Mervinskiy 446

Page 21

○ ○ ○

How you envisage clarifying the distinction between further processing and new processing What risks and benefits you envisage What limitations or safeguards should be considered

1.4 Legitimate Interests 55.

The UK has been a strong proponent of alternative lawful grounds to consent, recognising that there are a number of common scenarios where it may be appropriate to process personal data without seeking consent. This could be the case, for example, where it would be very difficult or inappropriate to seek the individual’s consent, or where a low risk processing activity is being undertaken without consent, but in line with an individual's expectations.

56.

The UK GDPR requires that all personal data processing is lawful. Therefore, data controllers must identify a lawful ground under the UK GDPR before processing personal data. These lawful grounds are set out in Article 6, which is one of the cornerstones of the UK’s data protection legislation. Indeed, most data protection regimes set conditions for the legality of personal data processing. In particular, processing is permitted where: a. It is based on the consent of the individual b. It is necessary for the performance of a contract c. It is necessary to comply with a legal requirement d. It is necessary for the vital interests of an individual e. It is necessary for the performance of a task carried out in the public interest task or the exercise of official authority (usually by a public authority) f.

It is necessary for the legitimate interest of a data controller where those interests are not outweighed by the data protection rights of individuals

57.

Regulatory guidance in the UK is clear that no one lawful ground should be seen as always better, safer or more important than the others, and there is no hierarchy in the order of the list in the UK GDPR. 11 From engagement with stakeholders, however, the government has found that 53% of those who thought that the UK GDPR is unclear stated that they spent a disproportionate amount of time working out the requirements of the UK GDPR and the Data Protection Act 2018. 12 Further, when asked which elements of UK GDPR could be clearer, 42% identified the lawful grounds that allow data processing. 13 The government considers that this uncertainty may have resulted in an over-reliance on consent. This may lower protections for individuals, who suffer from ‘consent-fatigue’ in the face of a large volume of consent requests which they might accept despite not having the time or resources to assess them properly.

58.

The government has heard that one factor driving over-reliance on consent is uncertainty about when it is possible to rely on the lawful ground of legitimate interests under Article 6(1)(f) of the UK GDPR. The government is also aware that some data controllers in the business sector appear to have found using legitimate interests for lawful processing to be more complicated and

11

ICO guidance: Lawful basis for processing Ibid 13 DCMS, ‘UK Business Data Survey 2020 Summary Report’, May 2021 12

21


Turn static files into dynamic content formats.

Create a flipbook

Articles inside

Privacy notice

4min
pages 144-146

5.9 Further Questions

1min
page 142

5.8 Biometrics Commissioner and Surveillance Camera Commissioner

1min
page 141

5.7 Enforcement Powers

14min
pages 134-140

5.6 Complaints

5min
pages 131-133

5.5 Codes of Practice and Guidance

4min
pages 129-130

5.4 Accountability and Transparency

5min
pages 126-128

5.3 Governance Model and Leadership

6min
pages 123-125

5.2 Strategy, Objectives and Duties

17min
pages 115-122

4.4 Building Trust and Transparency

7min
pages 107-110

3.6 Further Questions

0
page 102

3.5 Derogations

3min
pages 100-101

3.4 Certification Schemes

3min
pages 98-99

4.5 Public Safety and National Security

2min
page 111

3.3 Alternative Transfer Mechanisms

11min
pages 92-97

4.6 Further Questions

1min
page 112

3.2 Adequacy

11min
pages 87-91

2.4 Privacy and electronic communications

22min
pages 72-81

2.5 Use of personal data for the purposes of democratic engagement

6min
pages 82-84

2.3 Subject Access Requests

8min
pages 69-71

1.7 Innovative Data Sharing Solutions

10min
pages 47-51

1.8 Further Questions

0
page 52

2.6 Further Questions

1min
page 85

Ministerial foreword

1min
page 2

1.5 AI and Machine Learning

45min
pages 24-43

1.6 Data Minimisation and Anonymisation

7min
pages 44-46

1.2 Research Purposes

12min
pages 12-17

1.3 Further Processing

5min
pages 18-20

Overview of Consultation

3min
pages 9-10

1.4 Legitimate Interests

6min
pages 21-23

International Context

3min
page 8
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.