Unlock AI Compliance: Master the new EU AI Act with our comprehensive guide.

Roinn

2 min read

Writen by Adam

Posted on: December 19, 2020

Ico responds to government GDPR rule break

The UK Government admitted that the Track and Trace App, created to help stop the spread of Coronavirus, broke a key Data Protection Law – the failure to conduct a privacy risk assessment.

This means that the Trace and Trace system had been operating unlawfully since its launch on the 28th of May. However, the Department of Health and Social Care (DHSC) states there is no evidence that the data had been used illegally.

Although it seems user data was secure, a Data Protection Impact Assessment (DPIA) must still be carried out as this helps to identify issues, avoid risking user’s personal data and is a requirement under GDPR.

In response, a spokesperson for the DHSC stated: “NHS Test and Trace is committed to the highest ethical and data governance standards – collecting, using, and retaining data to fight the virus and save lives, while taking full account of all relevant legal obligations.”

The ICO responded to this rule-break, and welcomed the work of the NHS Track and Trace app, whilst pointing out the importance of protecting the health data of individuals. The ICO also stated: …Providing a high level of transparency and putting data protection at the heart of an app or service should help build people’s trust in the systems involved. We will continue to offer that guidance during the life of the app as it is further developed, rolled out more widely and when it is no longer needed…’

This highlights that no one is exempt from GDPR rule breaks, and that proper procedure should always be followed. However, a Data Protection Impact Assessment is long and complicated document and you must get it right.

At GDPRlocal, we can provide Data Protection Impact Assessment Template and help you fill it out so you can avoid fines and trouble from the ICO.

Déan Teagmháil Linn

Tá súil agam go mbeidh sé seo úsáideach duit. Má theastaíonn Ionadaí AE uait, má tá aon cheist GDPR agat, nó má fuair tú iarratas SAR nó Rialálaí agus má theastaíonn cabhair uait, déan teagmháil linn ag am ar bith. Táimid i gcónaí sásta cabhrú ...
Foireann áitiúil GDPR.

Déan Teagmháil Linn

Recent blogs

Navigating the Contradictions: Automated Decision-Making and Regulatory Legislation in AI Systems

The Dilemma of Automated Decision-Making At the heart of AI systems lies the promise of aut

How to Implement the New AI Law in Your Company

The implementation of the AI Act marks a significant stride towards responsible and fair use of art

Article 14 Guide: Meeting Regulatory Requirements for Personal Data Not Directly Obtained from Data Subjects

Imagine a software-as-a-service (SaaS) company looking to grow its clientele by purchasing leads fr

Faigh Do Chuntas Anois

Socraigh i gceann cúpla nóiméad. Cuir isteach sonraí do chuideachta agus roghnaigh na seirbhísí a theastaíonn uait.

Cruthaigh Cuntas

Téigh i dteagmháil

Níl tú cinnte cén rogha atá le roghnú? Glaoigh, ríomhphost, comhrá a dhéanamh linn
am ar bith.

Déan Teagmháil Linn
06 EOLAS GDPR

Fan Suas chun Dáta

Fág do chuid sonraí anseo agus seolfaimid nuashonruithe agus faisnéis chugat maidir le gach gné den GDPR agus d'Ionadaí an AE. Ní bheidh muid bombard tú le ríomhphoist agus beidh tú in ann a insint dúinn chun stop a chur ag am ar bith.

Tá Ainm Iomlán ag teastáil!

Tá Ríomhphost Gnó ag teastáil!

Tá cuideachta ag teastáil!

Glac leis na Téarmaí agus Coinníollacha agus an Polasaí Príobháideachais