Crime (Overseas Production Orders) Bill [HL] Debate

Full Debate: Read Full Debate
Department: Department for International Development

Crime (Overseas Production Orders) Bill [HL]

Lord Kennedy of Southwark Excerpts
Lord Paddick Portrait Lord Paddick
- Hansard - - - Excerpts

My Lords, were we to leave the European Union, the EU would examine our data protection regime to satisfy itself that it would be safe for the EU 27 to continue to exchange electronic data with the UK. This continued exchange of data is essential not only for law enforcement and counter- terrorism purposes but for commercial transactions.

The Government have recently passed the Data Protection Act 2018, which not only provides the necessary infrastructure to enable the UK to comply with the general data protection regulation, a piece of EU legislation, but ensures that the UK complies with EU standards of data protection in relation to law enforcement and national security that are not covered by the GDPR. In other words, the UK is ensuring that it complies with all EU data protection standards, so as to guarantee that it will be issued with a certificate of adequacy that will enable continued exchange of electronic data if we leave the EU.

If, as a result of this Bill or the treaties associated with it, UK companies were required to provide law enforcement agencies in other countries with personal data covered by the Data Protection Act and/or GDPR, and those foreign law enforcement agencies’ data protection standards were deemed by the EU to be inadequate, there is the potential for the EU to withdraw its adequacy certificate from the UK. Basically, if member states of the EU share data with the UK, and the UK shares that data under this Bill with law enforcement agencies that have inadequate data protection standards, the EU might stop sharing data with the UK. This amendment is designed to ensure that this does not happen. I beg to move.

Lord Kennedy of Southwark Portrait Lord Kennedy of Southwark (Lab Co-op)
- Hansard - -

My Lords, the noble Lord, Lord Paddick, raised an issue about which Act would take precedence in the event of a conflict between this Bill—when it becomes an Act—and the Data Protection Act 2018. His amendment makes it clear that, in the case of a conflict, the DPA, along with the GDPR, would take precedence. That seems quite sensible: it gives us certainty on the matter, for the reasons outlined by the noble Lord. I support his amendment.

Baroness Williams of Trafford Portrait Baroness Williams of Trafford
- Hansard - - - Excerpts

I thank both noble Lords for their points. There has been nothing in our own domestic law that requires a UK provider to comply with an overseas order. There will therefore be no conflict with domestic law if a CSP decides that complying with a foreign order would put it in breach of its obligations under the GDPR.

The existence of any conflict with UK data protection law does not have the effect of making the order from the other country invalid. Equally, the existence of the order does not compel the UK CSP to ignore its data protection obligations under UK law. It will be for the CSP on which an order is served to reconcile and comply with all legal obligations it is under. It could apply for the variation or revocation of the order, or use the dispute resolution mechanism that we expect all specific international agreements to include. That said, we do not think that this is likely to be necessary in practice. The GDPR contains several “gateways” which permit the cross-border transfer of personal data, including in response to a request or order from overseas law enforcement.

I know the noble Lord’s concerns about data protection, and I absolutely sympathise with him. We have discussed this before, and I think that ultimately we all want the same thing: adequate protection for the privacy rights of individuals. I hope that my explanation will satisfy the noble Lord that the Bill does not in any way threaten data protection rights, which are robustly protected by existing legislation. UK CSPs will continue to be bound by the GDPR and the Data Protection Act. Therefore, I hope that the noble Lord will feel happy to withdraw Amendment 12.