RISK

NEWS

Firms warned to be responsible when transferring client data

25 Nov 2020

The current economic climate is changing the way many firms operate, causing some to leave the market or merge with other firms. When this happens, the Financial Conduct Authority (FCA) is warning, firms must make sure they lawfully process and transfer client data.

What firms need to consider
Principles in the FCA Handbook require firms to organise and control their affairs responsibly and effectively, with adequate risk management systems (Principle 3). Before transferring clients’ personal data, firms should consider whether this is fair to and in the interests of their clients (Principle 6). Firms should also pay due regard to the information needs of their clients and communicate with them clearly and fairly (Principle 7).

Data protection legislation and the Information Commissioner’s Office
Data protection legislation applies to data controllers such as firms, compliance consultants, insolvency practitioners and liquidators. The Information Commissioner’s Office (ICO) is responsible for regulating and enforcing information and privacy rights in the UK. Relevant legislation includes:

  • Data Protection Act 2018 (DPA);
  • General Data Protection Regulation (EU) 2016/679 (GDPR); and
  • Privacy and Electronic Communications Regulations (EC Directive) 2003 (PECR).

How firms must protect client data
GDPR requires firms to provide information to clients clearly setting out ‘privacy information’, which includes the purposes for which they are collecting or processing client data, and individuals’ rights when their data is processed. Further detail on information that must be given when client data is collected, usually when taking on new clients, is available at the ICO Right to be informed page.

Firms should generally ensure they maintain a record of how and why they process, share and retain personal data. The ICO provides guidance on documentation and guidance on records management and security expectations.

Firms should also record the lawful basis for processing data. If they are processing data based on consent, they should maintain an effective audit trail of how and when consent was given. The ICO provides guidance on obtaining, recording and managing consent and guidance for small organisations.

How consumer interests are protected
The FCA will act where it identifies breaches of relevant parts of the FCA Handbook. Firms that intend to transfer or receive personal client data must be able to demonstrate how they have considered the fair treatment of consumers and how their actions comply with data protection and privacy laws.

The impact of Brexit
The GDPR currently has direct effect in the UK. At the end of the Brexit transition period the GDPR provisions will form part of retained EU law, with amendments made by DP exit regulations under the European Union (Withdrawal) Act 2018. The DPA 2018 and PECR will continue to apply, alongside the GDPR. There will be some amendments to ensure they work in a UK-only context. The ICO has produced guidance on data protection for the end of the transition period, which is regularly updated.

You may also be interested in

RELATED CONTENT

RELATED COURSES

Risk Assessment and Method Statements (RAMS)
Risk Assessment and Method Statements (RAMS)

The Risk Assessment and Method Statement (RAMS) course examines the HSE’s recognised five-step approach to risk assessment.

IOSH Managing Safely
IOSH Managing Safely

The world’s best-known health and safety certificate, designed for managers and supervisors in any sector or organisation.

IOSH Safety for Executives and Directors
IOSH Safety for Executives and Directors

IOSH Safety for Executives and Directors is designed for those who have operational or strategic accountability for a company.

Introduction to health and safety
Introduction to health and safety

Introduction to health and safety gives learners a basic introduction to managing safety in their workplace.

Data breaches: your best chance of survival
Data breaches: your best chance of survival

Data breaches: your best chance of survival

Data Sharing Code of Practice laid before Parliament
Data Sharing Code of Practice laid before Parliament

The government has laid a code of practice on data sharing before Parliament, which aims to assist organisations in legally sharing data.

Firms warned to be responsible when transferring client data
Firms warned to be responsible when transferring client data

The current economic climate is changing the way many firms operate, causing some to leave the market or merge with other firms. When this happens, th...

TikTok fined £12.7 million for misusing children’s data
TikTok fined £12.7 million for misusing children’s data

The Information Commissioner’s Office (ICO) has issued a £12,700,000 fine to TikTok Information Technologies UK Limited and TikTok Inc (TikTok) for a ...