Data protection: preparing for Brexit
Although there is uncertainty about what arrangements will apply when the UK leaves the EU, there are a number of practical steps that can be taken now to prepare from a data protection perspective and to ensure that any data flows to and from the EU can continue post Brexit.
09 October 2019
Although there is uncertainty about what arrangements will apply when the UK leaves the EU, there are a number of practical steps that can be taken now to prepare from a data protection perspective and to ensure that any data flows to and from the EU can continue post Brexit.
- Understand your data flows.
As part of preparing for the General Data Protection Regulation 2016/679 coming into force in May 2018, your organisation will have carried out a data mapping exercise. If this is up-to-date then you will be able to use this to assess to what extent your organisation will be impacted by Brexit. Where this is not up-to-date then this is a good opportunity to review it and update it.
The key is to identify any data flows to and, more importantly, from countries in the EU. Even if you do not think information is being transferred you will need to carefully consider your data processing arrangements and any sub-processing arrangements.
After Brexit, countries in the EU who are transferring personal data to the UK will need to comply with the international transfer provisions in the GDPR, until an adequacy decision is made by the European Commission in respect of the UK. In most cases this will be by using the Standard Contractual clauses.
- Consider whether the territorial scope provisions in Article 3 of the GDPR mean that your organisation will need to appoint an EU representative and , if so, take steps to identify and appoint an appropriate representative.
- Understand what policies, procedures and other documents may need revising following Brexit.
Regardless of the type of Brexit, the Data Protection Act 2018 will remain in force as this is domestic legislation. In terms of the GDPR, the Government has passed regulations that mean the GDPR will be incorporated directly into UK law (becoming the “UK GDPR”) and operating alongside the DPA 2018. If we Brexit with a ‘deal’ then there is likely to be a transition period where the GDPR will apply before we move to fully domestic arrangements. This may potentially allow for more detailed arrangements to be agreed to govern the transfer of data from the EU to the UK. - Maintain a watching brief to ensure that you are aware of important developments and any new guidance that is published.
- Finally, the Information Commissioner’s Office has published guidance to assist organisations with preparing for Brexit, including recent guidance aimed and small and medium organisations. Being familiar with this guidance and following it where appropriate will help your organisation to prepare and ensure you can meet your accountability obligations under the GDPR.
In any event, priority should be given to updating privacy notices and other data subject facing documents so that they can continue to understand how to exercise their data subject rights and to ensure you can continue to demonstrate compliance with your transparency obligations.
Contact
Mark Hickson
Head of Business Development
onlineteaminbox@brownejacobson.com
+44 (0)370 270 6000
Contact Mark
Related expertise
You may be interested in...
Podcast
#DigitalFrontiers podcast: AI, law and technology insights
Opinion - Life sciences connect
Femtech founder roundtable: Funding the future of women’s health
Blog
Mobility-as-a-Service opportunity: New mobility business models
Press Release
Browne Jacobson supports Cambridge Heartwear in launching wearable tech for rapid heart disease diagnosis
Legal Update - Health Bill
Briefing note: Key changes introduced by the Health Bill to the National Health Service Act 2006
Legal Update
Algorithms in the hiring room: ICO spotlight is on automated recruitment
Guide
Staff records management and retention: Practical steps for schools
Legal Update - Life sciences connect
EMA and FDA guiding principles for AI in drug development: A review
Legal Update - Schools white paper
Schools white paper on AI and data: Insights for school leaders
Legal Update
Trust and cybersecurity in retail
Legal Update
AI and emerging legal challenges in construction
Guide
Strategic approaches to managing subject access requests: A guide for public sector organisations
Published Article
Blueprint for AI success in local government
Legal Update
AI, data and security: Key insights for in-house lawyers and business leaders
Legal Update
Cookie compliance crackdown: SHEIN fined €150 million by CNIL
Legal Update - IP insights
IP insights: September 2025
On-Demand
Data (Use and Access) Act 2025: What schools and academy trusts need to know
Published Article - Shared Insights
Reimagining the NHS: The 10-Year Health Plan and legal issues
Legal Update
Otter chaos: Legal considerations when using AI notetakers
Legal Update
Individual pricing, or there and back again: What UK businesses can learn from Delta’s AI pricing U-turn
Legal Update - IP insights
IP insights: July 2025
Legal Update
“Silent AI”: The risk of unintended consequences
Legal Update
Privacy implications of facial recognition technology (FRT) in retail security
Legal Update
New DfE AI guidance: A welcome start, but needs further development
On-Demand
Managing data risks effectively in M&A strategies and corporate transactions
Guide
Using AI for recruitment: The data issues
Legal Update
AI-driven legal access to information: DSARs, FOI requests, and the emerging landscape
Published Article
Anonymity injunctions for clinicians
Guide - Autonomous vehicles
Autonomous vehicles in the UK: Where are we now?
Legal Update - IP insights
IP insights: May 2025
Legal Update
Lessons from the 2025 cyber security breaches survey for higher education
Legal Update
AI in care: Navigating risk
Legal Update
Hyper-personalisation: Key considerations for organisations implementing AI solutions
Legal Update
US tariffs: Market chaos and implications for the UK tech sector
Legal Update - IP insights
IP insights: April 2025
Legal Update
Information Commissioner announces new AI guidance and package of measures to support the Government’s growth agenda
Published Article
Cloud Computing guide 2024
Legal Update - DMCC Act
Consumer Law enforcement: Hot topics harmful online choice architecture and dark patterns
Legal Update
Why digital marketers need to comply with cookie regulations to avoid their campaigns being disrupted
Legal Update