Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Lord Markham and Baroness Lloyd of Effra
Lord Markham Portrait Lord Markham (Con)
- Hansard - -

As per the points made by other noble Lords, this is a prime example of when you realise how valuable it is to have in this House and, in particular, in this Committee people who have lived experience. Because of that, this is a well thought out set of proposals; I thank my noble friend Lady Harding for bringing them before us, and I thank my noble friend Lord Holmes and the noble Baroness, Lady Kidron, for supporting them.

These amendments mirror a lot of what I saw from the other side when I was the Health Minister and we had the problems with Synnovis and testing. That is where I am coming from: you realise that you need some real teeth because, even though you have public bodies such as the NHS, which you think would listen to the Minister on certain requirements, that that does not always follow. The point made by my noble friend Lady Harding about everyone telling you to keep quiet applies to state organisations just as much as it does to private companies. Having teeth is an important part of all this and of making things happen.

The staged approach has been mentioned. In your first 72 hours, it is all about wanting just to get the information out there. One of my questions—I will come on to the rest in a minute—is: what are we doing on our side with that information? We must make sure that it is being used valuably and used to alert others. Only later on, around the 30-day mark, do you get into the “lessons learned” stage. So staged reporting would be a very sensible and well thought out approach.

That brings me on to another point; I would be grateful if the Minister could address it. If we are requiring businesses to provide such information to the Government very quickly, what will they get back? The strong justification for rapid incident reporting is surely that the NCSC can aggregate the intelligence, identify common attack vectors and vulnerabilities, and rapidly warn other organisations before they, too, are attacked. Obviously, that is the difference between regulatory reporting and genuine national cyber defence. I would be grateful if the Minister could explain the planning and what will happen operationally when one of these early notifications is received. How quickly will the information be assessed? How quickly will actionable intelligence be disseminated to other potentially vulnerable organisations? What obligations will there be on the Government and the regulators to ensure that the information provided by one organisation improves the resilience of everyone else?

Of course, there is a wider point here. Throughout our consideration of the Bill, we need to guard against measuring success by the number of organisations regulated or the number of reports submitted. Rather, the real test is whether fewer attacks succeed, whether we identify attacks faster, whether organisations can recover more quickly and whether intelligence from one attack prevents the next one. That is the outcomes we want this regime to achieve.

I hope that the Minister will look seriously at the principles behind these amendments, and in particular at whether we can achieve a reporting structure that gives the Government the information they genuinely need quickly while allowing organisations to concentrate their scarce cyber expertise on the thing that matters most: defeating the attack.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments in this group. We have spoken previously about the importance of effectiveness, proportionality and clarity. I absolutely hear the experience of the noble Baroness, Lady Harding, in leading a telecommunications company and the experience it had.

We have learned from experiences across all sectors in introducing the new regime that is in the Bill, which puts in, as others have said, a staged approach that includes an early alert to regulators and the NCSC within 24 hours. That will provide awareness and enable the NCSC and regulator to provide early support, as well as potentially understand whether it is impacting multiple regulated entities.

--- Later in debate ---
Lord Markham Portrait Lord Markham (Con)
- Hansard - -

My Lords, we have heard very compelling cases from all noble Lords who have spoken on this group about why a particular sector should be included. I will not go through the list—it was gone through very well by the noble Lord, Lord Clement-Jones, a moment ago—but I think we can all agree that each one was a compelling case. That probably illustrates the wider problem, because we are almost getting into a game of cyber whack-a-mole here, where we can see them popping up left, right and centre. So our approach, with Amendments 92 and 92A in my name and those of my noble friends Lord Camrose and Lord Holmes, is to try to take a more strategic view, very much reflecting some of the views that the noble Lord, Lord Birt, was mentioning earlier as well. They ask the Government to assess strategically important entities outside the current NIS regime and consider whether they should be brought into scope where a cyber attack would have a sufficiently serious impact on the economy or the day-to-day functioning of society.

We are not asking for another long list of businesses to be regulated, because we need to be careful about the regulatory burdens that we are putting on people. Instead, Amendment 92A proposes a risk-based test and asks these questions: what would actually happen if this organisation went down? Would essential services stop? Would very important supply chains fail? Would significant parts of the economy cease to function? If the answer to those is yes, surely the Government should at least assess whether that organisation belongs within our national cyber security perimeter. This also illustrates why we need to see the national cyber action plan. It was promised this summer; we are now in September and, considering that this is very pertinent to everything we are talking about in Committee, I ask the Minister when we will see the plan.

I will highlight one further issue, which the noble Baroness, Lady Berger, illustrated very well, in the area of the data held in certain organisations, particularly in education. We all know that the reason that a lot of these organisations are attractive targets is not because of the essential services they often carry out but because they carry enormous quantities of valuable and sensitive data. Again, this was very much my experience with the attack on Synnovis when I was Health Minister. It caused massive disruption for operations and diagnostic services in London, but the question was: why was that organisation holding so much information in the first place? It had names and addresses of people going back 20 years, their test results and their full medical records, and it did not need any of it at all. It could all have been anonymised, and it definitely did not need to hold it for 20 years.

To me, the question we really need to answer—this speaks to an amendment we will be talking about later—is: what data do all these public bodies really need to hold? Of course, if the data is not there in the first place to be stolen, or if it is not interesting or valuable, then that is the best line of defence, because there is no reason for there to be a cyber attack on it. As I say, we will talk further on that on Amendment 174E, but the principle is directly relevant to what we are talking about here.

Before I come to the end, I have a special request from my colleague here, who I think knows a thing or two. I am told on good authority that the last government AI regulation White Paper has a lot of relevance and synergies here, so I would request the Minister to look at that between now and Report to see where, as I say, there are synergies and learnings from it.

In summary, first, we should systematically identify the organisations whose compromise would cause the greatest damage, as per our Amendment 92A, and, secondly, we should reduce both their vulnerability and attractiveness as targets, including by reducing the data prize available to the attacker, as per our Amendment 174E, which we will come to later on. That, to me, is genuine cyber resilience: not merely making the safe harder to crack but, wherever possible, ensuring that there is nothing valuable inside the safe to steal.

I hope the Minister will respond both on the important sectors raised by noble Lords and to the central question behind Amendment 92A: what systematic test are the Government applying to determine which strategically important organisations should fall within the NIS regime, and will that regulatory perimeter keep pace as technology and the threats change?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

My Lords, I thank noble Lords for raising so many aspects of the scope of the Bill. I recognise the sentiment among noble Lords today about the importance of expanding its scope. Our approach has been to target regulatory requirements on a select number of essential services, while using non-regulatory but effective measures to improve the cyber security and resilience of the wider economy.

As I set out at Second Reading, I have asked my officials to work across government to consider what additional services would merit being brought into scope of the regime in future. This will allow us to make a holistic and considered approach. To ensure our assessment is appropriately prioritised, I would first like to focus on the CNI sectors not already covered by the NIS regime.

I share the intent behind the objective from the noble Viscount, Lord Camrose—which the noble Lord, Lord Markham, spoke to—that the process to expand the scope of the regime should be rigorous and evidence based. As set out in the Bill, for something to be defined as a new essential activity under its powers, the Secretary of State must be satisfied that the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is reserved for the most vital activities in our nation. To the point raised by the noble Lord, Lord Birt, I believe that that is a clear test. In reaching a decision, the relevant departments would need to carry out a risk assessment and any economic assessments, and consider whether inclusion is proportionate. This is part of normal policy development. After that, proposals would be subject to consultations and the affirmative procedure.

The noble Viscount proposed in his amendment that assessment for inclusion be carried out on an entity-by-entity basis, which obviously differs from the sectoral approach we have taken thus far. Setting out the detail that would need to be published according to the amendment could lead to a release of information about individual companies that could pose commercial or national security risks, due to their criticality. I think that the sectoral approach is better. As others have said today, looking at a systemic approach to the sectors is the right way to look at what is in the statutory approach.

Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Lord Markham and Baroness Lloyd of Effra
Lord Markham Portrait Lord Markham (Con)
- Hansard - -

My Lords, I thank my noble friend for introducing this group; as it is the final group of the day, I will keep my remarks brief.

Amendments 15A and 15B in the names of my noble friend Lord Arbuthnot and the noble Lord, Lord Clement-Jones, seek to allow regulatory oversight of critical suppliers on whom operators of essential services and relevant service providers depend, be it directly or indirectly. We believe that this must be a reasonable approach. The aim of Clause 12 is to ensure the continued functioning of the central suppliers and providers by providing support for their critical suppliers. Surely whether they are supplied directly or indirectly is of little importance.

Amendment 16 from the noble Lord, Lord Ravensdale, would restrict the designation of critical suppliers to those who present systemic risk rather than a simple single-entity risk. We should seek to minimise government oversight wherever possible, and suppliers should not be designated unless they pose a genuine risk. I am also supportive of the noble Lord’s focus on cross-sectoral consistency and general macroeconomic risks, which is too often something that the Government neglect.

However, I am hesitant to endorse the amendment in its entirety. Having to assess every supplier of every OES, RDSP or RMSP and having to decide whether it meets the systemic threshold have the potential to place an unrealistic administrative burden on designated competent authorities. We are already concerned about the resources that they will need to undertake the changes that the Bill introduces; I am unsure whether we need to ask more of them.

To wrap up, I return to a more general point: the risk to the economy or to national security is a scale, and the legislation that we pass should reflect this. Perhaps the noble Lord, Lord Ravensdale, is correct that the designation of critical suppliers based solely on whom they serve is too permissive, but it is equally as likely that restricting designation to systemic risks would be too restrictive. This highlights—it goes back to earlier groups—that the binary distinction about which we are talking now does not cover the gradation of different types of risk. That is why I come back to the original point that my noble friend Lord Camrose made on adopting, perhaps, the Cyber Monitoring Centre’s severity scale, which offers a template for a more nuanced approach to definitions. I hope that the Minister can commit to reviewing the Bill’s definitions ahead of Report.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords, in particular the noble Lords, Lord Arbuthnot and Lord Ravensdale, for engaging with the incredibly important question of drawing the right scope in the Bill for the designation of those in the supply chain. It is incredibly important that we get this right and take into account the economic and security impact. To begin, let me explain our reading of the amendments and the practical impact they would have.

Amendments 15A and 15B would enable regulators to designate suppliers as critical beyond those which directly supply to regulated entities, if they are materially dependent on that supplier to provide the regulated service. This would extend the scope of the measure to include suppliers further down the chain, even where they have no direct relationship with the regulated entity. In addition, the amendments would introduce an additional assessment of whether a regulated entity is materially dependent on a supplier, which would form part of the designation process. This could create a higher bar for designation of a direct supplier than currently exists in the Bill and could limit designation by excluding suppliers whom it would be reasonable and prudent to include.

The Bill recognises the importance of supply chain security, has considered the risks that supply chains pose and has developed targeted and proportionate measures to address those risks. First, regulated entities are subject to an overarching duty to identify and manage the risks posed to the systems they rely on to provide their services. A core part of this is to consider the risks arising from their supply chains. Secondly, as will be set out in the forthcoming security and resilience requirements, we will require regulated entities to take specific steps to manage their supply chains through an analysis of the risks they could pose, and to include a requirement to put in place contractual obligations on those suppliers to manage the immediate risks and the risks posed further down the supply chain, which may not be in the immediate view of the primary regulated entity. Thirdly, it is recognised that some suppliers in the market are critical to certain sectors and therefore the most proportionate step is to regulate them in their own right and to subject their security posture to the scrutiny of regulators.

This clause is already designed to be a proportionate and targeted measure and is aimed at bringing into scope only those suppliers who are genuinely critical to the regulated entities they supply directly. Finally, as we discussed at the beginning of this Committee, some suppliers may present additional risk and are potentially the vector of attack from hostile actors. That is why we believe that we need to take measured but decisive steps to manage that risk before it crystallises and before those vendors are embedded in critical systems. The amendments would significantly increase the number of potential suppliers that regulators may need to consider for designation and could risk imposing additional burdens on smaller suppliers that may be several layers removed from the regulated service.

On Amendment 16 in the name of the noble Lord, Lord Ravensdale, I agree that a supplier should be designated only where they are genuinely critical to the provision of a regulated service. That is why the Bill includes strict designation criteria that must be met before a supplier can be designated. Importantly, an incident affecting the systems relied on by the supplier could disrupt regulated services in a way that significantly impacts the economy or the functioning of society. The Bill maximises the proportionality of the measure so that only the most critical suppliers to regulated entities are designated. It will also limit the number of small and micro enterprises that are likely to be designated.

The noble Lord’s amendment intends to limit that further. Its intention is to focus on suppliers whose activities being disrupted would cause systemic risk to the UK’s digital ecosystem, economy or essential services, and to prohibit designation if a supplier provides goods or services only to a single operator of essential services, a critical national infrastructure entity or a public authority.

We discussed a little earlier in Committee the risk of small but risky suppliers. Amending the designation criteria to focus on systemic risk to a wider number of entities could potentially leave many of the UK’s most essential services vulnerable to disruption. In fact, the compromise of just one of these providers could still have a significant impact on the economy or functioning of society in the UK or any part of it. Under the noble Lord’s amendments, a supplier that is essential to a single energy provider responsible for a county’s power, an NHS hospital looking after a whole city or a single cloud service provider used nationwide may not be judged as posing a systemic risk if it were disrupted. This would leave these essential end services vulnerable to severe disruption if that supply were compromised, with significant impacts for the huge number of citizens relying on them.

The amendment would also require the Government to issue statutory guidance for regulators on designating critical suppliers. I agree that consistency in the decisions taken by regulators will be crucial to the success of this regime. That is why my department will work with regulators to develop guidance to drive this consistency, and regulators will be required to consult with other regulators before designating suppliers where there is a relevant connection to multiple sectors. As we have discussed before, the statement of strategic priorities will also provide common objectives for regulators, which will further increase alignment between their approaches.

I heard very clearly what noble Lords said in introducing their amendments and the important other contributions during this discussion, which highlight how important it is to strike the right balance for this measure. I believe that the Bill establishes a proportionate and targeted framework that captures genuinely critical suppliers without extending regulation or excluding risks within the supply chain.

EU Technological Sovereignty Package

Debate between Lord Markham and Baroness Lloyd of Effra
Monday 20th July 2026

(1 month, 2 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Lord Markham Portrait Lord Markham (Con)
- View Speech - Hansard - -

My Lords, as someone who has experienced a few PM changes myself, I genuinely wish all the Ministers good luck and thank them for the work that they have done—I know how hard it is. Technological sovereignty ultimately depends not on where AI is regulated but on who owns the compute cloud infrastructure and frontier models. What proportion of government AI investment is building genuine UK-owned capability, rather than further increasing our dependence on overseas hyperscale cloud providers?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The Government are taking the approach of reducing overreliance and building up our own capability. We welcome foreign investment, including in our AI growth zones, and the ability of UK companies and citizens to access the best technology available, whether it is in the UK or elsewhere. That is an important part of our being able to benefit from the developments in AI. However, I absolutely agree that AI compute is the engine behind every AI breakthrough. That is why we are investing up to £2 billion in public compute infrastructure to 2030, so that researchers, start-ups, SMEs and public services can have free access to the computing power they need to work at the frontier of AI.

Artificial Intelligence: Global Governance

Debate between Lord Markham and Baroness Lloyd of Effra
Tuesday 23rd June 2026

(2 months, 1 week ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

Developments in AI, with AI as a general technology, are indeed permeating many sectors, including health, as we heard from my noble friend, and other areas, as the noble Lord mentioned. The best approach is to keep collaborating in multilateral forums and with bilateral partners, so that we can share standards and approaches, and be agile and nimble as the technology develops.

Lord Markham Portrait Lord Markham (Con)
- View Speech - Hansard - -

My Lords, recent restrictions by the United States on access by foreign nationals to certain advanced AI models have highlighted the extent to which access to frontier AI technology can be determined by decisions taken overseas. What discussions have the Government had with international partners to ensure that the United Kingdom retains reliable access to strategically important AI capabilities?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The noble Lord highlights the developments in frontier models, which are delivering unprecedented advances at present. We are ensuring that the UK has sovereign capability based on our strengths, so that we can compete in this new, developing technological area in areas where we contribute. For example, that is why we are backing the AI hardware plan, an area of real strength in the UK, and we have set up the sovereign AI fund to back those particular sectors which the UK is particularly strong in.

Digital Safety: Children

Debate between Lord Markham and Baroness Lloyd of Effra
Tuesday 9th June 2026

(2 months, 3 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Lord Markham Portrait Lord Markham (Con)
- View Speech - Hansard - -

My Lords, there is total agreement across the House that children must be protected from harms online. Noble Lords will recall that amendments tabled by my noble friend Lord Nash on the impact of social media on children’s well-being were repeatedly resisted by the Government. We therefore welcome the Government’s recognition that further action is needed.

The Government have said that industry has three months to act and that legislation will follow if companies fail to do so. If Ministers are satisfied that these protections are so necessary, why have they chosen to rely on expectations from tech companies rather than legislating directly now? The proposals also appear to involve age assurance, device-level protections and enforcement obligations. What assessment has been made of the risk that younger users will simply remain on old operating systems, and of the practical challenges of implementing these measures across different manufacturers? The Government have also suggested that some educational platforms may be treated differently. What criteria will be used to determine any such exemptions?

Finally, can the Minister assure the House that, if the industry fails to meet the Government’s expectations within the three-month period, the necessary legislation will be ready to proceed without further delay?

Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Business and Trade and Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
- View Speech - Hansard - - - Excerpts

I agree with the noble Lord that there is unanimity on the importance of tackling child sexual abuse online and taking measures to further restrict that and make it harder. As my noble friend Lord Hanson made clear during the passage of the Act, device-level nudity detection can play an important role in preventing children taking, sharing or viewing nude imagery.

This measure really looks at how to prevent those images getting online. That is a very important part of the strategy; it stops harm before it happens, in addition to the law enforcement activity that must happen in parallel. It applies to both old and new smartphones and tablets, and we expect tech companies to set up controls so that, if a parent hands down a phone, for example, all they have to do is reset it to enact this operating-level facility.

In respect of making sure that legislation is ready, as the Minister for Online Safety said in the other place yesterday, he is working carefully and closely in parallel with the Home Office to draw up legislation should that be needed, should the protections not be put in place at scale as expected.

Sovereign AI Fund

Debate between Lord Markham and Baroness Lloyd of Effra
Monday 1st June 2026

(3 months ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I welcome the noble Lord’s welcome, as it were, for the developments happening here in the UK. It is true that the UK has a lot to offer. On cloud discussions and the provision of data, the National Data Library is advancing and we have gone through our period of discovery, with five areas of kick-starters, so we can provide UK public data to those who can benefit from it. Separately, we are using the sovereign AI fund to develop the domestic technology sector, so that it can provide one of the options for government procurement in the future.

Lord Markham Portrait Lord Markham (Con)
- Hansard - -

My Lords, the Competition and Markets Authority has expressed concerns that AI may entrench the market power of a small number of cloud providers. If the sovereign AI fund is not designed to increase the UK’s strategic authority in the cloud space, what are the Government’s plans to do so?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The noble Lord is right to refer to the independent Competition and Markets Authority. It has conducted a major, 22-month investigation into the cloud market and is now acting. It has announced a package of actions to strengthen competition in business software and cloud services. It will be launching a strategic market status designation investigation into Microsoft’s business software system in May that will allow the CMA to examine cloud licensing and actions from Microsoft and Amazon on improving cloud interoperability and reducing egress fees. In terms of the role the AI sovereign fund might play, it is at a relatively early stage of development. Infrastructure is one of its priority areas, and we will see what opportunities come in the near future.

AI Growth Lab

Debate between Lord Markham and Baroness Lloyd of Effra
Thursday 26th March 2026

(5 months, 1 week ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

In our AI opportunities action plan we have indeed set out a plethora. That is because this is a technology that provides great potential benefits, and adoption is absolutely key. We need all areas of the economy to be thinking about the implications. We are a heavily service-based economy and it is very much in our future interests to adopt this technology and harness its benefits, whether that is in healthcare, energy efficiency or many other areas. So we will continue to focus on all areas of the development of AI, from data centres to regulation.

Lord Markham Portrait Lord Markham (Con)
- View Speech - Hansard - -

My Lords, my experience as Health Minister in this space is that we have fantastic innovation and fantastic pilots: the joke in the NHS is that the NHS has more pilots than British Airways. But the challenge is always the scale-up funding and, because that scale-up funding is not there, we then lose the best to America. The problem is that the AI budgets are all fragmented across hundreds of different hospitals. What are we doing to centralise those budgets so that we have the firepower to truly scale them and not lose our best British innovation to America?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

Building on both noble Lords’ recent questions, we need to look across the whole of the economy. There will be a great amount of private investment going in, as well as investment from our public financial institutions. We are also thinking about how we can harness the benefit of sovereign AI here in the UK, and we are making a particular effort to think about where our sovereign AI fund is going to invest, so that the UK can benefit British frontier AI companies, not seeking total self-reliance but to build and defend comparative advantage.

Children: Age Verification and Virtual Private Networks

Debate between Lord Markham and Baroness Lloyd of Effra
Thursday 4th December 2025

(9 months ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

We have ensured that Ofcom is resourced to implement its online safety duties and have increased the amount available to it year on year; its budget is, I think, £92 million to support all its Online Safety Act responsibilities. We believe that it has the resources it needs to effectively implement and supervise the Online Safety Act.

Lord Markham Portrait Lord Markham (Con)
- View Speech - Hansard - -

Following on from noble Lords’ comments, to me it is quite clear that Ofcom has a lot of the powers necessary to restrict underage usage but seems to lack the will. That was abundantly clear from the Radio 4 interview this morning. My experience in such matters is that the Ofcom leadership really needs to understand the strength of feeling in this House and Parliament as a whole—that they need to be more robust in enforcement. Will the Minister agree to arrange a meeting with the Ofcom CEO and key Lords here today so that we can fully hold Ofcom to account on this?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The noble Lord makes an important point about the strength of feeling here, which was replicated in the discussions yesterday in the Select Committee. I am very happy to take forward his request to set up a meeting with Ofcom.

Data Adequacy Status: EU Data Protection Standards

Debate between Lord Markham and Baroness Lloyd of Effra
Thursday 4th December 2025

(9 months ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The noble Earl asks a very interesting question but one which I am afraid, again, I am unable to give him any deep answer on. I shall have to revert to him on IP in particular.

Lord Markham Portrait Lord Markham (Con)
- View Speech - Hansard - -

My Lords, in view of the high stakes for UK services in digital trade with the 27 December deadline fast approaching, will the Government publish the adequacy risk assessment and correspondence that they have shared with the Commission, redacted where necessary, so that Parliament and stakeholders can see how they have satisfied themselves that the Data (Use and Access) Act is not put at risk?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

My understanding is that there is a lot of to and fro, and many requests between the EU and UK of a very technical nature to allow the European Commission to make its judgment. Quite a lot of those have been published already, in the European Commission report and in the European Data Protection Board’s opinion. The process by which this is set out is already transparent and clear.