Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, having exchanged some gestures with the noble Lord, Lord Hunt, I think it is me next. I am pleased to support this amendment, which I have cosigned, and I very much agree with everything that the noble Lord, Lord Markham, said.

My remarks will principally have China in mind. China is not the only repressive regime, of course, but certain examples come to mind. Take, for example, the political prisoners in Hong Kong, such as Jimmy Lai and Joshua Wong, who was in the news recently when he was outrageously imprisoned, on so-called national security grounds, for democratic expression and protest. There are many other such examples, of course. There are also concerns about electroshock weapons being demonstrated inside the Chinese embassy here, and we recently saw a considerable eight-year sentence under our National Security Act for the manager of the Hong Kong Economic and Trade Office in the UK because of attempts at repression in the UK. So there are problems of justice—or, rather, injustice—in Hong Kong and China, but the tentacles of repression are very much reaching into this country, particularly for the Hong Kong diaspora.

We have seen other examples, such as Interpol red notices being misused, so there is a great concern that requests for digital information sharing that have a nefarious purpose could be made by authoritarian states under the Bill. We have had examples in Hong Kong of residential surveillance and holding individuals incommunicado for up to six months, without access to a lawyer or family, which amount to enforced disappearance and increase the risk of torture. We have the lack of judicial independence, as the noble Lord, Lord Markham, mentioned, which explicitly prevents a fair trial, particularly in so-called national security cases. The treatment of imprisoned activists undermines any semblance of a fair trial. There are concerns about the admission of evidence obtained through torture in Chinese courts, which includes Hong Kong. The situation in prisons is intolerable. I understand that Jimmy Lai is being held in conditions where he is practically boiling in the heat of his cell. Anyway, this gives the Committee an illustration of everything that I think noble Lords are already aware of.

I understand that, under the Extradition Act, co-operation between the UK and Hong Kong authorities is permitted on a case-by-case ad hoc basis; if that is incorrect, I would accept correction. But if, under the Bill, NIS data—including sensitive information such as IP addresses, digital fingerprints and user-level logs from digital service providers—could increase the risk of extradition to a country without a bilateral treaty with the UK then that could trigger special extradition arrangements, bypassing traditional human rights safeguards. We are on a slightly uncertain basis of extradition to Hong Kong, into which the Bill could add another element, so there are no permanent safeguards against extradition to Hong Kong and this data sharing could serve as an intelligence-gathering tool, which facilitates that process by providing the evidence which then justifies the filing of an ad hoc extradition request. So we could increase the likelihood of an ad hoc extradition request, which would make it more difficult for the British authorities.

Of course, we all know that many of the diaspora in the UK are living in fear of their lives—not just fear for their safety but for their lives, with bounties on their heads. We are also aware of all the cyber attacks that we understand are being launched from a Chinese direction. This NIS data could help to identify the architecture of the UK’s critical systems and choke points. It could also assist with the harassment of dissidents and human rights defenders living in the UK.

For all these reasons, I very much support the amendment. As the noble Lord, Lord Markham, said, if the Government believe that there are institutional drafting problems then it is incumbent on them—if they agree with us that there is a danger in this zone of sharing data with a repressive regime, and I cannot see how they would not—to come up with something which fits the existing parameters but prevents opening the door to assisting repression. That would certainly be against any values in this country.

Lord Hunt of Kings Heath Portrait Lord Hunt of Kings Heath (Lab)
- Hansard - - - Excerpts

My Lords, I will briefly follow the noble Lord, Lord Markham, and the noble Baroness, Lady Ludford, in supporting this amendment. The noble Lord, Lord Alton, who is the architect of the amendment—indeed, of many amendments relating to China and human rights—unfortunately cannot be here, but both the noble Lord, Lord Markham, and the noble Baroness, Lady Ludford, explained eloquently why this is important, particularly the focus on China.

Over the years, British Governments of all colours have had a very ambiguous policy towards China. On the one hand, in terms of trade and the economy, it is crucial. On the other, we have to admit that Chinese repression and China’s appalling human rights record mean that the Government need to tread very carefully in their relationships with China.

My interest in this came from the problems, particularly in Xinjiang province, with enforced organ harvesting of dissidents and followers of Falun Gong. When we say “forced organ harvesting”, we essentially mean that prisoners are killed so that their organs may be taken and sold, in essence, on an international market. China makes billions of pounds from this appalling practice.

Over the years, the noble Lord, Lord Alton, has chipped away, legislatively, at a number of pieces of legislation to, in essence, preclude British companies from supplying China with goods, medicines or chemicals that could then possibly be used for organ harvesting. There are a number of pieces of legislation where this happens. Obviously, this Bill is different, but I note the argument that the noble Baroness, Lady Ludford, and the noble Lord, Lord Markham, made about why we should have special provisions for fair trials and the release of information to authoritarian countries.

I fully take the point from the noble Baroness, Lady Ludford, who, like the noble Lord, Lord Markham, referred back to the debates in the other place and the difficulty of drafting. I hope that the Government might be prepared to talk, particularly to the noble Lord, Lord Alton, about whether we can find a way forward here.

--- Later in debate ---
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

I apologise for interrupting the noble Baroness. My understanding was that, although the treaty had been suspended, there could be consideration on a case-by-case, ad hoc basis. Is that wrong? Is there a complete ban on extradition or, notwithstanding the suspension of the treaty, could there still be a case-by-case, ad hoc extradition?

Baroness Ramsey of Wall Heath Portrait Baroness Ramsey of Wall Heath (Lab)
- Hansard - - - Excerpts

I thank the noble Baroness. I will write to her on the case-by-case point.

Finally, I know that my noble friend the Minister will be very happy to meet noble Lords again to discuss this further, as she has done quite recently with the noble Lord, Lord Alton.

--- Later in debate ---
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

My Lords, Amendment 74 is in my name and those of the noble Baronesses, Lady Morgan and Lady Ludford. The noble Baroness, Lady Morgan, is very sorry that she cannot be in the Committee this afternoon but she particularly wanted me to thank the Minister for their helpful meeting last week. This amendment and Amendment 167 in the name of the noble Baroness, Lady Ludford, relate to the governance of regulated bodies that will be caught under this Act. The reason for this legislation is to reflect the rapidly changing cyber environment and to strengthen areas of current vulnerabilities of those organisations providing services critical to societal or economic life.

As we have discussed, regulators will be given powers to designate critical suppliers whose disruption could have a significant impact on essential services. As we have discussed in previous groups, many of us think the Bill does not go far enough in setting out who those critical suppliers are. We are going to see similar amendments in other forthcoming Bills that make provision for senior manager liability when new responsibilities are legislated. This is something that we have been through in other Bills: the only way to change the culture of an organisation is to start at the top.

I am sure that boards will grumble when they accept new duties, but they will keep their regulators happy were they to be in sight of the law. What really makes the difference to successful implementation is knowing that if it can be proven—I shall read out proposed new subsection (1)(b)—that

“the failure was committed with a consent or connivance of, or is reasonably attributable to any neglect on the part of, a senior executive or group of senior executives, deliberately or carelessly”,

that individual will be held responsible. I point noble Lords to recent court cases in the area of social media, where disclosure has repeatedly shown that senior executives knew of harm or stood in the way of harm mitigation for years. The idea that this might capture an unwilling or unwitting senior executive is shown clearly not to be the case by what I have just read out.

I understand that the Minister and the noble Baroness, Lady Morgan, also discussed this in the context of financial services and a regime introduced after the 2008 financial crash with the very intention of changing the culture of financial service businesses and focusing senior minds on the damage those businesses can do if they do not meet their responsibilities. A more recent example is the introduction of the consumer duty by the Financial Conduct Authority, which required relevant boards to appoint an individual consumer duty champion, something that the noble Baroness, Lady Morgan, was involved in. I also point to the Building Safety Act that was a response to the Grenfell Tower disaster.

I am hoping that the Government are sympathetic to this amendment, but if they find themselves unable to be sympathetic, I would be interested also to hear the Minister’s thoughts on whether we could require the relevant regulator to introduce a named senior manager regime, which indeed we did in the Online Safety Act.

The final point I make is that the senior manager must be senior. The intention behind the amendment is to change the culture of an organisation to ensure preventive action is taken to avoid penalties. As I said at the outset, culture change starts at the top. The services covered in the Bill are, by definition, considered by Ministers to be critical to national life, which means that the most senior governing body should be discussing them and responsible for them. While day-to-day management may be delegated, overall oversight and responsibility should sit at the top. For that reason, I support—as I know the noble Baroness, Lady Morgan, supports—Amendment 167, tabled by the noble Baroness, Lady Ludford. Her proposed new clause would focus the minds of those at the most senior levels of organisations caught by the Bill, and I really hope that the Government support this ambition. I beg to move.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, I am pleased to speak to Amendment 167 and grateful for the support from the noble Baroness, Lady Kidron—the support is mutual, as I co-signed her amendment. The two amendments are complementary, because Amendment 74 is about the liability of senior executives while Amendment 167 is about board oversight of an individual executive, responsibility and accountability. I was interested to hear the noble Baroness refer not only to financial and consumer conduct but to building safety as areas where such responsibility exists.

I am simultaneously involved in the Public Office (Accountability) Bill—the Hillsborough law—which will introduce a duty of ethical conduct, candour and transparency on public authorities and public officials. Perhaps what some of these other sectors have in common is that it has been an after-the-event thought that maybe boards and senior executives ought to have some kind of responsibility in this area. If we have had a catastrophe, often with a great deal of harm created—such as Hillsborough—maybe it would be a good idea if the people at the top, who are often extremely highly paid, took some interest in the area, rather than regarding it as some sort of lowly service, rather like cleaning the loos in the HQ building. I know it is now routine to refer to examples such as Jaguar Land Rover and Marks & Spencer, but there have been huge financial effects of cyber attacks. This is not some negligible issue; cyber security ought to be a core responsibility for senior people.

I am sitting close to the noble Baroness, Lady Harding, who today has referred to her own personal experience—we all remember it. I am sure it was painful for her and very public. She has actually been through it, so nobody knows better what it can be like when you have a big cyber data breach or cyber attack. It really is long past due that this ought to be a top responsibility of boards, directors and senior executives. Yet we understand—I think I get this from my noble friend Lord Clement-Jones—that the Government’s own Cyber Security Breaches Survey reveals that board-level ownership of cyber risk in the UK has declined from 38% to 27% over the past three years. It is going precisely in the wrong direction.

I do not think I need to persuade anyone here of how important it is for senior people in an organisation to be aware and carry not only responsibility, awareness and accountability but liability, so that it hits where it hurts if something goes wrong. Personally, it seems pretty much a no-brainer, and I hope the Minister will agree.

--- Later in debate ---
Moved by
79: After Clause 24, insert the following new Clause—
“Services to support political parties to be specified as essential activities(1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify that an activity carried out for the primary purpose of the operation of a registered political party is an essential activity.(2) In this section “registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000.(3) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the specified activities.”Member’s explanatory statement
This new clause would require the Secretary of State to specify services with the primary aim to support the operation of political parties as essential activities under Part 3, bringing them within the scope of the Bill’s security and resilience regime.
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, this is a group of rather wide scope. I am kicking off. I will also speak to Amendment 168 in my name so as not to speak twice. It is on an entirely different subject from Amendment 79, so we will probably have quite a long debate on this group.

Amendment 79 is about including political parties in this Bill. My honourable friend Victoria Collins MP made the same case in the other place, tabling a proposed new clause to designate political parties as carrying out essential activities. We have discussed, over several days, how cyber security is not just a technical matter confined to server rooms and IT departments; it is a matter of national resilience, economic strength, the functioning of society and, I argue, democratic integrity. On this last count, the Bill is silent.

I remind the Committee that, between August 2021 and October 2022, as we later learned, hostile actors sat undetected inside the systems of the Electoral Commission and exfiltrated copies of the electoral registers—an intrusion the Government attributed to a China state-affiliated actor. There was apparently reconnaissance against the email accounts of parliamentarians who had spoken out against China. So we are hearing of more and more denial-of-service attacks and other incidents affecting critical national infrastructure, which may have some knock-on effect on our democratic structures. Think about what political parties hold: membership lists, canvassing databases covering millions of electors, data on political opinion and special category data of the most sensitive kind—perhaps precisely the material valuable for espionage, transnational repression and targeted disinformation in a campaign period.

Let us think about the kind of defences that are protecting this information. Those of us who have experience of local party activity know that we are normally talking about a small office with a handful of staff and many volunteers, not massive enterprises—and they themselves have been the subject of cyber attacks. We perhaps have quite a weak link at the heart of our democracy.

The National Cyber Security Centre has defending democracy guidance, but this is voluntary, done on an opt-in basis and unenforced; there is no duty to report an incident, no assessment framework, no designated regulator and no floor beneath which a party cannot fall. So there is weakness around the cyber security of political parties and of electoral infrastructure. I am sure that the Minister will tell me that parties are not infrastructure—indeed they are not—but the Bill encompasses data centres and managed service providers on the basis that disruption there would significantly affect the day-to-day functioning of society. If the compromise of a major party’s voter database in the final week of a general election would not meet that test, I struggle to think what would.

Nothing in this amendment invites the Government into the internal affairs of parties; it asks only that the organisations through which the British people exercise their democratic voice are held to a basic standard of resilience. Democracy is essential infrastructure. It is a privilege that we must defend with the utmost priority, and the Bill should reflect that.

I will cover another, completely different matter in my Amendment 168. This amendment was prompted because, probably like others here, in July I had several notifications from either a charity, an arts organisation or an academic organisation—I cannot remember; I think I had four or five altogether—warning me of a data breach. This was a named company—I think it has been in the public domain—called Beacon. It experienced a cyber security incident involving unauthorised access to its systems. I understand it stores data on the membership and customers of a lot of organisations—about 1,000, I read.

This is a probing amendment because I am asking the Government where organisations like this sit. They are variously described as a customer relationship management service provider or a software as a service relationship provider. I do not think they fall into RMSP or RDSP; they are not cloud computing, they are not an online marketplace or search engine and so on. Maybe, arguably, they are a managed service or IT management, support, maintenance or monitoring. I do not know what the precise relationship is between the organisation and the Beacon customer relationship management service provider. I do not really understand it, and the point of the amendment is to find out whether the Government know where it sits in the sphere of cyber and data services. They will often have lots of personal data, including date of birth, contact data, records of donations and memberships, and the booking of events. There is quite a lot where you could profile somebody and find out a lot about them, so it is quite risky to have all of that in unauthorised hands.

I think these breaches triggered reporting duties to the Information Commissioner under the GDPR, but, as far as I know, I do not think that a comparable incident would trigger this Bill’s incident reporting duties. I do not know where these organisations fit, so can the Minister tell me where they live in the ecosystem and what could or should be done to try to increase their support for the organisations that they work for? I beg to move.

Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

My Lords, I wish to speak to Amendment 81A in my name. I was glad to add my name to Amendments 3, 8 and 13 in the name of the noble Baroness, Lady Kidron. I am sorry that I was unable to speak to them on Tuesday due to some caring responsibilities.

Amendment 81A is all about education. Our British educational institutions sit at the heart of our communities. They are key to developing our children and young people, and helping them grow, supporting them through the most important developments of their lives. This year, the UK was ranked as having the third best public education system in the world, something that we should be so proud of but which we must safeguard. We have seen our education system change rapidly in the past decade. We now have exam results revealed via an app. We have homework set through online portals. I receive it weekly for both of my children. Increasingly, vast amounts of student data is being stored online, including around attainment. If our young people are to be properly supported, that must extend beyond the classroom to the network and information systems now essential to their education—a point only reinforced as universities and colleges continue to further embrace online learning.

Exam results determine a young person’s future opportunities. We all remember just a couple of weeks ago the pictures, the interviews of the young people and the elation of many 16 and 18 year-olds as they received and revealed their GCSE and A-level results. We owe it to the next generation to do everything we can to give them the best possible chances—to protect the integrity of the system that determines their future and to prevent the chaos that could follow if, for example, university place allocation, clearing or accommodation processes could not proceed. Anyone who might have friends or family whose 18 year-olds are currently going through that process knows it is frenetic enough at this time—scrambling to get a place for young people who might not have made their grades, changing universities, changing courses, trying to get a university spot or university accommodation.

We have already seen what chaos looks like on a small scale. Noble Lords perhaps will recall students who sat their A-level physics paper with Cambridge International who had their results voided after just one paper was leaked online, with a substitute mark calculated from other components. That was just one paper from one exam board, and it was still enough to undermine confidence in the results for every student affected. We need to look no further than the terrible experience recently in India where the National Testing Agency’s medical entrance exam results were withdrawn after a paper was leaked. It triggered mass protests and, tragically, at least 21 reported suicides among students who had sat the exam. If a single compromised paper can cause that level of devastation, we cannot afford to leave our education system exposed to a compromise on a grand scale.

Amendment 81A would establish that the education sector is an essential activity by requiring the Secretary of State to make regulations under Part 3 of the Bill. This would bring within scope any institution that provides primary, secondary, further or higher educational and vocational training. It includes exam boards involved in setting, marking or awarding and grades, higher education admission bodies, and any body that is essential to the provision of primary or secondary education that holds substantial volume of student or staff data. The obligations would require that education bodies take appropriate and proportionate technical and organisational measures to manage risks to the security of their network and information systems. The bodies must: take appropriate and proportionate measures to prevent and minimise the impact of cyber incidents, with a view to ensuring continuity of service; have regard to the state of the threat; ensure that they have a high level of security appropriate to the risk; and have regard to any relevant guidance issued by their regulator.

--- Later in debate ---
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

I cannot possibly reply on any matters other than political parties. I am left unpersuaded that political parties are sufficiently supported and protected. Maybe bigger parties are not run on a shoestring as much as some of us. I am not talking about national level, but at the local level it could be justified to see some beefing up of the obligations and the support required.

Political parties come in for a lot of flak. They are always getting bashed around—“Who wants parties?”—but, actually, we would not have democracy in most cases without it being channelled through political parties, so they are an obvious target for any malefactor who wants to get at our democracy. It is really unsatisfactory not to give further support to political parties. Perhaps between now and Report we could reflect more on that.

On CRMs, the noble Lord, Lord Russell, prompted me to look at the website of the company Beacon—it is out there, so I am not giving away any secrets. It claims that 1,500 charities, NGOs and other organisations were affected. One was the English National Ballet, which I got a notification from. It manages an awful lot of personal data that has been subject to a cyber security incident. That happened in July, and I tabled this amendment in July, so I would welcome something from the Minister and her team to get a little more of a steer about where an organisation such as that stands in relation to this Bill and whether it should be encompassed to some extent within it.

From this company’s website, you would not know that anything had happened. Maybe that is par for the course. It lists all these security credentials and so on, saying how wonderful it is—I am sure it is, and I do not wish to impugn it—but the fact is that it has had a major cyber security incident affecting apparently maybe 1,500 organisations and the personal data of millions and millions of people in this country. Yet I did not feel we got much back from the Minister, so perhaps we can think more about that between now and Report. I beg to leave to withdraw Amendment 79.

Amendment 79 withdrawn.
--- Later in debate ---
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

My Lords, Amendment 83, in my name and those of the noble Baroness, Lady Ludford, and the noble Lords, Lord Holmes and Lord Tarassenko, would require the Secretary of State to publish and maintain a digital sovereignty strategy. Before the Recess, many of us participated in a debate on digital sovereignty, and the level of agreement across the Chamber was absolutely overwhelming about the importance of UK national sovereignty and the current threats to it from our current arrangements with the tech sector, particularly US-based behemoths. The same sentiment is articulated by Amendment 166 in the name of noble Baroness, Lady Ludford, and it is a sentiment shared in the other place, where Conservatives, Liberal Democrats and Greens all tabled similar Motions.

During the debate, I identified four areas in which the UK has surrendered its leverage to make its own decisions. We surrendered our political leverage by deferring to the power of US tech; we surrendered our economic leverage by placing UK businesses at a structural disadvantage and entering into expansive and extractive contracts; we surrendered our technological capability as we failed to invest in UK capacity and businesses; and we ensured our strategic vulnerability by depending on foreign companies for key infrastructure. Together, these weaken our economy, our security, our safety and, above all, our autonomy: the ability to choose. I doubt that any single government strategy put us in this position, but it reveals a lack of strategy that we find ourselves here.

Amendment 83 would set out a requirement for the Secretary of State to establish a digital sovereignty strategy. Proposed new subsection (2)(a) would require an assessment of the risks to networks and information systems from

“dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference, extra-territorial legal requirements that may be imposed on non-domiciled suppliers”—

such as cloud providers through the US CLOUD Act—

“vulnerabilities, undue control, or supply-chain dependency on foreign states or entities”,

the use of

“UK datasets without license or permission”

and vulnerabilities to valuable data assets that belong to the British public, including those related to the NHS, BBC, and Met Office. The rest of proposed new subsection (2) sets out further requirements to assess the risk of

“technological developments, market concentration or strategic dependencies”

and give consideration to vital elements of sovereignty, including open source technology and assets, talent procurement, capital markets and international collaboration with mid-sized partners whom we retain leverage with.

Finally, proposed new subsections (3) and (4) call for the development of a dashboard enabling the measurement of digital sovereignty. I am working with computer scientists at the British Computing Society who are developing a prototype for this and I urge the Government to look at this work and consider developing it, for their own procurement purposes and to provide it as a tool for the wider business community.

I set that out in some detail because I rather suspect that, if we had a proper strategy across the nation, we would not have had the conversation that we just had in our debate on the previous grouping. Sovereignty is now firmly on the agenda. This is partly due to the export ban on Anthropic and Claude Fable 5 introduced by President Trump in June, but stories highlighting our sovereign vulnerability across the digital stack predate that event and have continued since.

Dependency is not built overnight. It is the result of a systemic and concerted effort by entrenched big tech companies across many years to make themselves indispensable to the UK state, businesses and society, and of successive UK Governments failing to invest in our businesses, communities and people and choosing always to buy oven-ready tech, irrespective of the economic, societal and individual costs.

Just as dependence is not built overnight, neither can sovereignty be reclaimed overnight; nor is it a zero-sum game in which every part of the stack can or should be replaced. None the less, to restore any independence at all, we require an equally systematic and concerted approach to build where we can, to buy only products and services that adhere to our laws, to recognise our unique skills and assets, and to work co-operatively with other like-minded countries. That begins with a strategy that establishes a clear route for government and is fed into experts, free from lobbying and scrutinised by Parliament—which is the very purpose of the amendment in front of us. I beg to move.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, I shall speak to my Amendment 166. It offers an alternative route to the same destination, although the amendment in the name of the noble Baroness, Lady Kidron, is probably superior because it is fuller and more comprehensive; I readily concede that. Her amendment would add an important element—a digital sovereignty dashboard prepared by the Office for National Statistics, the Competition and Markets Authority, the National Cyber Security Centre and the AI Security Institute—so that we can measure whether anything is changing. The cross-party agreement on this matter, which the noble Baroness referenced, is important and might help persuade the Minister of the force of the argument.

The Competition and Markets Authority puts Amazon Web Services and Microsoft together at between 70% and 80% of the UK’s public cloud market. That is not only a duopoly but a digital sovereignty issue. In its report Rewiring the State, which was published in June, the Science, Innovation and Technology Committee in the other place found that major departments, including HMRC and the NHS, were locked into multiyear agreements that further entrench those dependencies. The National Audit Office has found no shared strategic approach across government towards the handful of very large suppliers that now dominate these markets and are, to a large extent, American. Research done by the British cloud provider Civo found that 83% of UK IT leaders believe that geopolitics threatens their ability to control their data, while only 35% know precisely where that data resides.

I have a history, as a Member of the European Parliament, of being involved in all the arguments about transatlantic data transfer and what happens to the data when it is in the US; this was all in the wake of the war on terror, Guantanamo and so on. We are back in that territory, I guess. It is not just about the economic side of non-national control; it is also about your vulnerability to decisions—including, sometimes, decisions that you do not like—about what happens to the data.

Moved by
10: Clause 8, page 7, line 36, at end insert—
“(1A) In paragraph (1), after “risks” insert “, including risks arising from fraud,”.”Member's explanatory statement
This amendment would explicitly include risks arising from fraud as one of the risks to the security of network and information systems that relevant digital service providers must identify and manage.
--- Later in debate ---
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, I apologise for not having been much around earlier, but I am also involved in the Hillsborough Bill in the Chamber.

Amendment 10 stands in my name and that of my noble friend Lord Clement-Jones. It would insert just five words into Regulation 12 of the 2018 regulations so that the risks which a relevant digital service provider must identify and manage explicitly include risks arising from fraud. The amendment might create no new duty if the duty is already encompassed in Clause 8, but it settles a question that the Bill currently leaves open. When an online marketplace, search engine or cloud provider—or a software or digital platform, under Amendment 7 from the noble Lord, Lord Birt—sits down with its regulator and asks which risks it is expected to manage, is fraud definitely on the list? At present, nobody can say so with confidence, and the answer matters a great deal because of who Clause 8 applies to. Relevant digital service providers are online marketplaces, search engines, cloud computing services and, possibly, digital and software platforms. These are not incidental to fraud in this country. They are increasingly where it begins.

We can see the impact of a lack of action to secure online and cyber spaces. Fraud makes up 44% of all UK crime, and online technologies, especially artificial intelligence, are supercharging that, with a big increase in online-generated fraud and scams. Research by Lloyds Bank found that Meta’s social media sites are a starting point for 76%—three-quarters—of purchase scams in the UK, with the value of losses to UK customers estimated at £66 million in the last year alone. The Government’s fraud strategy does not really focus on the role of social media giants and big tech in the proliferation of online scams, and now the Bill fails to address explicitly the risks that fraud and scams pose to critical infrastructure and organisations. That is very striking when we consider that the Government’s official statistics on cyber security breaches show that phishing attacks—scams—remain by far the most prevalent type of breach or attack in the UK.

The evidence of the impact of fraudulent online activity is not contested and is a huge concern for consumers. UK Finance’s annual fraud report, published in June, records that criminals stole nearly £1.3 billion through payment fraud in 2025, a rise of 4% on the previous year and the second consecutive year of growth. There were more than 4 million confirmed cases in 2025: that is eight people defrauded every minute. Authorised push payment losses rose 19% to £576 million, and around two-thirds of that fraud originated online. Investment fraud was up by 40%.

UK Finance describes fraud as a “national security threat” and I think it is right. The Government’s cyber security breaches survey published in April found phishing to be by far the most prevalent form of breach or attack, experienced by almost four in 10 businesses and rated the most disruptive by seven in 10 of those affected. Among businesses breached, more than half experienced only phishing. Fraud is not parallel to the cyber security threat. For most organisations, fraud is the cyber threat picture.

I anticipate the Minister will tell me that fraud is handled elsewhere: in the Online Safety Act, the reimbursement rules and the fraud strategy. However, I make two points. First, none of those regimes places a security and resilience duty on cloud providers or marketplaces in respect of the systems on which essential activities depend. Secondly, a regulatory architecture in which every regulator assumes that fraud is everybody else’s business is precisely how a gap of this size opens up in the first place.

This amendment was raised in the other place by my honourable friend Victoria Collins MP. The ministerial answer was, in essence, that the words were unnecessary. I would rather have them explicitly in the Bill rather than rely on inference. If the Minister cannot accept the amendment, I ask for two assurances: that the guidance the Information Commissioner must issue under paragraph (4)(a) of Regulation 3 will address fraud risk explicitly, and that the statement of strategic priorities under Clause 25 will name fraud among the risks to which regulators must have regard.

I shall turn to just one other theme in this group; my noble friend Lord Clement-Jones will sweep up at the end in his winding-up speech. I wish to speak to Amendment 15 on workforce competence and skills, as well as on the issues raised in Amendments 174C and 174D, which also refer to cyber security capability. We are all concerned about the shortage of cyber skills and competencies in the workforce, but one place where that has to start is with young people in schools and colleges. I sought to table an amendment calling for the Government to publish a strategy on improving the cyber security awareness and resilience of children and young people through education. Sadly, the PBO ruled it out of scope, but I hope that we might have that issue in mind. If we are going to get the increase in workforce skills and competence on cyber security that we vitally need, we need also to have an eye on developing those skills in our young people, who spend so much of their lives online. I beg to move.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The content of the statement of strategic priorities will be subject to consultation and we will be working with regulators on that. It could include specific risks, whether from quantum or from fraud. What I do not want to do right now is to commit that it will include that, because we are going through a process.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, I thank the Minister for her reply. Her last words gave me a little bit more hope than the rest of her response, to be honest, when she said that the statement of strategic priorities could include specific risks, because it seemed to me that she was otherwise being a bit generic and unspecific—almost above the fray. When I came in on a previous group—and other noble Lords are much more knowledgeable and expert in this field than I am—I picked up some frustration that the feedback from the Government and from the Minister today was a bit vague and not very responsive. All this is happening out there; there are huge cyber threats and there is a feeling that the Government are not really getting to grips with the actualité quite as much as they might.

I understand that the Minister might not be able to say now what will be in the statement of strategic priorities, but what we are searching for is that it will grapple with real problems out there in the economy, in society. I must admit that Amendment 82 from the noble Lord, Lord Ravensdale, on post-quantum cryptography, is somewhat above my pay grade. I wish I was more knowledgeable, but I ain’t. But I understand what he is saying, how real this is: the threat is out there. You just have to read newspapers to get the drift of what is happening. I mentioned that fraud is nearly half of all crime, so these are big issues. I think that what we want from the Government is a feeling that they get it, that there is going to be specificity in the way that they are going to implement this Bill and that they are really going to be on the case of these big threats. The Minister’s last words were a bit more encouraging than some of the rest of what she has been saying. That said, I am sure we will come back to some of these issues on Report, but I beg leave to withdraw my amendment.

Amendment 10 withdrawn.

Maccabi Tel Aviv FC: Away Fans Ban

Baroness Ludford Excerpts
Wednesday 22nd October 2025

(10 months, 3 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
Baroness Ludford Portrait Baroness Ludford (LD)
- View Speech - Hansard - -

My Lords, it seems clear that the main motivation locally was in fact to boycott Israel. None the less, it is necessary to get clear the degree of blame that has been attributed to the fans of Maccabi Tel Aviv. There is an account in the Guardian today which seems seriously distorted. Have the Government got it clear in their own mind, at least for all useful purposes, that while there may well have been bad behaviour, hooliganism and even some racist behaviour by a minority of fans in Amsterdam, the majority of the harm was committed against them and not by them? It is important to capture the picture that the Government have of what happened in Amsterdam, because it has been recycled a lot.

Baroness Twycross Portrait Baroness Twycross (Lab)
- View Speech - Hansard - - - Excerpts

My understanding of what happened in Amsterdam is as the noble Baroness has just outlined. One of the things that I found most appalling about the decision that was made is that it was based on the risk to fans, primarily. In a country where we manage violence associated with football on a regular basis, we cannot have a situation in which it is the risk to fans which means that those fans themselves are barred from a sporting or other public event.

Data Protection (Charges and Information) (Amendment) Regulations 2019

Baroness Ludford Excerpts
Monday 18th February 2019

(7 years, 6 months ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, I just want to add to what my noble friend Lord McNally has said. I am glad that this matter is being cleared up, because we had very confusing advice a few months ago. I also want to note, as one of the people who was involved in the European Parliament’s proceedings on the GDPR, that it is a UK decision to impose a fee on data controllers. The mandatory requirement was removed from the GDPR, and it is a unilateral UK decision to fund the ICO in this way so that, in effect, data controllers in the UK will not feel the change which perhaps will be felt by data controllers in other EEA states, where Governments make a decision to fund their data protection authorities from, for instance, general taxation. I realise that that decision was made in the Digital Economy Act rather than in last year’s Data Protection Act, but it is imposed not by Brussels but by Whitehall and Westminster.

Baroness O'Neill of Bengarve Portrait Baroness O'Neill of Bengarve (CB)
- Hansard - - - Excerpts

My Lords, these amendments represent a little island of calm in a turbulent ocean. For once, I am referring not to Brexit or the backstop but, rather, to the fact that we are in the middle of some very turbulent changes in our regimes for the protection of data and privacy and many other aspects of communication. This morning, we saw the publication of the report of the Digital, Culture, Media and Sport Committee of the other place on disinformation and “fake news”. In so far as I have got into the report—which is not very far—it is very welcome in that it represents a much broader view of the threats to democracy from the present regime for controlling the use of data. There is much more to be said, and I hope that the Minister will be able to say something about the ways in which the broader picture will be taken into account. These amendments do not need changing because of the broader picture, but it is curious to fiddle with the small stuff when such major and serious issues are happening in this domain.

Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019

Baroness Ludford Excerpts
Monday 18th February 2019

(7 years, 6 months ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Lord McNally Portrait Lord McNally
- Hansard - - - Excerpts

My Lords, I was planning a peroration, but I think I will leave it at that.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, first I have a couple of housekeeping questions which I hope are not too banal. I find considerable difficulty using the legislation.gov.uk website and its search function. Will the Minister ask his civil servants to check it out? Even if you search for “data protection 2019” under UK SIs, both the previous one and this are difficult to find. There was a 19 December version of these regulations, which were replaced in January. I must admit that I have not pored over every line of both to find the differences. Will the Minister explain why that was necessary?

Secondly, I want to ask about the absence of an impact assessment. Paragraph 12 of the Explanatory Memorandum states that:

“There is no, or no significant, impact on business, charities or voluntary bodies arising from this instrument”.


The pretext is that, while the Government recognise that:

“Data flows from the EEA to the UK may be restricted post-exit”—


because, if there is no deal, we will be plunged into a situation where there is no legal framework and no adequacy decision—

“that is as a consequence of the UK leaving the EU, not as a result of this instrument”.

That is the justification for having no impact assessment. However, if we left with a withdrawal deal and a transition there would be a legal framework, so this instrument, which provides for both a no-deal scenario and one in which there would be no adequacy decision, surely merits an impact assessment as well as the consultation to which the noble Lord, Lord Adonis, referred.

As the ICO has made clear, and as has been mentioned already, businesses may have to deal both with the ICO and with European data protection authorities in every EU and EEA state where they have customers. They may need a European representative if they process the data of people resident in the EEA or have customers in the EEA. There would be additional complexity if they had to comply with both the GDPR and the UK GDPR. They could face concurrent legal claims in both the UK and the EEA. Will the Minister amplify the justification for having no impact assessment? Data flows are crucial to many businesses, not just the tech industry—there is hardly a business or other organisation that they do not affect—so the rather blasé claim that no impact assessment is needed is not justified.

I am a bit confused—it may just be my lack of understanding—about the situation regarding EU adequacy decisions on third countries. Paragraph 2.8 of the Explanatory Memorandum says there will be,

“incorporated into UK domestic law … EU decisions on the adequacy of third countries and on standard contractual clauses, both of which are relevant for … international transfers”.

Paragraph 2.13 says:

“It will not be necessary to retain the EU decisions on adequacy and standard contractual clauses … so these are revoked by this instrument”.


If I have understood the Minister’s presentation, this is explained by the fact that we are recognising and incorporating past EU adequacy decisions, but that in the future, in a no-deal scenario, the UK will take over that function: I venture to suggest that that is not very clearly explained in the Explanatory Memorandum.

Lord Ashton of Hyde Portrait Lord Ashton of Hyde
- Hansard - - - Excerpts

Would it help if I just said that the noble Baroness is absolutely right in her interpretation?

Baroness Ludford Portrait Baroness Ludford
- Hansard - -

I do not often get that response from Ministers, so that is very gratifying.

Also, a second version of these regulations was published at the end of last week—I think the Minister referred to it—which is specifically about privacy shields in the US. I am rather surprised that we will have two separate considerations: why could they not have been incorporated into this debate? As the ICO pointed out in a notice a while ago, US companies will need to update their privacy shield commitments to state that they apply to transfers of personal data from the UK. That is a big deal for many companies. It is another reason for what I said about the need for an impact assessment. If that does not happen, a lot of companies will be in serious difficulty.

Will the Minister tell us what advice the Government are giving businesses on using standard contractual clauses or binding corporate rules in the absence of an adequacy decision? The European Data Protection Board issued a notice about this last week, on 12 February. Are the Government going to advise businesses, large and small, exactly how this will work? Lastly, what progress is being made on an adequacy decision? The Minister will know from discussions during the passage of the EU withdrawal Act and the Data Protection Act that many of us are worried about this issue. Last summer, the Government expressed their aspiration for a legally binding agreement that would be more than a unilateral adequacy decision and which would enable the ICO to have a seat on the European Data Protection Board. Essentially, it would be Brexit in name only and would retain all the benefits of being in the EU with regard to data protection structures. That aspiration is not recognised in the political declaration, which talks only about an adequacy decision, so the UK has been knocked back in that area. Perhaps the Minister could tell us precisely where we are. What signal is he getting from the Commission on an adequacy decision? Are we talking months or years?

--- Later in debate ---
Lord Adonis Portrait Lord Adonis
- Hansard - - - Excerpts

The noble Lord is right, but I do not think that that day is far off; I think it will come soon. Let us be clear: we are not talking about a natural disaster. As a Minister, I often had to deal with those. When there are ash clouds and volcanoes erupt, you have to take very difficult and extreme decisions at short notice. Here we are talking about an act which the Government are inflicting on the country, with no external agency whatever. Not only that, but the Government could this afternoon terminate the situation we are faced with, in respect of these no-deal regulations, by the Prime Minister announcing that she is not proceeding with no deal and that she will, on behalf of the United Kingdom, submit a request to extend Article 50—or, as we now know she can do from the judgments of the European court, rescind it unilaterally. This will be a big matter for the public inquiry that the noble Lord, Lord McNally, is referring to. All the consequences of this no-deal situation are caused by the Government, and the remedy for them is entirely at the disposal of the Government. It is our absolute duty to point this out all the way through this process, so that at least some of us in the parliamentary system can point to the fact that we did our level best not to take the nation to the edge of the cliff where we are now at.

Coming back to this instrument, it is totally unacceptable that we are dealing with such an important set of regulations relating to the fundamental issue of data and data protection and there has been neither an impact assessment nor any public consultation.

Baroness Ludford Portrait Baroness Ludford
- Hansard - -

My Lords, I asked the Minister about the state of play on an adequacy decision. I am told that the Minister in the other place, Margot James, confirmed a few weeks ago not only that those discussions can start—at least formally—only after the UK leaves the EU, but that they would take two years; that was her estimate. So that multiplies the gravity of having no impact assessment; if we crash out without a deal, we will have a legal void for a long time.

Lord Adonis Portrait Lord Adonis
- Hansard - - - Excerpts

The noble Baroness raises a very important question, to which the Minister should respond: how long will it take to consider this? Noble Lords who woke up to the “Today” programme this morning will have been astonished to find that Dr Liam Fox and the Foreign Secretary had written to the Japanese Prime Minister telling him to get a move on in signing a trade deal with Britain—as if we, because we are putting ourselves in a position of great jeopardy and undermining existing international agreements in five weeks, can now start instructing foreign Governments on the timescales in which they should conduct international negotiations. This is utterly humiliating to us as a country. It is a fundamental breach of the proper conduct of public affairs. What the noble Baroness said about it taking another two years even to get the basis of data adequacy agreements with the EU, because of our act of withdrawing from the European Union, simply underlines the point.

--- Later in debate ---
Lord Ashton of Hyde Portrait Lord Ashton of Hyde
- Hansard - - - Excerpts

My Lords, I took the advice of the noble Lord, Lord McNally, that it would not be easy—and he has proved to be right. It is reasonable to take on board the frustrations that some of these SIs have caused—in my view, not so much because of the process which is gone through but the fact that some noble Lords do not want to leave the EU and are highlighting the effects. What they are highlighting may well be the case, but when we are trying to pass an SI such as this one we need to concentrate on its effect and—that did not take long.

Baroness Ludford Portrait Baroness Ludford
- Hansard - -

I am sorry but the Minister must accept this. It is absolutely true—I speak for myself and my Benches—that we would prefer to remain in the EU, but that is not the point about an impact assessment. There is a difference between crashing out with no deal and a transitional period when EU law would continue to be applicable and we would not need all these arrangements. That is what an impact assessment would have to assess. This is about a no deal crash-out and it is perfectly valid to distinguish that from an advocacy of remain.

Lord Ashton of Hyde Portrait Lord Ashton of Hyde
- Hansard - - - Excerpts

I agree. That is why the Government are making all efforts to secure a deal. We agree that a deal is the best situation for the country. We are at one with that.

In answer to the noble Baroness, I will start with something which is my responsibility—the legislation.gov.uk website provided by the National Archives. I will take up the matter with it. I am told that it may be helpful to search for “draft statutory instruments” rather than “statutory instruments”. I certainly listened to what she said about the website not working and will check what we need to do.

The noble Baroness, the noble Lord, Lord Adonis, and others talked about the impact assessment and asked why it has not been published. The impact of this instrument, not the impact of leaving the EU, was assessed in line with standard practice following the existing Better Regulation framework. It is focused on the direct impact of the relevant SI compared with the current legislation. The whole point of this SI is to maintain an equivalent regulatory framework to protect personal data. The noble Lord, Lord Adonis, quite rightly pointed out that it affects not only UK businesses but mostly EU and EEA businesses, which will have to have representatives in this country, and I will come to that. It is a reciprocal arrangement. If these regulations come into force and we have a UK GDPR, the same necessity for representatives will take place both ways, and I will come to that.

The analysis, to the best of the Government’s ability, of the wider impact of the UK’s exit from the EU was published in the Long-term Economic Analysis in November last year. The noble Lord, Lord Adonis, talked about representatives and Article 27. He is correct that data controllers who offer goods and services to or monitor the behaviour of data subjects in the UK will need to appoint a representative in the UK, but that is a cost to non-UK businesses, which is what the impact assessment is meant to address. He is also correct that there will be organisations in the UK that will be required as a matter of EU law to appoint a representative in the EEA. The ICO provides data controllers with advice on this obligation and will continue to do so. If controllers and processors based abroad are routinely processing data, it is right that they should be accountable in the UK and have a presence here because this is about maintaining the status quo as far as possible, not about rolling back protections for individuals, so the representative is a point of contact for the data subject as well as the supervisory authorities, such as the Information Commissioner.

--- Later in debate ---
Baroness Kramer Portrait Baroness Kramer
- Hansard - - - Excerpts

I want to get some clarity on this and perhaps the Minister will be able to help me. He is quite clear that, for a wide variety of companies, there will need to be one representative in the UK and, he seems to imply, one representative in the EEA. Is that correct, or does there need to be one in each country within the EEA—or does the individual in the EEA have to deal with different regimes because of the different local regulators and because it is representing a third country in its work? I am trying to work out how great the burden that he has indicated will be, even though he does not think that it will be part of the impact.

Baroness Ludford Portrait Baroness Ludford
- Hansard - -

Before the Minister answers, I would like to press again this idea that an impact assessment is not needed since the impact comes from leaving. I say no to that; it depends how you leave. The Minister and I may differ on the desirability of the Prime Minister’s deal, whatever that is going to be, but there is a difference between crashing out and having a transition with a political declaration which may avoid the need for duplication; we do not know what the data protection provisions will be in the future relationships. We all hope that there will be a strong degree of mutual recognition, but the immediate impact of crashing out with no deal—with a void where any adequacy decision or future reciprocal relationship between regulators would otherwise be—is quite different. First, it is different from having a standstill transition and, secondly, it is different from having the prospect, or at least the hope, of a long-term relationship that preserves something of the single market. We need the impact assessment to assess the difference between those two scenarios; that is what the Minister does not seem to grasp.

Lord Ashton of Hyde Portrait Lord Ashton of Hyde
- Hansard - - - Excerpts

I agree with the noble Baroness that, if we leave with a deal, that is a different scenario from leaving with no deal. That seems an obvious fact and it is why the Government are trying to leave with a deal, which is what the Prime Minister is trying to achieve. This is a no-deal exit SI to prepare for that eventuality. If we leave with no deal, the object of the exercise will be to preserve the GDPR standard of data protection, which this SI will do. To return to the point raised by the noble Lord, Lord Adonis—sorry, it might have been raised by the noble Baroness, Lady Kramer—the requirement to appoint one representative in the EEA is, as I said, a result of EU law.

I say again to the noble Lord, Lord Adonis, regarding the impact on business of Article 27, that we think that if controllers based abroad are routinely processing the data of people in the UK then it is right that they should be accountable and have a presence in the UK, because it is about trying to maintain the status quo as far as possible for individuals and not rolling back their data protection. The representative is a point of contact for the data subject as well as supervisory authorities such as the Information Commissioner.

I turn to the points made by the noble Lord, Lord McNally, about the complexity for organisations potentially subject to dual regulation. The point of this instrument was to ensure the minimum disruption to organisations and to data subjects by trying to retain the effect of the data protection legislation where possible. The relationship is absolutely changing but the instrument ensures that we can co-operate on an international level with not only the EU supervisory authorities but those in other countries; that is why we have kept Article 50 of the GDPR. Where he is right, and I accept that he is right in this, is that if we move away from the GDPR—if the UK GDPR moves away from the EU GDPR—that will have consequences for the adequacy decision that we hope to achieve, which will be reviewed by the EU Commission. It is important that the EU has confidence that our data protection regime is “essentially equivalent”, which is what the adequacy decision is based on. Anything that we do in future will have to bear in mind that our data regime is essentially equivalent so that it gives the EU confidence.

I agree with the noble Baroness, Lady Ludford, that in previous times there were elements that were outside EU competence that it could not look at, but now of course in an adequacy decision it will be able to look at those. Again, as it does in other adequacy decisions, it will look at the overall adequacy requirement and say whether or not it is essentially equivalent. That is why the adequacy decision is not immediate. Where we start in a good place compared to other regimes is that we have started with an equivalent regime to the extent that we have enacted the GDPR, which other third countries have not. We start on a level playing field in that respect.

The noble Baroness talked about the US privacy shield and the reason why we are going to lay another set of regulations. The discussions on the US privacy shield were ongoing when this SI was laid and therefore we could not wait. It was our priority to lay this SI so that we had an ongoing regime in the event of no deal. Now that that has been agreed between us and the US, though, another SI will be laid—it may even have been laid—to ensure that the US requirements continue, and I think that will happen very soon.

The noble Baroness asked about the EDPB’s recently published guidance on the implications of the UK’s exit. That guidance confirmed that, if the EU Commission does not make an adequacy decision in respect of the UK, EU firms will need to put in place alternative transfer mechanisms, such as standard contractual clauses to continue to transfer personal data to the UK.

The noble Baroness suggested that the political declaration only covered adequacy. That is not right: paragraph 9 addresses the free flow of data while paragraph 10 addresses regulatory co-operation.

The noble Lord, Lord Adonis, and the noble Baroness, Lady Ludford, talked about consultation. The difference between this SI and many others is that the Data Protection Act came into force less than a year ago; it was enacted after extensive discussions in this House and the other place, after the referendum discussion had taken place. Those noble Lords who participated in the Data Protection Act discussions, which lasted for many weeks, all know that matters such as data adequacy were raised numerous times. The whole purpose of the Act, and the mixture between regulations and derogations from regulations, was that we would be on as level a playing field as we could be when it came to getting an adequacy decision.

--- Later in debate ---
Lord McNally Portrait Lord McNally
- Hansard - - - Excerpts

I withdraw the word “farce”. However, while the Minister is putting great emphasis on the good fit between what he is proposing and the GDPR, the reason why that good fit exists, as I said in my remarks, is that the GDPR itself was massively influenced by British officials, who played a major role in its construction. What he is gliding over in his assurances is that if, as is likely, there are changes in the European GDPR in future then we will be coming, like the Norwegians, only to listen and accept—because, make no mistake, if there are changes in future, it will be massively in Britain’s interest to accept them. This is the loss of sovereignty that the whole process is trying to glide over. We will not have the same influence on data protection in future as we have had in the GDPR itself, which is why the fit is so comfortable at the moment.

Baroness Ludford Portrait Baroness Ludford
- Hansard - -

Forgive me, but I would like to follow up on that. I really think the Minister is overselling what is in paragraph 9 of the political declaration. Last June, the Government issued a technical note about wanting a legally binding data protection agreement, and I described that earlier as a “Brexit in name only” kind of arrangement. They wanted that because there are,

“benefits that a standard Adequacy Decision cannot provide”.

Except for one sentence in paragraph 10 that talks about arrangements for appropriate co-operation between regulators, paragraph 9 is about a standard adequacy decision—no less but certainly no more. It talks about the European Commission recognising,

“a third country’s data protection standards as providing an adequate level of protection”.

It is not what the Government hoped for last June. I do not understand why the Government are trying to pretend. We can all read paragraph 9 once we have googled it and reminded ourselves, so to say that it is more than an adequacy assessment process is simply not true.

Lord Ashton of Hyde Portrait Lord Ashton of Hyde
- Hansard - - - Excerpts

I understand the point from the noble Lord, Lord McNally, that our new position will not be the same as being in the EU. If we were a third country, I would expect us to have less influence than if we were a member of the EU. I am not denying that; it seems obvious. He is absolutely right that the GDPR was influenced by the UK, not only by officials in the negotiations but specifically by the ICO, which is regarded as one of the leading regulators in Europe. Of course, it will not have the same position as it did if we are not in the EU; I take that point.

However, I do not base everything on just the political declaration, which may or may not have some influence. It is also that we have retained Article 50 of the GDPR. I cannot remember the exact words, but it is on the basis of that that the EU talks about international co-operation with third countries, so there is a mechanism. As I said to the noble Lord, Lord McNally, it will not be the same, but there are bases for international co-operation. The EU wants that to happen and understands that in things such as data protection, you have to have an international consensus. In fact, on that, it is more important to go beyond the EU and do it internationally. Other organisations should—and do—take views on this. I think we are at the start of the journey on control of cross-border data flows and it will provide a further basis to influence behaviour.

On adequacy, it is easy to ask for detailed timelines on when this will take place. It will not take place on exit day, because it is not possible for the EU to give an adequacy decision unless you are a third country. Preliminary discussions—which, as the noble Baroness, Lady Ludford, has indicated, may take some time—could begin now and we are ready to begin those discussions as soon as we can. We are already liaising with the European Commission—in fact, senior officials were in Brussels for talks last week—and we have liaised with member states on this subject. When the EU is ready to begin discussions, we are confident that we will be ready, but it is impossible to say how long that will take because, as the noble Baroness said, it is not a decision that is in our gift.

However, we start from a position of regulatory alignment on data protection. We implemented the GDPR and the law enforcement directive. We have also taken a GDPR approach on data protection to areas that were outside EU competence, such as law enforcement and national security, so we start in a very good position. In fact, it is such a good position that the UN special rapporteur on the right to privacy declared that the UK now co-leads in Europe and globally on privacy safeguards, and has made significant improvements in its oversight system since 2015. He said that,

“the UK has now equipped itself with a legal framework and significant resources designed to protect privacy without compromising security”.

It is important to note that there is a strong mutual interest in data adequacy.

The noble Lord, Lord Adonis, said that it is unsafe to pass this SI. I would like to point out what that would mean, if it is not passed and we have a no-deal exit. It would mean that we would cease to have properly functioning data protection law. The whole basis for adequacy decisions, which I think we all agree is very important, would go, because we would not be on a reciprocal basis—

--- Later in debate ---
Lord Ashton of Hyde Portrait Lord Ashton of Hyde
- Hansard - - - Excerpts

There are mitigations which prevent that—standard contractual clauses and binding corporate rules. Plus, it depends a lot on the proportionate approach that the regulators in the EU take. There would be an impact; we would have to arrange mitigations, which would be a cost to business. That is what has been set out in the technical notice to business.

Baroness Ludford Portrait Baroness Ludford
- Hansard - -

The Minister is making a very good case for why there should have been an impact assessment.

Lord Ashton of Hyde Portrait Lord Ashton of Hyde
- Hansard - - - Excerpts

I am making a very good case for why we want a deal. As I have said several times, we want a deal.

I think I have been through most of the questions raised by noble Lords. The important thing about this statutory instrument is to have a fully functioning data protection regime. If we go back to the original reasons why we passed the Data Protection 2018 with a fair bit—a lot, I would say—of cross-party support, the reason that it is important is to give individuals protection for their personal data. We must bear that in mind. These regulations will preserve that protection for individuals and set us on the road to a successful conclusion of our adequacy agreement when we get to the stage where the EU will allow us to negotiate it. That is why I beg to move.

Mobile Roaming Charges

Baroness Ludford Excerpts
Thursday 7th February 2019

(7 years, 7 months ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Lord Ashton of Hyde Portrait Lord Ashton of Hyde
- Hansard - - - Excerpts

My Lords, I think that there may be some misunderstanding about this. The Huffington Post commented on an SI that was laid which is a no-deal SI. The best way that noble Lords and Members of the other place can prevent these changes happening is to agree a deal. However, if there is no deal we have to face the inevitable consequences of that. A lot of the issues that have arisen not only with this subject but with other SIs stem from not distinguishing between the effect of the SI itself and the effect of leaving the EU. In this case, it is not fair to say that we have not prepared for that. In fact, the technical notice that outlined all these considerations was issued in September. It is not a question of simply withdrawing the instrument; if we are no longer in the EU, we will not be able to prevent EU operators increasing charges to UK operators. They will then have to accept those higher charges, which inevitably will be passed on to consumers. The issue is that if we leave the EU we will not be able to participate in the harmonised wholesale roaming prices, so I do not accept the analysis of the noble Baroness. That is why it is not possible to withdraw the SI, if we are acting responsibly in the event of no deal.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, the best way to avoid these changes is of course no Brexit. Surely the Minister will agree that the slashing of mobile roaming charges in the EU is one of the biggest successes for British consumers, travellers and businesses. British Ministers and MEPs played a big part in this triumph to stop rip-offs and nasty surprises on bills. Now the Government intend to steal this benefit from British citizens, even though they think it likely that costs will be passed on to consumers through the choice they have made. Why have the Government chosen—and it is a choice—not to impose a retail roaming price cap? Is this deregulation policy a foretaste of the Government’s intentions in other sectors? What estimate have the Government made of the total extra costs for a British holidaymaker arising from the reintroduction of roaming charges, the loss of the EHIC card, likely increases in the cost of travel insurance and EU fees for a visa-lite? Should the Government not put this choice back to the British people so that they can decide whether they want to Brexit at all?

Lord Ashton of Hyde Portrait Lord Ashton of Hyde
- Hansard - - - Excerpts

I do agree with the noble Baroness on one thing: this has been a great benefit since it was introduced 18 months ago. Of course, it did not exist until then. When we decided to leave, there were inevitable consequences. What I do not understand from her question is how she thinks, within the powers available to the UK, we could do something different. If we set a retail price cap, UK operators will have to accept all the increased charges and as sure as anything, those will have to be passed on to all consumers. The difference is that she would penalise all consumers, while this measure affects only those who roam in the EU.

Data Protection Bill [HL]

Baroness Ludford Excerpts
Lord Stevenson of Balmacara Portrait Lord Stevenson of Balmacara (Lab)
- Hansard - - - Excerpts

My Lords, I thank the Minister for moving his amendment and for his concluding remarks, which I will return to. I welcome this amendment, and the implication it carries that the Government have listened to the discussions we have had in the last few weeks and have moved from their initial position.

I will speak to Amendment 2, which I am delighted has also been signed by the noble Baroness, Lady Ludford. I am sure that your Lordships’ House will recognise that, in bringing forward a revised draft, we have reflected very deeply on the points made by noble and noble and learned Lords in the debate on the original amendment moved in Committee. In addition to noble Lords who spoke on that occasion, I thank the academic and practising lawyers—as well as many in industry—who have contributed to our emerging thinking on this topic. Before it was submitted to the gruelling process that happens to all amendments when they go to the Public Bill Office, I sent an earlier draft of this amendment to many Members of this House who spoke in that earlier debate. I am grateful for the comments I have received.

It is unusual to have two amendments bearing on very similar points. It is an advantage to be able to see the conflicting, and often overlapping, thinking that has gone into this. It is clear to all who have read both and thought about them that, while we are not yet in full agreement, we are very close. Indeed, I venture to suggest that there is more that unites us on this issue than divides us. What do we agree on? We both recognise that the key data protection rights currently enjoyed by citizens in the UK crucially underpin any assessment of adequacy that might need to be made by the EU post Brexit. They are crucial for the future of our successful data-handling industry. We both want the key data protection rights currently enjoyed by citizens in the UK to continue once the Bill becomes law, while the GDPR is in force, and then after Brexit—if that happens. We agree that the key question to be determined is not the exact wording of one or other but whether it is necessary for these key rights, currently enjoyed by UK citizens through Article 8 of the EU Charter of Fundamental Rights, to be expressed clearly for all to see on the face of the Bill, or whether their existence in various parts of the Bill—and in the GDPR and its recitals—is sufficient.

By putting down their own amendment on this issue, the Government seem to agree that explicit references in the Bill will be helpful, for the reasons given above. We now need to get together to find a form of words which will achieve this aim and which we can both support. I therefore agree with the noble Lord that the right thing to do is for both sides to withdraw their amendments on this issue today and for the Minister to confirm—as he has done—that the matter is of sufficient importance to be brought back for further consideration at Third Reading. If he will agree to that, I will not move my amendment when it is called.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, I also welcome the fact that we are in touching distance of an agreement on this matter. I thank the Minister for bringing forward Amendment 1. However, there is a little way to go. Amendment 1 is declaratory of what is contained in the Bill, whereas Amendment 2 is rather stronger and clearer.

Embedding a general right to data protection inspired by the Charter of Fundamental Rights is not only important for UK citizens but, as we have agreed in many debates and exchanges in this House, it is crucial for unhindered data flows between the UK and the European Union if we Brexit. It is absolutely crucial for business and law enforcement to be able to exchange data and have access to EU databases, such as the Schengen Information System, Europol and so on. The Government’s review of the charter, which was also most welcome and was produced last week, says that,

“domestic courts will be required to interpret retained EU law consistently with the general principle reflected in Article 8, so far as it is possible to do so”.

Is the Minister able to elucidate what that caveat leaves out? What would not be possible?

In the Watson case, to which the Brexit Secretary was a party until he became the Brexit Secretary, the European Court of Justice found that the current UK data protection regime in relation to data retention and acquisition was incompatible with Article 8 of the charter. This demonstrated the deep importance that the European Union places on charter rights in the protection of privacy. The draft resolution that the European Parliament is due to debate and vote on this Wednesday, on the joint report on the phase 1 divorce agreement that was reached last Friday,

“underlines that it will accept a framework for the future EU-UK relationship as part of the Withdrawal Agreement only if it is in strict concordance with the following principles”,

including the,

“United Kingdom’s adherence to the standards provided by international obligations, including fundamental rights … data protection and privacy”.

So we can expect this to be a very important matter, on which there will be a spotlight in the consideration of an adequacy assessment by the European Commission, which I think we all agree it is essential to achieve.

As I said in Committee, the adequacy assessment will be wide-ranging, taking in all aspects of law and practice in the United Kingdom. Of course, this will include the law and practice in terms of national security, which at the moment—rather ironically, or perversely—are excluded under the EU treaties. Once we are outside—if we are—there will be closer examination of how privacy fares in relation to the demands of national security than there is while we are in the EU. In that context, the national security issues in the Bill, which will be further debated as well, will perhaps take on a heightened importance.

On these Benches we believe that the rights under the charter in relation to data protection should be reflected in the Bill so as to have a general right to the protection of personal data in UK law. I very much agree with the course advocated by the noble Lord, Lord Stevenson, to reflect further and to accept the Government’s offer to come forward at Third Reading with something that we could all agree on.

--- Later in debate ---
Baroness Ludford Portrait Baroness Ludford
- Hansard - -

I thank the Minister for his response. I was glad that he addressed the question of an adequacy assessment at the end of his remarks, but with respect, it is not enough—or adequate—to address an adequacy assessment only at the point of asking for it. We must lay the foundations now. I cannot see the point in storing up potential problems when we could solve the problem of the basis. We ought to do everything in that prism. We can have delightful legal discussions—it is important to get the law right—but this is also crucial to business. We have had so many representations on that point. I am sure that the Minister’s colleague, the Secretary of State for Digital, Culture, Media and Sport, is preoccupied with this question. Surely we need to front-load our response? We cannot wait until the UK applies for an adequacy assessment to be told, “Well, it’s a pity that you didn’t enshrine the principles and the essence of article 8 of the charter”. We have a chance to do that now and ensure a solid platform for requesting an adequacy assessment. I admit that I am puzzled as to why the Government would not want to do that; it is important for law enforcement as well. Why would we not want to solve that problem now, instead of finding later that we have entirely predictable problems as a result of not doing so?

Lord Ashton of Hyde Portrait Lord Ashton of Hyde
- Hansard - - - Excerpts

I completely agree with the noble Baroness. We have applied the GDPR principles to areas such as defence, national security and the intelligence services in different parts of the Bill so that when we seek an adequacy arrangement, we can say to the EU that we have arranged a comprehensive data protection regime that takes all the GDPR principles into account, including areas that are not subject to EU law. That is why, contrary to what we said in Committee, we have taken the arguments on board and tabled government Amendment 1 to provide reassurance on that exact point. We originally said that the rights under article 8 were contained in the Bill, but we are now putting further reassurance in the Bill. Other areas of the Bill, without direct effect, signpost how the Bill should be regarded.

The noble Baroness supports the amendment but would like, I think, to create a free-standing right. I have explained why we do not agree with that. Before Third Reading, we will try to seek a form of words in our amendment that provides more reassurance, so that when it comes to seeking an adequacy decision—we cannot do that until we leave the EU—there will be no doubt about what this regime provides. That would be the best way to do it, I think.

Data Protection Bill [HL]

Baroness Ludford Excerpts
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, I am also pleased, as co-signatory, to support the amendment, the purpose of which is to retain in domestic law wording from the European Charter of Fundamental Rights concerning data protection. This is for the benefit of British citizens and to help ensure that vital data flows for business and law enforcement can continue if we Brexit.

The specific article in the EU charter, Article 8 on data protection, is stronger in this respect than the older non-EU European Convention on Human Rights, which deals with privacy only under the rubric of protection of family and personal life. The Government plan that the charter should cease to be part of UK domestic law after Brexit in Clause 5(4) of the European Union (Withdrawal) Bill. This broader issue will be considered as part of the scrutiny of that Bill, and there is a cross-party amendment tabled in the House of Commons and led by Dominic Grieve MP to remove that clause such that the charter continues to apply domestically in the interpretation of retained EU law. Liberal Democrats strongly support that amendment, but it seems appropriate not to wait for or depend on the success of that broader effort and at least effectively to embed the thrust of the charter as it concerns data protection in this Bill, which largely concerns EU law.

This is extremely important because if we Brexit, the UK will seek from the European Commission an adequacy decision on UK data protection so that transfers between the UK and the EU can continue smoothly—an objective the Prime Minister has singled out for mention. If we leave, EU states may no longer be able to share data with us unless our legal regime on matters including state surveillance powers aligns with EU requirements. The adequacy assessment will be wide-ranging, taking in all aspects of law and practice in the UK. The embedding of the charter’s data protection right in this Bill would be an important safeguard for business continuity—especially for tech companies, which depend crucially on the free flow of data—as well as ensuring that essential cross-border police and intelligence co-operation is not disrupted.

I, my noble friends Lord McNally and Lord Paddick, and other noble Lords raised at Second Reading the need for measures to protect us from threats, not to undermine our civil liberties. We are used to the European Court of Human Rights ruling on privacy issues, several times finding the UK in breach of the convention, but more recently in the digital age it is the European Court of Justice—the EU court—that has come into play as EU law on protection of electronic communications and the provisions of the Charter of Fundamental Rights has begun to bite. The Snowden revelations brought heightened sensitivity about the extent of the legitimacy of the activities of our intelligence services.

The EU data retention directive—the EU law on mandatory mass data retention—was pushed through Brussels in 2005 when the UK had the presidency of the EU by the then UK Home Secretary in an expert piece of lobbying after the London bombings of that year. In a landmark 2014 judgment, the court struck it down as incompatible with the right to respect for private life and data protection under Articles 7 and 8 of the charter. Then, as mentioned by the noble Lord, Lord Stevenson, the judgment on DRIPA last December—technically, the Tele2/Watson case, although initially also involving the then Back-Bench David Davis MP—continued in the same vein, declaring that mass data retention was “disproportionate” to citizens’ rights to privacy. Its implications for the Investigatory Powers Act and the question of whether bulk collection of communications data could be permitted to infringe privacy on the grounds of pursuit of serious crime or threats to national security may be ascertained by the reference to the European court made by the Investigatory Powers Tribunal in September. Certainly, the wide range of powers in the Investigatory Powers Act might look vulnerable to being found in conflict with EU law. The Independent Reviewer of Terrorism Legislation, Max Hill, suggested that it was unclear whether the ruling in the Watson case on safeguards for data retention regimes could be interpreted as applicable to national security.

It is true that while in the EU the national security exemption from EU competence applies but, as was brought out at Second Reading, if we were outside the EU the arrangements for our intelligence agencies would go into the whole mix that is assessed for compliance with EU standards. The court’s decision in July, rejecting the legality of the EU agreement with Canada on the transfer of passenger name record details, provides a salutary lesson in how the court approaches third-country transfers. It struck down the agreement because several of its provisions were incompatible with EU fundamental rights. It is therefore crucial that we embed the wording of Article 8 of the charter.

The Labour Opposition have tabled an amended version of Amendment 4, namely Amendment 4A. This is an interesting variation and I look forward to learning a bit more as we progress about exactly how the new wording would work. As I understand it, the safeguards in subsection (1) of the proposed new clause and the first part of subsection (2), which are replicated from Amendment 4, would and should still govern the,

“provisions, exceptions and derogations of this Act”,

otherwise, the point of writing in safeguards is undermined.

I wonder about the reference to,

“purposes as set out in the GDPR”,

since the GDPR is concerned only with the processes for data manipulated in accordance with purposes set down in other instruments. I am slightly unclear about that.

I believe that there has been concern about a conflict with press freedom. Of course we are suffering here from the fact that we have only a partial bite from the charter, which contains a firm provision on freedom of expression and information as well as on the right to security. When we succeed in retaining the whole charter in domestic law via the EU withdrawal Bill, the whole balancing exercise will become more apparent than with this snapshot. In the meantime, we have to proceed with entrenching this partial aspect of the charter as concerns data protection.

Lord Pannick Portrait Lord Pannick (CB)
- Hansard - - - Excerpts

My Lords, the problem with Amendment 4 is that it would not incorporate the charter provision relating to personal data. The reason for that is that it addresses the prima facie right to the protection of personal data, but not the limitations and exceptions recognised by the European charter itself. Article 8, like all the other rights in the European charter, is subject to the limitations stated in Article 52. That says that there can be limitations on protected rights if they are provided for by law, are necessary and meet,

“objectives of general interest recognised by the Union or the need to protect the rights and freedoms of others”.

It is because there has to be a balance between this prima facie right and exceptions and limitations that the Bill contains a very large number of exemptions which cover a whole range of circumstances in which the rights of the data subject have to give way to other considerations, such as national security, the detection of crime, taxation, judicial appointments or confidential references for employment. There are many such exemptions.

The Bill contains exemptions because there are other interests in this area, and other rights, which conflict with the right to protection of personal data, and a fair balance is required. The Committee will want to debate the scope of those exceptions and limitations and be satisfied that the balance has been struck correctly. But Amendment 4 suggests that there is some absolute right to the protection of personal data. That is simply wrong. That is why, I imagine, the noble Lord, Lord Stevenson, has tabled manuscript Amendment 4A, which attempts to address the defect in Amendment 4.

I would have wished for more time to consider Amendment 4A, which I understand was tabled only this morning, particularly if the noble Lord, Lord Stevenson, intends to divide the Committee today. I am concerned that Amendment 4A poses two difficulties of its own. First, the value of including Amendment 4A is not clear to me. The Bill already sets out in considerable detail the domestic implementation of the charter obligation; that is, Article 8 read with Article 52. I fear that including Amendment 4A in the Bill would be likely to cause legal confusion and uncertainty in an area where precision and clarity are essential—and, indeed, are provided by the substance of the detailed provisions in the Bill.

Secondly, I fear that the purpose of Amendment 4A is to confer some special, elevated legal status on Article 8 rights concerning personal data for the future, as subsection (4) suggests. I think that would be very unwise because, as I have said, Article 8 rights often conflict with other rights—whether it is freedom of expression, which we heard about, or the right to property—or other interests. The detailed provisions of the Bill illustrate the difficult choices that have to be made in this area.

Amendment 4A seeks to give a special legal status to one charter right in isolation and that is simply inappropriate. For those reasons, I hope that the noble Lord, Lord Stevenson, will not divide the Committee on Amendment 4A. If he does, I will vote against it.

Data Protection Bill [HL]

Baroness Ludford Excerpts
2nd reading (Hansard): House of Lords
Tuesday 10th October 2017

(8 years, 11 months ago)

Lords Chamber
Read Full debate Data Protection Act 2018 View all Data Protection Act 2018 Debates Read Hansard Text Read Debate Ministerial Extracts
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, I welcome the modernisation of data protection law that the Bill represents and the intention to comply with EU law in the regulation and directive—which of course we must do while we are still in the EU. I am particularly concerned with the future and the prospects for an adequacy decision from the Commission if we find ourselves outside both the EU and the EEA. A failure to get such a decision would be extremely harmful for both businesses and other organisations and for law enforcement.

I will look briefly at the past. In 2013 in the European Parliament I was one of the lead MEPs establishing the Parliament’s position on the regulation. I believe that we did a decent job—that was before the negotiations with the Council, which watered it down somewhat. The Government rightly acknowledge that the new system will build accountability with less bureaucracy, alleviating administrative and financial burdens while holding data controllers more accountable for data being processed—backed up by the possibility of remedies for abuse including notable fines. But the purpose is to provide incentives to build in privacy from the beginning through such instruments as data protection impact assessments and having a data protection officer, through data protection by design and default—thereby avoiding getting to the point of redress being necessary. As an aside, the routine registration with the Information Commissioner’s Office will be abolished, and I am not aware of how the ICO will be funded in future, because that was a revenue stream.

I will say briefly that the new rights that are in the regulation include tougher rules on consent, so we should see the end of default opt-ins or pre-selected tick boxes. That will probably be one of the most visible things for consumers; I hope that it does not become like the cookies directive, which has become a bit of a joke. The need for explicit consent for processing sensitive data is important, as is the tightening of conditions for invoking legitimate interests.

There are several matters which will give improved control over one’s own data, which is very important. There is also the right to be told if your data has been hacked or lost—so-called data breach notification—and a strengthened ability to take legal action to enforce rights. All these are considerable improvements. However, I am rather concerned about the clarity of this very substantial Bill. It is explained that the format is chosen to provide continuity with the Data Protection Act 1998, but whether or not as a result of this innocent, no doubt valuable, choice, it seems to me that some confusion is thereby created.

First, there is the fact that the GDPR is the elephant in the room—unseen and yet the main show in town. You could call it Macavity the cat. The noble Lord, Lord Stevenson, dubbed the Bill Hamlet without the Prince. Traces exist without the GDPR being visible. Is the consequent cross-referencing to an absent document the best that can be done? I realise that there are constraints while we are in the EU, but it detracts from the aims of simplicity and coherence. Apparently, things are predicted to be simpler post Brexit, at least in this regard, when the GDPR will be incorporated into domestic law under the withdrawal Bill in a “single domestic legal basis”, according to the Explanatory Memorandum. Does that mean that this Bill—by then it will be an Act—will be amended to incorporate the regulation? It seems odd to have more clarity post Brexit than pre-Brexit. It would no doubt be totally unfair to suggest any smoke-and-mirrors exercise to confuse the fact of the centrality of EU law now and in the future.

Secondly, we seem to have some verbal gymnastics regarding what “apply” means. The departmental briefing says that the Bill will apply GDPR standards, but then we have the so-called “applied GDPR” scheme, which is an extension of the regulation in part 2, chapter III. Can the Minister elaborate on precisely what activities part 2, chapter III covers? The Bill says that manual unstructured files come within that category. I do not know how “structured” and “unstructured” are defined, but what other data processing activities or sectors are outside the scope of EU law and the regulation, and are they significant enough to justify putting them in a different part?

Looking forward, I want to mention some of what I see as the possible weaknesses in the Bill which might undermine the potential for an adequacy decision for data transfers to the EU and the EEA. The future partnership paper published in August, which has already been mentioned by the noble Lord, Lord Jay, referred to a UK-EU model which could build on the existing adequacy model. Can the Minister explain what that really means? As the noble Lord, Lord Jay, said, while national security is outside EU law, when it comes to assessing the adequacy of our level of data protection as a third country, we could find ourselves held to a higher standard because the factors to be taken into account include the rule of law and respect for human rights, fundamental freedoms and relevant legislation, including concerning public security, defence, national security, criminal law and rules for the onward transfer of personal data to another third country. Therefore, our data retention and surveillance regime, such as the bulk collection of data under the Investigatory Powers Act, will be exposed to full, not partial, assessment by EU authorities. This will include data transfers, for instance to the United States, which I would expect to be very much under the spotlight, and could potentially lead to the same furore as other transatlantic transfers. I lived through a lot of that. I remember that in 2013 there was a lot of flak about the actions of the UK, but nothing could be done about it because we are inside the EU. However, in the future it could.

There are also a number of aspects in the Bill in which the bespoke standards applied to intelligence agencies are less protective than for general processing, such as data breach reporting and redress for infringement of rights. We will need to give serious thought to the wisdom of these, looking to the future. This will not just be a snapshot on Brexit day or even on future relationship day, because at issue will be how our standards are kept up to scratch with EU ones. The fact that with another part of their brain the Government intend to decline to incorporate the European Charter of Fundamental Rights into UK domestic law, with its Article 8 on data protection, will not help the part of the governmental brain which looks forward to the free flow of data exchange with the EU. Our Government seem to be somewhat at cross purposes on what their future intentions are.

I will highlight, rather at random, some other examples which need reflection. We may need seriously to look at the lack of definition of “substantial public interest” as a basis for processing sensitive data, or even of public interest. I think the noble Lord, Lord Stevenson, mentioned the failure or the non-taking-up of the option under Article 80(2) of the regulation to confer on non-profit organisations the right to take action pursuing infringements with the regulator or court. This omission is rather surprising given that a similar right exists for NGOs, for instance, for breach of other consumer rights, including financial rights. Perhaps the Minister could explain that omission.

There is also concern that the safeguards for profiling and other forms of automated decision-making in the Bill are not strong enough to reflect the provisions of Article 22 of the GDPR. There is no mention of “similar effects” to a legal decision, which is the wording in the regulation, or of remedies such as the right of complaint or judicial redress.

Very significant is the power for the Government under Clause 15 to confer exemptions from the GDPR by regulation rather than put them in primary legislation. That will need to be examined very carefully, not only for domestic reasons but also because it could undermine significantly an adequacy assessment in the future.

I will make one or two points in the health and research area. The Conservative manifesto commitment to,

“put the National Data Guardian for Health and Social Care on a statutory footing”,

is not fulfilled in the Bill; perhaps the Minister could explain why not. I would also expect clarification as the Bill proceeds on whether Clauses 162 and 172 sufficiently protect patients’ rights in the use or abuse of medical records. We know this is a sensitive issue given the history in this area, particularly of care data and other attempts to inform patients.

As a final point, I am glad that the research community was broadly positive about the compromises reached in the GDPR, although they were less explicit than the Parliament’s position. That leads to some uncertainty. I took note of what the noble Baroness, Lady Neville-Jones, said. Therefore, close examination will be merited of whether the Bill provides a good legal framework with sufficient legal basis for research, which many of us have all sorts of interests in promoting, balanced with a respect for individual rights. I very much hope this will be explored carefully at future stages.