Data Protection and Digital Information (No. 2) Bill

Written evidence submitted by the British Medical Association (BMA) to the House of Commons Data Protection and Digital Information (No.2) Bill Committee (DPDIB40)

About the BMA

The BMA is a professional association and trade union representing and negotiating on behalf of all doctors and medical students in the UK. It is a leading voice advocating for outstanding health care and a healthy population. It is an association providing members with excellent individual services and support throughout their lives.

Summary

· The BMA has serious concerns over the dilution of standards of data protection for health data within the Government’s Data Protection and Digital Information Bill and urges the Committee to seek reassurances from the Government and highlight key concerns.

· Our focus, in this wide-ranging Bill, is its impact on the processing of special category health data. We are concerned that some of the proposed reforms represent a departure from the existing high standards of data protection for health data.

· The BMA is concerned that the passage of this Bill in its current form could diverge from current EU standards and potentially put at risk the free flow of personal data between the EU and UK. The BMA also notes that in other areas the implications for health data are unclear and require clarification.

· Patients and the public rightly expect high standards of data processing to protect their confidential health data. The BMA believes not enough emphasis has been placed on the public’s expectations as to how confidential health data is handled. Such an approach fails to consider the detrimental impact of the loss of public trust in how the healthcare system manages data. If such a loss of trust occurs, it would be to the detriment of data quality both for the safety and effectiveness of individual care and for system-wide research and scientific development.

· The BMA calls for a significant re-evaluation of the implications for health data due to concerns that this Bill does not provide the high standards of protection that the public would expect to apply to some of their most sensitive data.

1. Divergence from EU standards

1.1 It is essential that the direction the UK is taking will not lead to the loss of data adequacy status with the EU which would put at risk the continued free flow of personal data between the EU and the UK. This data flow is critical to medical research and innovation, including important clinical trials. If the EU was to conclude that data protection legislation in the UK was inadequate, this would present a significant problem for organisations conducting medical research in the UK and would far outweigh any perceived benefits which might be achieved via the reforms.

2. Clause 9 – Information to be provided to data subjects

2.1 The BMA is deeply concerned that Clause 9 of this Bill will lead to a watering down in the transparency of information to data subjects.

2.2 Clause 9 disapplies the requirement to provide information to data subjects when personal data is processed for scientific research and where it would require ‘disproportionate effort’ to provide this information (clause 9 (2)(a)(v)).

2.3 Given the close relationship between transparency and public trust, any reduction in transparency requirements is a backward step in terms of promoting confidence in the use of health data. Disapplying transparency requirements is contrary to societal expectations such that more – not less – transparency is required to build and maintain public trust. A reduction in transparency is also in direct contradiction to the advice of the National Data Guardian that there should be ‘no surprises’ [1] for patients about how and why their data is used.

2.4 One of the factors which has a bearing on whether disproportionate effort is required is ‘the number of data subjects’ (clause 9(2)(b)). The implication therefore is that the more individuals whose personal data is being collected, the easier it will be for controllers to apply the exemption to provide information i.e. more processing means less transparency which is a deeply concerning direction of travel.

2.5 Existing transparency obligations generally do not require contact to be made with each individual data subject. Transparency obligations can usually be satisfied by providing privacy information using different techniques which can reach large numbers of individuals such as the use of relevant websites, social media, local newspapers etc. It is hard to envisage how using these methods might be considered to require disproportionate effort such that it would impair the progression of research. Failure to be transparent, however, may impair research should a loss of public trust occur.

2.6 The BMA urges the Committee to remove Clause 9 from the Bill.

3 Clauses 28, 31 and 100 – 101 Government directed Information Commission to replace the current ICO

3.1 The current Office of the Information Commissioner is to be abolished (clause 101 (1)) and replaced with a body corporate called the Information Commission (clause 100(2), new section 114A) which is subject to greater oversight from the Government.

3.2 The new structure risks dilution of the regulatory freedom of the ICO. Of particular concern is that the proposals will limit the ability of the ICO to function independently of Government interference and will expose it to political direction. For example, the ICO would be compelled to consider the Government’s priorities when exercising its regulatory functions (clause 28(2), new sections 120E and F) – which will be set out in an official ‘statement of priorities’ – and the Secretary of State would have the power to approve or veto any statutory codes of practice before they are laid before Parliament (clause 31(2), new section 124D).

3.3 It would be entirely inappropriate for the regulation of health data to be subject to Government interference. All governments have a vested interest in the increased use of, or access to, health data. To maintain public confidence there must be clear separation between the regulation of data and those who might wish to access it.

3.4 The BMA urges the Committee to remove Clauses 28, 31 and 100 - 101 from the Bill.

4 Clause 1 – Amended definition of ‘personal data’

4.1 Clause 1 amends the definition of personal data with the intention to provide clarification on the process for determining if information relates to a person who is ‘identifiable’.

4.2 It is important for the Information Commissioner’s Office (ICO) to be involved in discussions about the amended definition of personal data to ensure it meets the existing standards in ICO guidance. In particular, we would welcome reassurance that the ICO is content that the new definition of personal data does not alter the current position in relation to personal data which has undergone pseudonymisation but which nevertheless remains personal data.

4.3 The BMA is seeking confirmation from the Government that the ICO supports the amended definition of personal data.

5 Clause 3 - Consent for research

5.1 Clause 3 places recital 33 of the UK GDPR on a legislative footing. Recital 33 contains provisions that enable data subjects to give consent for data to be used in broader areas of scientific research when it is not possible to fully identify the purpose of personal data processing at the time of data collection (clause 3(3)).

5.2 Placing recital 33 onto a legislative footing may have the effect of decreasing rather than increasing certainty in the context of medical research, because consent is not usually relied on as the legal basis for processing personal data for health research purposes.

5.3 The clause fails to recognise that medical research already operates within an established framework of well-established and rigorous ethical standards for good research governance practice overseen by the Health Research Authority (HRA). Given that UK GDPR does not present barriers to researchers using health data for medical research, the benefits of this clause are unclear and may lead to unnecessary uncertainty about the lawful grounds for processing health data which must be avoided.

5.4 The BMA is calling for this clause to be removed to avoid creating unnecessary uncertainty for those who wish to process data for medical research.

6 Clause 5 and Schedule 1 – Lawfulness of processing

6.1 The effect of this clause is to introduce a new lawful basis of ‘recognised legitimate interest’ (clause 5(2)(b) and 5(4)). The list of ‘recognised legitimate interests’ specified in new Annex 1 of Schedule 1 are processing activities which are deemed to automatically satisfy the legitimate interests balancing test, which includes assessment of necessity and proportionality.

6.2 We are unclear on the extent of the impact of clause 5 on the processing of health data. We note that the ‘recognised legitimate interests’ avenue appears to be only available to data controllers that are not public authorities, therefore, NHS organisations appear to be excluded. We would, however, welcome confirmation that health data held by the NHS is beyond the scope of clause 5.

6.3 We would also welcome clarity and reassurance about whether there is any scope for the processing of special category health data held by non-public bodies for ‘recognised legitimate interests’ purposes. It would be of significant concern should it be deemed that the principles of necessity and proportionality are automatically met when health data is being processed.

7 Clause 11 – Removing the prohibition on automated decision-making

7.1 Clause 11 clarifies the safeguarding requirements within Article 22 of UK GDPR which apply to automated decision making. We note with concern, however, that the Secretary of State will have considerable powers via secondary legislation (to be subject to the affirmative resolution procedure) to amend the Article 22 safeguards (clause 11(3), new section 50D).

7.2 It appears that the Secretary of State can make regulations which determine whether or not (a) there has been any human involvement (regardless of the facts) and (b) whether processing would have a significant adverse effect (again regardless of the facts) – new Art 50D. Clause 11(3) therefore seems to give the Secretary of State powers to ignore the statutory protections which apply to automated processing, without the need for Parliamentary scrutiny.

7.3 We understand that the Secretary of State requires flexibility to amend legislation in an area of fast-paced technological change. However, we are concerned that this flexibility must not be used to reduce statutory protections. If the public is expected to have trust in AI technology, and in those companies and institutions holding and processing large quantities of health data, AI must operate with safeguards on which the public can rely. We would support legislation which provides the Secretary of State with the necessary flexibility for the law to keep pace with technology while at the same time ensures statutory safeguards are maintained.

8 Clause 14 – Senior responsible individual

8.1 Clause 14 removes the requirement for organisations to appoint a data protection officer (‘DPO’) and replaces it with a new requirement to appoint a ‘senior responsible individual’ (‘SRI’) who is ‘part of the organisation’s senior management’ (clause 14(2), new Article 27A (2) and (3)(a)).

8.2 It is essential that SRIs can operate independently from senior management otherwise they will be ‘marking their own homework’. The creation of a requirement for SRIs to be part of the collective responsibility of a senior management team will increase the potential for conflicts of interest and create specific difficulties for doctors, for example:

8.2.1 Many doctors who currently perform the role of DPO will also perform the role of Caldicott Guardian given the overlap of expertise which is required for both roles within healthcare organisations. Caldicott Guardians provide independent advice on complex considerations about the disclosure of confidential health data and must be free to raise concerns at senior management level and express an independent view that might not be the same as the corporate view. It is difficult to see how it will be possible for an individual to hold both roles in the future should it become a requirement for the SRI to be part of the decision-making body within an organisation.

8.2.2 If the ‘senior responsible individual’ cannot be an external consultant this may deprive healthcare organisations of specialist expertise which may not be available within the senior management.

8.3 The BMA calls on the Committee to amend this clause so that SRI role can operate independently of an organisation’s senior management team.

9 Clause 17 and 18 – Assessment of high-risk processing and Consulting the Information Commissioner

9.1 Clause 17 dilutes existing obligations in relation to conducting data protection impact assessments (DPIAs). The proposed data protection ‘assessments’ require only ‘a summary’ of the purposes of the processing, rather than the current requirement to carry out ‘a systematic description’ of the envisaged processing (clause 17(3)(d)). The result is a reduction in emphasis on obligations to identify and minimise data protection risks. Removing the requirement to conduct a thorough assessment of risks posed to health data is likely to lead to a less diligent approach to data protection for individuals and increases the risk of reputational loss for organisations processing health data.

9.2 Clause 18 removes the requirement for organisations to consult the ICO on high-risk processing (clause 18 (3)(5)(a)). Instead, it appears that informing the Information Commissioner will be optional prior to processing which is considered to be high risk. We view this approach as a backward step from good governance and a less rigorous approach to data protection which is not appropriate when organisations are processing large quantities of sensitive health data.

9.3 The BMA is concerned that Clauses 17 and 18 will water down high standards of data governance which are necessary when organisations are handling health data. The BMA urges the G overnment to retain the current obligations in relation to conducting DPIAs.

10 Clause 79 – Storing information in the terminal of a subscriber or user

10.1 Clause 79 amends the Privacy and Electronic Communications (PEC) Regulations. We understand that the effect of the clause is that consent will not be required for the use of online trackers (or ‘cookies’) to be placed on users’ devices for certain purposes, including collecting statistical information with a view to bringing about improvements to that service (clause 79(2)(a), new paragraph 2A).

10.2 The implications for health data require clarification. For example, if an individual has been seeking online advice about a particular health condition, will this clause enable the collection and storage of personal data, such as IP address, which reveals that the individual has visited certain health-related websites (unless the individual ticks a box to object).

10.3 The BMA seeks clarification from the Government on the implications this Clause will have on health data.

May 2023

 

Prepared 23rd May 2023