Select Committee on the European Union
EU Home Affairs Sub-Committee
Corrected oral evidence: The EU Data Protection Package
Wednesday 1 February 2017
10.30 am
Members present: Baroness Prashar (The Chairman); Lord Condon; Lord Cormack; Baroness Janke; Lord Jay of Ewelme; Baroness Massey of Darwen; Baroness Pinnock; Lord Ribeiro; Lord Soley; Lord Watts.
Evidence Session No. 1 Heard in Public Questions 1 - 8
Witness
I: Rt Hon Matt Hancock MP, Minister of State for Digital and Culture, Department for Culture, Media and Sport.
Examination of witness
Rt Hon Matt Hancock MP.
Q1 The Chairman: Good morning, Minister. Thank you very much for your time this morning. As you know, this is a public session. There will be a webcast of the session. We are looking at the EU data protection package. Before we start questions, is there anything that you would like to say by way of introduction?
Matt Hancock MP: It is a pleasure to be here. Getting right the UK’s response to the EU data protection package, which is part of the EU’s digital single market initiative, is incredibly important, both as we go through the period in which we remain members of the EU, fully engaged and making the case in Brussels, and through Brexit and beyond.
The Chairman: Thank you very much. I would like to start with a general question. We are looking at four elements of the data protection package: the general data protection regulation, the data protection directive, the EU-US privacy shield and the EU-US umbrella agreement. It would be helpful if you could outline for us in broad terms what the implications of those four measures are for the UK, in terms of their impact both on UK businesses and other data controllers and on people whose information is being shared—that is, the data subjects.
Matt Hancock MP: These are four important measures. There are other measures, too, that are part of the data management governance—including, for instance, the relatively new proposals to make changes to the EU privacy directive, which are at a much earlier stage in the Commission’s thinking. It is important to think of all these different pieces of EU legislation in the round.
The GDPR introduces obligations for data controllers and processors in several areas. It strengthens the rules for obtaining consent, strengthens the need for breach notifications and emphasises self-assessment in the management of data. We have said that the UK will implement the GDPR in full. There are two reasons for that. First, thanks to some significant negotiating successes during its development, we think that it is a good piece of legislation in and of itself. Secondly, we are keen to secure the unhindered flow of data between the UK and the EU post-Brexit. We think that signing up to the GDPR data protection rules is an important part of helping to deliver that.
The law enforcement directive ensures that personal data that is processed in the law enforcement field is processed lawfully and collected for specific, explicit and legitimate purposes. The privacy shield provides stronger obligations on international companies and more robust enforcement mechanisms. In so doing, it provides for data flows between the EU and the US. The umbrella agreement is similar, again in the law enforcement space. It provides standards and safeguards for the exchange of data in transatlantic law enforcement.
The Chairman: Can I clarify one thing? If I heard you right, you said “unhindered flow of data … post-Brexit”.
Matt Hancock MP: Yes.
The Chairman: Can you explain that a little?
Matt Hancock MP: At the moment, as part of the EU, we have data flows between the UK and other European countries that are all covered by the same data protection. Of course, flows of data have to be adequately and appropriately safeguarded, with a very strong emphasis on privacy. However, ultimately data can flow between different countries, within a company, and do so, appropriately, under the Data Protection Act, currently, and the GDPR, in future. Similarly, the privacy shield allows for these sorts of data transfers—all within data protection rules—with the United States. The ability of these flows of data to be unhindered, within appropriate data protection rules, is very important, not only for data-heavy and data businesses, but for law enforcement—and because, increasingly, they underpin any sort of trade. Typically, now, when a widget is sold from one country to another, there is a flow of data that goes alongside that physical good. Such flows of data are important in ensuring that trade is freely possible.
The Chairman: What would you identify as the key safeguards in the data protection package that will ensure that people’s fundamental rights, including the right to privacy, will be protected?
Matt Hancock MP: The No. 1 principle is that data should not be disclosed outside an organisation, except under certain circumstances. That principle currently underpins the Data Protection Act, which has a high degree of consensus behind it in the UK and is a very good piece of legislation. The principle has flowed forward into the GDPR. However, the GDPR also strengthens the safeguards against that and the disclosure requirements, where there has been a data breach. In future, under the GDPR, if there is a data breach by a company—if a company has lost a significant amount of data, for instance—there will be a requirement in short order, within a matter of 72 hours, to notify the Information Commissioner, who can make an appropriate judgment as to whether that should be made public. At the moment, such a provision does not exist. Both the higher safeguards and the more robust notification of breach procedures will significantly strengthen the UK’s data protection.
Q2 Lord Jay of Ewelme: I want to follow up on the discussion that we have just had about the implications of Brexit for data protection. I was glad to hear you say that the Government want to ensure unhindered data flows after Brexit. Assuming, as the Information Commissioner’s Office and others have said, that the UK will be treated as a third country on data protection issues once we are no longer in the EU, what will be the default position, as a matter of law, for data flows between the UK and the EU if we have not secured an adequacy decision at the point at which we leave? Secondly—this follows naturally from the previous question—will we seek an adequacy decision as part of the negotiations on Brexit? I know that you are not allowed to say much about that.
Matt Hancock MP: You have anticipated part of my answer, my Lord. We are keen to ensure that data flows are unhindered. As you have anticipated, I will not go into the details of how we do that when negotiations are yet to begin. Our goals are clear. We want an arrangement that provides for the unhindered exchange of data, within an appropriate data protection environment. However, I do not think that it is appropriate to speculate on what arrangements we may seek to put in place.
Lord Jay of Ewelme: You would agree that, somehow, we must have an adequacy decision before we leave if this is going to work.
Matt Hancock MP: Not only do we seek unhindered data flows but we want that to happen in an uninterrupted way—that is to say, on the morning on which we have left the European Union, it is very important that our data rules work, so that there is an uninterrupted system in place.
Baroness Janke: If we will no longer be under the jurisdiction of the European Court of Justice, who do you anticipate will be the arbiter and final adjudicator in such matters?
Matt Hancock MP: There are several different ways in which that can take place. We do not have the answer to that question, because we have not begun the negotiations, let alone concluded them.
Baroness Pinnock: I wonder whether you could expand a bit on that answer. There must be a range of possibilities. It would be good for us to understand what you have in mind. Obviously, you will not want to say where the end game will be, but a range of options must be in the Government’s mind.
Matt Hancock MP: Indeed. I do not want to stress any particular options, because we have to protect our negotiating position. What I will do is state very clearly the goal, which is unhindered flow of data. I cannot go any further than that on the pros and cons of various different arrangements to make that happen, because we have to go through a negotiation. We have been quite clear from a government point of view that, as the Prime Minister puts it, we are not going to give a running commentary on that. As you know, there are different ways to make it happen.
Lord Ribeiro: One of the major concerns of the medical bodies about the whole Brexit vote was the issue around medical research and data sharing. When we become a third country, we need assurances that that flow of data, which benefits the care and management of our patients hugely, will continue. You are saying that you are not in a position to say that.
Matt Hancock MP: I agree very strongly with the premise of your question. That is what we will seek to achieve.
Lord Ribeiro: No more than that.
Lord Cormack: What are your relations with your fellow Ministers like at the moment?
Matt Hancock MP: Relations are good. In fact, one of the things that has surprised me since the Brexit vote is that relations within the councils that I attend remain very good. As far as I can see, the UK voice remains influential. For instance, we have had discussions on data localisation rules, in which we managed to get an overwhelming majority of countries to oppose the principle of such rules—not least because that would undermine a single market in goods, let alone in data. We also succeeded in being on the winning side of the argument for mobile phone roaming, which is another important part of the digital single market, in a slightly different space. Indeed, we have just had a successful conclusion of the rules around mobile phone roaming, which will be one of the most visible successes of the digital single market. We are successful in making these arguments. While we are a member of the EU, we are fully engaged in going to councils and are heavily engaged at official level, to try to make sure that the design of the rules coming out of the EU over the Article 50 process period is as high quality as possible.
Lord Cormack: Is being both a Minister and a negotiator not going to bring on a sort of ministerial schizophrenia?
Matt Hancock MP: I hope not. Ministers often have to hold differing, sometimes competing, objectives in mind. That is one of the joys and challenges of the job. You have to balance those.
Lord Soley: I understand and accept fully that you cannot comment on negotiations. Clearly, a negotiated agreement in this area would be the best option. However, if, for whatever reason, that did not happen, it seems to me that an adequacy decision would work. It would just be a less smooth transition. Is that something you would agree with?
Matt Hancock MP: I am really sorry, but I will not go further than what I have said. I hope that you understand the reasons why. The goal is very clear. There are many ways to skin any cat. A discussion on conditional questions—on what will happen if this or that occurs—will not be particularly fruitful, because we need to protect our negotiating stance.
Lord Soley: I understand that. My question is slightly different. I am saying simply that an adequacy decision could work. There is no reason why there would be shock and horror about an adequacy decision. There will be some of those in other areas.
Matt Hancock MP: An adequacy decision could work. There are many different ways in which you could make this work. We must have a view both on our future position with the EU and on our future position with other jurisdictions that have high-quality data protection regimes, the US being the most obvious example. We must make sure that we have a free flow of data with them, too. Currently, we do that through the EU, but we will have to do it directly instead.
The Chairman: Can I press you a little harder? If you did not secure an adequacy decision, what would be the default position? I know where you want to be. If we do not get that, what is the default position?
Matt Hancock MP: We are seeking to have unhindered data flows. We are confident of being able to achieve that.
The Chairman: You do not have a contingency in case that happens. What would be the position if it in fact happened?
Matt Hancock MP: As you know, there are a number of different ways in which you can organise that. I do not want to go through and rank those or to fetter our discussion in what is a very important negotiation.
Lord Watts: Obviously, you are not contemplating failure in this discussion. Am I right in thinking that all the other EU partners would have to change their existing legislation to accommodate us outside, when we leave Europe?
Matt Hancock MP: I do not think that that is the position.
Lord Watts: The data protection is all wrapped up with and guaranteed by the European courts, which we would no longer be part of. They would have to accept that there was another system outside that allowed them to share data with other countries.
Matt Hancock MP: I see. They already accept that with respect to the United States. So it is possible to negotiate that sort of agreement.
Lord Watts: Under those circumstances, would we have to accept conditions very similar or identical to those that we now apply for the rest of Europe to accept us? Is that the American system? Have they really accepted—
Matt Hancock MP: The approach that we have taken, in order to maximise the ease with which we can negotiate an uninterrupted and unhindered flow of data, is to put the GDPR into UK law in full. In a sense, we are matching them, rather than asking them to match anything new from the UK.
We have done that, first, because it is a decent piece of legislation. There are people who say that you could make it easier in this way or less burdensome in that way. In some cases, that may be true, but our view is that we should bring the whole thing in, in full, so that we are operating the EU regime and the EU does not have to change its regime in order to bring compliance. That is the thing about this EU negotiation. We are starting from a position of harmonisation, rather than from a position of difference. One reason why there are a lot of interesting questions around the GDPR and data is that the EU is moving its own domestic law at the same time as we go through the Article 50 process. There are several different directives and regulations in question. We have to make sure that we look at the whole of that as we go through the process.
Lord Watts: How long did it take America and Europe to agree their own data-sharing legislation?
Matt Hancock MP: There had been a previous data-sharing agreement in operation. It was then struck down. They brought in the privacy shield relatively quickly. That process of bringing it in took nine months. Again, we will be starting from a point of harmonisation, rather than from a point of difference. It is much easier to negotiate from a point where both systems are the same.
Q3 Baroness Massey of Darwen: I heard your answer to the last question. Could I follow up on that? What changes will need to be made to the Data Protection Act 1998 to bring it into compliance with the GDPR and the data protection directive? What timeline are the UK Government looking at to make the necessary changes?
Matt Hancock MP: Our timeline is that this needs to be in force by May 2018, which gives us 16 months. Parts of the Data Protection Act 1998 will need to be repealed for data processing to be within the scope of the GDPR. It is necessary to ensure that we do not end up with the Data Protection Act duplicating or creating inconsistencies with the GDPR, because the GDPR will be directly applicable. We will bring forward legislation in the next session in order to put that into practice.
Baroness Massey of Darwen: If it is not too technical a question, could I ask which bits will be repealed?
Matt Hancock MP: Specifically, there are issues on the enforcement of the Data Protection Act. I can write to you with more detail of the sections that need to be repealed. I can give you the full technical detail.
Baroness Massey of Darwen: What are the resource implications for bringing the UK into compliance with the GDPR and the data protection directive?
Matt Hancock MP: It means that the data protection team in DCMS is working very hard, but we are fully resourced to deliver the GDPR inside government. As to resources outside government, this will, of course, place some requirements on companies, particularly data-heavy companies, to make sure that they comply. However, my view is that the requirements that it brings in are consistent with best practice for handling data, anyway. Companies that handle data appropriately, have good cybersecurity arrangements and respect the privacy of their customers and those whose data they hold should not find this much of a burden, but it will require some companies that do not have best practice to come up to speed. I do not think that that is a bad thing, given that data is increasingly important in corporate activity.
Baroness Massey of Darwen: Presumably, there are financial implications.
Matt Hancock MP: For some companies?
Baroness Massey of Darwen: Yes.
Matt Hancock MP: There will be a requirement to act, in some cases. In the same way that the Data Protection Act 1998 increased the requirements, but is undoubtedly a good thing and in the long-term best interests of corporate Britain, so, too, is the GDPR. I can add to that. When we bring forward legislation, of course, there will be an impact assessment attached to it.
Q4 Baroness Massey of Darwen: What changes do you anticipate to the UK data protection regulatory landscape post-Brexit? What changes, if any, do you foresee to the role of the Information Commissioner’s Office?
Matt Hancock MP: Maybe I can answer that question in two parts. First, because we are bringing in the GDPR before we leave the European Union, I do not foresee any great changes after we leave the European Union. Indeed, I hope that on D+1 life will continue much as on D-1, because we have taken the decision domestically to bring the GDPR into UK law.
That is a narrow, technical answer. There is a broader answer, of course. The ICO’s role has changed a lot in the past two decades. I am sure that it will evolve in future. The collapse in the cost of storing and replicating data, to an infinitesimal cost, because of digital technology, over 30 years—from the cost of copying paper to the cost of sending an email, which is essentially zero—has had a huge impact on the role of data in society and in the economy. The ICO in the UK has been a world leader in making sure that the rules and the framework around data are kept up to speed. There are big new advances going on all the time—in machine learning and in artificial intelligence, as well as in cybersecurity. The ICO needs to keep up to speed with those developments. I am sure that it will.
There is a bigger answer, which is that the world is moving fast and we need to make sure that the rules stay appropriate. We are doing quite a lot of work on that—not just in government, but with the Royal Society. We are doing work on making sure that the framework for how we think about data, as a society, stays up to speed with big changes in the use of data. The ICO will play an important part in that.
The Chairman: What will happen in the future? If the GDPR is updated after we leave, will we continue to mirror it? What will be the situation post Brexit?
Matt Hancock MP: We will have to make that decision at the time, according to what the changes are. There is the potential to make the GDPR easier to comply with or more flexible, but we would want to do that only consistent with maintaining unhindered data flows, within the data protection regime. Likewise, if the rest of the European Union, once we had left, chose to change its data rules, we would have to decide whether to change ours to mirror them—because there are advantages to being the same as the European system—or whether to maintain a slightly different system. Again, we would want to maintain unhindered data flows.
Once we have left, there is a corollary with our relationship with other major economies, the US being the best example. If the US changes its data rules now, the EU—and, in future, we and the EU—has to think about whether to update its own rules. Part of having an international accord like that is that you need to think about what happens when the other side changes its rules. That is the generality. Since there are no proposals by the EU to do that and it has only just landed the last one, I think that it is some way off.
Lord Soley: I see this as quite a core problem in a lot of areas. We have a global trade emerging and global data sharing, yet you are in a situation where, politically—not just in this country—people are saying, “We want to take more control over our own situation”. There is a clash in how you can deliver that. How much is the department looking at ways in which you can continually improve the relationship between the various countries in order to make that trade and information flow more smoothly, but without making people feel, “We voted for Brexit, but we are still obeying these laws from other countries”? That is a central problem in all sorts of areas.
Matt Hancock MP: Yes. As you say, what we will need is a set of global relationships, rather than relationships only at European level. The UK domestic Government will be able to decide the changes that we make domestically, given everybody else’s position. That means that, if we need to respond to other changes, we will be able to do so, as opposed to being dictated to by the European system.
Lord Soley: You will need a structure within ministries to deal with that constant change.
Matt Hancock MP: We are currently concentrating on implementing the GDPR and then the Brexit process. However, I am sure that we will be able to run the UK data protection policy thereafter.
The Chairman: We move on to the EU-US privacy shield.
Q5 Lord Ribeiro: You have just talked about the relationship with the United States. When we leave the European Union, we will automatically leave the EU-US privacy shield. What arrangements do you think will be made for data sharing between the UK and the United States? Will we be at the front of the queue?
Matt Hancock MP: We are considering all the options for the most beneficial way of ensuring that the UK data protection regime supports UK business in the global economy. Clearly, we have been strong supporters of the privacy shield with the US. Making sure that US-UK business can take place post Brexit is a very important consideration for the Government at the moment.
Lord Ribeiro: Do you foresee any restrictions being placed on us by virtue of our previous membership of the EU?
Matt Hancock MP: I am confident that we can come to a successful agreement to make sure that we have the same unhindered flow of data with the United States as we have now.
Lord Soley: I remind you that the European data protection supervisor and the Article 29 working party both expressed concern that the safeguards here would not be as strong as they were under the previous system of safe harbour. I understand that since that time there have been a number of legal challenges—at least two, I gather. Can you update us on the situation with legal challenges?
Matt Hancock MP: Yes. We have been notified of two challenges to the privacy shield decision. The Commission has lodged proceedings in the Digital Rights Ireland challenge, to have it dismissed on grounds of inadmissibility. We would expect a similar approach to the La Quadrature du Net and Others challenge. We have applied to intervene on the DRI challenge in support of the Commission.
Lord Soley: Are you expecting more challenges, or not?
Matt Hancock MP: We are confident that these two challenges will not succeed. We are confident of the legal basis of the privacy shield.
Lord Soley: You are content that the present system is as strong as, or stronger than, safe harbour.
Matt Hancock MP: We are content that it is legal and that the challenges will not succeed. We are joining in the first one and will consider whether to join in the second one in support of the Commission and in defence of the agreements that have been reached. We think that the agreements that have been reached are very good.
Lord Soley: I am not sure what the previous situation was. Were there successful challenges under the—
Matt Hancock MP: There was a successful challenge to safe harbour, which led to the negotiation that led us to agree the privacy shield.
Lord Soley: Does that lead you to conclude that the present system is more legally robust?
Matt Hancock MP: Yes, because the safe harbour rules were challenged and the privacy shield was put in place in response to those challenges. In a sense, it has taken into account the challenges that were made to safe harbour, so we think that it is stronger.
Lord Soley: Are you aware of why the European data protection supervisor and the Article 29 committee are expressing concern that the new system is not as legally robust? Why are they concerned about that?
Matt Hancock MP: We are very confident that it is robust.
Lord Soley: But you do not know what their concern is.
Matt Hancock MP: It is a matter for them.
Lord Soley: They have not made that known to your department.
Matt Hancock MP: Why they express those concerns is a matter for them. We think that it is robust and are confident of winning the legal cases, not least because the privacy shield was specifically designed to take into account the court’s concerns about safe harbour.
Lord Soley: I am a little puzzled by this. You would expect that two such significant groups—or individuals, in the case of the supervisor—would be able to say, “We do not think that it is as legally robust, for these reasons: A, B, C”. Have they not said that to you?
Matt Hancock MP: They have set out some of their reasons. I am partly being cautious, because there is a legal challenge and I do not want to say anything that undermines that—not least because we think that the grounds for the challenge are not robust and that the challenge not only should but will be defeated. We think that it will not succeed.
Lord Soley: As you are the head of department, you have obviously looked at this. I was a bit puzzled about why it is not clear why they think that it is less legally robust. They must have reasons for saying that. Well, one hopes that they have reasons—presumably, it is not an off-the-wall comment.
Matt Hancock MP: I am sure that they will look forward to their appearance before the Committee to explain themselves.
The Chairman: We move on to the umbrella agreement.
Q6 Lord Condon: I wonder whether we can seek your guidance on a couple of aspects of the EU-US umbrella agreement—first, while we are still in the EU. In your last correspondence, you updated us by telling us that the EU had put in place everything for the umbrella agreement, but the US had not. Are you in a position to update us? Has the US now put in place all its requirements?
Matt Hancock MP: Yes, I can update you. The timing of this Committee meeting is incredibly sensible. The decision to conclude the umbrella agreement was adopted before the EU-US JHA ministerial meeting in December, but the US was not ready to finalise the agreement at that stage. The US Judicial Redress Act is now in force, and the agreement can be implemented. It enters into force in the EU today.
Lord Condon: I am very pleased to hear that. Thank you. Can I move on to the position once we have left the EU, when the umbrella agreement, as is, will not apply to us? Recently, we published our report Brexit: future UK–EU security and police cooperation. When our expert witnesses identified the three most important issues facing security and law enforcement post Brexit, data sharing—data access—was in the top three consistently. It is things like second-generation Schengen, the European criminal records information system and passenger names; it goes on and on. There is a sense that these are now integral to day-to-day policing and security here—they are not luxurious bolt-ons. In the post-Brexit environment, do you feel that we will need a UK-US and a UK-EU umbrella agreement around these issues? Is there any more that you can say to give us confidence that there will be unhindered, uninterrupted continuation of these sorts of activities?
Matt Hancock MP: As you say, data sharing and the response to increasingly mobile threats are a critical part of our defences and security arrangements. The importance of law enforcement agencies working together across borders to share information to protect the public has not changed, and will not be changed by Brexit. Effective data sharing with our international partners, both EU and non-EU, will remain a top UK priority. We expect to play a leading role in that, as we do now, after we leave.
Lord Condon: The experts we received evidence from said that there were three potential big inhibiting factors that would prevent what you and I have just articulated as a desirable continuation. First, all those databases and all that co-operation are currently subject to European Court of Justice scrutiny and intervention. Secondly, it is quite expensive to maintain those databases, and we will be out of the club and not formally contributing to their upkeep. Thirdly, there was anxiety specifically in your area. Some experts felt that, outside the EU, the data protection challenges would be almost insurmountable for us when it came to showing either equivalence or adequacy in relation to some of the databases. Is work being done to try to make sure that there is not a cliff edge on our having access to those databases? Is that a shared task for your department, the Department for Exiting the EU and the Home Office? How specifically is that law enforcement challenge on data sharing being addressed?
Matt Hancock MP: Clearly, there is a strong desire to get this right and to get a deal that works, both with the rest of the EU and with other countries around the world. For the most part, this is a Home Office lead, but we work very closely with it, because of the interaction between law enforcement data rules and economy-wide data rules, which are our responsibility. Obviously, DExEU’s role in leading the negotiations with the EU is very important. There are good working-level relationships and good ministerial-level relationships, to make sure that we get an overall package. As I said right at the start, given the number of rules changes to data frameworks—in the loosest, broadest sense—that are happening at EU level, driven by the Commission and the digital single market and with the interest of the ECJ, we have to look at the package as a whole. Inevitably, that means work across departments.
Lord Condon: Interestingly, it is one of the areas where I have not heard any politician or expert suggest that leaving the EU is an advantage to the UK law enforcement agencies. There seems to be a unanimity of ambition to secure and maintain the status quo in these areas, as far as possible. Therefore, the challenge on data sharing seems to be whether it should be an umbrella agreement or some other mechanism that will ensure that these data exchanges and data flows continue unhindered. It seems non-controversial in terms of outcome. As you have suggested, the challenge will be to find the right mechanism that delivers the confidence around data sharing that will allow the EU and its institutions, such as Europol, to say, “Yes, of course. We can continue. It is in our mutual interests to continue sharing data”.
Matt Hancock MP: I hope that you are right. I certainly think that these arrangements carry a high degree of consensus in the UK. I also think that this is an area where—as with many areas of this negotiation—there is a mutual interest in having a good deal, both within the UK and the EU and with other partners around the world. I hope that the combination of a high degree of consensus behind the current arrangements and the degree of mutual interest will enable us to secure a very good deal. We are certainly seeking to secure the best deal that we can.
Baroness Pinnock: Can I pursue that a little further? I am very reassured that you are considering the huge advantages that have been outlined by Lord Condon for continuing with data sharing on security issues. I wonder whether there is consideration within government of retaining the Court of Justice as the arbiter for that aspect only. It seemed to me in our earlier investigation of policing and security matters that retaining some involvement in the Court of Justice was a critical factor in retaining data sharing on security issues.
Matt Hancock MP: The Prime Minister has been clear that it is one of our core positions on Brexit that we will not be under the jurisdiction of the ECJ. That does not mean that this cannot be done.
Baroness Pinnock: I look forward to seeing the outcomes.
Q7 Lord Watts: You told the EU Internal Market Sub-Committee that you are “confident” that the Data Retention and Investigatory Powers Act is consistent with the GDPR, even after the CJEU has ruled that some of the Act’s provisions are unlawful. What did the CJEU get wrong? What are the implications for the Investigatory Powers Act?
Matt Hancock MP: I think that I said that I was very confident. The GDPR sets out general safeguards for the protection of personal data. That is its overall role. The relevant provisions of the Data Retention and Investigatory Powers Act 2014, which are now repealed, were consistent with those safeguards. The CJEU has since given its judgment, which sets out further detail on the interpretation of the Digital Rights Ireland case—it is linked to the cases that we discussed earlier—and the requirements of the Charter of Fundamental Rights. It has not ruled on the lawfulness of the 2014 Act and was clear that the judgment must now return to the domestic courts, to allow them to determine how national legislation meets its terms. We are confident that the Investigatory Powers Act is consistent with the GDPR. However, because there are domestic legal proceedings ongoing, I cannot go into the detail much more.
Q8 The Chairman: Minister, I want to raise a broader issue. It is about the scrutiny process. The Committee has expressed disappointment about how the scrutiny of the data protection package has been handled by your department—particularly on the umbrella agreement, which incurred two scrutiny overrides. We would like to hear what steps your department is taking to ensure that those issues do not recur. We take the scrutiny process very seriously.
Matt Hancock MP: We take the scrutiny process very seriously. I would like to plead special circumstances. Two things happened at once this summer, neither of which is particularly regular, and one of which happens very rarely. First, at the time of the negotiations around the umbrella agreement, there was not only a reshuffle but a change of Administration. As you will understand, that meant that more time was taken to clear cross-government agreement on some positions, with the new Administration in place. That happened at the same time as something that is really unusual—the fact that the European Commission brought forward its proposals at a faster pace than expected.
We were in a position where it was moving faster than expected and we had had a recent change of Administration. The combination of those things meant that we were not able to reply in the normal way. I understand that, because the timescales were foreshortened, the timing of your meetings did not fit into them. I am very sorry that the scrutiny process could not happen in the normal way, but I hope that you will accept my plea of exonerating circumstances. We have processes in place to ensure that scrutiny happens appropriately and properly in future.
There was also an accelerated timetable in Europe in December. Of course, I am very happy to respond to any of your queries in this area, consistent with maintaining our position on our negotiating stance, and to appear in front of the Committee to explain it. However, I took the view that the crucial thing was to ensure that we had a negotiating position that could push the British objectives, even though we could not have that cleared through scrutiny in time.
The Chairman: We recognise that scrutiny overrides are sometimes essential. I note your explanation, but I think that it will be helpful in future if we can have processes that mean that we do not incur unnecessary scrutiny overrides.
Matt Hancock MP: That is absolutely what we should aim for. Of course, I reserve the right, especially if things move more quickly in Brussels than anticipated, to make and articulate a UK position within the timescales necessary.
Lord Soley: Although one understands the importance of the negotiating position, can I re-emphasise that the underlying argument is about the supremacy of Parliament, and Parliament being able to hold the Executive to account? Is that not an overriding factor?
Matt Hancock MP: Indeed. I suppose that my appearance here today demonstrates the effectiveness of that. However, you will understand that sometimes we have to win an argument. Sometimes that means acting very quickly. In that case, we apply for a scrutiny override, but sometimes we just have to go ahead and do it, in the national interest.
The Chairman: That is all from us. Thank you very much for your time. If you could write in response to the questions that Baroness Massey asked, we would be very grateful.
Matt Hancock MP: Yes.
The Chairman: Thank you very much.
Matt Hancock MP: It is a pleasure.