Question to the Department for Science, Innovation & Technology:
To ask the Secretary of State for Science, Innovation and Technology, whether the Government has assessed the compliance of its contracts with Oracle Corporation with UK GDPR in light of the US CLOUD Act; and whether the Information Commissioner’s Office has been consulted on this matter.
Public sector digital services are expected to be secure, resilient and effective. This is supported by a framework of safeguards, including data protection legislation, UK security standards, the Cloud First policy, commercial rules and the Data and AI Ethics Framework.
Under UK data protection law, data controllers (including Government Departments) must ensure personal data is protected, including internationally. Where cloud providers may be subject to overseas obligations, such as the US CLOUD Act, Departments as controllers are responsible for assessing and, if necessary, mitigating the risks.
The UK has an adequacy decision for certain US transfers under the UK Extension to the EU-US Data Privacy Framework, which assessed US access laws, including the CLOUD Act. Where adequacy is not relied upon, organisations must use Article 46 safeguards, such as standard contractual clauses.
Given the ICO's role as the UK’s independent regulator, the Government has not had individual engagement on this matter specifically but note that Departments (as data controllers) ensure compliance and engage with it as appropriate.