Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassW0rd – 22nd June 2016

PassW0rd – 22nd June 2016

Play

Speaker A: This program is brought to you by Resonance 104.4 FM. If you like what you hear and want to support our work, please make a donation at fundraiser.resonance.fm.

Speaker B: Hello and welcome to Password on Resonance 104.4 FM with me, Peter Warren. The technology show that brings you the background on the most important issues in the technology world. In today’s show, as we move into the last days of campaigning for the UK’s referendum on whether it should stay in Europe, we look at the issues surrounding the UK’s data economy and what impact a withdrawal from Europe could have on the UK’s participation with European data. Following exhaustive research into the views of leading figures in the IT world, we find once again a picture of uncertainty, with those bent on leaving stating that a new world free of EU regulation will see a sudden burst of expansion by the UK in the field of technology, and those in the Remain camp maintaining that the EU is responsible for much-needed rules on the use of data that we will have to adopt come what may. Adam Afriye is a Tory MP, internet entrepreneur, and a fervent leaver who is the chair of the Parliamentary Office of Science and Technology. He says that the pace of change in the information age means that Brexit and a UK free of EU red tape means that the UK will be able to engage fully in the information age.

Speaker C: I think Brexit would be very liberating. If there’s one thing about the digital economy, having spent 20 years in IT before getting into politics, is things move very, very quickly. And were we to be outside the European Union, we would actually be in a great position because we’d be able to choose whether or not we allow our data standards to match those of the EU, or whether we choose to allow them to match what the Americans or the South Americans or the Australians or the Far East want. So I think we’d have greater flexibility by being outside of the European Union because we could choose whether or not we wished to adhere to the rules of the that they decide to set up for their own markets.

Speaker D: So how would that be an advantage? Because a lot of the lawyers that I’ve spoken to, a lot of the business people I’ve spoken to, said, well, actually, we’re going to have to comply to EU regulations to participate with the Europeans and their data anyway. We would have to put in something like a General Data Protection Regulation Act of our own.

Speaker C: Well, we may need to do so in order to deal with the European digital market. I think that’s accepted. If we want to do trade with Japan, we do likewise. But the point My point is that by being a sovereign nation once again and able to make our own decisions about how we function, then we can choose to nimbly adapt to whatever we think is in our economic interest. And as I say, it may well be that we have 3 or 4 sets of regulations, 3 or 4 different standards to deal with different parts of the world because, you know, the EU is a very small part of our world when you look at the booming economies elsewhere. And the other thing about the digital economy and also financial technology where we excel, it can move at the blink of an eye. In fact, a lot of it is extraplanetary. So I think that the one thing I think that sends a shudder down my spine is the idea that the EU had had some sort of digital single market when Berners-Lee was inventing the internet. I suspect we wouldn’t have an internet.

Speaker D: But that— the point has been made that that digital single market is worth €415 billion a year, and that many companies have been coming to the UK because they saw the UK as a very convenient way to get into that market.

Speaker C: Yeah, absolutely. And were we to choose to leave the EU, I’m quite— I feel quite confident, particularly with my business hat on, that we would continue to make sure we are compatible to a certain degree with what enables us to access the European market. But I would just pull back from this just for a moment, because the European Union is often talking about an awful lot of grand projects, you know, single markets, digital single markets. These things take years and years to come about, so it may well be if Britain chooses to leave, that 5 years from now they still haven’t decided what they’re doing and the entire world has moved on beyond the issues that they’re discussing. So I think the important thing is that I think we can remain at the forefront whether we’re inside or outside the EU, but I think we have more flexibility. And also there’s a sense that, for me, there’s a sense that we would stop looking kind of backwards into the 1900s and some old-style Soviet EU bloc, and we’d start looking outwards to the rest of the world, which is really where all the action is.

Speaker D: Just coming to that thing about flexibility, because flexibility is one of the points that has been made from some of the people I interviewed in America. What they’re saying is this is an opportunity for the UK to actually become an extremely attractive area because it’s developing new and different models that may not be as restrictive as those proposed by the EU.

Speaker C: Well, I think that’s absolutely right. I mean, when you look at the way that financial technology has developed, literally in the last 3 or 4 years, organizations like Funding Circle and many, many others, and their business models transform literally in a period of 18 months. So the idea that massive committees of bureaucrats will be able to keep pace the way in which the digital world changes, it’s pretty unlikely. But one thing is for sure, if Britain’s outside the EU, we’re right at the forefront of fintech and digital now. The Americans come here to use us as a sandbox testing area for some of their technologies because we’re so innovative and fast-moving. So With Britain on the outside of the EU, actually, we have the best of both worlds. Not only can we look to the rest of the world, but actually we can very nimbly and briskly adapt our technologies to fit the European model when they eventually come up with one.

Speaker D: Okay, now one of the points that everybody’s been making about all of this is that one of the potential sticking points could be the Data Regulation and Investigatory Powers Act that is just going through the Lords at the moment. What is your position on that? Is that an issue?

Speaker C: I think it will be a bit of an issue. I mean, it’s certainly an issue today because the reason that myself and many other MPs in the Commons allowed the IPA to go to the Lords was because the government was very clear that they were willing to back off on pretty much every point in order to get it to the Lords so we wouldn’t have a showdown in the Commons. So I think the actual Investigatory Powers Act, when it comes back from the Lords, will have hundreds and hundreds of amendments, and I suspect that there will be some changes to the bulk data collection powers as well. But let’s not forget, Europe is not the arbiter of good law. In fact, it’s quite often the opposite. Here in Britain, we are good people, we are moral people, we are, if you like, from Magna Carta onwards, we are the people that recognize the importance of civil society, of civil rights, of privacy, and of human rights. We’re almost the inventors of these concepts. So the idea that the British Parliament would do something crazy because we weren’t members of the EU is just for the birds. Many of the European models have actually been shaped on what we’ve developed here in Britain in the first place.

Speaker B: As far as Afriya is concerned, arguments that EU laws will be safeguards for us against the abuse of our data by intelligence agencies and business are unfounded. The UK outside of the EU will mean more opportunities. It’s not a point of view that Labour MEP Mary Honeyball agrees with. A passionate advocate of human rights who coordinates the EU’s Culture and Education Committee, Honeyball is not surprisingly a Remainer who claims that the opportunities for the UK are within the EU, affecting legislation that many see as a model for the information age.

Speaker E: I, I just feel that we are not isolated. We have to exist in a global world and we have to do business on all levels with the European Union. Therefore, we will have to carry out the data Protection Regulations because the EU will insist on that. And we have EU citizens living in this country that we will have to respect their privacy and their privacy under the General Data Protection Regulation. And we will have to comply with what the EU wants if we are going to do any meaningful business with the EU. So it’s there. We can’t escape it. We can’t do these things in isolation. The United States, of course, is in rather a different position. And they are a world leader and they are also a very large entity and they’ve been a world leader in high tech for a long time. So they’re not quite in the same position as Britain leaving the European Union and having to start all this all over again. And if we want to have any trade deals with, or trade at all with the European Union, having to carry out EU regulations.

Speaker D: Obviously the data protection regulations are seen as onerous and some people are saying, well, this is great for UK business, it’ll be able to avoid the €20 million fines that the EU can impose and— or the 3% of global turnover, so we won’t have to worry about looking after data in that way. Is that something that is good or bad?

Speaker E: Well, the thing about data is that it’s not specific to a particular nation. It’s global, that it’s not done in isolation. It’s not just UK data. It’s global. So there is bound to be a large measure of international regulation that you have to abide by. We just can’t simply go out and do it on our own. It’s just not possible in this environment. It’s not possible actually with very many things, but certainly not with data. So we’re left with having to really comply with what the EU wants. And if we come out of the EU, we will, I’m sure, have to implement the same kind of regulations because we won’t be able to do any business with the EU if we don’t. I mean, I think it’s very stark.. And those who say that we can avoid the fines and we can do it on our own are just living in cloud cuckoo land.

Speaker D: What do you think the implications are in terms of participating in the European data economy for the UK leaving the EU?

Speaker E: I think it would be an absolute disaster if the UK left the European Union. At the moment we are in the European, the EU single market, and if we left the EU we would have to leave the single market. If we wanted to stay in the single market, we would have to have some sort of arrangement by Norway, where Norway is in the single market but doesn’t have any say over what happens. That would be just the same in the digital single market, which is all part of the EU single market. So if we were to come out of the EU, we would still be faced with this problem of what we do with the single market. And the digital single market is important already, and it will only go on increasing in importance for Europe and of course for the UK.

Speaker D: Because it’s also worth a lot of money, isn’t it?

Speaker E: It’s worth huge amounts of money. It’s worth €415 billion a year, which is absolutely massive, and we would lose that commercial advantage. We would just lose that trade. That to me just seems absolutely ridiculous.

Speaker D: This legislation that the EU has put in place has been highly regarded by many in business, both here and on the other side of the Atlantic, where people are actually saying that these three measures are very, very well thought out. Not only the General Data Protection Regulations, but also the ePrivacy Bill and the Network and Security Directive. And many people are saying the General Data Protection Regulations are actually a wonderful framework for data security and for cybersecurity, which are important industries. Do you think it’s a shame, given all of that, that this appears to be the moment that we pull out? Or do you think that probably will end up doing that anyway, in which case it seems a little odd.

Speaker E: It does seem a little odd, and I think we will end up doing it anyway. As I understand it, the GDPR, the General Data Protection Regulation, will be coming into force in a couple of years’ time, in about this time, 2018. And that, of course, is the minimum period for us to disengage from Europe were we to leave. It’s at least a 2-year process. It will probably take a lot longer. So we might be in this very bizarre situation where we’re just about to take on board the directive, the regulation, while we’re just about to leave the European Union. This is a recipe for total chaos, and it just seems absolutely ridiculous to put ourselves into that position. And we may well find anyway that the UK would have to introduce something very like the General Data Protection Regulation because we will need to conform to European laws if we’re going to do any business in data, cybersecurity, or anything like that with the EU. So we would have to do it, I believe, anyway. It just seems to be an awful lot of red tape, even more red tape, an even longer process to achieve what we already had in the European Union.

Speaker B: So for Mary Honeyball, the EU is not only about access to an information market the EU claims is worth 15 billion euros a year, but it is also a recognition that the EU rules on data are good for us and the world, and because of that, we will have to implement them anyway. Being outside, Honeyball claims, will only mean more red tape because we will have to renegotiate with all of the member states if we want to engage with data on European citizens. So what are the two options that Adam Afria and Mary Honeyball are talking about. We spoke to two experts on data and regulation to try to get down to the fine detail on the sort of world that the UK’s IT powerhouse might face: Daniel Castro, vice president of the respected Washington-based think tank the Information Technology and Innovation Foundation, and Mark Deem, an expert in technology law with the global law firm Cooley, which numbers Google among its many technology clients. For Daniel Castro, the free flow of data underpins a new world of big data and the Internet of Things, and being outside of the EU will be good for the UK’s data economy. Like Afriye, Castro says the UK is innovative and has a potentially bright future outside of the EU.

Speaker F: You know, when you talk about how companies are using data and the opportunities to innovate around this space, UK is generally a lot more, I think, forward-thinking in its policies. And so here’s an opportunity for it, sucked into the stricter data protection rules of the EU, and carve out its own path for how to go forward and how to enable companies to innovate around data. And that’s a big opportunity that I think shouldn’t be ignored if they were to go down that route.

Speaker B: What is the value of this market?

Speaker F: What’s interesting is so much of the value, of course, comes from the ability to share and mix data from different sources. To the extent that this will limit the ability of companies in the UK to pull in datasets that they were using before, that can hurt them in the short run because it’s not just if they have a great analytics system that’s good, but are they still able to pull in different datasets they were using, that’s kind of one of the key questions that especially any British company that has a heavy export to the rest of the EU or heavy customer base or supplier base even within the EU, that’s going to slow down at least or add cost to how they’re doing business today.

Speaker D: So it will add a cost. Some sort of framework will have to have been put in place by the UK government to say, okay, these are the guidelines.

Speaker F: Right, well, I mean, they have, you know, of course, their data protection laws that were implemented to fulfill the— question is, you know, how they’ll change that over time when they’re no longer held to that. And that’s where there’s opportunities to both kind of relax some conditions, but then as they’re doing that, figure out what the impact that will be on doing business, you know, doing business with the rest of Europe. And that’s where, again, long term, I think there’s an opportunity to be in some ways very, very different than the rest of Europe and free up the use of data. But in the short term, these companies are going to be hit with a lot of uncertainty. It’s basically, it’s very similar to what US companies felt when the Safe Harbor agreement was invalidated. They had all this data that they were sending and exchanging on a day-to-day, if not hourly basis, and suddenly that transfer of data was possibly illegal. And there was a huge risk that these companies had to figure out how to deal with very quickly. There were current projects they had to sometimes stall. There are future projects that are on hold. And that’s a problem. I mean, that’s a big problem that companies will have to deal with. And it’s not something that the government itself will be able to address very easily on its own. It’s something that they would have to end up negotiating.

Speaker D: A lot of people are saying that this would actually mean we wouldn’t have to implement the General Data Protection Regulation. But a lot of other people are saying actually, no, you’re wrong. You would have to. What’s your position on that?

Speaker F: Yeah, I don’t think you’d have to. I mean, the only reason you would have to do it is if you wanted to meet the adequacy requirement. First path is do exactly what the GDPR is. The second path is do something that is equivalent or similar, but not the same. And the third is do something that’s different but has other protections in place. That’s more like what the US has done in terms of trying to get a Privacy Shield agreement. And so they have in that sense more flexibility because they have these three options.

Speaker D: Okay, let’s look at one of those, which is where does this put us in relation to the US? If we’ve been in a structure that was actually going through Europe before, i.e., the Privacy Shield, will we have to start up some new trade deals with the US to actually deal with the flow of data, or will it be easier?

Speaker F: Well, it can certainly be easier in the sense that, you know, the UK doesn’t have to wait to see what an Irish court or a German court or even the, you know, EU Court of Justice will say about an agreement. They can make an agreement directly with the United States and, you know, have data flowing the next day. I’m confident that on the US side there would be very quick engagement to do that. So, you know, there were— in that sense, that could be a very big opportunity because there are a lot of companies that are, you know, US-based, or even frankly, there’s a lot of European companies that might set up shop in the UK simply because it’s easier to do business with the US, you know, from a country with, you know, more flexible laws around data.

Speaker D: So does that then mean that the UK could have the potential to be a strange data haven on the outside of Absolutely.

Speaker F: I mean, in that sense, you know, just as we’re seeing with the Irish law has attracted a lot of companies for tax reasons, for, you know, kind of data reasons, the UK, by being very— if it chose to, could be a place that companies flock to for providing certain services. Now, one of the biggest concerns right now is, of course, how the government accesses corporate data, you know, the idea of mandatory access. And, you know, the UK with its Investigatory Powers Bill introduced and debated recently in the Parliament, I mean, that law goes further than some others, even in some cases the United States, in kind of setting out law enforcement, you know, access to personal data, putting potential restrictions on things like encryption. That could certainly scare off companies. So it creates the opportunity for UK policymakers to attract investment in this area and attract companies into this area. But that’s no guarantee that the policy that follows will necessarily actually do that.

Speaker B: Daniel Castro of the Washington-based think tank the Information Technology and Innovation Foundation. So once again, the Data Regulation and Investigatory Powers Act has raised its head as an obstacle for the UK if it leaves the EU. It’s something that is currently at the core of the debate for those in the technology world. One of the few surveys that came out for leaving was from the UK manufacturing sector. The majority of those coming from the computer industry were for remaining, ironically because of the General Data Protection Regulations, which protect privacy, the time data can be held for, and will push through mandatory data breach regulations that will make companies tell customers if they’ve been hacked. That’s a big draw for a cybersecurity industry which is keen to sell its products. So it’s no surprise that 65% of those working in the area, when surveyed 2 weeks ago at InfoSec, the industry’s annual get-together at Olympia, said they wanted to stay in Europe, adding their voices to the 90% of financial service professionals who said the same. Mark Deem, a lawyer specializing in technology for the legal giant Cooley, which represents a number of top high-tech firms, claims one of the main reasons is the uncertainty that an exit will generate at a time when the technology sector was preparing to embrace much-needed guidelines. More importantly, according to Deem, Europe’s data economy is a big draw for companies.

Speaker G: Well, the economy is so large as far as data is concerned, it just can’t be ignored. And so for those people who are in any way involved in data transfers or conducting business throughout the European Union, what it actually means is that they then have to consider their roles and their obligations in relation to two places. Firstly, the UK outside the European Union, and also in relation to the other 27 member states. Who are remaining within the European Union.

Speaker D: Okay, what are the institutions that we currently use to transfer data then?

Speaker G: We do— at the moment we are operating under the Data Protection Act of 1998, which itself is the implementation of a 1995 European directive. And we’re currently in a 2-year transition period, which will come to an end on the 25th of May 2018 with the direct implementation in UK law of the General Data Protection Regulation. That is significant because the new regulation brings into play a whole new regime for people who are looking to use, transfer, hold on to data of data subjects throughout the European Union. Now the reason why this is significant is because under the present timetable, should the referendum favor Brexit on the 23rd of June, then notice would be given by the UK government seeking permission to leave the European Union, which itself would then trigger a process of up to 2 years. And we could be in an unenviable situation where the regulation comes into effect directly on the 28th of May 2018, but we actually are still in the European Union at that stage.

Speaker D: So I mean, basically, what does this mean?

Speaker G: So at the moment, whilst we are heading on a path which is looking towards the implementation of the Data Protection Regulation for all businesses within the UK with effect from 2018, just because we’ve come out of the European Union in 2018, it wouldn’t mean that you could just ignore those provisions.

Speaker D: So for example, I’m a business and I want to work with another business in Europe and that this involves the transfer of some information about employees, then that of course become subject to, in Europe it will be subject to the General Data Protection Regulations. Here, something would need to be put in place so that it would actually satisfy people in Europe that that information was being treated properly.

Speaker E: Exactly.

Speaker G: So in many ways what we’ll be looking at is a two-tier regime. We’ll have to be compliant under UK law and at the moment it’s the ICO, the Information Commissioner’s Office, that is the supervisory authority. For data so that we comply with EU rules and supervising authorities throughout member states. That won’t be a problem if we in the UK decide that we’re going to effectively implement precisely the same terms as the regulation upon exit. But in reality, it is very difficult to see how we can implement those same terms when the European General Data Protection Regulation deals with issues concerning cooperation, and the way in which data supervisory authorities deal with one another.

Speaker D: And of course there’s another issue here, isn’t there, which is a huge one, which is in effect we would be in a similar position to America. America’s trying to negotiate something called the Privacy Shield at the moment.

Speaker G: That’s right. And I mean, the one thing to bear in mind as well, of course, concerning the Privacy Shield is that is a process that is being put in place between the European Union and the the government of the United States. Now obviously if we come outside the European Union, then we would have to negotiate our own separate provision for data transfers as between the UK and the United States as well.

Speaker D: We have an issue, don’t we? We have an issue with the Data Regulation and Investigatory Powers Act.

Speaker G: We certainly do, and the position that we’d find ourselves in is whilst it might be adequate as far as the EU is concerned, we may not have that same adequacy as far as the UK is concerned, and we may end up in a situation where a regime that is put in place for privacy purposes could be potentially struck down under, under DRIPA.

Speaker D: It’s a fascinating situation. Obviously what this is doing is just increasing the uncertainty, isn’t it?

Speaker C: Absolutely.

Speaker G: We’ve been looking to try to increase certainty and get ourselves into a far better position concerning data protection over a number of years now. The General Data Protection Data Protection Regulation itself was first thought of back in 2012, and it’s taken 4 years to get it to a position where the final text has been agreed. We’re now in a 2-year transition period, so it’s taken a long time to get us tantalizingly close to a position where we have some degree of consistency, some degree of certainty, and unfortunately the referendum has now thrown up a whole complex network of issues. Which could ultimately seek to create further uncertainty and put British businesses in a worse position over the coming years.

Speaker D: So what will the short-term consequences of all of this be?

Speaker G: Initially, I think things will go slightly quiet and people will really realize very quickly that they have to carry on working towards the implementation of the General Data Protection Regulation or dealing with the consequences of that within their business.

Speaker B: Mark Deem of the law firm Cooley, who claims that one of the possible beneficiaries of a UK exit could be Dublin because of its attractive tax regime, predominantly English-speaking population, highly educated IT-literate workforce, similar legal system, and the fact that it would be inside the EU data zone. A Brexit, according to Deem, could see more IT businesses setting up in Southern Ireland. You’re listening to Password on Resonance FM with me, Peter Warren, and we’ve been discussing the ramifications of a Brexit on the UK’s IT sector. If you’ve just joined us, I’m afraid you’ve missed it, but you can listen again on Mixcloud. Password is brought to you by Future Intelligence and the Cybersecurity Research Institute, and if you’d like to find out more about the issues raised on the program, Go to our website on www.futureintelligence.co.uk.

Speaker D: Thanks for listening and goodbye.

Speaker A: This program has been brought to you by Resonance 104.4 FM. If you liked what you heard and want to support our work, please make a donation at fundraiser.resonance.fm.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00