DP Bills DPDI has been dropped and two more are now under review
With the recent election concluded and the Labour Party now leading the government, the King’s Speech at the State Opening of Parliament has set the stage for the legislative agenda. Among the 40 bills mentioned, several will impact how we handle personal data, particularly in the context of GDPR and data protection.
Two key bills stand out for their relevance to personal data and data security: the Digital Information and Smart Data Bill and the Cyber Security and Resilience Bill. Let’s delve into each and explore their key takeaways.
Digital Information and Smart Data Bill
The government aims to “harness the power of data for economic growth” through this bill, which provides a statutory footing for three main areas of innovation:
- Digital Verification Services: These services will support the creation and adoption of secure and trusted digital identity products and services from certified suppliers. This initiative aims to simplify everyday tasks such as pre-employment checks and purchasing age-restricted goods and services.
- National Underground Asset Register: This will involve creating digital maps of underground cables and pipes, aiding planners and workers by providing access to crucial data for their projects.
- Smart Data Schemes: These schemes will enable the secure sharing of customer data upon request, but only with authorized third-party providers. Unlike GDPR’s data portability, this focuses on sharing data while keeping it within the original system.
Additionally, the bill will:
- Allow scientists, including those in commercial settings, to make better use of data for research.
- Amend the Digital Economy Act to facilitate government data sharing about businesses using public services. This includes creating an electronic system for birth and death registrations and setting standards for IT suppliers in the Health and Social Care sectors.
- Modernize the Information Commissioner’s Office (ICO) with a new regulatory approach, a CEO, and stronger powers.
Interestingly, the King’s Speech hinted at targeted reforms to some data laws, though specifics are yet to be revealed.
Cyber Security and Resilience Bill
This bill focuses on “strengthening the UK’s cyber defences,” a crucial need in today’s digital age. It aims to secure critical infrastructure and digital services by updating relevant legislation urgently.
Key takeaways include:
- Expansion of Regulations: More digital services and supply chains will be protected under expanded regulations, addressing vulnerabilities highlighted by recent cyber-attacks on critical health services.
- Enhanced Regulatory Measures: Regulators will gain additional measures to ensure essential cyber safety practices are implemented.
- Mandated Incident Reporting: All companies will be required to report cyber incidents, including ransomware attacks, to help build a comprehensive understanding of the threat landscape.
These bills represent significant steps towards modernizing the UK’s approach to data and cyber security, reflecting the evolving technological landscape we operate within. As these bills progress, it will be interesting to see their practical implications and how they shape our data handling practices.
Is it worth DPOs investing in training to help with these new bills?
Extra training for Data Protection Officers (DPOs) can be incredibly beneficial in helping businesses adapt to the new requirements introduced by the Digital Information and Smart Data Bill and the Cyber Security and Resilience Bill. Here’s how:
Enhanced Understanding of New Legislation
In-depth Knowledge:
- Legislative Changes: Training will ensure DPOs fully understand the specifics of the new bills, including any amendments to existing laws and new compliance requirements.
- Practical Implications: DPOs will learn how these changes impact day-to-day operations and data management practices.
Regulatory Compliance:
- Updated Compliance Strategies: Training will help DPOs develop and implement updated compliance strategies that align with the new regulations.
- ICO Modernization: Understanding the changes in the Information Commissioner’s Office (ICO) and how to navigate the new regulatory landscape.
Improved Data Management and Security Practices
Digital Verification Services:
- Integration and Use: Training will cover how to integrate and use digital verification services effectively, ensuring secure and compliant identity verification processes.
- Risk Management: Identifying and mitigating risks associated with digital identity products.
Smart Data Schemes:
- Secure Data Sharing: DPOs will learn best practices for securely sharing customer data with authorized third parties, ensuring compliance with GDPR and other regulations.
- Customer Consent: Effective management of customer consent for data sharing, maintaining transparency and trust.
Strengthened Cyber Security Measures
Cyber Security Best Practices:
- Implementation: Training will focus on implementing best practices for cyber security, including encryption, multi-factor authentication, and regular updates.
- Incident Response: Developing and maintaining robust incident response plans to handle cyber incidents effectively.
Regulatory Requirements:
- Incident Reporting: Understanding the new requirements for mandated incident reporting and establishing clear reporting mechanisms.
- Regulatory Measures: Ensuring that all necessary cyber safety measures are in place and regularly reviewed.
Enhanced Organisational Preparedness
Proactive Adaptation:
- Future-proofing: Training will help DPOs anticipate future changes and adapt their strategies proactively, ensuring long-term compliance and security.
- Continuous Improvement: Encouraging a culture of continuous improvement in data protection and cyber security practices.
Stakeholder Communication:
- Internal Training: DPOs can train other staff members on new practices and regulations, ensuring organisation-wide compliance.
- External Communication: Effectively communicating with clients, customers, and regulators about the organisation’s data protection and cyber security measures.
By investing in extra training for DPOs, businesses can ensure they are well-prepared to meet the new legislative requirements, enhance their data protection practices, and strengthen their overall cyber security posture. This proactive approach will help build trust and confidence among stakeholders and safeguard the organisation’s data assets.
What training courses are out there for this sort of thing?
Leadership Through Data's Certificate in Managing Data Protection Compliance training course can significantly benefit organisations in adapting to the new requirements introduced by the Digital Information and Smart Data Bill and the Cyber Security and Resilience Bill. Here's how:
Comprehensive Understanding of Data Protection Laws
In-depth Knowledge:
- The course covers fundamental concepts of data protection law, including key definitions and principles. This foundational knowledge is crucial for understanding the new legislative changes and their implications.
- It also delves into the practical application of data protection laws, helping participants navigate complex scenarios and apply legal requirements effectively.
Legislative Updates:
- Participants will learn about the latest updates in data protection legislation, including the new bills. This ensures that they are up-to-date with current laws and can implement necessary changes in their organisations.
Practical Application and Compliance
Real-world Scenarios:
- The course includes practical exercises and group discussions that simulate real-world scenarios. This hands-on approach helps participants understand how to apply data protection laws in their daily operations.
- By working through these scenarios, DPOs and other data protection professionals can develop strategies to comply with the new requirements introduced by the bills.
Risk Management:
- Training on managing risks associated with personal data is a key component of the course. This is particularly relevant given the new bills' focus on data security and cyber resilience.
- Participants will learn how to identify, assess, and mitigate risks, ensuring their organisations are better prepared to handle data breaches and cyber threats.
Enhanced Data Management Practices
Digital Verification Services:
- The course will cover best practices for integrating and using digital verification services, which are a key aspect of the Digital Information and Smart Data Bill. This ensures that organisations can adopt these services securely and compliantly.
Smart Data Schemes:
- Participants will learn how to implement smart data schemes for secure data sharing with authorized third parties. This aligns with the bill's requirements and enhances data management practices within the organisation.
Strengthened Cyber Security Measures
Cyber Security Best Practices:
- The course includes training on cyber security best practices, which are essential for complying with the Cyber Security and Resilience Bill. This includes measures like encryption, multi-factor authentication, and regular updates.
Incident Response and Reporting:
- Participants will learn how to develop and maintain robust incident response plans and reporting mechanisms. This is crucial for meeting the new requirements for mandated incident reporting and ensuring timely and effective responses to cyber incidents.
Organisational Preparedness and Continuous Improvement
Proactive Adaptation:
- The course encourages a proactive approach to adapting to legislative changes. By staying informed and prepared, organisations can ensure long-term compliance and security.
Continuous Learning:
- The emphasis on continuous learning and improvement helps organisations stay ahead of regulatory changes and evolving threats. This ongoing education is vital for maintaining robust data protection and cyber security practices.
By investing in the Certificate in Managing Data Protection Compliance training course from Leadership Through Data, organisations can equip their DPOs and data protection teams with the knowledge and skills needed to navigate the new legislative landscape effectively. This not only ensures compliance but also enhances overall data security and operational efficiency.
Chat with our team if you'd like to know more or book your seat online.

Charlotte Easton
⭐ Account Executive
✉️ [email protected]
☎️ Use any of the numbers at the bottom of this page to get hold of me
🌐 Connect with me on LinkedIn




