Cyber Security Insights November 2024

Cyber Security Insights November 2024

Written by Bryan Altimas

The first days of November have been dull and cloudy without any sun. In many ways that reflects cyber security and data protection. Increasing numbers of attacks and data protection regulation being updated.

Welcome to the November edition of Cyber Security Insights where we look at:

  • The Data Use and Access Bill currently in the House of Lords for debate and its second reading.
  • Fake websites and shopping scams. The risk of thrift party scripts in websites.
  • The .io website extension is set to disappear following a UK Government agreement with Mauritius over the future of the Chagos Islands.

Data Use and Access Bill

25 May 2018 the EU General Data Protection Regulation (GDPR) came into force launching a framework that put the individual in control of what happened to their personal data. The UK finally left the EU at the end of 2020 and the EU GDPR was effectively copied and pasted into UK law as the UK GDPR and formed of the Data Protection Act 2018 and the Privacy and Electronic Communication Regulation 2003.

In June 2021 the EU adjudicated that our UK GDPR gave European citizens equal protection over their personal data and we were given an adequacy decision. The adequacy decision means that data can flow freely between the UK and the wider European Economic Area (EEA).

Since then, in July 2023, the EU agreed a Data Privacy Framework (DPF) with the US which allows data to flow freely between Europe and US companies that have accredited to the DPF. The very snappily named UK Extension to the EU-US Data Privacy Framework quickly followed in September 2023.

That is the current situation we can currently transfer data to our most important trading partners in a regulated environment.

The previous Conservative Government had introduced the Data Protection and Digital Information Bill (DPDI) but it did not proceed through Parliament before our July election. Talking of copying and pasting, the new Labour Governments Data Use and Access Bill is mostly copied and pasted from the DPDI with a few minor additions and some important omissions.

Risks of Changing the UK's Data Protection Regime

As mentioned above, we currently have a data protection adequacy agreement with the EU allowing the free transfer of data between the EU and UK. If the EU considers the UK have moved too far away from the EU GDPR we may lose the adequacy agreement and the ability to freely transfer data to and from the EEA.

Less of a risk, but also possible, the US could withdraw from the UK extension to the EU-US DPF.

Third party companies, particularly big tech, are significant stakeholders in the new regime. Their reputation with our data does not fill me with confidence.

What is the Data Use and Access Bill?

The Government says the new bill will "unlock the secure and effective use of data for the public interest" with a focus on the use of data in law enforcement and health and social care. There is an expected £10 billion economic boost according to the Government. Where is the economic boost coming from?

It is the divorce of the UK's data governance regime from the EU GDPR. The Government aims to use the legislation to modernise data governance, improve economic growth, streamline public services and enhance data security.

Timelines for implementation are not specified but it is expected to come into force during 2025.

How will Data Handling Change the NHS?

The core of the bill is a fundamental shift in the way personal data will be managed, accessed and shared across the public and private sectors. For personal data it means it could be easier for the public sector to use personal data more extensively to improve services. However, it also raises privacy and consent concerns.

Focusing on the NHS for the moment the bill mandates that all NHS IT systems adopt common data formats enabling real time sharing of patient data such as full medical records of patients including from different NHS trusts, GP surgeries, hospitals and ambulance services. According to the Department for Science, Innovation and Technology (DSIT) this will free up 140,000 hours of NHS time annually. DSIT says breaking down data silos will improve the efficiency of patient care, reducing medical errors and eliminating the need for duplicate tests.

The sharing of NHS patient data naturally leads on to the so called Patient Passport. At the core of the digital transformation of the NHS the Patient Passport is a centralised digital record holding medical history, test results and treatment notes. The idea is that across the breadth of the NHS and social care a patient's entire record can be accessed, whether this is by hospitals, GP's, ambulance crews and social care settings. Overall, the objective of the passport or centralised digital record is to enable clinicians to make quicker, well informed decisions reducing duplicate effort and cost and improving the quality of care.

What About Patient Data Privacy?

Under the existing UK GDPR all this data is currently classed as special category data and requires extra security controls. Who will have access to this sensitive data? To achieve the objectives of the NHS digital transformation multinational big tech companies will have to be involved their governance and transparency record is not exactly gold plated.

The NHS governance of the passport will have to beyond reproach especially with partnerships with private sector data firms. Without a robust governance process providing a high level of scrutiny sensitive patient data could be misused or shared without adequate patient control. Such centralised record keeping and storage of data is a new field for the UK and the governance processes must be right from the outset to ensure patient data rights.

The Police

The bill allows the police to automate certain manual data tasks. Currently, officers must log each instance they access personal information on the police database. Automating the process will save an estimated 1.5 million hours a year that can be devoted to front line duties.

Whilst an extra 1.5 million hours a year is to be welcomed the risk is overreach and lack of oversight. Automation and a lack of accountability could lead to unchecked surveillance and misuse of data.

Other In-scope Areas

  1. Infrastructure - the creation of a National Underground Asset Register of pipes and cables aiming to reduce 600,000 accidental strikes annually on buried assets to reduce disruption from roadworks and construction projects.
  2. Births and deaths - a digital transformation of birth and death certificates.
  3. Consumer data - for example energy usage to access better tariffs and purchasing history to provide tailored online shopping deals.
  4. The Secretary of State must establish a register of companies providing digital verification services, digitally verifying the identity of a person. A number of companies provide these services collecting sensitive personal data such as passport data. If these companies are compromised this leaves the government to clear up the mess of fake passports in circulation.

What Remains of the UK GDPR?

The UK GDPR is still in force and will remain with amendments.

The Data Use and Access Bill (DUA) makes it easier to obtain and give consent for uses of personal data that may reasonably be described as scientific research purposes and historical research purposes. Historical research purposes includes processing personal data for genealogical research processes.

The DUA clarifies that processing data for statistical purposes results in data that is aggregate data and not personal data. Also, that the results of processing personal data for statistical purposes can not result in that data being used in decision making about that person.

Further clarification is provided on the data subject giving consent for the processing of their data. The data controller must be able to demonstrate that the data subject provided consent, e.g. consent is evidenced and not by implication. Processing may only be carried out in reliance on consent if—

(a) before the consent is given, the controller or processor informs the data subject of the right to withdraw it, and

(b) it is as easy for the data subject to withdraw the consent as to give it.

Purpose of limitation is another area addressed. Where personal data is processed by a controller for a new different purpose to the original purpose of collecting the data the controller must consider whether the new purpose is aligned with the original purpose and what the lawful basis for that processing is.

There are other minor amendments that I will not detail here.

If you wish to talk about your data protection requirements message us either by LinkedIn messenger or by info@riversidecourtconsulting.co.uk with the message GDPR.

Shopping Scam on Websites

We all shop from websites and some of us are creative enough to develop websites to enable us to shop. This article is for both parties.

This is not a new problem but it is worth highlighting it again. Hundreds of thousands of consumers have been defrauded by a scheme labelled "phish n ships". Malicious code is inserted to legitimate websites to redirect customers to fake websites to purchase hard to find products. Of course the products never arrive.

As Black Friday, Cyber Monday and Christmas approach consumers need to be aware of such scams. Before clicking pay double check the URL of the website to make sure you are still on the website you think you are.

Website developers creating shopping sites and owners of shopping websites please get your developments penetration tested and scanned for vulnerabilities and malware regularly.

If you wish to talk about your website security requirements message us either by LinkedIn messenger or by info@riversidecourtconsulting.co.uk with the message website.

Future of the .io Domain Extension

Over the last few years the .io domain extension has become very popular. Countries and territories are assigned domain extensions by the Internet Assigned Numbers Authority (IANA). The UK has .UK for example. .IO was assigned to the British Indian Ocean Territory, the Chagos Islands.

The UK reached agreement with Mauritius to transfer sovereignty of the Chagos Islands to Mauritius. Assuming the treaty is signed next year as planned (although there has been a change of government since the agreement) the .IO domain should be retired according to IANA.

If you have a .IO domain keep abreast of the news on this.

If you wish to talk about your website message us either by LinkedIn messenger or by info@riversidecourtconsulting.co.uk with the message website.


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right