UK's data protection regulator is ineffective, says research

Apr 11, 2013
UK's data protection regulator is ineffective, says research

The regulator charged with overseeing data protection in the UK has been and will continue to be ineffective unless the government takes action, according to research by an academic at the University of East Anglia.

In a paper to be presented today, Dr Karen Mc Cullagh traces the development of the , currently the Information Commissioner's Office (ICO), since its inception almost 30 years ago, when a Conservative government enacted legislation establishing an independent regulator tasked with administering data protection law in the UK.

There has been little research evaluating the effectiveness of the regulator since its inception. Dr Mc Cullagh's study aims to address this by examining its development through four distinct phases, in order to assess the adequacy and effectiveness of the regulator to date, and predict its future potential.

Dr Mc Cullagh, from UEA's Law School, looked at: the period 1984-1998, when the Data Protection Registrar was first created and derived its powers from the Data Protection Act 1984; 1998-2010 when the Data Protection Registrar transformed into the (ICO) and gained enhanced powers under the Data Protection Act 1998; 2010 to the present, since the level of financial penalty the regulator could impose for serious breaches of the legislation was increased through the enactment of the Criminal Justice and Immigration Act 2008; and finally, the changes in proposed EU data protection regulation, which are tentatively scheduled to come into force in 2014.

"My analysis of the regulator's investigative and enforcement powers demonstrates that they have been, and continue to be, lamentably weak and ineffective," said Dr Mc Cullagh. "Despite the much-lauded enhanced powers for regulators in the proposed EU data protection regulation, there is a real risk that the ICO will remain an ineffective regulator in the future if the UK government does not take measures to create an adequately funded and properly staffed regulatory office, with appropriate investigative and enforcement powers."

Dr Mc Cullagh's analysis reveals that socio-economic, technical and political factors influenced the legislative process in each of the four eras of data protection. She shows that these factors influenced the independence of the regulator and the powers conferred on it, resulting in structural and operational weaknesses that impede its effectiveness.

"If the proposed EU regulation is implemented in its current form, the ICO will face a budgetary shortfall of £42.8m – an issue the UK government has yet to address, even though it will seriously impede the effectiveness of the regulator," added Dr Mc Cullagh.

Dr Mc Cullagh will present her research, entitled "Data Protection: regulatory (in)adequacy?", at the 28th annual British and Irish Law, Education and Technology Association (BILETA) conference, taking place at the Liverpool Law School, University of Liverpool, this week.

Explore further: Digital dilemma: How will US respond to Sony hack?

More information: www.bileta.ac.uk/Annual%20Conference/

add to favorites email to friend print save as pdf

Related Stories

Sony fined in UK over PlayStation cyberattack (Update)

Jan 24, 2013

British regulators have fined Sony 250,000 pounds ($396,100) for failing to prevent a 2011 cyberattack on its PlayStation Network which put millions of users' personal information—including names, addresses, ...

Data violations unpunished in EU: rights agency

May 07, 2010

Data protection in many European countries suffers from a lack of funds, staff, independence and most importantly, a lack of sanctions for violators, the EU's rights agency reported Friday.

French regulator warns of Google privacy policy

Feb 28, 2012

Google's new privacy policy appears to violate the European Union's data protection rules, France's regulator said Tuesday, just two days before the new guidelines are set to come into force.

Europe to move against Google over privacy rules

Feb 18, 2013

European data protection agencies intend to take action against the US Internet giant Google after it failed to follow their orders to comply with EU privacy laws, a French agency said on Monday.

EU data protection reform to replace national laws

Nov 28, 2011

The European Union wants to replace a mishmash of national laws on data protection with one bloc-wide reform, updating laws put in place long before Facebook and other social networking sites even existed.

Recommended for you

Digital dilemma: How will US respond to Sony hack?

Dec 18, 2014

The detective work blaming North Korea for the Sony hacker break-in appears so far to be largely circumstantial, The Associated Press has learned. The dramatic conclusion of a Korean role is based on subtle ...

UN General Assembly OKs digital privacy resolution

Dec 18, 2014

The U.N. General Assembly has approved a resolution demanding better digital privacy protections for people around the world, another response to Edward Snowden's revelations about U.S. government spying.

Online privacy to remain thorny issue: survey

Dec 18, 2014

Online privacy will remain a thorny issue over the next decade, without a widely accepted system that balances user rights and personal data collection, a survey of experts showed Thursday.

Spain: Google News vanishes amid 'Google Tax' spat

Dec 16, 2014

Google on Tuesday followed through with a pledge to shut down Google News in Spain in reaction to a Spanish law requiring news publishers to receive payment for content even if they are willing to give it away.

User comments : 0

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.