Data protection laws will not change following Brexit vote
Despite the UK voting to leave the EU, the ICO said the data protection laws will still remain as tight as they are now


Although the UK has voted to leave the EU, the Information Commissioner's Office (ICO) has said data protection laws will not change, despite being set by the European Union.
However, it stated that new data protection laws due to be introduced by the EU would not apply to England, Scotland, Northern Ireland and Wales if the UK leaves before they come into effect.
It explained that if the UK wants to trade with other countries in the EU, on equal terms, it would still have to provide 'adequacy', meaning any data protection standards we hold must be on par with those operating in the EU - specifically the GDPR.
"With so many businesses and services operating across borders, international consistency around data protection laws and rights is crucial both to businesses and organisations and to consumers and citizens. The ICO's role has always involved working closely with regulators in other countries, and that would continue to be the case.
"Having clear laws with safeguards in place is more important than ever given the growing digital economy, and we will be speaking to government to present our view that reform of the UK law remains necessary."
Before the result of the referendum was announced, the ICO's group manager for business and industry, Garreth Cameron, explained he did not think a vote to leave the EU would affect the UK's strong data protection laws, although the government would have to be held accountable to ensure they adequately protect any trade.
"The UK has a very long history of data protection laws," he told delegates at the Data Security in the Cloud conference. "So whatever happens, I think we will have strong data protection laws... How they work exactly is down to government, but we will need to have those in place."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives

Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.
-
AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse
News The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data
By Emma Woollacott
-
“You must do better”: Information Commissioner John Edwards calls on firms to beef up support for data breach victims
News Companies need to treat victims with swift, practical action, according to the ICO
By Emma Woollacott
-
LinkedIn backtracks on AI training rules after user backlash
News UK-based LinkedIn users will now get the same protections as those elsewhere in Europe
By Emma Woollacott
-
UK's data protection watchdog deepens cooperation with National Crime Agency
News The two bodies want to improve the support given to organizations experiencing cyber attacks and ransomware recovery
By Emma Woollacott
-
ICO slams Electoral Commission over security failures
News The Electoral Commission has been reprimanded for poor security practices, including a failure to install security updates and weak password policies
By Emma Woollacott
-
Disgruntled ex-employees are using ‘weaponized’ data subject access requests to pester firms
News Some disgruntled staff are using DSARs as a means to pressure former employers into a financial settlement
By Emma Woollacott
-
ICO reprimands Coventry school over repeated data protection failures
News The ICO said the academy trust failed to follow previous guidance, which caused a serious data breach
By Emma Woollacott
-
ICO dishes out fine to HelloFresh for marketing spam campaign
News HelloFresh failed to offer proper opt-outs, the ICO said, and customers weren’t warned their data would be used for months after they cancelled
By Emma Woollacott