<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>International data transfers &#8211; DPO Centre</title>
	<atom:link href="https://www.dpocentre.ca/blog/category/international-data-transfers/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.dpocentre.ca</link>
	<description>Empowering Compliance, Protecting Data, Ensuring Trust. - DPO Centre</description>
	<lastBuildDate>Mon, 07 Apr 2025 11:34:22 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.dpocentre.ca/wp-content/uploads/2026/07/cropped-DPO-Centre-32x32.png</url>
	<title>International data transfers &#8211; DPO Centre</title>
	<link>https://www.dpocentre.ca</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA</title>
		<link>https://www.dpocentre.ca/blog/international-data-transfers-explaining-eu-sccs-uk-addendum-and-uk-idta/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Sun, 21 Jan 2024 22:23:56 +0000</pubDate>
				<category><![CDATA[Data Sharing]]></category>
		<category><![CDATA[Global data privacy laws]]></category>
		<category><![CDATA[International data transfers]]></category>
		<category><![CDATA[Policies & Documentation]]></category>
		<guid isPermaLink="false">https://dpoca.server.terryh.uk/?p=20824</guid>

					<description><![CDATA[<p>EU and UK-based organisations regularly need to transfer personal data to different countries for a variety of reasons – project collaborations, partnerships, service providers etc.&#160; With the increasing complexity of global privacy legislation, it is vital for organisations to have the appropriate safeguards in place for these transfers. This ensures compliance with data protection laws, [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/international-data-transfers-explaining-eu-sccs-uk-addendum-and-uk-idta/">International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">EU and UK-based organisations regularly need to transfer personal data to different countries for a variety of reasons – project collaborations, partnerships, service providers etc.&nbsp;</p>



<p class="wp-block-paragraph">With the increasing complexity of global privacy legislation, it is vital for organisations to have the appropriate safeguards in place for these transfers. This ensures compliance with data protection laws, mitigates the risk of a data breach, and helps to maintain the trust of customers, stakeholders, and employees.&nbsp;</p>



<p class="wp-block-paragraph">There are several safeguarding options, depending on the nature of the data, where the individuals are located, and where the data is being sent.&nbsp;</p>



<p class="wp-block-paragraph">In this blog, we take a look at the EU Standard Contractual Clauses (EU SCCs), the UK Addendum, and the UK International Data Transfer Agreement (IDTA), explaining the suitability of each mechanism for EU and UK personal data transfers and the factors to consider.&nbsp;</p>



<h2 class="wp-block-heading">EU&nbsp;Standard Contractual Clauses (EU&nbsp;SCCs)&nbsp;</h2>



<p class="wp-block-paragraph">EU SCCs are one of the most commonly used data transfer mechanisms. They are popular because they have pre-approval by the European Commission and a level of assurance for compliance with the General Data Protection Regulation (GDPR).&nbsp;</p>



<p class="wp-block-paragraph">The European Commission published new EU SCCs on 4 June 2021, allowing organisations to use these for data transfers from the European Economic Area (EEA) to third countries from 27 June 2021.&nbsp;</p>



<h2 class="wp-block-heading">UK Addendum</h2>



<p class="wp-block-paragraph">As the UK is no longer part of the EEA, UK organisations cannot rely on the new EU SCCs. Only the old EU SCCs were valid in the UK until the Information Commissioner’s Office (ICO) introduced their own solution in the form of an Addendum, which came into force on 21 March 2022.&nbsp;</p>



<p class="wp-block-paragraph">The UK Addendum allows organisations to use the new EU SCCs for UK personal data transfers, ensuring compliance with both EU and UK data protection laws. A helpful solution for organisations with locations across the EU and the UK.&nbsp;</p>



<p class="wp-block-paragraph"><strong>The old EU SCCs expired on 27 December 2022. Any existing UK contracts have until 21 March 2024 to transition to the new EU SCCs with UK Addendum or the IDTA.</strong>&nbsp;</p>



<h2 class="wp-block-heading">UK&nbsp;International Data Transfer Agreement (IDTA)&nbsp;</h2>



<p class="wp-block-paragraph">The International Data Transfer Agreement (IDTA) was developed by the UK’s Information Commissioner’s Office (ICO) and has been in force since 21 March 2022. It is a legal framework for transferring personal data from the UK to countries outside the European Economic Area (EEA) not covered by adequacy decisions (these are known as UK Restricted Transfers).&nbsp;</p>



<p class="wp-block-paragraph">The IDTA is an alternative to the EU SCCs with the UK Addendum but is only suitable for transferring personal data from the UK.&nbsp;</p>



<p class="wp-block-paragraph">The IDTA sets out contractual obligations for both the data exporter (in the UK) and the data importer (in the third country) to protect the privacy and rights of individuals whose data is being transferred. It includes clauses on data handling, processing, security measures, and the rights of individuals.&nbsp;</p>



<h2 class="wp-block-heading">Should you use&nbsp;EU SCCs, UK IDTA or UK Addendum?&nbsp;</h2>



<p class="wp-block-paragraph">There are fundamental questions you should ask when choosing the most appropriate data transfer mechanism for your organisation. These include understanding the type of data being transferred, the frequency and volumes, and the countries involved.&nbsp;</p>



<p class="wp-block-paragraph">Here’s a helpful list of questions to consider and an overview of which mechanism to use for EU or UK data:&nbsp;&nbsp;</p>



<ul class="wp-block-list">
<li>Where do the individuals reside? EU, UK or both? </li>



<li>Are there any inter-company binding rules in place? If so, further mechanisms may not be required </li>



<li>Are you transferring data to an adequate country? If yes, the transfer can proceed, following the specific adequacy decision frameworks </li>



<li>Are you making a regular transfer to a non-adequate country? If yes, see EU SCCs or UK Addendum or IDTA  </li>
</ul>



<figure class="wp-block-image size-large is-resized"><img fetchpriority="high" decoding="async" width="1024" height="189" src="https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum-1024x189.png" alt="SCCs IDTA UK Addendum" class="wp-image-20826" style="width:800px" title="International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA 1" srcset="https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum-1024x189.png 1024w, https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum-300x55.png 300w, https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum-768x142.png 768w, https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum.png 1080w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading">The DPO Centre can help with your international data transfer queries </h2>



<ul class="wp-block-list">
<li>One of the largest teams of outsourced Data Protection Officers (DPOs) available </li>



<li>GDPR EU and UK Representatives </li>



<li>Specialist Advice Line offering a rapid response to important data protection queries </li>



<li>Highly cost-effective solutions </li>
</ul>



<p class="wp-block-paragraph">We have worked with over 800 clients globally across the spectrum of industry sectors, supporting their data protection compliance and bringing peace of mind.&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/international-data-transfers-explaining-eu-sccs-uk-addendum-and-uk-idta/">International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Data Protection in 2023: A year in review</title>
		<link>https://www.dpocentre.ca/blog/data-protection-in-2023-a-year-in-review/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Fri, 22 Dec 2023 22:22:34 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Global data privacy laws]]></category>
		<category><![CDATA[International data transfers]]></category>
		<guid isPermaLink="false">https://dpoca.server.terryh.uk/?p=20821</guid>

					<description><![CDATA[<p>This year has seen significant progress in the data protection industry, with many new privacy laws being enacted across the globe. In this blog, we look at some of the major events and news stories that have shaped the landscape, influencing the direction of policies and processes. What does the development of data protection laws [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/data-protection-in-2023-a-year-in-review/">Data Protection in 2023: A year in review</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">This year has seen significant progress in the data protection industry, with many new privacy laws being enacted across the globe.</p>



<p class="wp-block-paragraph">In this blog, we look at some of the major events and news stories that have shaped the landscape, influencing the direction of policies and processes.</p>



<p class="wp-block-paragraph">What does the development of data protection laws mean for organisations? And how will the data protection industry continue to evolve? Big questions to keep in mind as we go into 2024.</p>



<h2 class="wp-block-heading"><strong>Major data protection events</strong></h2>



<p class="wp-block-paragraph"><strong>5 years of the GDPR:</strong>&nbsp;The General Data Protection Regulation (GDPR) celebrated its 5<sup>th</sup>&nbsp;anniversary on 25 May 2023. Coming into force on 25 May 2018, it is cited as one of the toughest pieces of privacy legislation in the world. The EU’s principle-based directive was introduced to protect the fundamental rights of individuals by safeguarding their personal data and creating a harmonised framework for data flow across the EU’s digital single market.</p>



<p class="wp-block-paragraph">To mark the anniversary, The DPO Centre held a webinar to discuss the wins and challenges for businesses. Essentially, what worked, what didn’t, and why?&nbsp;<a href="https://www.dpocentre.com/resources/gdpr-webinar/" target="_blank" rel="noreferrer noopener"><strong>Watch The DPO Centre’s lively GDPR debate here</strong></a></p>



<p class="wp-block-paragraph"><strong>Facebook fined a record €1.2 billion:&nbsp;</strong>On 22 May 2023, after 10 years of litigation and 3 court procedures, the Irish Data Protection Commission issued Meta Ireland with the largest GDPR fine to date. It was the fourth fine Meta received this year. The Commission issued two penalties in January 2023 for breaching rules with targeted ads on Facebook and Instagram and in March 2023, a fine for GDPR breaches with WhatsApp.</p>



<p class="wp-block-paragraph">The fines sent a strong message to Tech giants that they cannot continue to neglect their obligations for compliance with data protections regulations. However, Meta has yet to pay the fine and announced its intention to appeal. One of the orders of the penalty charge was for Meta to discontinue its reliance on Standard Contractual Clauses (SCCs) by 12 October. In an update on 7 September 2023, Meta announced they will rely on the new EU-US DPF for data transfers.</p>



<p class="wp-block-paragraph"><strong>The AI Safety Summit</strong>&nbsp;took place in the UK on 1 November 2023 at Bletchley Park. Intended as a landmark event for artificial intelligence, the event brought together leading experts, researchers, and policymakers from around the world.</p>



<p class="wp-block-paragraph">An important outcome of the Summit was&nbsp;<strong>The Bletchley Declaration</strong>&nbsp;– a world-first agreement between 28 jurisdictions, including the EU, the US, and China. The Declaration establishes a shared responsibility to understand and manage the potential risks of AI development. Bias and privacy are topics covered within the Declaration, providing an agenda to focus on building respective risk-based policies across the countries. However, critics have highlighted the lack of detail and the absence of any actionable points for building an effective regulatory framework.</p>



<h2 class="wp-block-heading"><strong>Data protection developments in the EU, UK, and North America</strong></h2>



<p class="wp-block-paragraph"><strong>Europe’s GDPR continues to mature</strong></p>



<p class="wp-block-paragraph">Since its implementation in 2018, the General Data Protection Regulation (GDPR) has become a global standard for data protection. With each passing year, we see further clarification on its interpretation, and a greater understanding of the implications for businesses and individuals alike.</p>



<p class="wp-block-paragraph">There were several key court rulings by the Court of Justice of the European Union (CJEU) this year, which have helped to clarify certain areas of the legislation:</p>



<ul class="wp-block-list">
<li>Accountability principle – The CJEU ruled that not every violation of the GDPR would render all related processing to be unlawful (<a href="https://curia.europa.eu/juris/document/document.jsf?text=&amp;docid=273289&amp;pageIndex=0&amp;doclang=EN&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=3199198" target="_blank" rel="noreferrer noopener"><strong>Case C-60/22</strong></a>)</li>



<li>Right of Access – The CJEU clarified the scope of the GDPR right of access by stating that the right to obtain a ‘copy’ of personal data means that the data subject must be given a ‘faithful and intelligible’ reproduction of all those data</li>



<li>Joint Controllers – The CJEU stated that if a company doesn’t follow GDPR rules for making a joint controller agreement or keeping records of data processing activities, it doesn’t automatically mean that the company’s data processing is illegal.</li>



<li>Penalty fines – The CJEU ruled on 5 December 2023 that a supervisory Data Protection Authority (DPA) may only impose a fine for a GDPR infringement if it was committed wrongfully, either intentionally or negligently. In calculating a fine, a DPA must consider the total worldwide turnover of the entire group from the preceding business year.</li>
</ul>



<p class="wp-block-paragraph"><strong>The European Commission adopted its adequacy decision on EU-US data flows&nbsp;</strong>and established the EU-US Data Privacy Framework (DPF), which came into effect on 10 July 2023. The DPF replaced the invalidated Privacy Shield and aimed to address the concerns previously raised by the CJEU. However, only minutes after the announcement, Max Schrems, Austrian privacy lawyer and activist, expressed his scepticism of the decision and stated his intention to challenge the new deal. A challenge has yet to be submitted by Mr Schrems, but the debate over transatlantic data transfers is clearly not over and will continue into 2024.&nbsp;<strong><a href="https://www.dpocentre.com/eu-us-data-privacy-framework-3rd-time-lucky/" target="_blank" rel="noreferrer noopener">Learn more about the EU-US DPF</a></strong></p>



<h2 class="wp-block-heading"><strong>UK’s key data protection updates</strong></h2>



<p class="wp-block-paragraph"><strong>The UK-US ‘data-bridge’</strong>&nbsp;was approved on 21 September 2023, with it coming into force on 12 October 2023. Serving as an extension to the EU’s Data Privacy Framework (DPF), the data-bridge provides a mechanism for businesses in the UK to transfer personal data to US organisations certified under the ‘UK Extension to the EU-US Data Privacy Framework’ (UK Extension) without the need for further safeguards. However, criticisms of the EU-US DPF include concerns over the potential for increased surveillance by US authorities and the erosion of privacy rights. Many organisations have retained their existing data transfer mechanisms with a ‘wait and see’ approach.</p>



<p class="wp-block-paragraph"><strong>DSIT published AI Skills for Business Competency Framework&nbsp;</strong>for public consultation in November 2023. Supported by the Office for Artificial Intelligence within the Department for Science, Innovation and Technology (DSIT), the draft framework presents guidance on the essential knowledge, skills, and behaviours employees should have to benefit from AI technology. DSIT intends the framework to support businesses, enabling them to understand their AI upskilling needs and to assist training providers in developing relevant training solutions.&nbsp;<a href="https://iuk.ktn-uk.org/wp-content/uploads/2023/11/Final_BridgeAI_Framework.pdf" target="_blank" rel="noreferrer noopener"><strong>Read the draft AI Skills for Business framework</strong></a></p>



<p class="wp-block-paragraph"><strong>The UK’s proposed GDPR replacement moves closer</strong></p>



<p class="wp-block-paragraph">On 19 December 2023 the Data Protection and Digital Information (DPDI) Bill was debated at the second reading stage in the House of Lords. The government believes the updates to the current UK GDPR will support innovation and reduce unnecessary burdens on businesses and organisations. However, the new legislation has the potential to increase costs and complexities for all but the smallest of businesses.</p>



<p class="wp-block-paragraph">The Lords raised many concerns during the second reading, with Lord Bishop of Southwell and Nottingham quoting Rob Masson of The DPO Centre. The Lord Bishop used Mr Masson’s words when calling attention to the way in which the UK seems to be going in the opposite direction to the rest of the globe by lowering data protection standards.</p>



<p class="wp-block-paragraph">Lord Allan of Hallam said,&nbsp;<em>‘It is the concern around EU adequacy that I think should really be front and centre of our discussions when we consider this legislation.’</em></p>



<p class="wp-block-paragraph">This concern was echoed by several other Members, with Lord Vaux of Harrowden succinctly stating,&nbsp;<em>‘We must get this Bill right. If we do not, we risk substantial damage to the economy, businesses, individuals’’ privacy rights – especially children – and even, as far as the surveillance elements go, to our status as a free and open democratic society.’<br></em><a href="https://www.dpocentre.com/dpdi/" target="_blank" rel="noreferrer noopener"><strong>Read the key differences between the UK GDPR and DPDI</strong></a></p>



<h2 class="wp-block-heading"><strong>Canada seeks to update and strengthen its privacy laws</strong></h2>



<p class="wp-block-paragraph">There have been significant developments in Canada’s privacy laws this year. On 24 April, the Canadian House of Commons agreed on the entirety of Bill C-27, the Digital Charter Implementation Act 2022, which seeks to update and strengthen the Personal Information Protection and Electronic Documents Act (PIPEDA), including Canada’s first AI legislation.</p>



<p class="wp-block-paragraph"><strong>In Quebec</strong>, ‘An Act to modernise legislative provisions as regards the protection of personal information’ came into effect in 22 September 2023, with the right to portability under this Act is due to come into force on 22 September 2024.<br><a href="https://www.canlii.org/en/qc/laws/astat/sq-2021-c-25/latest/sq-2021-c-25.pdf" target="_blank" rel="noreferrer noopener"><strong>Read the PDF of Bill 64</strong>&nbsp;</a></p>



<h2 class="wp-block-heading"><strong>The United States sees a wave of new privacy laws</strong></h2>



<p class="wp-block-paragraph">It was a big year for privacy in the US, with 5 new state privacy laws:</p>



<ul class="wp-block-list">
<li>California Privacy Rights Act (CPRA) came into effect on 1 January 2023 and amends the California Consumer Privacy Act (CCPA)</li>



<li>Virginia Consumer Data Protection Act (VCDPA) came into effect on 1 January 2023</li>



<li>The Colorado Privacy Act (CPA) came into effect on 1 July 2023</li>



<li>The Connecticut Data Privacy Act (CTDPA) came into effect on 1 July 2023</li>



<li>The Utah Consumer Privacy Act (UCPA) will come into effect on 31 December 2023</li>
</ul>



<p class="wp-block-paragraph">These laws reflect a shift towards greater consumer control over personal data and increased obligations for organisations in terms of data processing. They also indicate a move towards harmonising state-level laws with global standards, providing new consumer rights aligned with those in the GDPR.</p>



<h2 class="wp-block-heading"><strong>Looking ahead: Data protection in 2024</strong></h2>



<p class="wp-block-paragraph"><a href="https://thedpia.com/" target="_blank" rel="noreferrer noopener"><strong>Subscribe to The DPIA</strong></a>&nbsp;– Keep updated on the latest, most important data protection news with our fortnightly email newsletter.</p>



<p class="wp-block-paragraph"><strong>UK’s DPDI Bill</strong></p>



<p class="wp-block-paragraph">As we move into 2024, all eyes are carefully watching the progress of the proposed Data Protection and Digital Information (DPDI) Bill. The hope of the data protection industry is that the Lords will take into consideration their numerous concerns and apply rigorous scrutiny to the proposed legislation. But only time will tell. We will keep you updated soon as we have further information.</p>



<p class="wp-block-paragraph"><strong>3<sup>rd</sup>&nbsp;party cookies in Chrome to be disabled</strong></p>



<p class="wp-block-paragraph">Google’s plan to phase out 3<sup>rd</sup>&nbsp;party cookies in its Chrome browser begins in quarter 1 of 2024. This is part of a larger initiative called the&nbsp;<strong><a href="https://privacysandbox.com/" target="_blank" rel="noreferrer noopener">Privacy Sandbox</a></strong>&nbsp;project, which aims to reduce cross-site tracking whilst still allowing functionality to keep online services and content freely available.</p>



<p class="wp-block-paragraph">Google will disable 3<sup>rd</sup>&nbsp;party cookies for 1% of users from early January, applying the changes to 100% of users by Q3 2024. The full rollout depends on Google addressing the competition concerns of the UK’s Competition and Markets Authority (CMA). The phasing out of non-essential cookies is in line with the wider global trend towards enhanced data protection and privacy.</p>



<p class="wp-block-paragraph"><a href="https://digital-strategy.ec.europa.eu/en/policies/eprivacy-regulation" target="_blank" rel="noreferrer noopener"><strong>The EU’s</strong>&nbsp;<strong>proposed ePrivacy Regulation</strong></a>&nbsp;establishes clearer rules on cookies, with a more streamlined solution for settings:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><em>‘no consent is needed for non-privacy intrusive cookies that improve internet experience, such as cookies to remember shopping-cart history or to count the number of website visitors.’ (Proposal for an ePrivacy Regulation)</em></p>
</blockquote>



<p class="wp-block-paragraph"><strong>International data transfers</strong></p>



<p class="wp-block-paragraph"><strong>SCCs and IDTA</strong>&nbsp;– From 21 March 2024, UK organisations can no longer use the old EU Standard Contractual Clauses (SCCs) for restricted data transfers. Instead, they must rely on the UK’s International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum (‘UK Addendum’).</p>



<p class="wp-block-paragraph"><strong>EU-UK adequacy</strong>&nbsp;– Later in 2024, the European Commission is due to review the EU-UK adequacy, which will expire on 27 June 2025. The outcome of the UK’s proposed DPDI Bill could significantly affect this decision and create further complications for organisations operating across multiple jurisdictions.</p>



<p class="wp-block-paragraph"><strong>EDPB action: Right of access by controllers</strong></p>



<p class="wp-block-paragraph">The European Data Protection Board (EDPB) will launch a national action in 2024 on ‘The right of access by controllers’. Each year, the EDPB seeks to prioritise certain topics for data protection authorities (DPAs) to work on at a national level. This will be the third co-ordinated enforcement action to date. The results allow for analysis and insight into the topic, which allows for targeted follow-up at both national and EU levels.</p>



<p class="wp-block-paragraph"><strong>The EU’s AI Act</strong></p>



<p class="wp-block-paragraph">With European Parliamentary Elections scheduled for 6-9 June 2024, the EU is likely to adopt the proposed AI Act in early 2024. Otherwise, the elections could delay its passage until 2025. The Act has seen a certain amount of progress in 2023, with the European Parliament adopting amendments to the proposal on 14 June 2023. However, there have been stumbling blocks, especially over the way generative AI platforms like ChatGPT should be regulated. Big Tech companies have been lobbying to weaken the proposed EU legislation and there have also been calls from the French, German, and Italian governments to reduce some of the stringent measures to ensure AI innovation.</p>



<p class="wp-block-paragraph"><strong>The UK’s AI Regulation Bill</strong></p>



<p class="wp-block-paragraph">The AI Regulation Bill is a Private Member’s Bill, originating in the House of Lords during the 2023-24 session. Last updated on 29 November 2023, the Bill includes provisions for the creation of a body called the AI Authority and the appointment of designated AI officers. The government intends to publish a draft AI risk register for consultation, an updated AI regulatory roadmap, and a monitoring and evaluation report after March 2024.</p>



<h2 class="wp-block-heading"><strong>Data Protection support and advice for 2024</strong></h2>



<p class="wp-block-paragraph">Data protection and privacy is a rapidly evolving industry. The pace of change is a challenge for organisations across all sectors, with new laws and new guidance being released regularly. The ever-pressing need for professional advice and guidance from data protection experts looks set to increase as we move into 2024.</p>



<p class="wp-block-paragraph"><strong>The DPO Centre</strong> offers a range of data protection services, including consultancy, outsourced Data Protection Officers (DPOs), GDPR Representatives and AI Explainability (XAI) Services.</p>



<p class="wp-block-paragraph">This year has seen significant progress in the data protection industry, with many new privacy laws being enacted across the globe.</p>



<p class="wp-block-paragraph">In this blog, we look at some of the major events and news stories that have shaped the landscape, influencing the direction of policies and processes.</p>



<p class="wp-block-paragraph">What does the development of data protection laws mean for organisations? And how will the data protection industry continue to evolve? Big questions to keep in mind as we go into 2024.</p>



<h2 class="wp-block-heading"><strong>Major data protection events</strong></h2>



<p class="wp-block-paragraph"><strong>5 years of the GDPR:</strong>&nbsp;The General Data Protection Regulation (GDPR) celebrated its 5<sup>th</sup>&nbsp;anniversary on 25 May 2023. Coming into force on 25 May 2018, it is cited as one of the toughest pieces of privacy legislation in the world. The EU’s principle-based directive was introduced to protect the fundamental rights of individuals by safeguarding their personal data and creating a harmonised framework for data flow across the EU’s digital single market.</p>



<p class="wp-block-paragraph">To mark the anniversary, The DPO Centre held a webinar to discuss the wins and challenges for businesses. Essentially, what worked, what didn’t, and why?&nbsp;<a href="https://www.dpocentre.com/resources/gdpr-webinar/" target="_blank" rel="noreferrer noopener"><strong>Watch The DPO Centre’s lively GDPR debate here</strong></a></p>



<p class="wp-block-paragraph"><strong>Facebook fined a record €1.2 billion:&nbsp;</strong>On 22 May 2023, after 10 years of litigation and 3 court procedures, the Irish Data Protection Commission issued Meta Ireland with the largest GDPR fine to date. It was the fourth fine Meta received this year. The Commission issued two penalties in January 2023 for breaching rules with targeted ads on Facebook and Instagram and in March 2023, a fine for GDPR breaches with WhatsApp.</p>



<p class="wp-block-paragraph">The fines sent a strong message to Tech giants that they cannot continue to neglect their obligations for compliance with data protections regulations. However, Meta has yet to pay the fine and announced its intention to appeal. One of the orders of the penalty charge was for Meta to discontinue its reliance on Standard Contractual Clauses (SCCs) by 12 October. In an update on 7 September 2023, Meta announced they will rely on the new EU-US DPF for data transfers.</p>



<p class="wp-block-paragraph"><strong>The AI Safety Summit</strong>&nbsp;took place in the UK on 1 November 2023 at Bletchley Park. Intended as a landmark event for artificial intelligence, the event brought together leading experts, researchers, and policymakers from around the world.</p>



<p class="wp-block-paragraph">An important outcome of the Summit was&nbsp;<strong>The Bletchley Declaration</strong>&nbsp;– a world-first agreement between 28 jurisdictions, including the EU, the US, and China. The Declaration establishes a shared responsibility to understand and manage the potential risks of AI development. Bias and privacy are topics covered within the Declaration, providing an agenda to focus on building respective risk-based policies across the countries. However, critics have highlighted the lack of detail and the absence of any actionable points for building an effective regulatory framework.</p>



<h2 class="wp-block-heading"><strong>Data protection developments in the EU, UK, and North America</strong></h2>



<p class="wp-block-paragraph"><strong>Europe’s GDPR continues to mature</strong></p>



<p class="wp-block-paragraph">Since its implementation in 2018, the General Data Protection Regulation (GDPR) has become a global standard for data protection. With each passing year, we see further clarification on its interpretation, and a greater understanding of the implications for businesses and individuals alike.</p>



<p class="wp-block-paragraph">There were several key court rulings by the Court of Justice of the European Union (CJEU) this year, which have helped to clarify certain areas of the legislation:</p>



<ul class="wp-block-list">
<li>Accountability principle – The CJEU ruled that not every violation of the GDPR would render all related processing to be unlawful (<a href="https://curia.europa.eu/juris/document/document.jsf?text=&amp;docid=273289&amp;pageIndex=0&amp;doclang=EN&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=3199198" target="_blank" rel="noreferrer noopener"><strong>Case C-60/22</strong></a>)</li>



<li>Right of Access – The CJEU clarified the scope of the GDPR right of access by stating that the right to obtain a ‘copy’ of personal data means that the data subject must be given a ‘faithful and intelligible’ reproduction of all those data</li>



<li>Joint Controllers – The CJEU stated that if a company doesn’t follow GDPR rules for making a joint controller agreement or keeping records of data processing activities, it doesn’t automatically mean that the company’s data processing is illegal.</li>



<li>Penalty fines – The CJEU ruled on 5 December 2023 that a supervisory Data Protection Authority (DPA) may only impose a fine for a GDPR infringement if it was committed wrongfully, either intentionally or negligently. In calculating a fine, a DPA must consider the total worldwide turnover of the entire group from the preceding business year.</li>
</ul>



<p class="wp-block-paragraph"><strong>The European Commission adopted its adequacy decision on EU-US data flows&nbsp;</strong>and established the EU-US Data Privacy Framework (DPF), which came into effect on 10 July 2023. The DPF replaced the invalidated Privacy Shield and aimed to address the concerns previously raised by the CJEU. However, only minutes after the announcement, Max Schrems, Austrian privacy lawyer and activist, expressed his scepticism of the decision and stated his intention to challenge the new deal. A challenge has yet to be submitted by Mr Schrems, but the debate over transatlantic data transfers is clearly not over and will continue into 2024.&nbsp;<strong><a href="https://www.dpocentre.com/eu-us-data-privacy-framework-3rd-time-lucky/" target="_blank" rel="noreferrer noopener">Learn more about the EU-US DPF</a></strong></p>



<h2 class="wp-block-heading"><strong>UK’s key data protection updates</strong></h2>



<p class="wp-block-paragraph"><strong>The UK-US ‘data-bridge’</strong>&nbsp;was approved on 21 September 2023, with it coming into force on 12 October 2023. Serving as an extension to the EU’s Data Privacy Framework (DPF), the data-bridge provides a mechanism for businesses in the UK to transfer personal data to US organisations certified under the ‘UK Extension to the EU-US Data Privacy Framework’ (UK Extension) without the need for further safeguards. However, criticisms of the EU-US DPF include concerns over the potential for increased surveillance by US authorities and the erosion of privacy rights. Many organisations have retained their existing data transfer mechanisms with a ‘wait and see’ approach.</p>



<p class="wp-block-paragraph"><strong>DSIT published AI Skills for Business Competency Framework&nbsp;</strong>for public consultation in November 2023. Supported by the Office for Artificial Intelligence within the Department for Science, Innovation and Technology (DSIT), the draft framework presents guidance on the essential knowledge, skills, and behaviours employees should have to benefit from AI technology. DSIT intends the framework to support businesses, enabling them to understand their AI upskilling needs and to assist training providers in developing relevant training solutions.&nbsp;<a href="https://iuk.ktn-uk.org/wp-content/uploads/2023/11/Final_BridgeAI_Framework.pdf" target="_blank" rel="noreferrer noopener"><strong>Read the draft AI Skills for Business framework</strong></a></p>



<p class="wp-block-paragraph"><strong>The UK’s proposed GDPR replacement moves closer</strong></p>



<p class="wp-block-paragraph">On 19 December 2023 the Data Protection and Digital Information (DPDI) Bill was debated at the second reading stage in the House of Lords. The government believes the updates to the current UK GDPR will support innovation and reduce unnecessary burdens on businesses and organisations. However, the new legislation has the potential to increase costs and complexities for all but the smallest of businesses.</p>



<p class="wp-block-paragraph">The Lords raised many concerns during the second reading, with Lord Bishop of Southwell and Nottingham quoting Rob Masson of The DPO Centre. The Lord Bishop used Mr Masson’s words when calling attention to the way in which the UK seems to be going in the opposite direction to the rest of the globe by lowering data protection standards.</p>



<p class="wp-block-paragraph">Lord Allan of Hallam said,&nbsp;<em>‘It is the concern around EU adequacy that I think should really be front and centre of our discussions when we consider this legislation.’</em></p>



<p class="wp-block-paragraph">This concern was echoed by several other Members, with Lord Vaux of Harrowden succinctly stating,&nbsp;<em>‘We must get this Bill right. If we do not, we risk substantial damage to the economy, businesses, individuals’’ privacy rights – especially children – and even, as far as the surveillance elements go, to our status as a free and open democratic society.’<br></em><a href="https://www.dpocentre.com/dpdi/" target="_blank" rel="noreferrer noopener"><strong>Read the key differences between the UK GDPR and DPDI</strong></a></p>



<h2 class="wp-block-heading"><strong>Canada seeks to update and strengthen its privacy laws</strong></h2>



<p class="wp-block-paragraph">There have been significant developments in Canada’s privacy laws this year. On 24 April, the Canadian House of Commons agreed on the entirety of Bill C-27, the Digital Charter Implementation Act 2022, which seeks to update and strengthen the Personal Information Protection and Electronic Documents Act (PIPEDA), including Canada’s first AI legislation.</p>



<p class="wp-block-paragraph"><strong>In Quebec</strong>, ‘An Act to modernise legislative provisions as regards the protection of personal information’ came into effect in 22 September 2023, with the right to portability under this Act is due to come into force on 22 September 2024.<br><a href="https://www.canlii.org/en/qc/laws/astat/sq-2021-c-25/latest/sq-2021-c-25.pdf" target="_blank" rel="noreferrer noopener"><strong>Read the PDF of Bill 64</strong>&nbsp;</a></p>



<h2 class="wp-block-heading"><strong>The United States sees a wave of new privacy laws</strong></h2>



<p class="wp-block-paragraph">It was a big year for privacy in the US, with 5 new state privacy laws:</p>



<ul class="wp-block-list">
<li>California Privacy Rights Act (CPRA) came into effect on 1 January 2023 and amends the California Consumer Privacy Act (CCPA)</li>



<li>Virginia Consumer Data Protection Act (VCDPA) came into effect on 1 January 2023</li>



<li>The Colorado Privacy Act (CPA) came into effect on 1 July 2023</li>



<li>The Connecticut Data Privacy Act (CTDPA) came into effect on 1 July 2023</li>



<li>The Utah Consumer Privacy Act (UCPA) will come into effect on 31 December 2023</li>
</ul>



<p class="wp-block-paragraph">These laws reflect a shift towards greater consumer control over personal data and increased obligations for organisations in terms of data processing. They also indicate a move towards harmonising state-level laws with global standards, providing new consumer rights aligned with those in the GDPR.</p>



<h2 class="wp-block-heading"><strong>Looking ahead: Data protection in 2024</strong></h2>



<p class="wp-block-paragraph"><a href="https://thedpia.com/" target="_blank" rel="noreferrer noopener"><strong>Subscribe to The DPIA</strong></a>&nbsp;– Keep updated on the latest, most important data protection news with our fortnightly email newsletter.</p>



<p class="wp-block-paragraph"><strong>UK’s DPDI Bill</strong></p>



<p class="wp-block-paragraph">As we move into 2024, all eyes are carefully watching the progress of the proposed Data Protection and Digital Information (DPDI) Bill. The hope of the data protection industry is that the Lords will take into consideration their numerous concerns and apply rigorous scrutiny to the proposed legislation. But only time will tell. We will keep you updated soon as we have further information.</p>



<p class="wp-block-paragraph"><strong>3<sup>rd</sup>&nbsp;party cookies in Chrome to be disabled</strong></p>



<p class="wp-block-paragraph">Google’s plan to phase out 3<sup>rd</sup>&nbsp;party cookies in its Chrome browser begins in quarter 1 of 2024. This is part of a larger initiative called the&nbsp;<strong><a href="https://privacysandbox.com/" target="_blank" rel="noreferrer noopener">Privacy Sandbox</a></strong>&nbsp;project, which aims to reduce cross-site tracking whilst still allowing functionality to keep online services and content freely available.</p>



<p class="wp-block-paragraph">Google will disable 3<sup>rd</sup>&nbsp;party cookies for 1% of users from early January, applying the changes to 100% of users by Q3 2024. The full rollout depends on Google addressing the competition concerns of the UK’s Competition and Markets Authority (CMA). The phasing out of non-essential cookies is in line with the wider global trend towards enhanced data protection and privacy.</p>



<p class="wp-block-paragraph"><a href="https://digital-strategy.ec.europa.eu/en/policies/eprivacy-regulation" target="_blank" rel="noreferrer noopener"><strong>The EU’s</strong>&nbsp;<strong>proposed ePrivacy Regulation</strong></a>&nbsp;establishes clearer rules on cookies, with a more streamlined solution for settings:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><em>‘no consent is needed for non-privacy intrusive cookies that improve internet experience, such as cookies to remember shopping-cart history or to count the number of website visitors.’ (Proposal for an ePrivacy Regulation)</em></p>
</blockquote>



<p class="wp-block-paragraph"><strong>International data transfers</strong></p>



<p class="wp-block-paragraph"><strong>SCCs and IDTA</strong>&nbsp;– From 21 March 2024, UK organisations can no longer use the old EU Standard Contractual Clauses (SCCs) for restricted data transfers. Instead, they must rely on the UK’s International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum (‘UK Addendum’).</p>



<p class="wp-block-paragraph"><strong>EU-UK adequacy</strong>&nbsp;– Later in 2024, the European Commission is due to review the EU-UK adequacy, which will expire on 27 June 2025. The outcome of the UK’s proposed DPDI Bill could significantly affect this decision and create further complications for organisations operating across multiple jurisdictions.</p>



<p class="wp-block-paragraph"><strong>EDPB action: Right of access by controllers</strong></p>



<p class="wp-block-paragraph">The European Data Protection Board (EDPB) will launch a national action in 2024 on ‘The right of access by controllers’. Each year, the EDPB seeks to prioritise certain topics for data protection authorities (DPAs) to work on at a national level. This will be the third co-ordinated enforcement action to date. The results allow for analysis and insight into the topic, which allows for targeted follow-up at both national and EU levels.</p>



<p class="wp-block-paragraph"><strong>The EU’s AI Act</strong></p>



<p class="wp-block-paragraph">With European Parliamentary Elections scheduled for 6-9 June 2024, the EU is likely to adopt the proposed AI Act in early 2024. Otherwise, the elections could delay its passage until 2025. The Act has seen a certain amount of progress in 2023, with the European Parliament adopting amendments to the proposal on 14 June 2023. However, there have been stumbling blocks, especially over the way generative AI platforms like ChatGPT should be regulated. Big Tech companies have been lobbying to weaken the proposed EU legislation and there have also been calls from the French, German, and Italian governments to reduce some of the stringent measures to ensure AI innovation.</p>



<p class="wp-block-paragraph"><strong>The UK’s AI Regulation Bill</strong></p>



<p class="wp-block-paragraph">The AI Regulation Bill is a Private Member’s Bill, originating in the House of Lords during the 2023-24 session. Last updated on 29 November 2023, the Bill includes provisions for the creation of a body called the AI Authority and the appointment of designated AI officers. The government intends to publish a draft AI risk register for consultation, an updated AI regulatory roadmap, and a monitoring and evaluation report after March 2024.</p>



<h2 class="wp-block-heading"><strong>Data Protection support and advice for 2024</strong></h2>



<p class="wp-block-paragraph">Data protection and privacy is a rapidly evolving industry. The pace of change is a challenge for organisations across all sectors, with new laws and new guidance being released regularly. The ever-pressing need for professional advice and guidance from data protection experts looks set to increase as we move into 2024.</p>



<p class="wp-block-paragraph"><strong>The DPO Centre</strong>&nbsp;offers a range of data protection services, including consultancy, outsourced Data Protection Officers (DPOs), GDPR Representatives and AI Explainability (XAI) Services.</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/data-protection-in-2023-a-year-in-review/">Data Protection in 2023: A year in review</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
