Version française disponible ici.

As of 1 January 2021, the Brexit transition period (Transition Period) ended, and the United Kingdom (UK) officially finalized its exit from the European Union (EU) and the 11th-hour commercial agreement (Agreement) should allow for a smoother transition on the data protection front as the General Data Protection Regulation (GDPR) stops being directly applicable to the UK. It also provided the UK with a six-month grace period to hope for an adequacy decision that would allow for the free transfer of personal data from the EU to the UK.

As the European Data Protection Board (EDPB) amended on 13 January 2021 its Brexit communications further to the Agreement (Communications), it only addresses:

  • The issue of data transfers from the EU to the UK;
  • The end of the One-Stop-Shop (OSS) mechanism for the UK; and
  • The need for UK entities that would be subject to GDPR to appoint a representative further to Art. 27 GDPR.

However, aside from enacting the end of the OSS and commenting that “the EDPB has been liaising with the ICO [Information Commissioner’s Office, the UK’s Supervisory Authority] over the past months in order to enable a smooth shift to this new situation by ensuring that the EEA authorities follow a shared and efficient approach in handling the existing complaints and cross-border cases involving the ICO, whilst minimizing delays and possible inconveniences to affected complainants[,]”  the EDPB did not comment on how such collaboration will effectively play out for companies whose lead Supervisory Authority was the ICO.

This is all the more relevant for personal data breaches, which were the basis of the most significant fines adopted by the ICO under the GDPR prior to Brexit. Although the general framework is substantially similar between the GDPR and its UK equivalent, which transposed it into UK national law (UK GDPR), the split in applicable regimes could require companies to comply with additional regulatory obligations.

Under the GDPR and its UK counterpart, companies are expected to notify their competent Supervisory Authority of any breach that would create “risks” for data subjects within 72 hours of becoming aware of such breach, as well as to inform those data subjects when the risks are deemed “high.”

Different scenarios may arise, depending on (i) when the personal data breach occurred and (ii) when the notification to a Supervisory Authority was made:

  • The breach and the notification both occurred before the end of the Transition Period (Scenario 1);
  • The breach occurred before the end of the Transition Period, but the notification was made within the 72-hour window, after the end of the Transition Period (Scenario 2); or
  • The breach and the notification both occurred after the end of the Transition Period (Scenario 3).

All three scenarios may apply to situations in which companies are now subject to both the GDPR and the UK GDPR (for instance, the breach occurred in the UK but the GDPR would also be applicable following the end of the Transition Period, or the breach occurred in the EU but the UK GDPR would also be applicable following the end of the Transition Period).

According to the Communications, Scenario 1 would be the most straightforward: proceedings were already underway and notified to the then-competent Supervisory Authority. It is expected that the ICO and its European counterparts, under the coordination of the EDPB, will cooperate to process, investigate and, where appropriate, pursue these cases. However, companies should not need to take any additional steps to comply with both regimes.

Similarly, Scenario 3 should, in theory, be sufficiently clear. Since the breach and its notification both occurred after the end of the Transition Period, companies will need to assess whether they are exclusively subject to one of the regimes (GDPR or UK GDPR), or whether both regimes apply simultaneously. In the latter case, and due to the end of the OSS mechanism, companies will need to notify their personal data breach to both the ICO and the competent lead Supervisory Authority in the EU.

Ideally, the question of which EU Supervisory Authority is competent as the lead authority should have been addressed before the end of the Transition Period, and a representative in the EU, in accordance with Art. 27 GDPR, should have been appointed. The EU Member State in which this representative has been appointed should, in any event, allow for alignment with the competent EU lead Supervisory Authority for data breaches.

However, additional guidance from the ICO and/or the EDPB would have been welcome for Scenario 2, in which the breach occurred before the end of the Transition Period, but the notification was made within the 72-hour window, after the end of the Transition Period.

In addition to the EDPB’s statements in its Communications, the ICO itself affirmed that although it “is no longer part of the one-stop-shop mechanism,” it “will continue to cooperate and collaborate with European supervisory authorities, as we did before the GDPR and the one-stop-shop mechanism, regarding any GDPR breach that affects individuals in the UK and in other EU and EEA Member States.” However, aside from providing guidance on how notifications should be made after the Transition Period, the ICO did not provide any concrete guidance regarding the timeline for data breaches.

Given the short timeframe for notifying a breach, a limited number of events might be involved. However, since this timeframe starts running from the moment the controller becomes aware of the breach, the number of cases could be more significant.

Indeed, under the GDPR (Art. 33 GDPR) and the UK GDPR (Section 67 of the UK GDPR), the breach itself is the event that triggers the notification requirement. As such, any breach that occurred before the end of the Transition Period should be exclusively subject to the GDPR, whether it was discovered before or after the end of the Transition Period. Accordingly, UK companies should be able to notify their personal data breaches to the ICO, which would then liaise with its counterparts (and vice versa for notification to an EU Supervisory Authority), within the cooperation mechanism detailed for Scenario 1.

Read the full article on Lexology, since the Radar First blog link is dead…