---
title: GDPR - UK Unveils Plan to Diverge from GDPR
date: '2021-09-06'
year: 2021
lang: en
type: post
wp_slug: uk-unveils-plan-to-diverge-from-gdpr
wp_url: 'http://armingaud-avocat.fr/en/uk-unveils-plan-to-diverge-from-gdpr/'
categories:
  - Brexit
  - Data Transfer
  - Privacy
tags:
  - site
Language: English
created: '2021-09-06'
modified: '2021-09-06'
published: '2021-09-06'
---

The UK government has [announced](<https://www.gov.uk/government/news/uk-unveils-post-brexit-global-data-plans-to-boost-growth-increase-trade-and-improve-healthcare>) that it intends to consult on a new, post-Brexit data protection regime, potentially moving away from the UK General Data Protection Regulation that currently underpins the UK’s data protection legislation. The Digital Secretary, [Oliver Dowden](<https://twitter.com/OliverDowden>), said, “ _It means reforming our own data laws so that they’re based on common sense, not box-ticking._ ”

A public consultation on the new legislation will follow, but it is clear that the United Kingdom must be careful about any changes it makes to its data regime in order to avoid disrupting the [EU-UK adequacy decision](<https://ec.europa.eu/commission/presscorner/detail/en/ip_21_3183>) with [EU GDPR](<https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN>) awarded just two months ago. The adequacy decision allows personal data from the European Union to flow freely to the United Kingdom (and vice versa), without businesses needing to put any additional paperwork in place. In granting the adequacy decision, the European Union placed particular emphasis on the fact that the United Kingdom was continuing to base its data protection laws on the same EU GDPR rules that had applied when it was a member of the European Union. A European Commission spokesperson [commented](<https://www.irishtimes.com/business/technology/eu-warns-over-post-brexit-data-agreement-with-uk-1.4657172>) that the EU will be closely monitoring any developments in UK data laws and noted that: “ _In case of problematic developments that negatively affect the level of protection found adequate, the adequacy decision can be suspended, terminated or amended, at any time by the Commission._ ”

It will be interesting to see how far the United Kingdom diverges, particularly as the current trend is that [other countries](<https://www.euractiv.com/section/data-protection/news/china-passes-tough-new-online-privacy-law/>) seem to be keen to state that their data protection laws closely follow the EU GDPR.

The UK government also [announced](<https://www.gov.uk/government/news/government-announces-preferred-candidate-for-information-commissioner>) that its preferred candidate to be the next Information Commissioner, head of the UK data protection regulator, will be John Edwards, currently in charge of [New Zealand’s data regulator](<https://www.privacy.org.nz/>), a country that also maintains an [EU adequacy decision](<https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32013D0065>).

**First publication** : **[K&L Gates Cyber Law Watch Blog](<https://www.cyberlawwatch.com/2021/08/uk-unveils-plan-to-diverge-from-gdpr/>)** with Noirin McFadden
