Saudi Arabia’s New Data Protection Law Comes into Force on Saturday

Saudi Arabia’s first ever comprehensive  Personal Data Protection Law (PDPL) comes into force this Saturday (14th September 2024). The new law regulates the collection, handling, disclosure and use of personal data. The Saudi Arabian Authority for Data and Artificial Intelligence (SDAIA), which will initially enforce the new law, has now finalised the following documents following a period of consultation:  

Guidelines for Binding Common Rules: These guidelines aim to specify the obligations of the parties involved in the transfer when personal data is transferred or disclosed to a country or international organisation that does not have an adequate level of protection for personal data. 

Standard Contractual Clauses (SCCs) for Personal Data Transfer: These clauses are one of the appropriate safeguards that Controllers and Processors may use in addition to the Binding Common Rules (BCR) and accreditation certificates from a body licensed by the Competent Authority. 

There are other useful guidelines on the SDAIA website including on personal data destruction, anonymization and pseudonymisation as well as data processing activities records. 

Training for the Data Protection Officer 

The draft rules for the appointment of a DPO have also been finalised. Article 5 of the rules states that the following Data Controllers need to appoint a DPO: 

  • A Public Entity that provides services involving processing of personal data on a large scale 
  • A Controller whose core activities are based on processing operations that, by their nature, require regular and systematic monitoring of data subjects 
  • A Controller whose core activities are based on processing of sensitive personal data. 

Whilst there is no requirement for others to appoint a DPO, in our view, it is good practice to do so as it will help drive compliance forward especially in the initial phases of implementing the new law. 

The rules places great importance on training for and by the DPO. Article 9(6) states: 

“The Controller shall work on training and developing DPO’s in the fields of Personal Data protection and support them in obtaining professional certificates in this field to ensure raising their efficiency.” 

This has to be read alongside Article 4 and Article 8 (above). The latter states that one of the roles of the DPO is: 

“Participating in awareness activities, training and transfer of knowledge to Controller personnel regarding Personal Data protection and compliance with provisions of the Law, Regulations and ethics of data handling.” 

Through our  KSA privacy programme, Act Now Training offers comprehensive and cost-effective training from one hour awareness-raising webinars to comprehensive full day workshops and DPO certificate courses.  

New Information and Records Management Practitioner Certificate 

Act Now Training is delighted to announce the launch of the Information and Records Management Practitioner Certificate.  

Effective information and records management is vital for all organisations. It ensures compliance with legal requirements, enhances decision-making, mitigates risks, preserves institutional memory, supports accountability and facilitates efficiency.  

This new certificate programme meets the need of information management professionals to equip themselves with practical skills to navigate the full information and records lifecycle. The course is one of the outcomes of our work to develop a comprehensive IG skills and competency framework.  

Course Content and Format 

Our comprehensive course syllabus has been designed by leading records management specialists. By the end of the course, delegates will gain skills in, amongst other things, legal frameworks and terminology to data auditing, retention schedules, and digital preservation.  

Scott Sammons will be teaching the first course starting in November. Scott is a recognised expert on records management. He was previously the Chair of the Information and Records Management Society (2016-2020) and now leads the IRMS work on accreditation. Scott said: 

“Records management is essential good business practice as well as a key component of compliance with IG legislation such as GDPR and FOI. Using practical hands on teaching methods, I aim to inspire delegates to implement records management best practice in their workplace.” 

The course is structured over four days, approximately one day per  month, and can be undertaken online or in the classroom. Each day includes engaging discussions, exercises and case studies. Upon completion, delegates must submit a practical assessment within 30 days. Personal tutor support is provided, throughout the course, together with comprehensive training materials. 

Special Introductory Price 

Whether you are a records manager, Freedom of Information Officer or Data Protection Officer this practitioner level certificate will teach you the theory of records management alongside practical hands-on application. The first course starts in October with a special introductory price. Places are limited, so please book now  to avoid disappointment.  

Labour Party Reprimanded for Subject Access Delays 

Last week, the Information Commissioner’s Office (ICO) issued the Labour Party with a Reprimand, under the UK GDPR, for repeatedly failing to respond to subject access requests (SARs). This is an embarrassing development for a party in government which recently announced a number of parliamentary bills in the area of information governance.   

Background 

In November 2022, the Labour Party found itself inundated with 352 SARs that required timely responses. 78% of these requests remained unanswered within the maximum compulsory time limit of three months, and more than half (56%) were significantly delayed by over one year. The backlog stemmed from a cyber-attack on the Labour Party in October 2021, which triggered a surge in SARs. 

During the ICO’s investigation, it came to light that a ‘privacy inbox’ within the Labour Party had not been monitored since November 2021. This inbox contained approximately 646 additional SARs and around 597 requests for deletion of personal data. None of these requests had been responded to.  

This reprimand comes a few months after a report by openDemocracy, an independent international media platform. The report claims that people requesting copies of their data, such as police or immigration records, have faced long delays or had their requests ignored entirely. Others have been given folders with key documents missing. Apparently this is having a knock-on effect on the justice system, with lawyers telling openDemocracy that asylum applications and claims for false imprisonment have been put on hold due to the delays. Victims of the Windrush Scandal have also struggled to obtain copies of their immigration papers in order to claim compensation. 

Since engaging with the ICO, the Labour Party has taken steps to address its backlog including assigning three temporary staff members to focus solely on handling outstanding requests and allocating  additional resources to expedite responses.  

Enjoy reading our blog? Help us reach 10,000 subscribers bysubscribing today!  

Our upcoming Handling SARs course can help you deal with complex subject access requests. Places are limited so book early to avoid disappointment. 

Transport for London Cyber Attack 

Transport for London (TfL) is currently dealing with a cyber attack that has targeted its computer systems. Sources within TfL have revealed that staff have been encouraged to work from home where possible, as the attack primarily affects the transport provider’s back-office systems at its corporate headquarters. TfL is collaborating closely with the National Crime Agency and the National Cyber Security Centre to respond to the incident. 

Shashi Verma, TfL’s Chief Technology Officer, said: 

“We have implemented several measures to address an ongoing cybersecurity incident within our internal systems. The security of our systems and customer data is of utmost importance, and we are continuously assessing the situation throughout this incident.”  

Mr Verma emphasised that, although a complete assessment is still underway, there is no current evidence of customer data being compromised. If it turns out that any personal data has been compromised, whether employee or customer data,  of course TfL will need to consider reporting the matter to the Information Commissioner’s Office (ICO) as a personal data breach under Article 33 of the UK GDPR. As a statutory body, failure to do so could lead to TfL being fined up to £8.7 million. If the ICO investigates and finds a breach of the DP Principles (e.g. security) this could rise to £17.5 million. 

Back in the day major cyber incidents involving personal data were sure to be the subject of an ICO fine. In 2018, British Airways and  Marriott International were fined £20 million and  £18.4 million respectively. More recently the ICO has issued more reprimands in line with its policy on public sector enforcement. It recently issued a reprimand to the Electoral Commission following the discovery that unspecified “hostile actors” had managed to gain access to copies of the electoral registers, from August 2021. On 26th June 2024, the ICO announced that it will now review the two-year trial before making a decision on the public sector approach in the autumn.  

This is not the first cyber attack on a major public service provider in the capital.  Last month the ICO announced that it had issued a GDPR Notice of Intent of £6.09 million to an NHS IT supplier. This comes after its findings that the company failed to adequately protect the personal data of 82,946 individuals in breach of Article 32 of the UK GDPR.  As a key IT and software provider for the NHS and other healthcare organisations across the country, Advanced often holds role of Data Processor for many of its clients. The breach in question occurred during a ransomware attack in August 2022. Hackers exploited a vulnerability through a customer account that lacked multi-factor authentication, gaining access to multiple health and care systems operated by Advanced. The compromised data included phone numbers, medical records, and even details on how to access the homes of 890 individuals receiving at-home care. 

We have two workshops coming up (How to Increase Cyber Security in your Organisation and Cyber Security for DPOs) which are ideal for organisations who wish to up skill their employees about cyber security. See also our Managing Personal Data Breaches Workshop

When Oasis met GDPR

To celebrate the Gallagher brothers new tour, we asked ChatGPT to compose a poem about privacy using Oasis song titles. How many can you spot? Answers in comments.

In the wonderwall of data, we stand tall, Guarding our privacy, one and all. 

With champagne supernovadreams, we strive, To keep our personal info alive.

Don’t look back in anger, they say, As we navigate the GDPR way. 

Our supersonic rights, clear and bright, In the digital world, we fight the good fight.

Live forever in a world that’s free, From breaches and leaks, let it be. 

With some might say, we take a stand, For privacy laws across the land.

In this morning glory, we find our way, To protect our data, come what may. 

So let’s embrace the GDPR light, And keep our privacy shining bright.

Enjoy reading our blog? Help us reach 10,000 subscribers by subscribing today! 

Data Protection Prosecutions and Employer Liability

Rogue workers accessing and abusing personal data for their own gain is a perennial issue for organisations with vast databases of personal data that may have commercial value. Section 170 of the Data Protection Act 2018 makes it a criminal offence for a person to knowingly or recklessly: 

(a) obtain or disclose personal data without the consent of the controller, 

(b) procure the disclosure of personal data to another person without the consent of the controller, or 

(c) after obtaining personal data, to retain it without the consent of the person who was the controller in relation to the personal data when it was obtained. 

In June 2023, the ICO disclosed that since 1st June 2018, 92 cases involving S.170 offences were investigated by its Criminal Investigations Team.  A recent prosecution involved a man who worked for Enterprise Rent-A-Car where he illegally accessed customers’ records. He was ordered to pay a fine of £265, along with costs of £450 and a victim surcharge of £32. S.170 is similar to the offence under section 55 of the old Data Protection Act 1998. S.55 can still be used to bring a prosecution where an offence pre-dates the current S.170 coming into force.  

In August, Jonathan Riches pleaded guilty under S.55 at Cardiff Crown Court. Mr. Riches, also a former employee of Enterprise Rent-A-Car, left the company in 2009 to establish his own personal injury firm. However, he remained in contact with former colleagues, through whom he illegally obtained details of individuals involved in road traffic accidents, then contacted them to offer legal services. At one point, Mr. Riches, through his accomplices, gained access to Enterprise’s internal database, allowing him to retrieve clients’ personal details. 

Previously, Mr. Riches had been ordered to pay Enterprise Rent-A-Car a £300,000 civil settlement. He was later interviewed by the ICO, which led to him being summoned to court in 2016. However, having relocated to the United States, he failed to appear, prompting a warrant for his arrest. He eventually returned to the UK and surrendered to authorities in 2024. 

Mr. Riches’s accomplices in the crimes had all been sentenced earlier. Judge Francis described Riches’s actions as part of a sophisticated and long-running scheme that involved a cynical breach of trust. He fined £10,000, plus £1,700 in costs.  

Of course prosecutions for mishandling personal data would have a much greater deterrent effect if the available sanctions included a custodial sentence. Successive Information Commissioners have argued for this but to no avail. This has led to some cases being prosecuted under section 1 of the Computer Misuse Act 1990 which carries tougher sentences including a maximum of 2 years imprisonment on indictment.  In July 2022, a woman who worked for Cheshire Police pleaded guilty to using the police data systems to check up on ex-partners and in August 2022, the ICO commenced criminal proceedings against eight individuals over the alleged unlawful accessing and obtaining of customers’ personal data from vehicle repair garages to generate potential leads for personal injury claims. 

Employer Liability 

If a disgruntled or rogue employee commits an offence under section 170, might their employer also be liable for the consequences? 

In 2020, the Supreme Court ruled that as an employer, Morrisons Supermarket could not be held responsible when an employee, Andrew Skelton, uploaded a file containing the payroll data of thousands of Morrisons employees to a publicly accessible website as well as leaking it to several newspapers. The court decided that, whatever Skelton was doing when he disclosed his colleagues’ personal data, he was not acting “in the course of his employment”, and accordingly no vicarious liability could be imposed under the old Data Protection Act 1998. 

However, Morrisons lost on the argument that the DPA 1998 operated so as to exclude vicarious liability completely. This principle can also be applied to the GDPR and so employers can “never say never” when it comes to vicariously liability for malicious data breaches by staff. It all depends on the facts of the breach. 

This case only went as far as it did because the Morrisons employees failed to show, at first instance, that Morrisons was primarily liable for the data breach. If an employer fails to comply with its security obligations in a manner that is causally relevant to a rogue employee’s actions, it can still be exposed to primary liability under Article 32 of GDPR as well as the 6th Data Protection Principle which both impose obligations to ensure the security of personal data. 

This and other data protection developments will be discussed in detail on our forthcoming  GDPR Update  workshop. 

Enjoy reading our blog? Help us reach 10,000 subscribers by subscribing today!

Waltzing Through Privacy: Strictly Come Dancing Meets GDPR 

The prime time BBC show, Strictly Come Dancing, is currently embroiled in a significant controversy following allegations of bullying and a toxic work environment. Reports have surfaced from celebrity contestants and crew members claiming abuse and mistreatment from some professional dancers and production staff. 

The controversy began in October 2023 when actress Amanda Abbington withdrew from the show, citing “personal reasons.” She later revealed she had experienced difficulties with her professional partner, Giovanni Pernice, and had been diagnosed with PTSD. In January 2024, Abbington requested rehearsal footage, leading to an investigation into Pernice’s teaching methods. Pernice denied any abusive behavior but was not included in the 2024 line-up. 

Around the same time, Graziano Di Prima was also accused of mistreatment by his celebrity dance partner, Zara McDermott. It was alleged that Di Prima had kicked his partner during a training-room session. At the time he apologised for his behaviour, which he said he “deeply regretted”. “My intense passion and determination to win might have affected my training regime,” he said. But since his exit Di Prima has cast doubt on how the incident was portrayed and is seeking to challenge his “dismissal.” 

The Times reported last week that lawyers acting on behalf of Di Prima have made a GDPR subject access request to the BBC for all evidence related to the “decision to sack” the former Strictly Come Dancing professional. They have asked to see “all internal BBC correspondence related to the issue, including emails and text messages”. The information is likely to be used to allow Di Prima’s legal team to assess the strength of the legal grounds to challenge his alleged dismissal.  

The Article 15 Right of Subject Access allows data subjects to see what personal data is held about them, how it is being processed and precisely who it is being shared with. In 2023, Dame Alison Rose, the then CEO of NatWest, resigned after Nigel Farage made a subject access request which disclosed information that contradicted the bank’s justification for downgrading his account. 

In the present case the emails and text messages requested by Di Prima’s legal team will do doubt include lots of personal data about third parties including contestants and production staff. Part 3 of Schedule 2 of the Data Protection Act 2018 states that the GDPR Subject Access right “does not oblige a Data Controller to disclose information to the data subject to the extent that doing so would involve disclosing information relating to another individual who can be identified from the information.” However, disclosure is still required if the other individual has consented, or it is “reasonable” to disclose the information without consent. In determining what is reasonable, the controller must have regard to all the relevant circumstances including, amongst other things, the type of information that would be disclosed and any duty of confidentiality owed to the other individuals. 

It will be interesting to know the outcome of Di Prima’s subject access request. Will it be a slow waltz towards litigation, or will the BBC be able to cha-cha away from legal liability? 

Our upcoming Handling SARs course can help you deal with complex subject access requests.  

Enjoy reading our blog? Help us reach 10,000 subscribers by subscribing today! 

ICO 5th Call for Evidence on Generative AI 

Recently we wrote about how “How Generative AI’s Data Appetite is Fuelling Privacy Battles.” Last week the Information Commissioner’s Office (ICO) published its fifth call for evidence on Generative AI.  This call focuses on the allocation of accountability for data protection compliance across the generative AI supply chain. It is part of the ICO’s consultation series on generative AI ICO consultation series on generative AI and data protection

The fifth call for evidence addresses the recommendation for ICO guidance on the allocation of accountability in AI as a Service (AIaaS) contexts made in Sir Patrick Vallance’s Pro-innovation Regulation of Technologies Review.  
 
The allocation of accountability is complicated because of the different ways in which generative AI models, applications and services are developed, used and disseminated, but also the different levels of control and accountability that participating organisations may have.  
 
The ICO is interested in additional evidence on how this works in practice. In the meantime, it provides a summary of our current analysis, the policy positions we want to consult on and some examples which show how this analysis could be applied in practice.  
 
The deadline for submissions is 18th  September 2024.  

Enjoy reading our blog? Help us reach 10,000 subscribers by subscribing today! 
 
Join our Artificial Intelligence and Machine Learning, How to Implement Good Information Governance workshop for hands-on insights, key resource awareness, and best practices, ensuring you’re ready to navigate AI complexities fairly and lawfully. 

International Transfers under Saudi Arabia’s New Data Protection Law

Saudi Arabia’s Personal Data Protection Law (PDPL) comes into force on 14th September 2024 and regulates the collection, handling, disclosure and use of personal data. Like many data protection laws around the world, including the UK GDPR, the PDPL contains strict rules about when personal data can be transferred outside the jurisdiction. 

Article 29 of PDPL states that when transferring personal data outside Saudi Arabia, Data Controllers must ensure that that the receiving country or international organisation has an appropriate level of personal data protection. The Regulation on the Transfer of Personal Data Outside the Kingdom (Transfer Regulation) provides more detail about the rules to be followed upon transfer. Two of the circumstances where personal data transfers are allowed outside the Kingdom is when Standard Contractual Clauses are used and where personal data is transferred among a group of multinational entities, provided that the Data Controller and its entities abide by Binding Common Rules (BCRs).

The Saudi Arabian Authority for Data and Artificial Intelligence (SDAIA), which will initially enforce the new law, recently released the draft Standard Contractual Clauses (SCCs) for Personal Data Transfer and Guidelines for Binding Common Rules. Bothe are open for comment for the next 8 days. In July SDAIA also published draft rules for the appointment of a DPO under the PDPL.

SCCs and BCRs are vital safeguards, defining the obligations of Data Controllers and Data Processors involved in cross-border data transfers, thereby ensuring compliance and protecting personal data even beyond the Kingdom’s borders. Organisations doing business in the Middle East need to carefully consider the impact of the rules on international transfers under the PDPL. Thought must also be given to the appointment and training of a suitably qualified DPO. 

Through our  KSA privacy programme, Act Now Training offers comprehensive and cost-effective training from one hour awareness-raising webinars to comprehensive full day workshops and DPO certificate courses

Enjoy reading our blog? Help us reach 10,000 subscribers by subscribing today!

ICO to Review Public Sector GDPR Compliance Enforcement Approach

In June 2022, the Information Commissioner’s Office (ICO) revised its approach to enforcement of the UK GDPR against public sector organisations.  The two-year trial was announced in an open letter from the Information Commissioner, John Edwards, to public authorities in which he indicated that greater use would be made of the ICO’s wider powers, including warnings, reprimands and enforcement notices, with fines only issued in the most serious cases. Mr Edwards said:

“I am not convinced large fines on their own are as effective a deterrent within the public sector. They do not impact shareholders or individual directors in the same way as they do in the private sector but come directly from the budget for the provision of services. The impact of a public sector fine is also often visited upon the victims of the breach, in the form of reduced budgets for vital services, not the perpetrators. In effect, people affected by a breach get punished twice.”

This new approach has seen the Commissioner over the last two years issue more reprimands than fines. One example of this approach was the issuing of reprimand to the Department for Education (DfE) following its misuse of the personal data of up to 28 million children. The ICO said at the time that, had the new trial approach not been in place, the DfE would have been issued with a fine of over £10 million. Some would say that the DFE got off very lightly and, given their past record, perhaps more stringent sanctions should have been imposed. Two years ago, the ICO criticised the DfE for secretly sharing children’s personal data with the Home Office, triggering fears it could be used for immigration enforcement as part of the government’s hostile environment policy.

More recently the ICO was criticised for only issuing a  reprimand to the Electoral Commission following the discovery that unspecified “hostile actors” had managed to gain access to copies of the electoral registers, from August 2021. Hackers also broke into its emails and control systems. The Commission estimated the register for each year contained the details of around 40 million people. The ICO reprimand revealed that the Commission did not take basic security steps to ensure the protection of personal data.

On 26th June 2024, the ICO announced that it will now review the two-year trial before making a decision on the public sector approach in the autumn. It will be interesting to see whether the ICO views the approach as a success and if it will be continued or even extended to the private sector.

Enjoy reading our blog? Help us reach 10,000 subscribers by subscribing today!

This and other data protection developments will be discussed in detail on our forthcoming  GDPR Update  workshop.