Showing posts with label Data Use & Access Bill. Show all posts
Showing posts with label Data Use & Access Bill. Show all posts

Tuesday, May 20, 2025

Lib Dem response on Data Use & Access Bill

 I've had a reponse from the Liberal Democrats on my concerns about the Data Use & Access Bill.

 "Dear Ray,

Thank you for taking the time to write. We are responding on Layla’s behalf whilst she takes parental leave. You can view the full transcript of the Bill’s third reading, along with a record of Layla’s proxy votes on amendments, here. 

The Liberal Democrats welcome the omission of many of the more objectionable elements of the previous DPDI bill, which was introduced by the previous Conservative government but fell when the General Election was called.

Despite these changes, retention and enhancement of public trust in data use and sharing is a major issue in the bill. The focus on smart data and sharing of government data means that the Government must do more to educate the public about how and where our data is used and what powers individuals have to find out this information.

There are still major changes proposed to the Data Protection Act 2018 (GDPR), such as in regard to police duties and Automated Decision Making, which continue to make retention of data adequacy for the purposes of digital trade with the EU of the utmost priority in considering any changes.

We continue to believe that GDPR is not in need of fundamental reform, but rather, where there is any ambiguity in interpretation, clarifications incorporating relevant recitals to the GDPR should be made in the legislation and in improved guidance.

The Liberal Democrats will continue to follow the progress of this Bill closely. Thank you once again for taking the time to get in touch. 


Best wishes,

Office of Layla Moran"

Bottom line - the Lib Dems are not concerned about the expansion in data sharing proposed in the Bill, just that "that the Government must do more to educate the public" about it and the GDPR is not in need of reform.

Tuesday, April 29, 2025

MPs propose amendments to Data Use & Access Bill

I've written to my MP, again, about the Data Use & Access Bill, which is due back for a vote in the House of Commons next week, requesting her support for digital rights amendments to the Bill proposed by Siân Berry of the Greens, Alex Sobel from Labour and Steff Aquaone of the Lib Dems. 

"Please pass on my thanks to your colleague, Steff Aquaone MP, for proposing an amendment to the Data Use and Access Bill that creates a right to use non-digital forms of ID, which will, hopefully, improve accessibility and digital inclusion.

I would also ask that you support two other important amendments to the Bill, when it comes back to the House of Commons in early May, tabled by Sian Berry of the Green Party and Alex Sobel of Labour. The Bill is scheduled for its report stage on the 7th May.

These amendments aim to improve the protection of personal data for vulnerable groups — something I hope you’ll agree is essential.

1. Supporting those most at risk of harm
The Information Commissioner’s Office currently faces a serious backlog in handling complaints. This affects everyone, but especially vulnerable individuals. For example, survivors of domestic abuse and gender-based violence often face heightened risks from online stalking and other forms of digital harm.

Siân Berry is proposing an amendment to introduce a statutory complaints procedure for people in vulnerable situations, along with a right of appeal to the Information Tribunal. This would give those most at risk a clearer, fairer route to justice.

2. Protecting data from unsafe overseas transfers
The Bill also makes it easier for personal data to be transferred outside the UK — including to countries that lack strong data protection laws. Once data is moved abroad, it can be accessed or misused in ways that would be illegal in the UK.

For vulnerable groups — such as refugees, survivors of abuse, and people facing persecution — this poses serious risks. A single data breach overseas could have life-altering consequences.

Alex Sobel MP has tabled an amendment to strengthen safeguards for international data transfers. It would help ensure that UK citizens’ data is not exposed to harmful misuse abroad.

3. The right to non-digital ID verification
The bill establishes a framework for digital ID verification services. It is absolutely critical that people should continue to have the right to use a non-digital form of ID. This would improve accessibility and digital inclusion. As you know, Steff Aquarone MP has tabled this amendment.

A copy of these amendments are included below and is also available on the amendment papers for the Bill at

https://publications.parliament.uk/pa/bills/cbill/59-01/0179/amend/data_use_rm_rep_0422.pdf

Thank you for your time, and I look forward to your reply.

Siân Berry MP - Complaints procedure for vulnerable individuals - NC15

Siân Berry
.To move the following Clause—
“Complaints procedure for vulnerable individuals
(1) The Data Protection Act 2018 is amended in accordance with subsections (2)
to (4).
(2) After section 165(3) insert—
“(3A) For complaints under subsection (2), the Information Commissioner
must provide appropriate complaints-handling procedures for—
(a) victims of modern slavery,
(b) victims of domestic abuse,
(c) victims of gender-based violence, or
(d) data subjects otherwise in a position of vulnerability.
(3B) Procedures under subsection (3A) must include—
(a) appropriate support for vulnerable individuals;
(b) provision of specialised officers for sensitive cases;
(c) signposting to support services;
(d) provision of a helpline;
(e) de-escalation protocols.”
(3) After section 166(1)(c) insert—
“(d) fails to investigate a complaint appropriately or take adequate action to remedy findings of inadequacy.”
(4) After section 166(2)(b), insert—
“(c) to use formal powers as appropriate to investigate a complaint and to remedy any findings of inadequacy, unless the request from the data subject is manifestly unfounded or excessive.””

Member's explanatory statement

This new clause would require the Information Commission to introduce a statutory complaints procedure for individuals in a position of vulnerability and new grounds of appeal to an Information Tribunal.

Alex Sobel MP –Data transfers overseas - Amendment 10

Alex Sobel
.Schedule 7, page 201, line 5, at end insert—
“(1B) A third country cannot be considered adequate or capable of providing
appropriate safeguards by any authority where there exists no credible means
to enforce data subject rights or obtain legal remedy.
(1C) For the purposes of paragraph 1A, the Secretary of State must make a
determination as to whether credible means are present in a third country.
(1D) In making a determination regarding credible means, the Secretary of State
must have due regard to the view of the Information Commissioner.
(1E) Credible means do not exist where the Secretary of State considers that any
of the following are true:
(a) judicial protection of persons whose personal data is transferred to that
third country is insufficient;
(b) effective administrative and judicial redress are not present;
(c) effective judicial review mechanisms do not exist; and
(d) there is no statutory right to effective legal remedy for data subjects.”

Member's explanatory statement

The amendment would prohibit personal data transfer to countries where data subject rights cannot be adequately upheld and prohibit private entities from using contracts to give the impression that data security exists.

Steff Aquarone MP - “Right to use non-digital verification services - NC7
(1) This section applies when an organisation—
(a) requires an individual to use a verification service; and
(b) uses a digital verification service for that purpose.
(2) Where it is reasonably practicable for an organisation to offer a non-digital
method of verification, the organisation must—
(a) make a non-digital alternative method of verification available to any
individual required to use a verification service; and
(b) provide information about digital and non-digital methods of
verification to those individuals before verification is required.”

Member's explanatory statement
This new clause would create a duty upon organisations to support digital inclusion by offering non-digital verification services where practicable."

Friday, February 07, 2025

Privacy concerns about the Data Use and Access Bill

At the prompt of the Open Rights Group, I've written to Layla Moran about the government's proposed the Data Use and Access Bill.

Dear Layla Moran,

I am a resident of Abingdon getting in touch with you as the Liberal Democrat MP for Oxford West and Abingdon

I am writing to you with concerns about the Data Use and Access Bill. The Bill will have its second reading in the House of Commons on Wednesday, 12 February.

This Bill threatens to undo data protections that have safeguarded people's privacy and security for years. It is a significant move away from the EU's GDPR model towards a weaker, US-style system. This dangerous step could leave individuals vulnerable to data exploitation and harm. Businesses depend on a shared set of data protection standards under a common Human Rights framework with our closest trading partners. If we allow this to happen, we not only risk the UK's adequacy agreement with the EU—which is crucial for trade—but, more importantly, erode the fundamental rights of millions of people.

I want to live in a country where personal information is handled respectfully, not where corporations and the government can make decisions about us behind closed doors, using algorithms we can't possibly hope to understand. This Bill weakens key protections and removes essential safeguards, leaving people with little recourse if they are unfairly treated. Have we not learnt anything from recent scandals such as the Horizon Computer system scandal with postmasters? I urge you to stand against these dangerous provisions and fight for amendments that protect people's rights.

1. Safeguarding Rights Against Automated Decision-Making and AI

This Bill dismantles the right not to be subject to fully automated decisions (Clause 80), meaning AI systems could make significant choices about people's lives—including their job prospects, credit eligibility, or access to public services. We already know AI systems can reinforce discrimination and errors, so why weaken protections when we should strengthen them?

Recommendation: Drop Clause 80 and expand Article 22 protections to include increased safeguards around automated decision-making. This helps to ensure a safer roll-out of the expanding role of AI in Government.

2. Preventing Unaccountable Ministerial Powers Over Data Protection.

This Bill grants new secondary legislation powers to the Secretary of State (Clauses 70, 71, 74, 80, 85, and Schedule 7), allowing them to override protections with the limited scrutiny Statutory Instruments receive. This is an affront to democratic accountability. Open Rights Group warns in its latest report how this power could undermine integrity in UK elections, as any party in power could, at very short notice, change the rules on how they can use voters' data in elections. Also, recent events in the United States have shown how access to Government data can become a battlefield in the event of a constitutional crisis: giving unaccountable powers to the Secretary of State is a dangerous proposition that unnecessarily exposes us to the risk of seeing data we gave to a local authority or department being abused via Statutory Instruments.

Recommendation: Remove these Henry VIII powers and instead define what you want to do with data in primary statutory legislation.

3. Strengthening Accountability in Law Enforcement Data Sharing

The Bill lowers accountability for how police and other authorities access and use people's data. It removes the requirement for law enforcement to consider the impact of data-sharing on individuals (Schedules 4 and 5) and even eliminates the need for police to record why they are accessing a database (Clause 81). This makes abuse and overreach far more likely. The example of the Sarah Everard case, in which Police Officers were sacked for wrongful accessing case files, demonstrates why these safeguards are required.

Recommendation: Drop Schedules 4 and 5 and Clause 81 to restore accountability and transparency in law enforcement data use.

4. Addressing the ICO's Failure to Enforce Data Protection Laws.

The Information Commissioner's Office (ICO) is failing in its duty to enforce data protection laws. This is leaving people you represent in Oxford West & Abingdon —especially the most vulnerable—at risk of harm. Open Rights Group's Alternative Annual Report 2023-24 reveals that the ICO has repeatedly failed to act against serious breaches, particularly in cases affecting marginalised individuals. Instead of strengthening the ICO, this Bill weakens its independence, allowing more political influence over its work (Clauses 90 and 91, Schedule 14). This must not be allowed to happen.

Recommendation: Strengthen the ICO's independence by removing ministerial interference and increasing its enforcement powers. Also, the ICO's use of 'reprimands' should be limited, as these are ineffective methods of enforcing data protection laws.

Beyond individual rights, this Bill has significant economic implications. Losing the EU's adequacy agreement would be devastating to UK businesses, potentially costing between £1 billion and £1.6 billion in compliance costs and lost opportunities (New Economics Foundation and UCL European Institute). This is an unnecessary, self-inflicted wound that Parliament must prevent.

We need a data protection system that works for people—not just corporations. Please advocate for your constituents' rights by opposing these damaging provisions and working towards amendments that will restore public trust and accountability.

Yours sincerely,
Ray Corrigan