DMA welcomes the new pro-growth DPDI data privacy reforms
08 Mar 2023
The DMA welcomes the new Data Protection and Digital Information Bill (DPDI). The proposed reforms will provide businesses with additional pro-growth opportunities and legislative clarity while maintaining a high standard of protection for customers.
The Bill, containing a series of revisions to three pieces of existing legislation, will safeguard the key ethical principles of existing laws while clarifying areas of confusion and simplifying onerous administrative burdens on small businesses. The government expects these data reforms to unlock £4.7 billion in savings for the UK economy over the next 10 years.
During the most recent phase of consultation, Chris Combemale, DMA CEO, chaired the Business Advisory Group which provided valuable input to the Secretary of State and Department for Science, Innovation and Technology DSIT (formerly DCMS) officials.
Combemale said: “The DMA has collaborated with the government throughout the Data Protection and Digital Information Bill (DPDI)’s development to champion the best interests of both businesses and their customers. We are confident that the bill should act as a catalyst for innovation and growth, while maintaining robust privacy protections across the UK – an essential balance which will build consumer trust in the digital economy.”
Clarifying legitimate interests key for business
One of the most significant reforms is the greater clarity offered on what constitutes a legitimate interest, which will encourage more businesses to use it as a lawful basis for data processing where appropriate.
Many businesses were not confident they could rely on legitimate interests as the main legal basis for processing data for direct marketing – thereby reducing opportunities to attract new customers and to know their existing customers better.
Attracting and retaining customers and donors (through direct marketing) is now clearly identified as a legitimate interest, but customers retain an overriding right to object to marketing should they not wish to do business with a specific organisation.
For several years, the DMA community championed the need to establish legal certainty around legitimate interests as one of the six legal bases for processing in GDPR, so this reform is credit to its members for their support and input.
Combemale added: “Attracting and retaining customers and donors is a fundamental legitimate interest of businesses and charities, so we are delighted the government has acknowledged this in the reforms to help drive innovation and growth. The DMA was well placed to advise on these developments over the past two years through our strong relations with UK businesses and government. It was important to our community that we focused reforms on the needs of both businesses and their customers to ensure the right balance was achieved for all.”
Important reforms for the marketing community
Critically for charities, the bill amends PECR to extend the soft opt-in for email to non-commercial organisations, which will enable charities to communicate with existing donors and volunteers more easily and on the same basis as commercial organisations.
The DPDI Bill will reduce the amount of paperwork that organisations and their marketers need to complete to demonstrate compliance in several areas, especially beneficial to smaller organisations. Business will be exempt from onerous paperwork if they are not undertaking any high risk data processing.
There are an expanded range of exemptions to consent for cookies, which will reduce consent banners, especially for ecommerce and charity websites, that do not take advertising.
This will improve the customer experience by reducing the number of consent banners while also reducing unnecessary red tape for legitimate website functionality, which will benefit online users and the businesses trying to understand them better.
Additionally, the fines for rogue cold callers will be increased in PECR to £17.5 million from £500,000 or 4% of global turnover in line with fines in GDPR.
Technical FAQs marketers will find useful
- What about Special Category Data? Businesses must still obtain consent for collecting and processing special category data e.g., racial or ethnic origin (same as before DPDI reforms).
- Why clarity on LI was needed? Many businesses were incorrectly advised that consent should be the main legal basis for data collection for marketing – thereby reducing opportunities to attract new customers and to know their existing customers better. The new text gives greater certainty that legitimate interests is an appropriate basis for processing data to attract new and retain existing customers.
Many issues that the DMA community highlighted during its consultation response have been addressed by the government, but the DMA hopes this will provide the foundations for additional meaningful reforms.
“The DMA will continue working closely with parliament and DSIT as the bill progresses, to continue to seek improvements such as clarity on the scope of industry codes of conduct as specified in UK GDPR. This is significant for creating an industry ethical and legal framework to build trust in the digital economy,” concluded Combemale.
Read the government press release on how British businesses can save billions under new UK version of GDPR.
The DPDI Bill exploratory notes can be found here.
DMA Membership will provide your business with fantastic benefits, including advocacy, legal and compliance support, best practice guidance, research, insight and events.
Plus, with access to an online learning platform containing a range of qualification and bitesize learning modules, you’ll gain a cost-effective and simple way to keep your team upskilled.
Find out how DMA Membership will help your business thrive here.