At this stage, all of this remains vague enough to be fairly innocuous. What businesses, citizens, and the UK's international trading partners are still waiting for is a more concrete articulation of the Government's intentions. In particular, which GDPR-mandated "box-ticking" requirements might be removed, and how much of the protection currently afforded to data subjects is the government prepared to sacrifice in pursuit of a more business and innovation-friendly agenda?
Much of the ongoing uncertainty can be attributed to the breadth of the initial Consultation. It contains over 150 specific questions on issues spanning some of the most significant aspects of the data protection regime, including purpose limitation rules, profiling and automated decision-making (ADM), scope of data subject rights, cookie requirements, international data transfers, and reform of the ICO.
It is uncontroversial that several of these aspects currently present practical difficulties for businesses, and could potentially be recalibrated to ease the compliance burden without substantial detriment to individuals. However, if data protection impact assessments, legitimate interest balancing tests, requirements to appoint DPOs, data breach reporting and maintenance of records of processing activities (ROPAs) are all on the chopping block, it is questionable whether organisations would make sufficient voluntary use of such tools to avoid material reduction in standards. While large, multinational organisations may continue using these tools in order to adopt a uniform approach across all jurisdictions in which they operate, smaller organisations with a UK focus may welcome the freedom to bypass these obligations in favour of a more flexible approach to risk assessment.