LEGAL, REGULATORY & COMPLIANCE CONSULTANTS

Handley Gill Limited

Our expert consultants at Handley Gill share their knowledge and advice on emerging data protection, privacy, content regulation, reputation management, cyber security, and information access issues in our blog.

You know how i feel

Handley Gill Limited, and its specialist data protection consultants, respond to the Information Commissioner’s (ICO’s) consultation on its draft ‘Employment practices and data protection: information about workers’ health guidance, which address the use of special category data concerning health in the context of maintaining sickness, injury and absence records, occupational health schemes, conducting medical examinations and testing (including drug testing) and other health monitoring.

Read More
Data Protection Day 2023

In advance of Data Protection Day 2023 - aka Data Privacy Day 2023 - on 28 January, Handley Gill Limited’s specialist data protection consultants identify 5 ways you can use the occasion to enhance your data protection management programme / privacy management programme.

Read More
Watch and learn

Handley Gill Limited, and its specialist data protection consultants, respond to the Information Commissioner’s (ICO’s) consultation on its draft ‘Employment practices: monitoring at work’ guidance, which addresses the lawfulness of the use of workplace monitoring and surveillance technologies in the workplace (whether office, home or remote working) and on workers’ devices.

Read More
HM Coroner vs the Online Safety Bill

As the deadline approaches for the government and social media platforms to respond to HM Coroner’s recommendations in the Prevention of Future Deaths report following the Molly Russell inquest verdict, Handley Gill considers how the recommendations stack up against the provisions of the Online Safety Bill.

Read More
Take Two

Handley Gill Limited’s response to the Information Commissioner’s second consultation on the draft statutory ‘Data protection and journalism code of practice’, on the processing of personal data for the purpose of journalism under the UK GDPR and Data Protection Act 2018. The ICO is obliged by s.124 Data Protection Act 2018 to prepare and submit the code to the Secretary of State at the Department for Digital, Culture, Media & Sport (DCMS) for it to be laid before Parliament.

Read More
Risky business

New guidance issued by the Information Commissioner’s Office on the approach to assessing the risk of restricted ex-UK international data transfers may ease restrictions on transfers of personal data to the US and presents an opportunity to revisit ex-UK international data transfers that had previously been rejected as non-compliant.

Read More
Biden waves Privacy Magic Wand

President Biden issued Executive Order On Enhancing Safeguards For United States Signals Intelligence Activities on 07 October 2022, enhancing the safeguards afforded to global citizens and laying the foundation for adequacy findings by the European Commission and Secretary of State for ex-EEA and ex-UK restricted international data transfers. While the risk of legal challenge to any adequacy finding would remain, such findings would provide welcome respite for the millions of data exporters who are neither equipped nor resourced to conduct wide ranging reviews of foreign legislation at an individual level.

Read More
GDP-ouR

In a speech at the Conservative Party Conference 2022, Michelle Donelan MP, the Secretary of State for Digital, Culture, Media and Sport, announced a bespoke British system of data protection, appearing to indicate a significant revision to the Data Protection and Digital Reform Bill currently undergoing Parliamentary consideration and a potential consolidation of the UK’s data protection law framework.

Read More
Revocation and Reform offers no R & R

Without intervention by DCMS, the Retained EU Law (Revocation and Reform) Bill will decimate the UK’s data protection law framework.

Read More
See ya SCCs, enter the IDTA

New data processing or other sharing agreements governed by the UK GDPR, which are entered into on or after Thursday 22 September 2022 and which involve the export of personal data from the UK to third countries and will rely on appropriate safeguards under Article 46 UK GDPR in the form of standard data protection clauses, can no longer rely on the standard contractual clauses (SCCs) or ‘model clauses’ issued by the European Commission and valid as at 31 December 2020 and must instead incorporate the International Data Transfer Agreement or modernised SCCs and International Data Transfer Addendum.

Read More
DCMS SoS?

Handley Gill considers the impact of the new Prime Minister, Liz Truss, and Secretary of State at the Department for Digital, Culture, Media and Sport, for the Online Safety Bill and the Data Protection and Digital Information Bill.

Read More
Keeling calling: Data Protection & Digital Information Bill

Unofficial Keeling schedules demonstrating the effect that the Data Protection and Digital Information Bill (Bill 143 2022-23) (as introduced) will have on the Data Protection Act 2018 and Privacy and Electronic Communications Regulations (PECR), and a comparison between the GDPR, UK GDPR and the UK GDPR with prospective amendments from the Data Protection and Digital Information Bill.

Read More
Truss calls time for TikTok?

As Conservative Party Leadership Contest candidate Liz Truss threatened to crack down on ByteDance, the Chinese owner of social media platform TikTok, during the BBC’s News Special ‘Our Next Prime Minister’ on 25 July 2022, we explore how she might seek to do that under the National Security and Investment Act 2021, through amendments to the Online Safety Bill and/or Data Protection and Digital Information Bill and through the actions of regulators Ofcom and the Information Commissioner.

Read More
In the Firing Line?

ICO25, the Information Commissioner’s new draft strategic plan for the period 2022-25, currently open for consultation, identifies 15 industry sectors and data processing activities proposed to be the intended focus of the Commissioner’s investigations and enforcement activity in relation to data protection and the processing of personal data under the UK GDPR, Data Protection Act 2018 and Privacy and Electronic Communications Regulations (PECR), including recruitment, banking and finance, biometrics, the care sector, gambling, CCTV, law enforcement, health, AI and algorithms.

Read More
Rishi’s capital gains?

Former Chancellor and Conservative Party leadership candidate Rishi Sunak’s promise that one of his top priorities will be the removal of the burdens of the GDPR need not be interpreted as a significant departure from the proposals for the Data Reform Bill set out in the Government’s response to the Data: A New Direction consultation, but it will rely on the European Commission adopting equality of approach and not seeking to punish the UK for Brexit.

Read More
Is the Online Safety Bill safe?

Conclusion of the Report stage of the Online Safety Bill in the House of Commons, which was scheduled for 20 July, has now been postponed until after the summer recess. Responding to the news, Conservative Party leadership candidate Kemi Badenoch described the Bill as being “in no fit state to become law”, raising the prospect that the Online Safety Bill may become safer, but for whom?

Read More
Bill of Rights... and Wrongs?

Handley Gill considers the impact of the Bill of Rights (Bill 117 2022/23), which would repeal and replace the Human Rights Act 1998, on the law of data protection, privacy and freedom of expression in the UK.

Read More
Pile Up Ahead?

Handley Gill comments on the Government’s response to the ‘Data: A New Direction’ consultation, which previews the content of the forthcoming Data Reform Bill, and identifies other issues which would merit being addressed in the proposed legislation.

Read More
Nicola CainHandley Gill LimitedPERSONAL DATA, UK GDPR, UK GENERAL DATA PROTECTION REGULATION, DATA PROTECTION ACT 2018, DPA 2018, PECR, PRIVACY AND ELECTRONIC COMMUNICATIONS REGULATIONS, DATA: A NEW DIRECTION, DATA PROTECTION REFORM, BREXIT, NATIONAL DATA STRATEGY, CONVENTION FOR THE PROTECTION OF INDIVIDUALS WITH REGARD TO AUTOMATIC PROCESSING OF PERSONAL DATA, POLITICAL PROCESSING, ARTICLE 6 UK GDPR, SPECIAL CATEGORY PERSONAL DATA, SCHEDULE 1 DATA PROTECTION ACT 2018, ANONYMITY, ANONYMOUS DATA, ARTICLE 4(1) UK GDPR, THE COUNCIL OF EUROPE’S CONVENTION 108, THE COUNCIL OF EUROPE CONVENTION 108, PRIVACY MANAGEMENT PROGRAMME, DATA PROTECTION OFFICER, ARTICLE 37 UK GDPR, DATA PROTECTION IMPACT ASSESSMENT, DPIA, ARTICLE 35 UK GDPR, ARTICLE 30 UK GDPR, RECORDS OF PROCESSING ACTIVITIES, ARTICLE 36 UK GDPR, PRIOR CONSULTATION, ARTICLE 12(5) UK GDPR, MANIFESTLY UNFOUNDED OR EXCESSIVE, VEXATIOUS OR EXCESSIVE, ARTICLE 45(2) UK GDPR, INTERNATIONAL DATA TRANSFERS, ADEQUACY DECISION, S.17B(1) DATA PROTECTION ACT 2018, COOKIES, COOKIE CONSENT, REGULATION 6 PRIVACY AND ELECTRONIC COMMUNICATIONS REGULATIONS, REGULATION 22(2) PRIVACY AND ELECTRONIC COMMUNICATIONS REGULATIONS, SOFT OPT-IN, MARKETING, INFORMATION COMMISSIONER, EXPERT PANEL, ENFORCEMENT, MONETARY PENALTY NOTICE, ARTICLE 15 UK GDPR, DATA SUBJECT ACCESS REQUEST, SUBJECT ACCESS REQUEST, BILL OF RIGHTS, EUROPEAN COURT OF HUMAN RIGHTS, UK SUPREME COURT, SUPREME COURT, EUROPEAN COMMISSION, COMMISSION IMPLEMENTING DECISION C(2021) 4800, Data Protection & Digital Information BillComment
U-turn?

Handley Gill summarises the Government's publication of its response to the ‘Data: A New Direction’ consultation, previewing the content of the forthcoming Data Reform Bill, which was proposed in ‘The Benefits of Brexit’ policy paper and formally announced in the Queen’s Speech 2022.

Read More
Nicola CainPersonal Data, UK GDPR, UK General Data Protection Regulation, Data Protection Act 2018, DPA 2018, PECR, Privacy and Electronic Communications Regulations, Data: A New Direction, Data Protection Reform, BREXIT, National Data Strategy, Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, Article 89 UK GDPR, Recital 159 UK GDPR, Recital 33 UK GDPR, Article 14 UK GDPR, Recital 62 UK GDPR, Disproportionate effort, Article 6(1)(f) UK GDPR, Political processing, Article 6 UK GDPR, Special Category Personal Data, Schedule 1 Data Protection Act 2018, Anonymity, Anonymous Data, Article 4(1) UK GDPR, the Council of Europe’s Convention 108, the Council of Europe Convention 108, Privacy management programme, Data Protection Officer, Article 37 UK GDPR, Data Protection Impact Assessment, DPIA, Article 35 UK GDPR, Article 30 UK GDPR, Records of Processing Activities, Article 36 UK GDPR, Prior Consultation, Article 12(5) UK GDPR, Manifestly Unfounded or Excessive, Article 45(2) UK GDPR, International data transfers, Adequacy Decision, s.17B(1) Data Protection Act 2018, Alternative Transfer Mechanisms, Article 46 UK GDPR, Law enforcement processing, Part 3 Data Protection Act 2018, Part 4 Data Protection Act 2018, Cookie Consent, Regulation 6 Privacy and Electronic Communications Regulations, Regulation 22(2) Privacy and Electronic Communications Regulations, Soft Opt-In, Marketing, Regulatory Enforcement, Information Commissioner, Statutory Duties, Statement of Strategic Priorities, Expert Panel, Technical Reports, Notice of Intent, Final Penalty Notice, AI, Artificial Intelligence, Article 22 UK GDPR, Automated Processing, Voluntary Undertakings, Data Breach Reporting, Article 33 UK GDPR, Article 15 UK GDPR, Data Subject Access Request, Reverse Transfers, Article 49 UK GDPR, Derogations, s.35 Digital Economy Act 2017, Data Sharing, Algorithm Transparency, Schedule 1 Part 2 Data Protection Act 2018, Substantial Public Interest, Biometric Data, Impact Assessments, Legitimate Interests Assessment, Biometrics Commissioner, Smart Data Schemes, Data Intermediaries, Article 46(2)(f) UK GDPR, Certification Regime, Surveillance Camera Commissioner, Schedule 16 paragraph 2(2) Data Protection Act 2018, Data Protection & Digital Information BillComment
I Always Feel Like Somebody's Watching Me

In this presentation, to coincide with London Tech Week 2022 and the Future of Work Summit, Handley Gill identifies the legal and regulatory issues arising from the deployment of employee monitoring and surveillance technologies in the hybrid workplace, and provides guidance on how to establish a compliant programme.

Read More