{"id":3991,"date":"2021-03-17T15:46:13","date_gmt":"2021-03-17T12:46:13","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=3991"},"modified":"2021-03-17T15:46:13","modified_gmt":"2021-03-17T12:46:13","slug":"dpa-compliance-in-the-uk-during-covid-19","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/dpa-compliance-in-the-uk-during-covid-19\/","title":{"rendered":"DPA Compliance in the UK during COVID-19"},"content":{"rendered":"<p>Data protection in the United Kingdom currently falls under the incidence of the\u00a0<a href=\"https:\/\/www.endpointprotector.com\/blog\/the-uks-bid-for-gdpr-compliance\/\" target=\"_blank\" rel=\"noopener\">Data Protection Act 2018<\/a>\u00a0(DPA). The DPA was adopted into the UK\u2019s national legislation while the country was still part of the European Union. It was originally drafted as a supplement to the EU\u2019s\u00a0<a href=\"https:\/\/www.endpointprotector.com\/epp\/gdpr-the-most-in-depth-guide-to-stay-compliant\" target=\"_blank\" rel=\"noopener\">General Data Protection Regulation<\/a>\u00a0(GDPR) that the UK had an obligation to comply with at the time.<\/p>\n<p>Under the\u00a0<a href=\"http:\/\/www.legislation.gov.uk\/ukpga\/2018\/16\/contents\/enacted\" target=\"_blank\" rel=\"noopener\">European Union (Withdrawal) Act 2018<\/a>, the text of the GDPR was added to the DPA as a single regime for general processing activities and integrated into UK domestic law to remedy any potential deficiencies arising from the UK\u2019s departure from the EU.<\/p>\n<p>The <a href=\"https:\/\/ico.org.uk\/\" target=\"_blank\" rel=\"noopener\">Information Commissioner\u2019s Office<\/a> (ICO) is the UK&#8217;s independent body tasked with upholding information rights and enforcing DPA compliance. The ICO has been one of the most active Data Protection Authorities in Europe, issuing some of the biggest GDPR fines to date, involving a number of major organizations. In October 2020, the ICO fined British Airways a record-breaking \u00a320 million after it ruled the airline had failed to protect their customers\u2019 personal data. Hotel chain Marriott was fined \u00a318.4 million for the same reasons.<\/p>\n<p>As the COVID-19 pandemic swept the world, the ICO temporarily paused some of its investigations as it refocused its attention and resources on how to best address the new challenges faced by the general public and their sensitive data. It created a <a href=\"https:\/\/ico.org.uk\/global\/data-protection-and-coronavirus-information-hub\/\" target=\"_blank\" rel=\"noopener\">Data Protection and Coronavirus Information Hub<\/a> and issued a series of guidance for <a href=\"https:\/\/ico.org.uk\/global\/data-protection-and-coronavirus-information-hub\/coronavirus-recovery-data-protection-advice-for-organisations\/\" target=\"_blank\" rel=\"noopener\">organizations<\/a> about <a href=\"https:\/\/ico.org.uk\/for-organisations\/working-from-home\/\" target=\"_blank\" rel=\"noopener\">remote work<\/a> and its <a href=\"https:\/\/ico.org.uk\/media\/2617613\/ico-regulatory-approach-during-coronavirus.pdf\" target=\"_blank\" rel=\"noopener\">updated regulatory approach<\/a> in response to the pandemic. Let\u2019s take a closer of look at what these mean for businesses and their compliance efforts.<\/p>\n<h2>Greater leniency<\/h2>\n<p>The good news is that the ICO has emphasized that it will be adopting a more lenient approach to enforcement, taking into account the context organizations are currently operating in and the potential burdens they might face in navigating the present situation. This means that, in accordance with their Regulatory Action Policy, before issuing fines, the ICO will consider economic impact and affordability which will likely lead to lowered fines.<\/p>\n<p>However, that does not give companies a license for noncompliance. The ICO warned that any organizations looking to exploit the public health emergency for their own benefit will be met with firm action on their side.<\/p>\n<p>When deciding whether to take formal regulatory action, the ICO will also take into consideration whether noncompliance resulted due to the COVID-19 pandemic. When a data breach occurs, organizations will be given more time to put things right if the pandemic has impacted the organization\u2019s ability to take steps to rectify the situation and the delay will not cause further risks to the public.<\/p>\n<h2>Data breach notifications are still mandatory<\/h2>\n<p>The COVID-19 pandemic does not absolve companies from reporting data breaches when they occur. In fact, organizations are still required to notify the ICO within 72 hours after they become aware of a breach.<\/p>\n<h2>Devices used while working from home<\/h2>\n<p>The ICO dedicated <a href=\"https:\/\/ico.org.uk\/for-organisations\/working-from-home\/bring-your-own-device-what-should-we-consider\/\" target=\"_blank\" rel=\"noopener\">an entire section<\/a> of its recommendations for organizations to the different approaches companies can adopt when it comes to the devices employees use while working from home. These include using a company-issued device which is deemed the most secure option, personal devices that use company software for work, and using personal devices directly.<\/p>\n<p>The ICO urges organizations to consider the security risks for each option and put mitigation methods in place to avoid data breaches. These include issuing security guidance to employees that should include advice such as keeping software up to date and choosing strong passwords. Employees should also be able to report data breaches internally when they affect devices used for work.<\/p>\n<p>When it comes to company-owned devices, the ICO recommends ensuring that devices can be supported and updated remotely and putting in place mechanisms that prevent data from being transferred outside from a device such as <a href=\"http:\/\/endpointprotector.com\" target=\"_blank\" rel=\"noopener\">Data Loss Prevention<\/a> (DLP) solutions. DLP tools can also help organizations prevent personal data from being copied onto insecure personal storage devices such as USB sticks.<\/p>\n<h2>In conclusion<\/h2>\n<p>While the ICO has taken into account the struggles organizations face under these extraordinary circumstances, they also acknowledge the potential security risks involved in large-scale remote work and have issued guidance accordingly.<\/p>\n<p>While companies can rest assured that, if the pandemic has limited their capacity to comply with DPA requirements, the ICO will be understanding, willful negligence is unlikely to be tolerated or to reduce penalties.\u00a0 Organizations must therefore continue their compliance efforts to the best of their abilities despite the pressures of a global pandemic.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Data protection in the United Kingdom currently falls under the incidence of the\u00a0Data Protection Act 2018\u00a0(DPA). The DPA was adopted into the UK\u2019s national legislation while the country was still part of the European Union. It was originally drafted as a supplement to the EU\u2019s\u00a0General Data Protection Regulation\u00a0(GDPR) that the UK had an obligation to &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/dpa-compliance-in-the-uk-during-covid-19\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;DPA Compliance in the UK during COVID-19&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":3994,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[115,1],"tags":[],"class_list":["post-3991","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","category-data-loss-prevention","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/3991","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=3991"}],"version-history":[{"count":3,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/3991\/revisions"}],"predecessor-version":[{"id":3996,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/3991\/revisions\/3996"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/3994"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=3991"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=3991"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=3991"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}