had to say, but they did, because the attitude taken towards them, from the very first person they spoke to, was ‘they’re kicking up a fuss, so we’re going to shut them down’.

In another set of cases, requests had only been partly dealt with, and so the individual had to keep writing back, to get the rest of the data they had asked for, which they knew the organisation held, because they had been told that it was held. Again, it wasn’t the individuals’ fault that they needed to write again (the fault lay with the people who had given incomplete responses the first time round), but the organisations in question didn’tlike it and would have shut them down for being ‘vexatious’ if they could, yet again, until the Data Protection Team got involved, and started directing matters properly.

Sometimes Rights Requests aren’t even passed to the Data Protection Team to handle, again, resulting in completely inappropriate pushbacks, and the individual has to communicate many times over, even to get someone to escalate to the correct team.

The effect of the Data Protection and Digital Information Bill may be to permit such bad attitudes and practices to have a 'legal' footing. Enshrining such bad attitudes (and practices) in Law will lead to people being blocked, with an insurmountable barrier, from having their Rights actioned. This disenfranchises people of a set of Fundamental Human Rights and is arguably likely to impact people’s mental (and possibly physical) well-being as a direct result- Through stress, distress and moral injury.

The Sections of the DPDI Bill that I have highlighted are arguably both unethical and unlawful, and, arguably wouldn’t reduce costs for organisations, either. Again, to take the example of Right to Access Requests, organisations will still have to provide all of the information required by Article 15, as well as copies of personal data.

In addition to undermining Trust and lowering UK Data Protection standards, the DPDI Bill may cause costs of complaints handling and handling legal action to rise from the 'lucky' (if you can call them that!) few who can afford to take organisations and/or the UK Government to Court (both from a money and job-preservation perspective).

Many more people may lose out on their Rights as they won’t be able to afford to take organisations to Court, which will mean that, as well as causing (sometimes serious) harms to individuals (because they can't check accuracy of their data, get inaccurate data corrected, or get, sometimes harmful data destroyed, sometimes get data destroyed to prevent harm), which can sometimes even lead to people who have no credit issues being mixed up with those who do and can also lead to taxation mix-ups with consequent unfortunate penalties falling on entirely innocent parties) organisations' bad behaviour will get worse and may lead even to serious personal data breaches because poor conduct is left unchecked.

In addition, whilst an individual may not be able to finance a legal challenge under the proposed new regime, the Government should be aware of the increasing number of cases where Group Litigation is encouraged by the Legal Profession and the escalating costs of such legislation which could, in fact, lead to greater costs for the UK Government and/or the companies subject to such litigation.

Those that can afford to take organisations to Court may be triggered to litigate, when litigation would have been unnecessary if the organisation had handled their Rights Request fairly and properly in the first place.

UK organisations may be left with further costs of having to try to handle two different processes, one for the European Union/ Europe and one for the UK or risk losing profits from losing European business. European Citizens rights will remain fully protected under the GDPR. It appears to me to be fundamentally wrong that UK Citizens should be less well protected than those who live in the European Union/ who are EU Citizens and it would also be discriminatory to charge UK Citizens when they cannot do so for those from the EU.

One wonders what issues it may cause if the Republic Of Ireland's Citizens had more Rights and/or better protections for them than those in Northern Ireland.

It may be worth remembering that Your Data Protection Rights are Human Rights, NOT privileges and no Government or other organisation should ever be entitled to restrict that, or, take it away without reaching a very high bar, indeed, a bar, that must always be much higher than simply because we have annoyed it.

It appears that the ICO believes that the Bill will ' maintain our already high standards of data protection and will bring benefits for the people of the UK . '

Unfortunately, my understanding is a little different, since the Data Protection Standard appears to be being clearly and demonstrably lowered, by the removal of Rights and barriers to getting action on those Rights (some of which in this email, aforementioned, many others already handed to yourselves in my evidence bundle on Parts 1-5 of the Bill, if I may kindly refer you to that to avoid too much repetition) as well as by reducing the Data Protection Test for Third Country and International Transfers (which includes viewing and accessing personal data abroad, not just sending it from/ to there).

Such a reduction in Rights and Rights Protections, as well as the arguably problematic new 'data protection test' for third country and international transfers as well as what appears to be the lack of requirement for "effective and enforceable data subjects rights or effective legal remedies" for the transfer mechanisms that fall under S.2 of Article 46 (including Standard Contractual Clauses and Binding Corporate Rules, to name two), appear to widely differ from what the EU is doing and may well cause the European Union to deem the UK no longer 'adequate' and cause issues with data flows between them as a direct or indirect result.

These documents may assist the Scrutiny Committee further with understanding the issues I highlight:

https://www.privacysecurityacademy.com/wp-content/uploads/2021/01/edpb-recommendations-202002-europeanessentialguaranteessurveillance-en.pdf

If I may direct the committee in particular to the following paragraphs:

Paragraph 4. In its Schrems II judgment, the CJEU stated that the examination of the Commission Decision 2010/87/EU on standard contractual clauses for the transfer of personal data to processors established in third countries, in the light of Articles 7, 8 and 47 of the Charter, has disclosed nothing to affect the validity of that decision, but invalidated the Privacy Shield Decision. The CJEU held that the Privacy Shield Decision was incompatible with Article 45 (1) GDPR, in the light of Articles 7, 8, and 47 of the Charter. The judgment can thus serve as an example where surveillance measures in a third country (in this case the U.S. with Section 702 FISA and Executive Order 12 333) are neither sufficiently limited nor object of an effective redress available to data subjects to enforce their rights, as required under EU law in order to consider the level of protection in a third country to be "essentially equivalent" to that guaranteed within the European Union within the meaning of Article 45 (1) of the GDPR.

Paragraph 20. The CJEU reiterated that EU legislation involving interference with the fundamental rights guaranteed by Articles 7 and 8 of the Charter "must lay down clear and precise rules governing the scope and application of the measure and imposing minimum safeguards, so that the persons whose personal data is affected have sufficient guarantees that data will be effectively protected against the risk of abuse ", in particular where personal data is subjected to automatic processing and "where there is a significant risk of unlawful access to that data".

Section 3. THE EUROPEAN ESSENTIAL GUARANTEES

Paragraph 24. Following the analysis of the jurisprudence, the EDPB considers that the applicable legal requirements to make the limitations to the data protection and privacy rights recognised by the Charter justifiable can be summarised in four European Essential Guarantees:

A. Processing should be based on clear, precise and accessible rules
B. Necessity and proportionality with regard to the legitimate objectives pursued need to be demonstrated
C. An independent oversight mechanism should exist
D. Effective remedies need to be available to the individual


Paragraph 25. The Guarantees are based on the fundamental rights to privacy and data protection that apply to everyone, irrespective of their nationality.

Pages 7-14 are also significant.

This document may also be helpful to aid the Scrutiny Committee's understanding.

https://edpb.europa.eu/system/files/2021-06/edpb_recommendations_202001vo.2.0_supplementarymeasurestransferstools_en.pdf

The ICO also appears to believe that he and his office will have greater ' independence ' when the reverse appears to be true. Again, as I have evidenced in my articles on the subject, provided within my bundle on Part 5 of the DPDI Bill.

For ease:

The UK Information Commissioner's Office (ICO) appears to be being disbanded and rebranded, to become the Information Commission [ P112, Paragraph 101 Abolition of the office of Information Commissioner ], with a new 'raison d'être', which appears to take it away from, what, arguably its core aims and objectives should be - i.e. to stand up for and enforce people's Privacy Rights (wider than Data Protection) of which some are enshrined in Article 8 of the European Convention of Human Rights and Human Rights Act, 1998, some are in the UK-GDPR and some are in the Privacy and Electronic
Communications Regulations, 2003 (PECR) and just a few are in the Data Protection Act, 2018.

Individuals have the Right to: benefit from special procedural safeguards and an effective procedural framework to uphold one’s rights. P67, https://www.echr.coe.int/Documents/Guide_Data_protection_ENG.pdf

Arguably such safeguards and framework should include a Supervisory Authority that is mandated to protect people's fundamental Rights and actively enforces for single individuals, not just groups and not only those who it deems particularly vulnerable, and, thereby 'worthy' of its support.

Specifically, the GDPR and UK-GDPR set out that the relevant Supervisory Authority, in this instance, the ICO is subject to the following provisions:

https://gdpr-info.eu/

Art. 51 GDPR: Supervisory authority
1. Each Member State shall provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation, in order to protect the
fundamental rights and freedoms of natural persons in relation to processing...

Art. 57 GDPR Tasks
a) monitor and enforce the application of this Regulation;
f) handle complaints lodged by a data subject, or by a body, organisation or association in accordance with Article 80 , and investigate, to the extent appropriate, the subject
matter of the complaint and inform the complainant of the progress and the outcome of the investigation within a reasonable period, in particular if further investigation or
coordination with another supervisory authority is necessary;
v) fulfill any other tasks related to the protection of personal data.

Art. 55 GDPR Competence
1. Each supervisory authority shall be competent for the performance of the tasks assigned to and the exercise of the powers conferred on it in accordance with this
Regulation on the territory of its own Member State.

Recital 122 Responsibility of the Supervisory Authorities*
Each supervisory authority should be competent on the territory of its own Member State to exercise the powers and to perform the tasks conferred on it in accordance with
this Regulation. ...This should include handling complaints lodged by a data subject, conducting investigations on the application of this Regulation...

The Data Protection and Digital Information Bill (DBDI Bill), on the other hand, as well as, again, lowering the threshold for dismissing a case, to 'vexatious' [set out in
Page 69 DPDI Bill Number 2 Paragraph 165A - Power of Commissioner to refuse to act on certain complaints], changes the ICO's overriding objectives from those set out in the GDPR and in the ECHR's Guidelines to:

' secur [ ing ] an appropriate level of protection for personal data, having regard to the interests of data subjects, controllers and others and matters of general public interest'
and


'to promote public trust and confidence in the processing of personal data' -Paragraph 120A, P47, of the DPDI Bill, Number 2.

These changes, arguably significantly lower the standard of Data Protection and arguably shift the focus away from protecting people and their Rights.

Paragraph 120B, (P48 DPDI Bill Number 2) confirms that the Information Commissioner's duties will include:
' hav [ ing ] regard to such of the following as appear...relevant in the circumstances
a) the desirability of promoting innovation
b) the desirability of promoting competition
c) the importance of the prevention, investigation, detection and prosecution of criminal
offences,
d) the need to safeguard public security and national security.'

Paragraph 120C, P48 DPDI Bill Number 2, sets out that there must be a strategy for
the ICO to carry out its tasks under 120A and B.

Read together and juxtaposed with the Duties and Powers under the UK-GDPR, it can be seen that there appears to be a direct conflict of interests between the ICO's duties
and powers designed to help it in its position as Supervisory Authority to protect the Rights and Freedoms of individuals (as set out in the UK-GDPR and the ECHR Guidance) and these new requirements in the DPDI Bill.

Also it may be worth remembering that undermining people's Privacy and Data Protection Rights, in fact harms National Security and Public Security, again as I have outlined in the bundle (Part 1 in particular may be of assistance to the committee in this regard) and it may be worth considering (again evidence within Part 1 of the bundle, already provided) that Public Security Agencies and Law Enforcement Agencies, appear to have been proven time and time again to already have enough data about people to carry out their tasks effectively (without any need to legislate to get them more/ for them to obtain more - this makes things like biometrics/ facial recognition for police work arguably unnecessary, to take a simple example).

Both the new paragraphs and Paragraph 120E, of P49 of the DPDI Bill Number 2, which states that 'the Secretary of State may designate a statement as the statement of strategic priorities'... if certain conditions are met, appears to suggest that the ICO may also no longer be as independent as is required of a Supervisory Authority for the purposes of Data Protection, which again may have an adverse impact on people getting their Rights upheld.

It is a long-held principle of EU Law that Legislation must be clear and readily applicable by those who are subject to it- It appears from the wide debate surrounding the Bill that the legislation is not at all clear, on many of these points.

I respectfully thank the Scrutiny Committee for taking the time to read and review my concerns and to take them into account when considering the Data Protection and Digital Information Bill and the ICO's evidence and statements in relation to it.

With Kind Regards

Judith Ratcliffe

May 2023

 

Prepared 16th May 2023