Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Personal Data And The EU-UK Trade Deal – One Month In
Articles

Personal Data And The EU-UK Trade Deal – One Month In

ISBuzz TeamBy ISBuzz TeamFebruary 1, 2021Updated:February 15, 20235 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Data protection post-Brexit was not the most polarising subject facing EU and UK trade deal negotiators last year.  It was, however, of fundamental importance for both sides to agree a framework.

Whether this was achieved in the resulting Trade and Cooperation Agreement is subjective – the data provisions in the Agreement provide some degree of short-term certainty for businesses and organisations, but the long-term arrangements are yet to be settled.

Under the Trade and Cooperation Agreement, data has continued to flow from the EU and EEA to the UK since 1 January 2021. This is because the Agreement allows for an interim “specified period” during which the existing data protection regime continues as the status quo. Data is continuing to flow from the UK to the EU and EEA, but this was a UK decision and was not addressed in the Agreement.

The specified period will last for four months from 1 January 2021, but the EU and UK can agree to extend the period by a further two months. This time is needed because an “adequacy decision” has not yet been made by the European Commission. As the UK is now a third country from the EU’s perspective, an adequacy decision reflects whether the EU considers the UK’s data protection regime to be sufficiently similar, or equivalent, to the EU’s data protection regime.

The Trade and Cooperation Agreement anticipates two possible outcomes in relation to the adequacy decision. The first possible outcome is that an adequacy decision will be made within the specified period. This is the preferred outcome for pragmatic reasons, as the result of an adequacy decision will be that personal data can continue to flow from the EU and EEA to the UK without additional measures being introduced. The foregoing will apply for so long as neither jurisdiction substantively changes its legislation because an adequacy decision would be regularly reviewed and could be revoked.

The second possible outcome is that the specified period will end – on 30 June 2021 at the very latest, if the EU and UK agree to the maximum length of extension – without an adequacy decision being made by that time. In this scenario, data would still flow to the UK but be subject to new legal and administrative requirements. For example, UK businesses which trade with entities in the EU or EEA will need to enter into specific new contracts with their EU contacts. These contracts will contain EU-approved Standard Contractual Clauses, the purpose of which is to establish that the contracting UK business has adequate data protection standards.

There is therefore genuine uncertainty surrounding the adequacy decision. The Information Commissioner’s Office (ICO) recommends that UK businesses that are currently involved in relevant data flows into the EU or EEA, or may be involved in such activity in the future, make precautionary arrangements during the next few months in case an adequacy decision is not made. For UK businesses with no customers or contacts in the EU or EEA, precautionary measures are not necessary.

For UK businesses receiving, or likely in the future to receive, personal data from EU and EEA entities, precautions are recommended but the specific preparations will depend on the size and type of a business. Some preparations should be undertaken in any event as part of compliance with existing data protection laws (namely the GDPR, now called the UK GDPR).

Businesses should map where their personal data is coming from. Data mapping should involve identifying the specific EU or EEA country or countries where the data is being transferred from or to, and whether this might change in the future. Questions to then ask include how is the data processed (processing is a broad term and encompasses the obtaining, recording, storing, updating and sharing of data) and who is responsible for it?

As mentioned earlier, Standard Contractual Clauses should be considered and incorporated in to relevant existing and future documentation if appropriate. The Standard Contractual Clauses are standards terms and conditions that serve to protect personal data that flows from the EU or EEA to a third country – which the UK became on the 1 January 2021 – when a third country does not benefit from an adequacy decision. The EU has approved the wording of the clauses and the ICO strongly recommends their use as a safeguard for maintaining the flow of personal data in the event of no adequacy decision.

In addition, businesses should consider the extent of any personal data acquired from the EU or EEA before 1 January 2021. This is called ‘legacy data’. It is important to establish this type of data because, in the event of no adequacy decision, that data will continue to be subject to the EU’s GDPR, rather than the UK’s GDPR, which came into force on 1 January 2021. If there is an adequacy decision, legacy data will not be subject to the EU’s GDPR.

The prospect of several more months of waiting for a view on the adequacy decision is not ideal. Yet the Trade and Cooperation Agreement records that the EU and UK “affirm their commitment to ensuring a high level of personal data protection”.  Such wording reflects the fact that historic alignment, up to 1st January 2021, evidences mutual acknowledgement that each jurisdiction already has a high level of personal data protection and, that absent any changes in legislation on either side, each jurisdiction should view the other’s data protection regime favourably.

[author_box_person person_id=”1069″]

[author_box_person person_id=”1071″]
ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}