---
title: 'GDPR/Brexit - Brexit, GDPR, and the Timeline for Data Breaches'
date: '2021-01-19'
year: 2021
lang: en
type: post
wp_slug: brexit-gdpr-and-the-timeline-for-data-breaches
wp_url: 'http://armingaud-avocat.fr/en/brexit-gdpr-and-the-timeline-for-data-breaches/'
categories:
  - Data Breach
  - Data Transfer
  - Europe
  - Privacy
tags:
  - site
Language: English
created: '2021-01-19'
modified: '2021-01-19'
published: '2021-01-19'
---

As of 1 January 2021, the Brexit transition period (Transition Period) ended, and the United Kingdom (UK) officially finalized its exit from the European Union (EU) and the 11th-hour commercial agreement (Agreement) should allow for a smoother transition on the data protection front as the [General Data Protection Regulation](<https://eur-lex.europa.eu/eli/reg/2016/679/oj>) (GDPR) stops being directly applicable to the UK. It also provided the UK with a six-month grace period to hope for an adequacy decision that would allow for the free transfer of personal data from the EU to the UK.

As the [European Data Protection Board](<https://edpb.europa.eu/edpb_fr>) (EDPB) amended on 13 January 2021 its [Brexit communications](<https://edpb.europa.eu/sites/edpb/files/files/file1/edpb_statement_20201215_brexit_en.pdf>)² further to the Agreement (Communications), it only addresses:

  * The issue of data transfers from the EU to the UK;
  * The end of the One-Stop-Shop (OSS) mechanism for the UK; and
  * The need for UK entities that would be subject to GDPR to appoint a representative further to Art. 27 GDPR.



However, aside from enacting the end of the OSS and commenting that _“the EDPB has been liaising with the ICO [Information Commissioner’s Office, the UK’s Supervisory Authority] over the past months in order to enable a smooth shift to this new situation by ensuring that the EEA authorities follow a shared and efficient approach in handling the existing complaints and cross-border cases involving the ICO, whilst minimizing delays and possible inconveniences to affected complainants[,]”_  the EDPB did not comment on how such collaboration will effectively play out for companies whose lead Supervisory Authority was the ICO.

Read the full article on [Radar First blog](<https://www.radarfirst.com/blog/brexit-gdpr-and-the-timeline-for-data-breaches/>).
