About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

Brexit and the UK Data Protection Bill: How does it impact you?

Subscribe to our newsletter

By Dennis Slattery, CEO at EDMworks

On September 13, the UK government introduced in Parliament the Data Protection Bill. Its purpose is to implement a comprehensive data privacy framework for the UK in the post-Brexit environment. The scope of the bill covers:

  • Implementing the General Data Protection Regulation (GDPR) into UK law
  • Implementing the EU Law Enforcement Directive (LED), which member states have until May 6, 2018 to transpose into national law
  • Adopting the standards on processing of personal data carried out by the intelligence services.

The bill is meant to function as a bridge between the existing UK approach to data protection under the 1998 Data Protection Act and the new framework created by the GDPR and the LED. In essence, the bill reinforces the UK’s position on data protection by replicating many of the provisions and safeguards contained in the 1998 Act.

These include processing of sensitive data around criminal convictions, automated decision-making safeguards and exemptions for processing under certain types of circumstances, for example, crime and taxation purposes, research, historical or statistical purposes. The age of a child for UK consent purposes is set at 13, as against 16 in the GDPR.

New criminal offences

The existing offence of unlawfully obtaining personal data is retained with the penalty of unlimited fines. Two new offences are created: (1) re-identification of personal data which is contained in an anonymised dataset; and (2) alteration of personal data to prevent disclosure in response to a data subject access request.

Watch out for the Brexit negotiations!

Transferring data across the EU boundary is tricky. The EU Commission controls a list of ‘3rd’ countries it deems as having ‘adequate levels’ of data protection. Only a few countries are listed: Andorra, Argentina, Canada (commercial organisations), Faeroe Islands, Guernsey, Israel, Isle of Man, Jersey, New Zealand, Switzerland and Uruguay. To transmit data to an entity in another country involves additional legal mechanisms such as the EU/US ‘Privacy Shield’ agreed between the US Department of Commerce and the EU Commission.

In simple terms, EU privacy law puts human rights at the core of data protection, while the US prioritises ‘national security’ ahead of personal privacy. ‘Privacy Shield’ tries to resolve this by providing a legal framework, but it is subject to constant (and successful) legal challenge, which generates uncertainty for everyone involved.

Arguably, the UK position on privacy lies somewhere between the EU and US positions. The status of post-Brexit cross border flows is one of the key items in the EU/UK Brexit negotiations. The outcome will determine whether the UK has 3rd country status, some ‘special’ status or no status at all.

Watch this space. This UK bill may not be the end of the story.

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: How to move to a modern, component based trading architecture using a Buy AND Build approach

To remain competitive in today’s electronic markets, firms need trading architectures that support rapid innovation, effortless integration of new capabilities, and the agility to respond to shifting market demands. This is prompting technology leaders to move beyond the traditional “Buy vs. Build” debate, a false dichotomy that oversimplifies the choice between generic, off-the-shelf platforms and...

BLOG

DORA CTPP List Published, But Who’s Missing?

When the European Supervisory Authorities (ESMA, EBA and EIOPA) published the first list of Critical ICT Third-Party Providers (CTPPs) in November 2025, the step marked a major milestone in the rollout of the Digital Operational Resilience Act (DORA). The regulators described the designations as “crucial” to implementing the Union-level oversight framework. Yet despite the significance...

EVENT

AI in Capital Markets Summit London

Now in its 3rd year, the AI in Capital Markets Summit returns with a focus on the practicalities of onboarding AI enterprise wide for business value creation. Whilst AI offers huge potential to revolutionise capital markets operations many are struggling to move beyond pilot phase to generate substantial value from AI.

GUIDE

Regulatory Data Handbook 2024 – Twelfth Edition

Welcome to the twelfth edition of A-Team Group’s Regulatory Data Handbook, a unique and useful guide to capital markets regulation, regulatory change and the data and data management requirements of compliance. The handbook covers regulation in Europe, the UK, US and Asia-Pacific. This edition of the handbook includes a detailed review of acts, plans and...