Request a callback today »

GDPR After Brexit | Essential Guide for Employers

December 17, 2020 | By: Victoria Owings

gdpr after brexitFollowing the UK’s exit from the European Union, the UK has been undergoing a yearlong transition period during which the UK and EU have attempted to negotiate the rules and arrangements that will apply at the end of this period. We review the potential impact on the GDPR after Brexit and provide a guide for businesses.
Once the transition period ends, the UK will be classed as a ‘third country’, falling outside of the GDPR zone (consisting of EU states, Norway, Iceland, and Liechtenstein). However, as the UK intends to retain the provisions of the GDPR within domestic law, there will be very little change to the rules around data protection. Therefore, if your business has still not achieved GDPR compliance, then we recommend that you continue working towards this.

GDPR After Brexit | Is Your Business GDPR Compliant?

As long as you are already compliant with the GDPR and have no contacts or clients within the European Economic Area, there is very little you will need to do to ensure you remain compliant.
However, if you are a business or organisation that transfers or receives data from the EEA, then you will need to ensure that you are compliant with both UK national law, and the provisions of the GDPR.
The GDPR restricts the transfer of personal data to third countries unless the data is adequately protected, or an exemption applies. The European Commission (EC) is responsible for determining whether a third country has adequate protection in place to allow the free flow of personal data without additional safeguards, however, as yet no adequacy decision has been made in respect of the UK.
The transfer of data from the UK to EEA should not present any problems post-Brexit, as the UK have assumed the EU’s pre-existing adequacy decisions, which allow for personal data to be transferred from the UK to the 30 EU/EEA, counties, and 12 ‘third countries’ – Andorra, Argentina, Canada, the Faroe Islands, Guernsey, Israel, Isle of Man, Japan, New Zealand, Switzerland and Uruguay. Personal data transfers from the UK to these countries will be able to continue uninterrupted.
However, if the EU determines that the UK does not have adequate safeguards in place, then EU and EEA counties will not be able to transfer personal data to the UK without contractual agreements in place between organisations, similar to those currently required between the UK and third countries such as the US.
Therefore, if you are a business that has dealings with customers, suppliers or partners in EU countries, we would recommend that your first priority should be to undertake an audit of the personal data you receive from other countries.

Check Contracts and Agreements

It would also be worthwhile checking that your contracts and commercial agreements can be amended if necessary, to ensure that the transfer of personal data will not be interrupted if the EU determine that the UK’s data protection regime is not adequate. For the majority of business, incorporating Standard Contractual Clauses into commercial contracts will be the simplest way to ensure this – you may find the tools available on the ICO’s website helpful in this regard.
If you are a business or organisation that offers services or good to individuals in the EU, but you do not have any offices, branches, or other forms of establishment, e.g., shops or warehouses, then it may be necessary for you to appoint an EU representative.
Your EU representative will need to be based in the same location as the people whose personal data your process and must have the authority to represent you and act on your behalf regarding GDPR compliance. There is no need for this representative to be an employee – you could instead instruct a law firm or consultancy. However, if you are only processing low risk data, on an occasional basis, then you may not be required to appoint a representative.
Unfortunately, until the EC makes an adequacy decision about the UK, there remains a great deal of uncertainty as to what data transfers will look like post-Brexit. However, we will aim to keep you updated on the decision and provide further guidance once the situation becomes clearer.
If you have any queries about the GDPR after Brexit, or any questions about data protection and generally, please get in touch with our team for more information about the GPDR services we can provide.

About the Author
Victoria Owings
Victoria Owings
Victoria Owings, Author at Wirehouse Employer Services

Prior to joining Wirehouse Employer Services in June 2017 Victoria worked as a consultant for another health and safety consultancy company for over 10 years. Victoria has experience of working in a wide range of different industries including engineering, manufacturing, hospitality, construction, care sector, funeral homes, veterinary practices, dental & doctors surgeries, golf clubs, transport and distribution, pharmaceutical and office environments. She has extensive knowledge with ISO 18001: 45001: Level 5 Achilles Building Confidence. RISQS, SafeContractor, Construction Line, SMAS, CHAS, Exor, Build UK, Altius VA CDM Comply, Eurosafe CDM Competent, Acclaim, Avetta, CQC and FORs.

More from the site

Ensuring Data Protection Compliance When Sending Emails

Ensuring Data Protection Compliance When Sending Emails

Rules for Using CCTV and / or Email Monitoring Evidence for Disciplinary Investigations

Rules for Using CCTV and / or Email Monitoring Evidence for Disciplinary Investigations

Data Protection and the Use of CCTV

Data Protection and the Use of CCTV

Unvaccinated Workers in Care Homes – What Employers Need to Know

Unvaccinated Workers in Care Homes – What Employers Need to Know

Workplace Covid Testing & Data Protection Considerations

Workplace Covid Testing & Data Protection Considerations