A very busy month at RCC towers! We have had 2 data privacy issues of cyber security insights looking at the UK government's attempts under the Investigatory Powers Act 2016 to force Apple to develop a backdoor into iCloud storage encryption. Apple appealed to the Investigatory Powers Tribunal which is held in secret and is presumably ongoing.
In this edition we look at:
Two relatively long articles so grab a delicious coffee and make yourselves comfortable.
When we develop a cyber security strategy we are not doing it in a silo. The company's objectives and strategy must be considered as well as the external environment.
The internal and external inputs create a strong foundation for the strategy. The strategic inputs in a cyber security strategy are:
What we call the threat landscape is continuously evolving with emerging cyber security risks such as AI (probably a maturing risk and evolving at the same time), quantum computing and the internet of things (IOT meaning internet connected home devices such as white goods) whilst at the same time providing opportunities. To mitigate the evolving threat landscape a robust cyber security strategy is required which will have 7 fundamental foundations.
Involving cyber security during the design phase identifies vulnerabilities and mitigations early on and saves money. Retro-fitting cyber security and data protection controls is very expensive.
Secure by design builds resilient systems that safeguard critical assets and generates stakeholder trust.
Implementing and successfully operating the basic cyber security controls are non-negotiable. The basic controls are:
A properly educated and informed team are, simply, your strongest asset.
A breach is inevitable and organisation must prepare for rapid incident detection, containment and recovery. A well-documented but agile incident response plan minimises disruption and enhances resilience.
Engaging with stakeholders ensures alignment between cybersecurity and business strategy. Clear communication fosters trust and secures buy-in for strategic initiatives.
Third-party vendors often introduce vulnerabilities. Organisations should assess vendor security postures, enforce contractual safeguards and implement continuous monitoring to mitigate supply chain risks.
Regular independent assessments of security controls validate their effectiveness. This ongoing process strengthens the organization’s risk posture and ensures compliance with industry standards.
If you have been promoted to consider your cyber security strategy contact us on LinkedIn messenger or by email at info@riversidecourtconsulting.co.uk with the message strategy.
The Data Use and Access Bill (DUAB) proposes significant changes to the UK's data privacy framework and introduces potential risks to our ability to freely transfer data to the EU and wider EEA, the US and other countries that have an adequacy agreement with the UK over their data privacy frameworks. We feel your pain as you think back to the implementation of GDPR.
Perhaps the most controversial aspect of DUAB is its approach to automated decision-making and AI-driven data processing. Unlike GDPR, which imposes strict limitations on automated decision-making affecting individuals, DUAB allows broader use of AI and other automated processes for most personal data, with the exception of special category data such as health or biometric information.
This shift could enable businesses to implement AI-driven profiling and employment screening but will require safeguards to allow individuals to challenge or appeal decisions made solely by automated systems.
While special category data remains subject to stricter rules, the bill signals a more relaxed regulatory approach to AI compared to the European Union.
One of the core elements of DUAB is the addition of a lawful basis for processing personal data. Recognised legitimate interests means that public bodies will be able to request data from private companies to support their work, with limited rights for individuals to object to this data sharing.
A notable new addition in the legislation is the recognition of neurodata as a special category of sensitive data.
Neurodata refers to information generated from devices or technologies that interact with the human brain or nervous system, such as smartwatches and neural interfaces.
Given the highly personal nature of this data, the ICO has taken a proactive stance in ensuring heightened protections and ethical considerations when processing neurodata.
Clarification is provided the handling of data subject access requests (SAR) by introducing timelines and defining reasonable and proportionate searches for requested data. Organisations will have the ability to stop repeated clarification requests on provided data to the individual.
The clarification aims to reduce the administrative burden on organisations responding to a SAR.
Another significant revision concerns the exemption for ‘disproportionate effort or impossibility’ in providing information to individuals whose data was not directly collected from them. For instance, historical records used for research purposes may not require direct notification if informing each data subject would be unreasonably difficult or impossible.
Procedural changes are aimed at resolving data-related complaints more efficiently. Individuals will now need to file complaints directly with the organisations data controller before escalating them to the Information Commissioner’s Office (ICO). This approach is designed to streamline resolutions at the company level and reduce the regulatory workload on the ICO.
DUAB relaxes restrictions by allowing third parties to contact individuals using an opt-out approach, rather than requiring explicit consent.
This change will likely benefit businesses engaged in direct marketing, but organisations must still conduct a balancing test to ensure that their interests do not override individuals’ rights.
Data subjects will retain the right to object to such processing, ensuring some level of control over their personal information.
One of the most impactful changes for businesses relates to data processing beyond its original purpose. DUAB permits further processing if it aligns with the initial reason for data collection, with the government determining what qualifies as “compatible” processing.
Additionally, the bill upholds the lawful basis for US law enforcement agencies to access UK telecommunications data in serious crime investigations. This measure ensures that businesses remain compliant when handling cross-border law enforcement requests.
Modernising rules that originated from the Privacy and Electronic Communications (PECR) Regulations 2003. A key update involves the regulation of data collected automatically from user devices, including IP addresses and device identifiers. The revised rules extend to remote data collection techniques such as server-side tracking, aiming to close loopholes that previously allowed tracking without user knowledge or consent.
Further ePrivacy changes introduce new exemptions for certain cookies and tracking technologies. In some cases, explicit user consent will no longer be required, provided that individuals receive clear information and retain the right to object. This includes analytics cookies used for website performance measurement, preference cookies that store user settings, and security-related cookies that detect fraud or enhance network security. In many cases the cookie pop-up requesting consent will not be required.
The government will have the authority to modify cookie consent exemptions in the future, allowing for regulatory flexibility in response to technological advancements and emerging privacy concerns.
DUAB significantly strengthens enforcement measures, particularly in direct marketing and cookie-related breaches. While previous fines were capped at £500,000, under the new framework, violations could incur penalties equivalent to those under UK GDPR—up to £17.5 million or 4% of a company’s total worldwide turnover. This increased penalty structure serves as a strong deterrent against unlawful tracking and intrusive marketing practices.
The bill also promotes Smart Data schemes, aiming to facilitate controlled and regulated data exchanges between businesses.
Similar to the UK’s Open Banking initiative, Smart Data schemes could drive innovation and competition across industries such as energy and telecommunications. By establishing open standards and interoperability, businesses could enhance customer experiences, improve service customisation, and increase efficiency in switching providers.
Organisations operating in sectors that may adopt Smart Data schemes should consider how this shift could impact their business models and customer relationships.
There are potential risks to our adequacy agreement with the EU and the UK extension to the EU-US data privacy framework as well as adequacy agreements we have with other countries.
Certainly the EU will review the changes to satisfy themselves that there are no weaknesses compared to the EU GDPR and our current UK GDPR.
