Data protection: preparing for Brexit
Although there is uncertainty about what arrangements will apply when the UK leaves the EU, there are a number of practical steps that can be taken now to prepare from a data protection perspective and to ensure that any data flows to and from the EU can continue post Brexit.
09 October 2019
Although there is uncertainty about what arrangements will apply when the UK leaves the EU, there are a number of practical steps that can be taken now to prepare from a data protection perspective and to ensure that any data flows to and from the EU can continue post Brexit.
- Understand your data flows.
As part of preparing for the General Data Protection Regulation 2016/679 coming into force in May 2018, your organisation will have carried out a data mapping exercise. If this is up-to-date then you will be able to use this to assess to what extent your organisation will be impacted by Brexit. Where this is not up-to-date then this is a good opportunity to review it and update it.
The key is to identify any data flows to and, more importantly, from countries in the EU. Even if you do not think information is being transferred you will need to carefully consider your data processing arrangements and any sub-processing arrangements.
After Brexit, countries in the EU who are transferring personal data to the UK will need to comply with the international transfer provisions in the GDPR, until an adequacy decision is made by the European Commission in respect of the UK. In most cases this will be by using the Standard Contractual clauses.
- Consider whether the territorial scope provisions in Article 3 of the GDPR mean that your organisation will need to appoint an EU representative and , if so, take steps to identify and appoint an appropriate representative.
- Understand what policies, procedures and other documents may need revising following Brexit.
Regardless of the type of Brexit, the Data Protection Act 2018 will remain in force as this is domestic legislation. In terms of the GDPR, the Government has passed regulations that mean the GDPR will be incorporated directly into UK law (becoming the “UK GDPR”) and operating alongside the DPA 2018. If we Brexit with a ‘deal’ then there is likely to be a transition period where the GDPR will apply before we move to fully domestic arrangements. This may potentially allow for more detailed arrangements to be agreed to govern the transfer of data from the EU to the UK. - Maintain a watching brief to ensure that you are aware of important developments and any new guidance that is published.
- Finally, the Information Commissioner’s Office has published guidance to assist organisations with preparing for Brexit, including recent guidance aimed and small and medium organisations. Being familiar with this guidance and following it where appropriate will help your organisation to prepare and ensure you can meet your accountability obligations under the GDPR.
In any event, priority should be given to updating privacy notices and other data subject facing documents so that they can continue to understand how to exercise their data subject rights and to ensure you can continue to demonstrate compliance with your transparency obligations.
Related expertise
You may be interested in...
Legal Update
Using AI to help spot vulnerable customers
Legal Update
Is your cyber resilience shored up?
Legal Update
CrowdStrike: Assessing the fallout of potentially the “largest IT outage in history”
Legal Update
Alternative dispute resolution: The future of ADR in the UK legal system
Legal Update - DORA
EU Digital Operational Resilience Act: Countdown to comply with the January 2025 deadline
Press Release
Jeanne Kelly recognised in the list of Top 100 people in Irish Tech by the Business Post
Legal Update
Artificial intelligence in insurance: Targeted marketing as a quasi-underwriting function
Opinion - Maternity services
New online system streamlines maternity services at The University Hospitals of Derby and Burton NHS Foundation Trust
On-Demand - Shared Insights
Shared Insights Data: Strategies for handling cyber attacks and data breaches
Legal Update
Mandatory cybersecurity requirements for businesses in the IOT supply chain
Legal Update
A reflection of FIMA Connect 2024
On-Demand - Shared Insights
Duty of Candour review: Submission to the Department of Health and Social Care
Legal Update
Economic Crime and Corporate Transparency Act 2023 – impact of changes implemented on 4 March 2024
Press Release
‘Privacy by design’ approach will help health and care organisations gain public trust in using technology as ICO publishes new guidance
Legal Update
Understanding the ICO's new fining guidance
Legal Update
ICO consultation on accessing care records: A legal perspective
Legal Update
Cyber-attacks in UK universities: Why failing to prepare is no longer an option
Legal Update
Artificial intelligence – shaping a sustainable future
Press Release
Spring Budget 2024: Browne Jacobson reaction
Legal Update
Not quite a blanket ban on mobile phones in schools: DfE guidance insights
On-Demand - Shared Insights
Shared Insights: Sexual safety in the workplace — how leaders can help to create a sexual safety culture
Legal Update
Progress on the Automated Vehicles Bill
Legal Update
Data protection in higher education: what to expect in 2024
Legal Update
The rise of AI in construction
Legal Update
Government foreshadows significant savings for public bodies as part of data protection overhaul
Legal Update
ICO consultation on transparency in health and social care
Legal Update
How to mitigate risk in disputes arising from AI use in technology projects
Opinion
Monitoring workers – ICO guidance
Legal Update
ICO consultation on fertility tracking apps
Published Article
UK: Legal issues with deepfakes
Legal Update
New guidance for employers on subject access requests published by the ICO
Legal Update
Ali Round 2 - High Court gives further guidance on causation and quantum for data breaches
Press Release
Browne Jacobson welcomes former ICO lawyer to support growing UK&I data privacy and tech practice
Legal Update
Update on data protection claims - Austrian Post Case
Press Release
Browne Jacobson launches specialist Ascensus programme for in house lawyers and business leaders
Opinion
Mopping up after a leak – how businesses can take steps to protect their confidential information
Legal Update
Cyber security and data breaches
Legal Update
Update on the Digital Services Act (“DSA”) – Important Dates and Deadlines Looming
Legal Update
Government publishes its proposals for expanding the Scope of the Network and Information Systems Regulations 2018
19 December 2022