UK Cyber Privacy Regulations I Brit Insurance

We’ve compiled this information on privacy and cybersecurity legislation in the UK.

It’s designed as a high-level overview with links to sources for further research. Please read our disclaimer at the bottom of this page.

Organisations in the UK that process personal data must comply with Data Protection Act 2018 and UK GDPR or risk fines of up to £17.5 million or 4% of annual global turnover – whichever is greater. 

Data Protection Act 2018

The UK Data Protection Act (DPA) 2018 is a law that establishes how personal data should be collected, handled, and stored to protect people's privacy. Everyone responsible for using personal data has to follow strict rules called ‘data protection principles’.

The Data Protection Act 2018 is the UK’s implementation of the General Data Protection Regulation (GDPR).

Data Protection Act 2018

UK GDPR

The General Data Protection Regulation (GDPR) came into force on 25 May 2018 through the Data Protection Act 2018.

It’s about protecting citizens’ personal data when it’s being processed or moved.  

UK GDPR requires that personal data must be processed securely using appropriate technical and organisational measures. The regulation does not mandate a specific set of cybersecurity measures, but rather expects ‘appropriate’ action. What is appropriate for each organisation will depend upon their circumstances, as well as the data processed and therefore the risks posed.

UK GDPR places a direct responsibility on companies to prove they comply with the principles of the regulation. This means firms must commit to mandatory activities such as staff training, internal data audits and keeping detailed documentation. Breaches must be reported to the relevant authorities within 72 hours of the incident.

UK GDPR

Networks and Information Systems (NIS) Directive 2018

The NIS Directive aims to raise levels of the overall security and resilience of network and information systems across the EU. It applies to companies and organisations identified as:

·       Operators of Essential Services (OES).

·       Outsourced IT and managed service providers (MSPs).

·       Essential service providers, such as energy, transport, healthcare and water companies. Also, providers of important digital services, such as cloud computing and online search engines.

The regulatory responsibilities are carried out by Competent Authorities (CAs). The criteria for identifying OES and the list of CAs in the UK are in thNIS Regulations. 

Read more on the NCSC cyber security toolkit for boards.

Networks and Information Systems (NIS) Directive 2018

What about NIS 2?

The UK will not be implementing EU NIS 2, but is planning its own NIS changes. The main changes expected to be seen include:

  • More regulation of managed service and digital service providers - e.g. providers of social networking platforms.
  • Regulation of critical suppliers to operators of essential services in more sectors (e.g. major GP IT providers) by Competent Authorities.
  • Organisations that provide critical services across multiple sectors will be regulated by one Competent Authority, which will be agreed by the government.
  • Lowering the threshold of the type of incidents where regulated organisations must report them to their respective Competent Authority. The specifics of this are to be confirmed, but it is suspected that these will be incidents that may have affected servers, resilience or security in any way.

What about NIS 2?

The Privacy and Electronic Communications Regulations (PECR) 2003

The Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) complements the general data protection regime. It sets out more specific privacy rights on electronic communications. 

It also recognises that widespread public access to digital mobile networks and the internet opens up new possibilities for businesses and users, but also new risks to their privacy. 

A business that sends electronic marketing or uses cookies (or similar technologies) must comply with both PECR and the UK GDPR. This includes, but is not limited to, websites, emails and SMS; and keeping communications services secure; and customer privacy as regards traffic and location data, itemised billing, line identification, and directory listings.

The Privacy and Electronic Communications Regulations (PECR) 2003

Laws/Regulations directly regulating AI

The UK government's AI Regulation White Paper of August 3, 2023 - and its written response of February 6, 2024 - indicated that the UK did not intend to use broad AI regulation that covers all industries (known as horizontal regulation).

Instead, the government supported a "principles-based framework" where regulators in specific industries will interpret how best to use AI, and what to provide rules for.

The White Paper also indicated that there are no existing plans to establish a central AI regulator either.

However, on July 17, 2024, the King’s Speech proposed a set of binding measures on AI, which deviates from the previous agile and non-binding approach. Specifically, the government plans to establish "appropriate legislation to place requirements on those working to develop the most powerful AI models". The Digital Information and Smart Data Bill was also announced, which will be accompanied by reforms to data-related laws, to support the safe development and deployment of new technologies (which may include AI). It is not yet clear exactly how this will be implemented.

Laws/Regulations directly regulating AI

A quick disclaimer about this advice

The information here is not, and doesn’t intend to be, legal advice.

All information, content, and materials are for general information only. The information may not be the most up-to-date, legally or otherwise and may not be exhaustive. This website contains links to other websites – these are for convenience; Brit does not recommend or endorse the contents of the third-party sites.

A quick disclaimer about this advice

Insights

Read the latest insights from our cyber security partners.

Insights

Artboard – 5

Operational Technology (OT): Protecting Critical Systems in a Connected World

19-06-2024 |Cyber
Read more
Woman working on a computer with digital screens in view

Digital Forensics:
Managing a Digital Crime Scene

19-09-2024 |Cyber
Read more
Breach Counsel Teaser

Breach response: leave it to the experts

24-01-2025 |Cyber
Read more
Ai Snippet

Risk Versus Reward: Using AI In Business

22-05-2024 |Cyber
Read more
Cyberpam Header

How cybercriminals exploit MFA reset prompts

25-04-2024 |Cyber
Read more
Ransomware Fullbleed1

Ransomware negotiation: Don’t try this at home

18-03-2024 |Cyber
Read more
Adcybergap Pageimg

Addressing The Cyber Gap With SMEs

29-01-2024 |Cyber
Read more
NIS2 Header

Brit - NIS2: What does it mean for cyber security?

30-11-2023 |Cyber
Read more
DT

The Cyber Security Threat from Digital Twins - Brit

30-11-2023
Read more