Unlock AI Compliance: Master the new EU AI Act with our comprehensive guide.

Partager

3 min read

Writen by Zlatko Delev

Posted on: April 22, 2021

Changes in the Data protection after UK has left the EU .

Following the UK’s departure from the European Union, these are the latest updates on how this affects GDPR and the sensitive issue of data protection.

Overview of the current situation:

  1. The General Data Protection Regulation (GDPR) has been retained in UK law and will continue to be read alongside the Data Protection Act 2018, but with some technical amendments to ensure it can function in UK law. 
  2. The Information Commissioner remains the UK’s independent supervisory authority on data protection. 
  3. The UK is now deemed a ‘third country’ by the EU and so will require an adequacy decision to continue personal data transfers from the EU/EEA. However, the EU-UK Trade and Cooperation Agreement contains a bridging mechanism that allows the continued free flow of personal data from the EU/EEA to the UK after the transition period until adequacy decisions come into effect, for up to six months.
  4. Transfers of personal data from the UK can continue as before.
  1. Receiving personal data from the EU/EEA.

    – For the duration of the bridging mechanism, you can continue to receive personal data from the EU/EEA, but you should work with any EU/EEA organisations that transfer personal data to you to put in place alternative transfer mechanisms to safeguard against any interruption to the free flow of EU-to-UK personal data.

    – For most organisations, the most relevant of these will be Standard Contractual Clauses (SCCs).The ICO also provides more details  on what actions might be necessary and an interactive tool that allows you to build SCCs.

    -11 of the 12 third countries deemed adequate by are maintaining unrestricted personal data flows with the UK.
  2. Transferring personal data from the UK:

    – There are currently no changes to the way you send personal data to the EU/EEA, Gibraltar and other countries deemed adequate by the EU.

    – For international data transfers from the UK to other jurisdictions, further information can be found on ICO website.
  3. Holding personal data of individuals based outside the UK (whether in the EEA or not) which is processed in the UK but acquired before 31 December 2020:

    – Article 71(1) of the Withdrawal Agreement contains provisions that continue to apply EU data protection law to certain ‘legacy’ personal data until full adequacy decisions are adopted by the EU and come into effect.

    – Although UK organisations may not need to do anything differently immediately to accommodate the Withdrawal Agreement requirements in practice, they may want to consider, where possible, taking stock of the personal data they hold so they can identify and track relevant legacy personal data to which EU data law applies in line with the Withdrawal Agreement requirements.
  4. Appointing EU-based representatives

    – Some UK data controllers and processors may also need to appoint EU-based representatives if they do not have an office, branch or other establishment in the EEA but offer goods or services to individuals in the EEA or monitor the behavior of individuals in the EEA.
  5. Updating documentation

    – Any references to EU law, UK-EU transfers and your EU representative (if you need one) will need to be updated in your privacy notices, DPIAs and other documentation.

Nous contacter

Nous espérons que ces informations vous seront utiles. Si vous avez besoin d'un représentant de l'UE, si vous avez des questions sur le GDPR ou si vous avez reçu une demande de SAR ou d'un régulateur et que vous avez besoin d'aide, n'hésitez pas à nous contacter à tout moment. Nous sommes toujours heureux de vous aider...
L'équipe locale GDPR.

Nous contacter

Recent blogs

The Future of Finance: Adapting to AI and Data Privacy Laws

The rapidly evolving landscape of financial technology is witnessing a significant transformation w

Navigating the Contradictions: Automated Decision-Making and Regulatory Legislation in AI Systems

The Dilemma of Automated Decision-Making At the heart of AI systems lies the promise of aut

How to Implement the New AI Law in Your Company

The implementation of the AI Act marks a significant stride towards responsible and fair use of art

Obtenez votre compte maintenant

L'installation se fait en quelques minutes. Saisissez les coordonnées de votre entreprise et choisissez les services dont vous avez besoin.

Créer un compte

Prendre contact

Vous ne savez pas quelle option choisir ? Appelez-nous, envoyez-nous un courriel ou discutez avec nous à l'adresse
à tout moment.

Nous contacter
06 GDPR INFO

Rester à jour

Laissez vos coordonnées ici et nous vous enverrons des mises à jour et des informations sur tous les aspects du GDPR et du Représentant de l'UE. Nous ne vous bombarderons pas d'e-mails et vous pourrez nous demander d'arrêter à tout moment.

Le nom complet est obligatoire !

L'adresse électronique professionnelle est obligatoire !

L'entreprise est nécessaire !

Veuillez accepter les conditions générales et la politique de confidentialité