With all the attention on GDPR and the Article 29 Working Party guidance it would have been easy this month to overlook the Digital Economy Act 2017 and its impact on the funding of the ICO.
Whilst the ICO receives an annual grant-in-aid from the Department for Culture, Media and Sport it also funds itself through the current legal notification obligation and fee payment by data controllers under the Data Protection Act 1998. GDPR removes the notification requirement as it increases responsibility for data processors and takes a wider view at the overall processing function irrespective of which party is actually doing the processing. The Digital Economy Act 2017 includes a provision prospectively repealing the notification and fee obligation and states”the secretary of State may by regulations require data controllers to pay charges of an amount specific in the regulations to the Information Commissioner.”
The ICO may now be confident of its future, but can data controllers also be confident that fining under GDPR will not be the sole source of funding for the UK regulator and that a similar approach to fining by the ICO will continue in the new post GDPR world? Only time will tell – watch this space for more.