Two of 2018's biggest news topics were the introduction of GDPR and the apparently never ending Brexit saga. You might be forgiven for rolling your eyes, as it seems that pretty much everyone in the country has had enough of both of these stories.
The latest developments in the Brexit saga now have new implications for GDPR and your compliance. GDPR came into force on the 25th of May last year and required all companies to bolster their existing data management processes with the aim of improving the rights for EU citizens whose data was held by third parties. As the 25th of May passed the UK was still a fully functioning member of the EU but it now looks increasingly likely that the UK will leave the EU in a, dreaded by some, 'no deal' scenario. If the UK does leave without a deal there could be dramatic ramifications for anyone who deals with partners on the continent.
The 29th of March 2019 has been repeatedly confirmed as the deadline for an initial Brexit deal, subject to potential transition periods which are yet to be confirmed. If the deadline is reached and no agreement has been found between the UK and the 27 EU member states interaction between UK based companies and partners or subsidiaries in the EU will have to change.
In that scenario the UK would then be considered a 'third country' and as a result EU organisations will have to be able to demonstrate that transfers to and from UK companies comply with their internal GDPR regulations. You might be thinking we comply now so surely we will comply even if we leave the EU. Don't be so sure.
The UK government have already taken precautionary steps by releasing guidance around Data Protection if the UK chooses to leave with 'no deal'. The guidance outlines planning requirements and the government's approach to preparing the UK for this potential outcome and can be found here.
In the event of a 'no deal' exit the EU will have to make a decision on whether the UK can be awarded 'adequacy status'. This would require the UK to demonstrate that its existing data protection laws are adequate and that companies within the UK are safe and suitably regulated to manage and process EU citizen's data. If the UK passed the rigorous testing the EU commission would be able to make an adequacy decision and if successful personal data would be able to be transferred without further restriction. This would require vigorous investigation of the current legislation in place within the UK, in the form of the Data Protection Act 2018. The UK government have applied for a decision to be made in advance of any potential exit but the EU have decided they are not able to make any deliberations in advance and must wait until official confirmation of the UK becoming a third country.




