Data Privacy Outlook in the UK, October 2022
The Information Commissioner's Office (ICO) has been making headlines recently with several significant announcements concerning data protection. Here's a roundup of the latest developments:
ICO Fines Large Social Media Provider £27 Million
The ICO has announced its intention to impose a £27 million fine on a major social media provider for alleged failures in protecting children's privacy. The specific details of the breach have not been disclosed yet.
ICO's Consultations and Guidance
- The ICO launched a second consultation on its draft data protection and journalism code on 21 September 2022. The deadline to submit feedback is 16 November 2022.
- The ICO is also consulting on employee monitoring at work guidance, but further details are provided in the Employment and immigration section.
- The ICO has published guidance on the research provisions in the UK GDPR and Data Protection Act 2018 following a consultation earlier this year.
- The ICO is evaluating the impact of the Age Appropriate Design Code of Practice (or children's code) and is running a public consultation on the code which ends on Friday 11 November 2022.
Enforcement Actions
- The ICO has taken action against several high-profile organisations who failed to respond to a subject access request (SAR) within the required time frame.
- The ICO has fined Easylife Ltd £1,350,000 for unlawfully using personal information of 145,000 customers.
- Easylife Ltd was also fined £130,000 for making over one million "predatory" direct marketing calls.
- In addition, Easylife Ltd used personal information to predict customers' medical conditions and target them with health-related products, leading to further action by the ICO.
- More information on the enforcement action against Easylife Ltd can be found on the ICO's website.
Certification Schemes and Partnerships
- The European Data Protection Board (EDPB) has approved the first European Data Protection seal under this certification scheme.
- Our firm has been selected and qualified as a Europrivacy official partner, able to support businesses in obtaining EDPB authorised certification.
- Europrivacy is a certification scheme that enables organizations to assess and certify their compliance with the General Data Protection Regulation (GDPR) and complementary national data protection regulations.
US-EU Data Transfers
US President Joe Biden signed an Executive Order on Enhancing Safeguards for United States Signals Intelligence Activities, paving the way for new adequacy decisions for EU-US and UK-US data transfers.
As the ICO continues to enforce data protection laws and provide guidance, it's crucial for businesses and individuals to stay informed and ensure compliance. For more updates, visit the ICO's website.