Skip to main content

Insight article

November 3, 2017

The Data Protection Bill: How will it affect e-business?

How safe is your customers’ data? Are you managing their information responsibly, and, more importantly, correctly in the eyes of the law?

The new Data Protection Bill is designed to update the existing laws, and hopefully plug a few gaps along the way. It is big, it is important, and it affects every single business that collects any kind of client or customer data, no matter how inconsequential a tiny packet of data may seem. It also gives your customers the ‘right to be forgotten’ – a major development and one you must be aware of.

The new bill gives greater customer consent over not only how their personal information is used, but how it is stored, who has access, and how long companies can keep that information on file. The bill also means that customers can now request that their data is returned to them, and the holder is obliged to comply.

Given the number of massive data breaches over the past couple of years (from the TalkTalk debacle through to the most recent NHS hack), it is about time that something was done to give the public a little more confidence in how businesses and the public sector, stores and uses personal data.

Tying in with GDPR

The Data Protection Bill is designed to herald the introduction of EU guidelines as laid down in the sweeping GDPR regulations, which land on our shores in less than a year and are set to be implemented into UK legislation, regardless of whether or not we’re in the EU at the time. Brexit be damned – GDPR is coming and everyone will have to fall into line.

The combination of GDPR and the Data Protection Bill demonstrates very clearly that the UK government is taking data protection very seriously. It is no surprise though, as the government cannot afford not to treat the issue of data protection as a priority. It has the potential to affect every single person in the UK, who also just happen to be voters.

It is also a message to our EU partners that post-Brexit, the UK will have a ‘strong and stable’ data protection policy, ensuring that businesses trading with UK companies can do so with confidence, and without worrying whether a data leak will compromise their personal information.

The impact on e-businesses

So, what does all this mean for e-businesses? Well, because e-businesses are at the very forefront when it comes to using personal data, and trust is always an issue when it comes to online activity, they are going to have to respond quickly and proactively to any changes.

Industry leaders believe that the new act raises the bar for businesses, especially as the information covered by the bill has been extended. Businesses will now need to protect not only the financial information of their customers, but their IP addresses, online DNA and even cookies. So, everything from postcodes to browsing history is protected.

Taking another look at your T&Cs

Businesses will need to have an effective consent policy in place, so their Terms & Conditions documents may need looking at again. Businesses cannot get around the legislation by claiming ignorance, either, so they’ll have to know exactly how and where data is being stored.

The ‘right to be forgotten’ will be eagerly seized upon by a public that’s increasingly concerned about just how much exposure their personal data is subject to online. However, e-businesses that demonstrate a good understanding and a flawless interpretation of the new legislation could benefit from these changes, by raising customer trust levels to new heights. Those who don’t comply will find a rapid decline in customers, as their demographic seeks out competitors who offer a more secure online environment.

Non-compliance could be expensive, too, with fines of up to 4% of global turnover. That means fines could run into millions of pounds, so effective data management just took on a whole new level of importance for e-businesses of all sizes.

Compliance is a necessity

The key is to identify exactly which data is subject to the new legislation, and to ensure compliance. That could mean legal experts who are specialists in e-commerce and data protection legislation are going to be busy over the coming months, as businesses rush to ensure they’re complying fully. From T&C documents and operational guidelines, through to data management policies and compliance with the ‘right to be forgotten‘ legislation, staying on the right side of the Data Protection Act and GDPR has never been more important.

The existing Data Protection Act was created before e-commerce was even a ‘thing’. Because the pace of change has been so fast, customers’ expectations and how they use e-commerce has changed well beyond the limits of the current law, which is why the new legislation has been brought in.

With just months to go before GDPR goes live, businesses must act sooner rather than later to ensure they are complying.

Speak to Karen Cole today to check you are ticking all the right Data Protection boxes.

Note: This is not legal advice; it is intended to provide information of general interest about current legal issues.

Stay in touch

Subscribe to our newsletter

Stay in touch

By completing your details and submitting this form you confirm you are happy for us to send you marketing communications and that you agree to our Website Privacy Policy and Legal Notice and to us using Mailchimp to process your data.


Sending

News/Insight

  • The Employment Rights Act is a call to action for employers 
    A new year, a new employment framework: what employers need to know about the Employment Rights Act passed by parliament in December 2025.


    Read more
  • Dilapidations explained: What commercial tenants and landlords need to know
    Dilapidations are a common source of dispute at the end of a commercial lease. They can involve significant sums of money and often come as an unwelcome surprise to tenants who believed they had left a property in reasonable condition. Understanding


    Read more
  • The role of due diligence in corporate transactions
    In corporate transactions, due diligence is a key stage that usually follows agreement of Heads of Terms, allowing the Buyer to investigate the target company or its assets before committing to the deal.


    Read more
  • Love in later life and the inheritance tax trap
    Increasingly, lawyers are seeing couples who have chosen to live together rather than marry, sometimes for many years, without fully appreciating how differently the law treats them, particularly when it comes to inheritance tax and financial protect


    Read more
  • Understanding Heads of Terms in corporate transactions
    Heads of terms are a crucial first step in corporate transactions. Learn what they include, why they matter, and how they shape successful deals.


    Read more

What they say...

  • Amish Bristol, January 2026
    Absolutely brilliant, fast, professional, clear and delivered a robust service “Recent mortgage oversight from Ben Marks and Anne was superbly dealt with, and I intend on moving all my business to them. For a big firm, they really do pay attent

  • Client, January 2026
    Excellent experience “The process of my work was quick and effective.”

  • Vicky, January 2026
    Clear, friendly, helpful “Very efficient and helpful with arrangements for my will.”

  • R Cook, December 2025
    Settlement Sorted “Grayson Stuckey was great. Efficient and friendly with all aspects of the support provided. We worked well together and achieved a positive outcome. Recommended.”

  • Ivan Naisbitt, December 2025
    More than just a service “Michael Davies has been representing me for about 35 years, and I cannot recommend him or RIAA Barker Gillette (UK) highly enough. Aside from the normal conveyancing, he is always on hand to advise and guide you throug

Read more
Send this to a friend