Now that Britain has left the European Union (EU), will it still fall under the jurisdiction of the GDPR? The short answer is yes.
Before Brexit, the United Kingdom (UK) was a member of the EU and fell under the jurisdiction of the General Data Protection Regulation (GDPR), the EU’s comprehensive and notoriously stringent data privacy law. This relationship ended at midnight on 31 December 2020 when the UK officially left the EU. However, most of the provisions of the GDPR will still apply.
When it was passed, the UK’s Data Protection Act 2018 (DPA) was designed to incorporate the provisions of the GDPR as they related to the United Kingdom. An amended version of this law came into effect on 1 January 2021 after the official transition, overseen by the secretary of state.
The amended regulations replace all mentions of EU locations, laws, institutions, and so on with their British equivalents and it remains as stringent as its predecessor.
Legally, the UK will be viewed by the EU as a ‘third country’ under the GDPR. This means that data can only be transferred under special agreements between organizations and their partners. However, the UK and EU have agreed in principle on a further transition period of up to six months to enable the European Commission to complete its adequacy assessment of the UK’s data protection laws. Data can continue to flow freely until then.
Interestingly, tech giants Google and Facebook plan to move all their users in the UK with agreements with Facebook Ireland into user agreements with the corporate headquarters in California to bypass European law. Ireland remains a member of the EU.
Businesses affected by Brexit are advised to study their data flows and current security frameworks to ensure their data protection practices are compliant with the DPA. Data privacy solutions like Hush-Hush Data Masking can help you control the flow of data in your business in order to reach your compliance goals.