Information rights and responsibilities, with the Information Commissioner

4 min read
Curated from ico.org.uk →

Thank you for that kind introduction.

Forgive me for being a bit of a tourist. You may be aware that my office is based in a small town called Wilmslow in Cheshire. So even though I am often in the capital, I haven’t developed my London Cool, yet.

I still find it remarkable that, just this morning, for example, when I am essentially on my way into work, I walked past landmarks that millions of people travel across the world to see. Trafalgar Square, St Martins in the Field, the National and Portrait Galleries. And, of course, just a stone’s throw from these rooms, Buckingham Palace.

Queen Victoria was the first monarch to live there. And today is the anniversary of her state funeral – 117 years ago.

So long ago, and yet that time – and the 60 odd years before it – are synonymous with progress, reform and innovation.

Fitting then that as February 2 1901 marked the end of that era, I am here to talk to you about the beginning of another.

On 25 May – a mere 112 days away – the General Data Protection Regulation comes into effect.

It is the beginning of something new, but it is an evolution of what’s gone before. It builds on what was good about the Data Protection Act and brings it in line with our 21 century world.

GDPR rebalances the relationship between individuals and organisations.

It gives greater control to people about how their data is used and it compels organisations to be transparent and account for their actions.

As individuals, most of us applaud a stronger framework. As heads of agencies, some of you may have a different view.

Those organisations that thrive under the new rules will see the GDPR as an opportunity to commit to data protection and embed it in their policies, processes and people.

Get the AI & data signal, daily.

335k+ subscribers read this every morning. One email, both newsletters. Unsubscribe anytime.

Those that merely comply, that treat the GDPR as another box-ticking exercise, miss the point. And they miss a trick.

Because this is about restoring trust and confidence. Only one in five people in the UK trust organisations to look after their data. That’s not good enough.

The GDPR is an opportunity to reset the equilibrium.

But the GDPR is just part of the reform. The government’s Data Protection Bill brings the GDPR into UK law and tackles some of the details over which we have discretion.

You may like to know that the ICO will shortly be publishing an overview – a road map if you like – to help organisations navigate the Data Protection Bill.

But there’s more. Add in the law enforcement directive, which sets out how we’ll tackle crime across borders, the NIS directive, which sets out reporting rules for organisations that suffer a cyber attack, and the e-privacy directive, which sets the rules for direct marketing via phone, text and email. That’s quite a substantial suite of data protection changes.

My office is working in a new age of data protection. Where this government and others around the globe have recognised that personal data is the fuel that powers so much of what makes our economy, our home life, our public services function.

The UK is a leader in data protection – it’s one of the things that attracted me to this job – and the government has made clear its intention that we retain our world-class status as well as making the UK the safest place to be online.

That’s a huge challenge for my office. But we have to deliver.

I am strengthening my team in number and expertise and we’re moving the ICO to a place where we can deliver our new responsibilities and obligations to organisations and, importantly, the public. Earlier this month Treasury has provided the ICO pay flexibility for the next three years – this is critically important to be able to retain our expert staff and attract new technologists, lawyers and auditors.

We’re expecting more of everything. More breach reports because the law requires it in high risk cases. More complaints, because people will be better informed of their rights. Greater engagement as organisations turn to us for advice at the outset.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at ico.org.uk →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.