ENGLAND & WALES Law and Practice Contributed by: James Ross, Paolo Palmigiano, Debbie Cloake, Helen Farr, Debbie Heywood and Louise Popple, Winston Taylor
9. Looking Forward 9.1 Upcoming Legal Reforms
legislation, it imposes security requirements through - out the supply chain. A variety of other sector-specific cybersecurity laws may be relevant, and the D(UA)A also introduces new provisions relating to the sharing of personal and non- personal data, the detail of which will be brought in Most of these laws have extraterritorial effect, apply - ing to businesses operating in the UK, targeting or supplying the UK, or processing the personal data of UK individuals, regardless of the organisation’s loca - tion. The UK GDPR applies to any organisation pro - cessing the personal data of UK individuals where the processing relates to offering them goods or services, or to monitoring their behaviour. It applies to the pro - cessing of personal data by a controller or processor in the context of an establishment located in the UK, regardless of where the processing takes place. There are strict rules around the export of personal data from the UK. 8.3 Role and Authority of the Data Protection Agency The Information Commission (IC) is the agency in charge of enforcing data protection and cybersecu - rity rules, and it also produces guidance and codes of practice (notably the Children’s Code, which covers the processing of children’s personal data by online services). The IC has various powers. Under the UK GDPR, for example, it has a range of enforcement powers, including to impose fines for non-compli - ance of up to the higher of GBP17.5 million or 4% of annual global turnover. Data controllers are required to pay annual fees to the IC of between GBP52 and GBP3,763 depending on their size and subject to minor exceptions. under secondary legislation. 8.2 Geographical Scope
The UK commenced a review of its design laws in 2025. This follows amendments to the EU design regime. The UK is expected to pass the Cyber Secu - rity and Resilience (Network and Information Systems) Bill in 2026. This will expand and update the scope of the current NIS Regulations largely (but not wholly) in line with the EU NIS2 Directive, which was enacted after Brexit. The government plans to legislate on AI, although this is expected to cover AI infrastructure rather than AI safety. New restrictions on filing documents at Companies House are expected to take effect no earlier than November 2026. Only directors or employees of a company who have verified their identity at Compa - nies House will be able to file on behalf of that com - pany, other than authorised intermediaries who are registered with Companies House. Identity verification requirements for corporate directors, relevant legal entities with control and corporate members of LLPs, as well as new restrictions on the use of corporate directors, are expected to take effect at a similar time. The UK government consulted on proposed amend - ments to the NSIA notification regime in 2025 and published its response in March 2026. The proposed changes will refine the scope of mandatory filings by introducing new sensitive sectors (including water, critical minerals and a standalone semiconductors category) while narrowing certain definitions, particu - larly in relation to AI, to focus the regime more closely on transactions that present genuine national security risks. The reforms are expected to be implemented later in 2026; until then, the existing NSIA rules remain in force.
347 CHAMBERS.COM
Powered by FlippingBook