Insight

The European Regulation on Data Protection and Brexit

After many years of negotiations, on 27 April 2016, the European Regulation concerning the protection of individuals in respect of the processing of personal data and the free movement of this data (hereafter, “the Regulation”), has finally seen the light of day.

Brexit Data Protection
AJ

Anna Viladàs Jené

December 2, 2016 12:00 AM

After many years of negotiations, on 27 April 2016, the European Regulation concerning the protection of individuals in respect of the processing of personal data and the free movement of this data (hereafter, “the Regulation”), has finally seen the light of day.
This approval came at almost the same time as the vote by the United Kingdom on 23 June in favour of their exit from the European Union, which as we shall see may have an important effect as regards data protection.

Let us first see what are the principal new elements introduced by the Regulation, which will not come into force until 25 May 2018, until which time the current rules regarding data protection will continue to apply.

a.) Data protection representative ("DPO"): all public bodies must have such a person, and must private companies that carry out large scale regular and systemic monitoring of data or that process particular classes of data, such as for example data relating to health. With regard to his duties, they will consist of advising on and supervising the compliance by the entity as regards data protection, the preparation of reports assessing the impact of specific types of data processing on personal data and cooperation with the supervisory authorities.
b) Enhanced consent: the Regulation introduces greater demands upon the data protection representative at the time of obtaining the consent of those concerned, even doing away with the implied consent that is acceptable under the current rules.
c) File registration: the obligation to register files containing personal data with the relevant data protection authority is discontinued: nevertheless, there will be a duty to maintain a written register of all the personal data processing performed.
d) Reporting data breaches: this point establishes the obligation to report breaches which may occur, stating that the data processing representative is obliged to notify the relevant data protection authority and the individual affected at the latest 72 hours after becoming aware of the breach. Undoubtedly, in our view, this is one of the flagship measures as regards compliance, since it will force entities to have in place permanent and coordinated active legal and technical response
mechanisms which also cover information media, on a permanent and coordinated basis.
e) Penalties: the penalties are substantially increased up to the sum of 20 million euros or the equivalent of 4% of the annual worldwide turnover of the business for the previous financial year at the time that the breach occurs.
f) Application: the application of the general data processing Regulation has been extended: the Regulation will not only apply to companies established in the European Union, but also to data processing by companies resident in the Union through a representative or manager not resident in the European Union, when the data processing activities are related to the offer of goods or services to interested parties in the Union, or who are in charge of how it is conducted, to the extent that this takes place in the European Union.
g) Right to privacy: the Regulation introduces the concept of the right to erasure, better known as the right to privacy, namely the right of individuals concerned to restrict the dissemination of their personal data on search engines.
Ultimately the new Regulation should involve a further step towards European harmonisation as regards data protection, and therefore in the free movement of data on a European level.
But this aim may be sharply affected, as we said, as a result of the United Kingdom's vote in favour of their exit from the European Union, the famous Brexit.
Indeed, once the departure of the United Kingdom from the Eu is complete, the Union's treaties with the United Kingdom will be suspended, and, therefore, the free movement of data will also be suspended.
What we mean is that it is highly likely that on leaving the European Union the United Kingdom will become a country without an equivalent level of data protection to that of Europe, and it will have to begin the process by which the European Commission will once again recognise it as a country with a comparable level of protection. The process is neither speedy nor simple; in fact, it could take years.

Under this scenario, the transfer of data between the United Kingdom and the other European Union countries will become more complicated, since these transfers will be considered to be international transfers of personal data whose requirements are far stricter than those applicable to the movement of data within the European Union or between countries with a comparable level of protection. And in this regard, reports have already been published about telecommunications companies who are considering transferring their head offices from the United Kingdom to an EU country in order to avoid these complications. They will undoubtedly be the first of many to do so.

Thus, the entry into force of this new Regulation shall certainly be affected by the exit by the United Kingdom from the European Union, thereby necessitating the regulation of the movement of data to and from the United Kingdom and the European Union. This is not a trivial issue, and it will be advisable to deal with it with the aim of arriving at the date when the Regulation comes into force with a gradual and well-organised compliance process, that will increase, without doubt, the legal and operational security of all entities, especially in the context of the actual exit of the United Kingdom from the European Union.

Related Articles

Connecticut Attorney General Releases Status Update on Data Privacy Act


by Gregory Sirico

Connecticut's attorney general recently released a report on the current status of the Data Privacy Act, focusing in on some keys areas of enforcement.

Animated woman's face with code scattered everywhere

Current State of EU to U.S. Data Transfers


by Gregory Sirico

The Biden Administration and European Commission recently came to a principle political agreement concerning the ever-changing future of EU to U.S. data transfers.

New Framework for EU and U.S. Data Transfers

Privacy Practice


by Casey Waughn

Data protection is all the rage among tech companies and state, national (and even transnational) governments alike. Is it a passing fad or here to stay? And how should businesses and groups of all sizes handle compliance with a blizzard of new laws?

Data Protection Prompt New Privacy Laws

Announcing the 7th Annual Women in the Law Publication


by Best Lawyers

The 7th Annual Women in the Law publication is a celebration of all the female legal talent across the country, honoring every woman listed in The Best Lawyers in America and Best Lawyers: Ones to Watch in America.

Honoring Female Lawyers in the United States

A Sea Change on Land


by Suneel Gupta and Linda A. Klein

Autonomous vehicles will revolutionize almost every area of the law. Here’s a look at what’s rapidly approaching.

Legal Considerations for Autonomous Vehicles

A Startup Accelerator Program Sets Cuatrecasas Apart


by Best Lawyers

Miguel de Almada and Frederico Bettencourt Ferreira from the Portuguese firm discuss their 2019 "Law Firm of the Year" award for Litigation and Arbitration.

Cuatrecasas "Law Firm of the Year"

How Do I Protect My Child From Online Predators?


by Kelly L. Frey Sr.

New technologies open up new ways for children to be exploited online. The Children’s Online Privacy Protection Act offers a solution.

What COPPA Means for Your Child

Recent Developments on Privacy and Data Protection in Brazil


by Ricardo Barretto Ferreira da Silva and Camila Taliberti Ribeiro da Silva

A change of paradigm is urgent and requires a robust legislation on personal data protection.

Privacy and Data Protection Brazil

The Future of Data Privacy: You Can Run but You Can’t Hide (or Can You?)


by Chad W. King

In Ernest Cline’s dystopian novel "Ready Player One," the world’s population is addicted to a virtual reality game called the OASIS.

The Future of Data Privacy

My Data My Rules: An Overview of Data Protection in Brazil


by Fábio Pereira

My Data My Rules

Trending Articles

Introducing the 2026 Best Lawyers Awards in Australia, Japan, New Zealand and Singapore


by Jennifer Verta

This year’s awards reflect the strength of the Best Lawyers network and its role in elevating legal talent worldwide.

2026 Best Lawyers Awards in Australia, Japan, New Zealand and Singapore

Revealing the 2026 Best Lawyers Awards in Germany, France, Switzerland and Austria


by Jamilla Tabbara

These honors underscore the reach of the Best Lawyers network and its focus on top legal talent.

map of Germany, France, Switzerland and Austria

Effective Communication: A Conversation with Jefferson Fisher


by Jamilla Tabbara

The power of effective communication beyond the law.

 Image of Jefferson Fisher and Phillip Greer engaged in a conversation about effective communication

The 2025 Legal Outlook Survey Results Are In


by Jennifer Verta

Discover what Best Lawyers honorees see ahead for the legal industry.

Person standing at a crossroads with multiple intersecting paths and a signpost.

The Best Lawyers Network: Global Recognition with Long-term Value


by Jamilla Tabbara

Learn how Best Lawyers' peer-review process helps recognized lawyers attract more clients and referral opportunities.

Lawyers networking

Jefferson Fisher: The Secrets to Influential Legal Marketing


by Jennifer Verta

How lawyers can apply Jefferson Fisher’s communication and marketing strategies to build trust, attract clients and grow their practice.

Portrait of Jefferson Fisher a legal marketing expert

Is Your Law Firm’s Website Driving Clients Away?


by Jamilla Tabbara

Identify key website issues that may be affecting client engagement and retention.

Phone displaying 'This site cannot be reached' message

A Guide to Workers' Compensation Law for 2025 and Beyond


by Bryan Driscoll

A woman with a laptop screen reflected in her glasses

Best Lawyers Launches CMO Advisory Board


by Jamilla Tabbara

Strategic counsel from legal marketing’s most experienced voices.

Group photo of Best Lawyers CMO Advisory Board members

Common Law Firm Landing Page Problems to Address


by Jamilla Tabbara

Identify key issues on law firm landing pages to improve client engagement and conversion.

Laptop showing law firm landing page analytics

Changes in California Employment Law for 2025


by Laurie Villanueva

What employers need to know to ensure compliance in the coming year and beyond

A pair of hands holding a checklist featuring a generic profile picture and the state of California

New Employment Law Recognizes Extraordinary Stress Is Everyday Reality for NY Lawyers


by Bryan Driscoll

A stressed woman has her head resting on her hands above a laptop

Turn Visitors into Clients with Law Firm Website SEO That Converts


by Jamilla Tabbara

Learn how to create high-converting law firm landing pages that drive client engagement and lead generation.

Laptop screen displaying website tools to improve client conversion rates

Best Lawyers Introduces Smithy AI


by Jamilla Tabbara

Transforming legal content creation for attorneys and firms.

Start using Smithy AI, a content tool by Best Lawyers

SEO for Law Firms: Overcoming Common Challenges


by Jamilla Tabbara

Tackle common SEO challenges and take the next step with our guide, How to Make Your Law Firm Easier to Find Online.

Graphic image of a phone displaying SEO rankings, with positions 1, 2 and 3 on the screen

Medical Malpractice Reform Trends in Texas, Utah, Georgia and SC


by Bryan Driscoll

A fresh wave of medical malpractice reform is reshaping the law.

Medical Malpractice Reform Trends hed