The first days of November have been dull and cloudy without any sun. In many ways that reflects cyber security and data protection. Increasing numbers of attacks and data protection regulation being updated.
Welcome to the November edition of Cyber Security Insights where we look at:
25 May 2018 the EU General Data Protection Regulation (GDPR) came into force launching a framework that put the individual in control of what happened to their personal data. The UK finally left the EU at the end of 2020 and the EU GDPR was effectively copied and pasted into UK law as the UK GDPR and formed of the Data Protection Act 2018 and the Privacy and Electronic Communication Regulation 2003.
In June 2021 the EU adjudicated that our UK GDPR gave European citizens equal protection over their personal data and we were given an adequacy decision. The adequacy decision means that data can flow freely between the UK and the wider European Economic Area (EEA).
Since then, in July 2023, the EU agreed a Data Privacy Framework (DPF) with the US which allows data to flow freely between Europe and US companies that have accredited to the DPF. The very snappily named UK Extension to the EU-US Data Privacy Framework quickly followed in September 2023.
That is the current situation we can currently transfer data to our most important trading partners in a regulated environment.
The previous Conservative Government had introduced the Data Protection and Digital Information Bill (DPDI) but it did not proceed through Parliament before our July election. Talking of copying and pasting, the new Labour Governments Data Use and Access Bill is mostly copied and pasted from the DPDI with a few minor additions and some important omissions.
As mentioned above, we currently have a data protection adequacy agreement with the EU allowing the free transfer of data between the EU and UK. If the EU considers the UK have moved too far away from the EU GDPR we may lose the adequacy agreement and the ability to freely transfer data to and from the EEA.
Less of a risk, but also possible, the US could withdraw from the UK extension to the EU-US DPF.
Third party companies, particularly big tech, are significant stakeholders in the new regime. Their reputation with our data does not fill me with confidence.
The Government says the new bill will "unlock the secure and effective use of data for the public interest" with a focus on the use of data in law enforcement and health and social care. There is an expected £10 billion economic boost according to the Government. Where is the economic boost coming from?
It is the divorce of the UK's data governance regime from the EU GDPR. The Government aims to use the legislation to modernise data governance, improve economic growth, streamline public services and enhance data security.
Timelines for implementation are not specified but it is expected to come into force during 2025.
The core of the bill is a fundamental shift in the way personal data will be managed, accessed and shared across the public and private sectors. For personal data it means it could be easier for the public sector to use personal data more extensively to improve services. However, it also raises privacy and consent concerns.
Focusing on the NHS for the moment the bill mandates that all NHS IT systems adopt common data formats enabling real time sharing of patient data such as full medical records of patients including from different NHS trusts, GP surgeries, hospitals and ambulance services. According to the Department for Science, Innovation and Technology (DSIT) this will free up 140,000 hours of NHS time annually. DSIT says breaking down data silos will improve the efficiency of patient care, reducing medical errors and eliminating the need for duplicate tests.
The sharing of NHS patient data naturally leads on to the so called Patient Passport. At the core of the digital transformation of the NHS the Patient Passport is a centralised digital record holding medical history, test results and treatment notes. The idea is that across the breadth of the NHS and social care a patient's entire record can be accessed, whether this is by hospitals, GP's, ambulance crews and social care settings. Overall, the objective of the passport or centralised digital record is to enable clinicians to make quicker, well informed decisions reducing duplicate effort and cost and improving the quality of care.
Under the existing UK GDPR all this data is currently classed as special category data and requires extra security controls. Who will have access to this sensitive data? To achieve the objectives of the NHS digital transformation multinational big tech companies will have to be involved their governance and transparency record is not exactly gold plated.
The NHS governance of the passport will have to beyond reproach especially with partnerships with private sector data firms. Without a robust governance process providing a high level of scrutiny sensitive patient data could be misused or shared without adequate patient control. Such centralised record keeping and storage of data is a new field for the UK and the governance processes must be right from the outset to ensure patient data rights.
The bill allows the police to automate certain manual data tasks. Currently, officers must log each instance they access personal information on the police database. Automating the process will save an estimated 1.5 million hours a year that can be devoted to front line duties.
Whilst an extra 1.5 million hours a year is to be welcomed the risk is overreach and lack of oversight. Automation and a lack of accountability could lead to unchecked surveillance and misuse of data.
The UK GDPR is still in force and will remain with amendments.
The Data Use and Access Bill (DUA) makes it easier to obtain and give consent for uses of personal data that may reasonably be described as scientific research purposes and historical research purposes. Historical research purposes includes processing personal data for genealogical research processes.
The DUA clarifies that processing data for statistical purposes results in data that is aggregate data and not personal data. Also, that the results of processing personal data for statistical purposes can not result in that data being used in decision making about that person.
Further clarification is provided on the data subject giving consent for the processing of their data. The data controller must be able to demonstrate that the data subject provided consent, e.g. consent is evidenced and not by implication. Processing may only be carried out in reliance on consent if—
(a) before the consent is given, the controller or processor informs the data subject of the right to withdraw it, and
(b) it is as easy for the data subject to withdraw the consent as to give it.
Purpose of limitation is another area addressed. Where personal data is processed by a controller for a new different purpose to the original purpose of collecting the data the controller must consider whether the new purpose is aligned with the original purpose and what the lawful basis for that processing is.
There are other minor amendments that I will not detail here.
If you wish to talk about your data protection requirements message us either by LinkedIn messenger or by info@riversidecourtconsulting.co.uk with the message GDPR.
We all shop from websites and some of us are creative enough to develop websites to enable us to shop. This article is for both parties.
This is not a new problem but it is worth highlighting it again. Hundreds of thousands of consumers have been defrauded by a scheme labelled "phish n ships". Malicious code is inserted to legitimate websites to redirect customers to fake websites to purchase hard to find products. Of course the products never arrive.
As Black Friday, Cyber Monday and Christmas approach consumers need to be aware of such scams. Before clicking pay double check the URL of the website to make sure you are still on the website you think you are.
Website developers creating shopping sites and owners of shopping websites please get your developments penetration tested and scanned for vulnerabilities and malware regularly.
If you wish to talk about your website security requirements message us either by LinkedIn messenger or by info@riversidecourtconsulting.co.uk with the message website.
Over the last few years the .io domain extension has become very popular. Countries and territories are assigned domain extensions by the Internet Assigned Numbers Authority (IANA). The UK has .UK for example. .IO was assigned to the British Indian Ocean Territory, the Chagos Islands.
The UK reached agreement with Mauritius to transfer sovereignty of the Chagos Islands to Mauritius. Assuming the treaty is signed next year as planned (although there has been a change of government since the agreement) the .IO domain should be retired according to IANA.
If you have a .IO domain keep abreast of the news on this.
If you wish to talk about your website message us either by LinkedIn messenger or by info@riversidecourtconsulting.co.uk with the message website.
