Skip to content

Why does the UK Data Protection Bill exempt the ‘risk profiling’ industry?

Anyone trying to open a bank account or send money overseas must undergo extensive risk assessment by private data-brokers, which amass non-credible data and falsely blacklist the wrong people on a speculative basis.

Published:
4475786680_d8a00179c4_b.jpg
4475786680_d8a00179c4_b.jpg

Flickr/Al Ibrahim. CC BY-SA 2.0.The EU General Data Protection Regulation (GDPR) is one of the most important pieces of human rights and consumer protection legislation of the 21st century. It extends the rights we have as citizens and overhauls a framework developed in the 1990s that governs the way states and corporations can collect and use information about us. The GDPR also allows the free movement of personal data across the EU and the government’s decision to seek to implement the measure in full, regardless of the Brexit negotiations, is a mark of its importance.

However, the bill transposing the GDPR into UK law is complex and labyrinthine. As the GDPR must be applied by May next year, the government has set a tight legislative timetable for its passage, and the bill has already had its second reading in the Lords.

Yet to be raised is the significance of the exemptions set out in Schedule 2 to the Bill, which, as drafted, would potentially remove entire industries dedicated to vetting, profiling and blacklisting private individuals from the reach of the law. Whether intentional or not, the language it contains means that private companies that vet people on behalf of banks, employers and landlords could claim exemption.