Data Protection and Digital Information (No. 2) Bill

 Written evidence submitted by Lucy Purdon, Senior Tech Policy Fellow at Mozilla Foundation (DPDIB24)

Evidence on the Data Protection and Digital Information (No. 2) Bill and proposed amendments to the House of Commons Public Bill Committee.

 Executive Summary

It is my personal view that aspects of the The Data Protection and Digital Information (No. 2) Bill (the Bill) weaken protections and increase barriers to people’s enjoyment of and ability to exercise their rights.

Data protection gives meaningful rights to individuals and control over when and how their data is used and for what purposes. The switch of focus to "reducing the burden" on companies weakens hard fought protections against, for example, the harms of the online advertising industry. In addition, transparency and accountability are crucial for trustworthy AI development and data protection greatly contributes to this goal.

The following comments are presented in the context of the UK’s forthcoming online advertising reform [1] and consideration of the whitepaper, "A pro-innovation approach to AI regulation" [2] . Data protection law is the centrepiece of existing protections in both of these proposals.

The Bill increases barriers to exercising and enjoyment of rights under data protection by introducing the notion of "vexatious" or "excessive" subject access requests; no longer requiring data controllers to appoint a UK based representative; removing the requirement to conduct data protection impact assessments and only requiring records of processing to be kept if activities are considered "high risk", which is not defined. As a whole, these changes remove incentives for companies to respect privacy and present additional barriers to people exercising their rights.

Introducing "direct marketing" as a "recognised legitimate interest" as grounds for lawful processing and removing the balancing exercise in the interest of the data subject is out of step with efforts to reign in invasive online tracking. It will be even harder to exercise the right to object to personal data being used in direct marketing.

There is a growing body of evidence demonstrating the need for human review of automated decisions and the ability to analyse and challenge algorithmic decisions as AI develops. Reframing Article 22 to remove the general prohibition on solely automated decision making undermines this need. Article 22 is one of the only legislative checks and balances we have on the application of AI, at a time when the whole world is calling out for the development of AI to be paused or regulated. We are still at the stage where we should be questioning whether AI should be used at all in high-stakes consumer environments like health or credit.

Article 22 should be strengthened. It could align more with the requirement in the proposal for AI regulation that requires organisations to make it clear when they are using AI. Including mandatory safeguards related to transparency when automated decision making takes place could go some way to supporting this principle.

Removing consent requirements for cookies, even where there is a low risk to privacy, should still be subject to safeguards to avoid broad interpretations that could allow, as technology develops, additional data collection, profiling and targeting without consent. To future proof protections and avoid broad interpretations the clause could clarify that improvement of a service does not include profiling or targeting.

 Introduction

I welcome the scrutiny provided by the Public Bill Committee and thank the Committee for the opportunity to submit comments on the Bill. [3]

I have worked at the intersection of tech policy and human rights for over ten years. In my role as a Senior Tech Policy Fellow at Mozilla Foundation [4] I am focused on incorporating a gender perspective into online advertising reform in the UK and EU, with the aim of achieving greater protections for women’s health data. [5] Since 2019, Mozilla Foundation has focused a significant portion of its internet health movement-building programs on AI, with a core focus on trustworthy AI. This aligns with my research goals, alongside the enforcement of data protection laws.

In my previous role as Policy Director at Privacy International (PI), I relied on data protection legislation when advocating for improved transparency and accountability in the online advertising ecosystem, especially harms caused by data brokers and ad tech companies, leading to action by regulators in the UK and EU. [6]

I co-ordinated PI’s submission to the first consultation on data protection reform in November 2021 [7] . PI raised concerns about the framing of the proposal, which was in danger of being driven by the commercial interests of a few companies who may benefit from weaker rights protections. The result was the proposed loss or weakening of important protections for people.

I also coordinated PI’s response to DCMS’ Online Advertising Programme consultation to review the regulatory framework for paid for online advertising [8] in June 2022. Here PI advocated for stronger enforcement of existing data protection standards.

With AI developing at speed, there is no time to waste. The ICO has already warned organisations they must assess the risks of using emotion analysis technologies before implementing systems due to the risks of discrimination. [9] The EU AI Act will ban the use of emotion recognition AI-powered software in the areas of law enforcement, border management, workplace, and education. [10]

I urge the Committee to scrutinise the Bill with regard to the proposal for AI regulation and online advertising reforms and uphold strong data protection to ensure responsible innovation in both sectors benefit society for years to come.

Part 1 of the Bill (Changes to the Data Protection regime)

 1. The Bill increases barriers to exercising and enjoyment of rights under data protection.

1.1 The Bill weakens a number of existing protections for data subjects:

Clause 7 (3) inserts Article 12A and Article 12B: Charging fees for "vexatious" or "excessive" subject access requests, lengthening the timeframe for data controllers to respond and exemptions of information provided.

Removal of Article 27: Data controllers will no longer be required to appoint a UK based representative.

Removal of Article 30: Removing the requirement to keep records of processing unless processing activities are considered "high risk".

Replacing heading of Article 35 from "Data protection impact assessment" (DPIA) to "Assessment of high risk processing". Removing the requirement to conduct DPIA’s as standard. Records of processing personal data only kept if processing deemed "high risk" to rights and freedoms of individuals.

The term "high risk" is not defined.

1. 2. As a whole, these changes remove incentives for companies to respect privacy and present additional barriers to people exercising their rights.

1. 3. To put in context, it is often hard enough for people to find out which companies have their data in the first place in order to then exercise their rights. The ad tech and data broker industry is made up of companies you have never heard of, the mysterious "third parties" or "business partners" sometimes referenced in so many clicked-accept-but-didn’t-read privacy policies. Their business is to collect a huge amount of personal information from all over the internet and essentially sell it for marketing purposes. [11]

1.4 The ICO has called this kind of activity "invisible processing", where an individual is not aware that personal data is being collected and processed. The ICO says, "Invisible processing results in a risk to the individual’s interests as they cannot exercise any control over [..] use of their data. In particular, they are unable to use their data protection rights if they are unaware of the processing." [12]

1.5 The harms of invisible processing run right the way through the industry, as demonstrated through investigations into, for example, pregnancy clubs [13] , mental health apps [14] and menstruation apps [15] , where personal data was collected and sold or shared without the user’s knowledge or consent.

1.6 The hope is that forthcoming online advertising reform will go some way to tackle this extractive and intrusive ecosystem, but the right of people to access the data organisations hold about them, challenge and object to its use and request deletion is a cornerstone of data protection. Existing data protection law is key to curbing abuses like those outlined above and holding organisations accountable.

1.7 In the context of AI, this issue is going to get worse without strong data protection as one of several regulatory and legislative protections needed. Restricting individuals rights to their own data is problematic for many data subjects trying to address a power imbalance in the application of AI. For example, low paid gig economy workers are increasingly challenging decisions made by algorithms which affect their pay and employment. [16] This journey begins with finding out what data the company holds about them and it is essential for companies using automated decision making to adhere to data protection principles.

1.8 As we enter a new era of the use of personal data in the development of AI products and services, it is important to keep the fundamental rights and freedoms of people at the forefront, and this starts with data protection.

1.9 The Mozilla Foundation white paper, Creating Trustworthy AI [17] , sketches out a vision and theory of change for achieving this goal. It identifies parallels between the problems of the online advertising industry and the challenges of AI. In a section on data governance and privacy, the report warns,

"Because AI requires access to large amounts of training data, companies and researchers are incentivized to develop invasive techniques for collecting, storing, and sharing data without obtaining meaningful consent.

In the decades spent developing the online advertising ecosystem, companies have engaged in invasive data collection without meaningful user consent in an effort to amass data and gain a competitive edge, all while skirting accountability. The ubiquity of complex, invasive ad targeting on the web has led many internet users to begrudgingly accept that large tech companies have access to their data.

…even with GDPR limitations in place, companies may continue to collect data without obtaining meaningful consent. It is unclear, for instance, whether individual requests for deletion of personal data filed under the GDPR may apply to models trained on personal information." [18]

Now is not the time to reduce protections which will impact on the safety, transparency and accountability of AI and undermine public trust in its use and application. Or undermine the goal of online advertising reform "to tackle the evident lack of transparency and accountability across the whole supply chain." [19]

 2. Introducing "direct marketing" as a "recognised legitimate interest" as grounds for lawful processing is out of step with efforts to reign in invasive online tracking.

2.1 Under the current UK GDPR, processing for "legitimate interests" is one of six lawful bases for processing personal data. It allows flexibility to process personal data without a particular purpose (such as fulfilling a contract) and where an individual has not given specific consent. Processing personal data on this basis is subject to an important "balancing exercise" to demonstrate the processing is in an organisation’s legitimate business interest and does not impact the data subject's fundamental rights and freedoms.

2.2 The concept of legitimate interests is broad and already gives organisations a lot of flexibility. The balancing exercise is at the heart of using legitimate interests as a legal basis for processing personal data. Without it, only business interests are considered and not the data subject’s rights.

2.3 The Bill inserts Article 6(1) into the UK GDPR, creating a new lawful ground for processing personal data where it is necessary for a "recognised legitimate interest" without the necessity to perform a balancing exercise. One of these recognised legitimate interests is "processing for the purposes of direct marketing".

2.4 Rectial 47 of the UK GDPR says that legitimate interests "may" apply to direct marketing, but the balancing exercise must be applied. [20]

2.5 Clause 81 of the Bill inserts a definition of direct marketing in PECR, which is welcome:

"Meaning of "direct marketing"

In regulation 2(1) of the PEC Regulations (interpretation), at the appropriate place, insert-

""direct marketing" means the communication (by whatever means) of advertising or marketing material which is directed to particular individuals;"."

2.6 To recognise direct marketing as a legitimate interest and remove the balancing exercise in the interest of the data subject in the Bill is out of step with efforts to reign in invasive online tracking. It will be even harder to exercise the right to object to personal data being used in direct marketing. Not only does this overturn decades of data protection law, it travels in the opposite direction of the current trends for reigning in invasive ways to track people online. Direct marketing online involves the collection of a range of personal information, from personal details to browsing habits from first and third party cookies and tracking pixels. The online advertising industry, the source of the majority of online tracking, is undergoing huge technical [21] and regulatory changes, not least in the UK’s own proposal "to tackle the evident lack of transparency and accountability across the whole supply chain." [22]

2.7 The internet is built on advertising revenues, which means that many apps and websites are collecting information and passing it on to third parties. Data brokers then use this information for the purpose of advertising, decision making, and profiling – often without the user’s knowledge or informed consent. This has long been a focus of ICO investigations. [23]

2.8 The current cycle of data collection, profiling, and targeting has a unique impact on women. When it comes to personal information relating to reproductive rights – such as menstruation, pregnancy, birth, miscarriage, abortion and menopause – intimate details are being fed into algorithms for unknown reasons and producing unknown results. Trustworthy AI starts with the data that is collected, and women are being betrayed at every turn.

2.9 It is a practice so ubiquitous, yet the resulting targeted advertising can be so wrong and distressing. Tommy’s, the UK charity advocating for safer pregnancy and research into baby loss, even published advice on how to stop adverts for baby products following you around the internet after suffering a miscarriage. [24]

2.10 The complex and opaque online advertising ecosystem needs more transparency, not less. Removing the requirement to conduct balancing exercises when using legitimate interest as a lawful basis when processing personal data for the purposes of direct marketing is a backward step. I urge the Committee to recognise the harms and reconsider this carte blanche use of personal data for direct marketing.

 3. Protect Article 22: Automated decision making

3.1 Data protection law stands out as one the UK’s most established laws to specifically tackle AI related harms. As the UK’s proposal for AI regulation [25] relies on enforcing existing laws in line with a set of principles, it is even more important to retain robust protections in the laws we already have. Article 22 is one of the only checks we have on the deployment of automated decision making, a type of AI system that has the potential to have profound impacts on people. Therefore it is a relief that Article 22 has not been removed from the UK GDPR altogether following the first consultation on data protection reform in November 2021.

3.2 However, Article 22 is already complex and has been significantly reframed in the Bill. Currently, Article 22 of the UK GDPR prohibits solely automated decision making, framed as an individual’s right not to be subject to it, with three specific conditions where it could take place. [26]

3.3 The ICO has clear guidance on the significance of Article 22 for people’s rights. People have the right,

"Not to be subject to a decision that is based solely on automated processing if the decision affected their legal rights or other equally important matters eg. automatic refusal of an online credit application, and e-recruiting practices without human intervention.

To understand the reasons behind decisions made about them by automated processing and the possible consequences of the decisions.

To object to profiling in certain situations, including for direct marketing." [27]

3.4 There is a growing body of evidence that demonstrates the importance of this existing protection and the need to strengthen it. Automated decision making can be responsible for cutting the pay or firing gig economy workers. [28] Algorithmic hiring can be biassed against women. [29] Automated decision making decides who does or does not get a mortgage or a loan [30] or who gets a visa. [31] Who can forget the disastrous AI grading system which risked significantly impacting the lives and future of thousands of students in 2020? [32] These examples highlight the need for human review of automated decisions and the ability to analyse and challenge algorithmic decisions.

3.5 Although complex, the current Article 22 is the best line of defence against these costly mistakes and abuses. As AI develops at speed, the ability to question and contest automated decision making in our lives is increasingly important. There are already indications it should be strengthened. Existing examples of contesting AI-related harms are resource intensive and the burden of proof placed on the user, as demonstrated in the landmark case brought in the Netherlands to contest an algorithmic welfare risk assessment, which was brought under human rights law rather than the GDPR . [33]

3.6 The Bill replaces Article 22 with new Articles 22A-D, removing the general prohibition on solely automated decision making and instead focusing on specific safeguards when a "significant decision" is being taken through solely automated processing.

3.7 The safeguards mirror the existing Article 22, although the Secretary of State will have the power to amend safeguards and also what is considered to be a "significant decision". In the current climate, it is worrying to think how this power might be applied without Parliamentary oversight to vulnerable people such as those on welfare, migrants and asylum seekers.

3.8 Reframing Article 22 in this way reframes it away from the right of people into the right for organisations to innovate at all costs. It is one of the only legislative checks and balances we have on the application of AI, at a time when the whole world is calling out for the development of AI to be paused or regulated. We are still at the stage where we should be questioning whether AI should be used at all in high-stakes consumer environments like health or credit.

3.9 The proposed Article 22 opens up the potential for automated decision making and therefore more areas where people can be impacted by the decisions. It shifts the burden onto users to not only know when automated decision making is involved, but also the impact it has on their lives, what data has been used about them and the avenues to challenge decisions.

3.10 Article 22 should be maintained as it and efforts to strengthen it by aligning with the requirement in the proposal for AI regulation requiring organisations to make it clear when they are using AI. Including mandatory safeguards related to transparency when automated decision making takes place could go some way to supporting this principle.

  Part 4: Privacy and Electronic Communications

4.1 Clause 79 of the Bill amends the PEC regulations to introduce exemptions from the cookie consent requirement. These include removing consent requirement where the sole purpose of "cookies and similar technologies", including,

"For the purpose of collection of statistics, carried out with a view to improve the website or information society service, (Regulation 6(2A))."

4.2 Removing consent requirements, even where there is a low risk to privacy, should still be subject to safeguards to avoid broad interpretations that could allow, as technology develops, additional data collection, profiling and targeting without consent.

4.3 Although statistical purposes are defined in Part 1 2.6 (a), the explanatory notes accompanying the Bill give examples of statistical information as, "...showing how many people are accessing a service, what they are clicking on and for how long they are staying on a particular web page". [34] The examples in italics are core information for profiling activities. To future proof protections and avoid broad interpretations, the clause could clarify that using statistics for improvement does not include profiling or targeting.

END 

May 2023


[1] Online Advertising Programme - GOV.UK

[2] A pro-innovation approach to AI regulation - GOV.UK

[3] Data Protection and Digital Information (No. 2) Bill - Parliament (publications)

[4] www.mozilla.org

[5] Lucy Purdon, The Context "FemTech : healthcare revolution or source of exploitation? " 8th March 2023

[6] See UK data regulator takes enforcement action to rein in data brokers' use of people's personal data | Privacy International (27th October 2020) and BREAKING: following PI investigation into exploitation of data, Quantcast is under investigation by Irish Data Protection Commission | Privacy International (2nd May 2019) and French regulator launches investigation of Criteo following PI's complaint | Privacy International (13th March 2020 ) and Mental health site sharing your personal data? We're going after them | Privacy International (updated 25th January 2022)

[7] PI's response to DCMS' consultation on data protection reform in the UK | Privacy International (31st May 2022)

[8] PI's response to DCMS' Online Advertising Programme consultation in the UK. | Privacy International (28th June 2022)

[9] ‘Immature biometric technologies could be discriminating against people’ says ICO in warning to organisations (26th October 2022)

[10] www.europarl.europa.eu/news/en/press-room/20230505IPR84904/ai-act-a-step-closer-to-the-first-rules-on-artificial-intelligence

[11] Lucy Purdon, Al Jazeera, " Advertisers should fear more than the chaos at Twitter " 17th December 2022

[12] Principle (a): Lawfulness, fairness and transparency | ICO

[13] How a company illegally exploited the data of 14 million mothers and babies | Privacy International (15th September 2021) and Emma's Diary fined £140,000 over data sale to Labour - BBC News (9th August 2018)

[14] Are mental health apps better or worse at privacy in 2023?| Mozilla Foundation (May 1st 2023) and Your mental health for sale | Privacy International (3rd September 2019)

[15] No Body's Business But Mine: How Menstruation Apps Are Sharing Your Data | Privacy International (updated 7th October 2020) and Reproductive Health | Privacy & security guide | Mozilla Foundation and Ban surveillance-based advertising – Forbrukerrådet

[16] Managed by Bots: surveillance of gig economy workers | Privacy International (13th December 2021) and Privacy International's proposed amendments to the EU Directive on Working Conditions and Platform Work (7th October 2022) and Workers Info Exchange, Historic digital rights win for WIE and the ADCU over Uber and Ola at Amsterdam Court of Appeal (April 4th 2023)

[17] Creating Trustworthy AI |Mozilla Foundation (15th December 2020)

[18] Creating Trustworthy AI |Mozilla Foundation (2020) p16-17

[19] Online Advertising Programme - GOV.UK

[20] GDPR recitals and articles CHAPTER I GENERAL PROVISIONS

[21] The future of ads and privacy | Mozilla Foundation (May 28th 2021 )

[22] Online Advertising Programme - GOV.UK

[23] ICO investigation into data protection compliance in the direct marketing data broking sector - organisations using marketing services of data brokers

[24] How to stop pregnancy ads following you after a loss | Tommy's (14th January 2021)

[25] AI regulation: a pro-innovation approach - GOV.UK

[26] Explanatory notes 34 DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL EXPLANATORY NOTES

[27] Your rights relating to decisions being made about you without human involvement | ICO

[28] See: Managed by Bots: surveillance of gig economy workers | Privacy International (13th December 2021) and Workers Info Exchange, Report reveals the algorithmic dismissal of workers over false fraud allegations at Just Eat (April 22nd 2023) and Workers Info Exchange, Historic digital rights win for WIE and the ADCU over Uber and Ola at Amsterdam Court of Appeal (April 4th 2023)

[29] Gender bias in recruitment: How AI hiring tools are hindering women’s careers | Euronews (8th March 2022)

[30] UK regulators warn banks on use of AI in loan applications | Financial Times (13th February 2022)

[31] Home Office drops 'racist' algorithm from visa decisions - BBC News (4th August 2020)

[32] UK ditches exam results generated by biased algorithm after student protests - The Verge (17th August 2020)

[33] Blackbox welfare fraud detection system breaches human rights, Dutch court rules | TechCrunch (6th February 2020)

[34] DATA PROTECTION AND DIGITAL INFORMATION (NO. 2) BILL EXPLANATORY NOTES (p75)

 

Prepared 16th May 2023