When the transition period ends on 31 December 2020, completing the UK’s exit from the European Union, businesses with customers in Europe will need to keep on the right side of data protection legislation.
The EU’s General Data Protection Regulation (GDPR) establishes strict requirements for businesses processing personally identifiable information about individuals who live within the EEA, which comprises EU member states plus Iceland, Liechtenstein and Norway.
GDPR has continued to apply alongside the UK Data Protection Act 2018 during the transition period. However, any UK business managing personal data relating to EEA citizens after 31 December 2020 must act in line with the requirements of Article 27 of the GDPR which spells out the obligations for data controllers and processors outside the EU.
Even though GDPR will be retained in domestic law at the end of the transition period, the UK will no longer be part of the EU, so if you handle data relating to citizens in the EEA and your organisation does not have an office or representation within Europe, then you will have to appoint someone to fulfil that requirement. You need a provider in the EEA who offers services as a GDPR representative to act on your behalf with individuals and data protection authorities in the EEA.
This is most likely to affect small to medium-sized businesses, as larger organisations will probably have a base somewhere in the EU already. Although you may have gone through the compliance process when GDPR was introduced in 2018, you must check the position now to ensure you will be compliant from January onwards.
Equally, you should also check that your privacy information and documentation is up to date and reflects any changes that may be required, such as those concerning European-based representation and the UK’s (probable) status as a “third country”.
If any GDPR breaches come to light, significant fines can be imposed by the Information Commissioner of up to 10m Euros or 2% of global revenues, so it’s worth consulting a specialist to confirm that your business has everything in order.
The Information Commissioner’s Office, or ICO, is the independent supervisory body for the UK’s data protection legislation and will continue in that role following transition. The ICO website includes guidance for data processors on managing the departure from the EU, with an interactive toolkit to help organisations understand what they need to do to maintain a free flow of data to the UK from the EU.
Post-transition, the provisions of GDPR will be incorporated directly into UK law, to sit alongside the Data Protection Act 2018. Therefore, any organisation operating in the UK and processing data regarding UK residents must continue to comply with all related legislation.