The Information Commissioner’s Office (ICO) issued a further response to the Data Protection and Digital Information (No 2) Bill now that it has been through the House of Commons Committee Stage. Here is the Information Commissioner’s full response:

Information Commissioner’s response to the Data Protection and Digital Information Bill

The Data Protection and Digital Information Bill was was first introduced during the 2022-23 session as the Data Protection and Digital Information (No. 2 Bill). The Bill has now been carried over to the 2023-24 session.

It is important to note that the ICO response primarily focuses on broader data protection issues rather than specific school operations. However, aspects like the handling of biometric data, amendments around consent, data provided for court proceedings and codes of conduct could have implications for how schools manage data, particularly in areas like student records and research activities.

With that in mind, here is a summary of the key points from this response:

The Information Commissioner’s Office (ICO) supports the bill for enhancing regulatory certainty, promoting growth, and protecting individual rights. However, the ICO raises concerns about unaddressed issues, particularly regarding high-risk processing definitions. It appreciates government amendments like enhancing ICO’s independence and aligns with the UK GDPR on data breach reporting timelines.

Concerns are noted about new clauses introduced without extensive consultation, especially the power to require information for social security purposes, questioning its proportionality and clarity in safeguarding individual rights.

The ICO suggests amendments to ensure data protection principles are met and to limit the scope of information gathering. These amendments include:

  1. Limiting the scope of information gathering to only necessary data for identifying relevant accounts and individuals.
  2. Clarifying which organizations are subject to information notices.
  3. Restricting data use gathered under these notices to specific purposes related to social security and benefits compliance.

These amendments aim to balance fraud prevention with individual rights and data protection, providing necessary safeguards against arbitrary interference.
.

The Annexes

The response includes two annexes as part of the response. Annex One provides technical comments on amendments to the DPDI Bill from the House of Commons Report stage. Key points include:

Regarding Gov NC9, the Commissioner’s comments focus on court procedures related to subject access requests. The proposed clause intends to replicate an aspect of the Data Protection Act 1998, adding assurance that information shouldn’t be disclosed to the data subject until a court determination. Concerns are raised about the phrase “as is available to the controller,” which might lead to arguments over the availability of information, potentially complicating court proceedings. The Commissioner suggests removing this phrase and clarifying that controllers must provide necessary information for the court’s decision. This may impact on schools where data is requested for family court proceedings, for example. We will also be keeping an eye on this.

In Annex Two, the Commissioner addresses two main areas:
.

If you have any other questions about this or any other data protection topic, please contact us at DPO@schoolpro.uk.

Stay safe and healthy,

The SchoolPro TLC Team

SchoolPro TLC Ltd (2024)

SchoolPro TLC guidance does not constitute legal advice.

SchoolPro TLC is not responsible for the content of external websites.


Fatal error: Uncaught Error: Call to undefined function wc_get_cart_url() in /home/schoolpro/public_html/test.schoolpro.uk/wp-content/themes/hello-theme-child-master/functions.php:122 Stack trace: #0 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/class-wp-hook.php(324): redirect_menu_cart_to_cart_page('') #1 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/class-wp-hook.php(348): WP_Hook->apply_filters(NULL, Array) #2 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/plugin.php(517): WP_Hook->do_action(Array) #3 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/general-template.php(3208): do_action('wp_footer') #4 /home/schoolpro/public_html/test.schoolpro.uk/wp-content/themes/hello-elementor/footer.php(24): wp_footer() #5 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/template.php(810): require_once('/home/schoolpro...') #6 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/template.php(745): load_template('/home/schoolpro...', true, Array) #7 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/general-template.php(92): locate_template(Array, true, true, Array) #8 /home/schoolpro/public_html/test.schoolpro.uk/wp-content/themes/hello-elementor/index.php(36): get_footer() #9 /home/schoolpro/public_html/test.schoolpro.uk/wp-includes/template-loader.php(106): include('/home/schoolpro...') #10 /home/schoolpro/public_html/test.schoolpro.uk/wp-blog-header.php(19): require_once('/home/schoolpro...') #11 /home/schoolpro/public_html/test.schoolpro.uk/index.php(17): require('/home/schoolpro...') #12 {main} thrown in /home/schoolpro/public_html/test.schoolpro.uk/wp-content/themes/hello-theme-child-master/functions.php on line 122