UK will not get data breach notification law
Private firms will not be required to tell the ICO when they lose data.
The Government has announced it will not be implementing a data-breach notification law.
Government departments are already required to notify the Information Commissioner's Office (ICO) of any potential data losses, and the data breach notification law would also have made it compulsory for private businesses.
A similar law is already in effect across the US, however, the ICO reported in July that it saw little benefit in enacting it here. Instead the ICO has produced guidance for businesses on when it should be notified of data breaches as a matter of good practice. The Government agrees with this stance.
"After considering the analysis of the experience of the US in the area of data-breach notification legislation, the Government is not intending to implement similar legislation to that in operation in the US," said the Ministry's report, dismissing the law.
"As a matter of good practice any significant data breach should be brought to the attention of the ICO and that organisation should work with the ICO to ensure that remedial action is taken.
"The ICO will take into account the failure of an organisation to notify any breaches of the data protection principles when considering enforcement action."
The Government's stance could put it at odds with the EU, which plans to force companies to own up to data breaches as part of its new ePrivacy Directive.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The decision also flies in the face of a report into personal internet security by the House of Lords Select Committee on Science and Technology, which concluded that data breach notification "would be among the most important advances that the United Kingdom could make in promoting personal Internet security."
-
HPE's new Cray system is a pocket powerhouseNews Hewlett Packard Enterprise (HPE) had unveiled new HPC storage, liquid cooling, and supercomputing offerings ahead of SC25
-
High performance and long battery life: How Dell AI PCs offer the best of both worldsUnlocking the true potential of on-device AI requires a perfect balance between software and hardware
-
New Zealand privacy commissioner tipped to become next ICO headNews John Edwards is said to be an 'anti-Facebook' regulator who would fit well in the UK's plans to clamp down on big tech
-
What is a freedom of information (FOI) request?In-depth We look at the mechanism citizens can use to hold public bodies to account
-
ICO hints at Facebook hypocrisy over data protection goalsNews Elizabeth Denham asks Facebook to drop appeal after CEO's call for greater internet regulation
-
ICO to investigate Google over GDPR violationsNews UK Watchdog to liaise with other European regulators over 'forced consent' push by the tech giant
-
ICO myth-busts on the flow of data post BrexitNews The Information Commissioner explains how data will move between the UK and EU in a no-deal scenario
-
Leave.EU faces big fine over data law breachesNews Information commissioner reveals Leave.EU was fined a total of £75,000 for “serious breaches”
-
ICO website knocked offline for more than 24 hoursNews The outage was caused by an “unprecedented electrical surge” that damaged its host’s circuits
-
Elizabeth Denham appointed ICO bossNews Denham will be tasked with helping the UK leave the EU without any knock-on effects on privacy