0% found this document useful (0 votes)
3 views7 pages

IT Assignment

The document outlines the evolution and key provisions of the UK's Data Protection Act (DPA), highlighting its historical context from the 1984 Act to the 2018 iteration, which aligns with the GDPR. It discusses the impact of the DPA on corporate accountability, individual empowerment, and the challenges posed by emerging technologies. Additionally, it touches on the Obscene Publications Act (OPA), distinctions between slander and libel, and various compliance types in IT law.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views7 pages

IT Assignment

The document outlines the evolution and key provisions of the UK's Data Protection Act (DPA), highlighting its historical context from the 1984 Act to the 2018 iteration, which aligns with the GDPR. It discusses the impact of the DPA on corporate accountability, individual empowerment, and the challenges posed by emerging technologies. Additionally, it touches on the Obscene Publications Act (OPA), distinctions between slander and libel, and various compliance types in IT law.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Question 1: The History of the Data Protection Act (DPA)

Introduction

The regulation of personal data has become one of the most important areas of modern law.
As digital technology, e-commerce, and online services increasingly permeate every aspect of
life, the ability of governments, corporations, and even individuals to collect, process, and
disseminate personal data has raised profound questions about privacy and accountability.
The United Kingdom’s Data Protection Act (DPA), now in its 2018 iteration, is the primary
legal instrument designed to safeguard individuals’ privacy while balancing the legitimate
interests of organisations. This section explores the history, key provisions, and impact of the
DPA, with attention to how the law has evolved in response to technological, political, and
social pressures.

Historical Background

The Early Stages: Data Protection Act 1984

The earliest attempt to regulate data in the UK was the Data Protection Act 1984, enacted
following international pressure, particularly from the Council of Europe’s Convention 108
(1981), which was the first binding international treaty on data protection. The 1984 Act
created a framework requiring data controllers to register with the Data Protection Registrar
and imposed duties relating to accuracy and security of personal data. However, its scope was
narrow, covering only computerised records and excluding manual files, which limited its
effectiveness.

The Data Protection Act 1998

The Data Protection Act 1998 represented a major step forward, aligning UK law with the
European Data Protection Directive (Directive 95/46/EC). Unlike the 1984 Act, it
extended protection to manual filing systems and broadened the rights of individuals, such as
access to personal data, correction of inaccuracies, and the ability to prevent certain
processing activities. It introduced the eight data protection principles, which became the
cornerstone of UK data protection law.

Nevertheless, rapid digitalisation in the early 2000s exposed weaknesses in the 1998 Act. The
rise of social media, online retail, targeted advertising, and big data analytics created
new risks, such as profiling, mass surveillance, and large-scale data breaches. These
developments led to mounting calls for reform at both domestic and European levels.

The General Data Protection Regulation (GDPR) and DPA 2018

In May 2018, the GDPR came into effect across the European Union. In the UK, it was
implemented alongside the Data Protection Act 2018, which repealed most of the 1998 Act.
The DPA 2018 supplements the GDPR by creating rules specific to the UK context,
including provisions for law enforcement processing, national security exemptions, and the
regulation of intelligence services.
Importantly, following Brexit, the UK retained the DPA 2018 but amended it through the
Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit)
Regulations 2019. This created the so-called “UK GDPR,” which mirrors EU standards but
is subject to domestic interpretation.

Key Provisions of the DPA 2018

1. Lawful Bases for Processing


Organisations must demonstrate a clear lawful basis before processing personal data.
The main bases include consent, contractual necessity, compliance with legal
obligations, protection of vital interests, performance of tasks in the public interest,
and legitimate interests of the data controller.
2. Consent Requirements
The Act strengthens rules around consent, requiring it to be freely given, specific,
informed, and unambiguous. Pre-ticked boxes or silence no longer qualify as valid
consent.
3. Individual Rights
The Act enhances data subject rights, including:

 Right of access (data subject access requests)


 Right to rectification
 Right to erasure (the “right to be forgotten”)
 Right to data portability
 Right to object to processing
 Rights related to automated decision-making and profiling

4. Special Category Data


Stricter rules apply to sensitive categories of data, such as health records, political
beliefs, or biometric information.
5. Fines and Enforcement
The Act, aligned with GDPR, empowers the Information Commissioner’s Office
(ICO) to impose significant fines for breaches: up to €20 million or 4% of global
annual turnover.
6. Data Protection Officers (DPOs)
Public authorities and organisations engaged in large-scale monitoring or processing
of sensitive data must appoint a DPO to oversee compliance.
7. Children’s Data
Special protections apply to children’s personal data, particularly concerning online
services. Consent for processing children’s data must be verifiable, with a default
minimum age of 13 in the UK.

Impact of the DPA 2018

Corporate Accountability
The DPA has forced organisations to adopt stricter compliance measures, such as data
protection impact assessments (DPIAs), staff training, and stronger security systems. High-
profile enforcement actions illustrate this accountability, such as the ICO’s fines against
British Airways (£20m, 2020) and Marriott International (£18.4m, 2020) for data
breaches.

Empowerment of Individuals

The Act empowers individuals to control their digital identities, enhancing trust in digital
commerce. For instance, the Google Spain v AEPD (2014) case, though an EU decision,
resonates strongly in the UK, confirming the enforceability of the right to erasure.

International Trade and Brexit

The EU granted the UK an “adequacy decision” in June 2021, allowing personal data to flow
freely from the EU to the UK. However, this adequacy decision is conditional and may be
revoked if UK law diverges too far from EU standards.

Criticism and Challenges

 Complexity: The coexistence of the DPA 2018 and GDPR provisions has been
criticised as overly complex.
 Enforcement limits: The ICO has faced criticism for not using its full enforcement
powers.
 Technology gaps: New technologies such as artificial intelligence, facial recognition,
and big data analytics challenge the adequacy of existing protections.

Conclusion

The history of the Data Protection Act illustrates the UK’s evolving response to the
challenges of regulating personal data in a digital society. From the limited protections of the
1984 Act to the comprehensive framework of the 2018 Act, the trajectory reflects the
growing recognition of data as both an asset and a vulnerability. While the DPA 2018 has
strengthened individual rights and corporate responsibilities, future reforms may be required
to address emerging technologies and the post-Brexit landscape. In this sense, data protection
remains a dynamic and contested field of law, balancing privacy, commerce, and state
interests in the information age.

Question 2: The Aim of the Obscene Publications Act


(OPA)
Introduction

The regulation of obscene materials is a long-standing legal issue, reflecting the need to
protect public morality while safeguarding freedom of expression. The Obscene
Publications Act (OPA) 1959, alongside its amendments in 1964, remains a cornerstone of
UK obscenity law.

Purposes of the OPA

1. Preventing Distribution of Obscene Material


The OPA criminalises the publication, distribution, or possession of obscene material,
extending to books, magazines, films, and digital content.
2. Protecting Morality and Social Values
The law seeks to preserve public decency, especially for vulnerable groups such as
minors. Courts apply the “deprave and corrupt” test to evaluate whether material is
legally obscene.
3. Landmark Case: Lady Chatterley’s Lover (1960)
One of the most famous applications of the OPA was R v Penguin Books Ltd (1960),
where the court acquitted Penguin Books for publishing D.H. Lawrence’s novel. This
case highlighted shifting societal norms around sexuality and literature.
4. Addressing Technological Change
The OPA has been applied to online content, such as in R v Fellows & Arnold (1997),
which confirmed that digital materials fell within the Act’s scope.
5. Preventing Exploitation of Children
The Act intersects with the Protection of Children Act 1978, which prohibits
indecent images of minors. Together, these laws tackle child pornography and online
exploitation.
6. Enforcement and Penalties
The OPA empowers law enforcement to seize obscene materials and prosecute
offenders. Penalties include fines and imprisonment. The Video Recordings Act
1984 expanded these principles to regulate video content.
7. Modern Developments
Emerging challenges such as online pornography, “revenge porn,” and AI-generated
explicit content have forced lawmakers to revisit obscenity law. The Online Safety
Bill 2023 seeks to extend OPA principles into the digital era, compelling technology
companies to remove harmful content.

Critical Discussion

The OPA has faced criticism for being vague and open to subjective interpretation. While it
protects vulnerable groups, it raises concerns of censorship and potential suppression of
artistic freedom. Striking a balance between morality and free expression remains a central
challenge.

Question 3A: Distinction Between Slander and Libel in


English Law
Introduction
Defamation law exists to protect individuals and organisations from reputational harm caused
by false statements. Under English law, defamation is divided into slander and libel, with
distinctions historically based on the medium of publication.

Definitions and Key Differences

1. Libel – Defamation in permanent form (e.g., written statements, recordings,


broadcasts, or online posts). Traditionally treated as more serious since written words
have wider reach.
2. Slander – Defamation in transient form (e.g., spoken words or gestures). Historically
harder to prove unless actual damage can be shown, with exceptions for allegations of
crime, contagious disease, unchastity, or professional incompetence.

Case Examples

 McAlpine v Bercow (2013): A tweet insinuating involvement in child abuse was found
libellous, showing that social media is treated as permanent publication.
 Sim v Stretch (1936): Defined defamatory meaning as words lowering the plaintiff in
the estimation of right-thinking members of society.

Reforms under the Defamation Act 2013

The 2013 Act introduced the “serious harm” test, requiring claimants to show actual
reputational damage. This reform aims to curb trivial claims while addressing online
defamation.

Conclusion

While slander and libel distinctions persist, the digital age blurs boundaries since even spoken
words may be recorded and widely disseminated. Modern law increasingly focuses on impact
rather than form.

Question 3B: How the Web Creates Legal Problems


ICANN and the Multi-Stakeholder Model

The Internet Corporation for Assigned Names and Numbers (ICANN) manages domain
names and IP addresses under a multi-stakeholder governance model. While inclusive, this
model has led to disputes over jurisdiction, cyber-squatting, and trademark abuse.

 Example: Companies have faced “cyber-squatters” registering domain names in bad


faith, leading to disputes resolved through ICANN’s Uniform Domain Name Dispute
Resolution Policy (UDRP).

Interflora v Marks & Spencer (2014)


This case clarified trademark use in keyword advertising. The Court of Appeal ruled that
Marks & Spencer’s use of Interflora’s trademark in Google Ads could mislead consumers,
amounting to infringement.

Other Internet Legal Challenges

1. Jurisdictional Issues – Online offences often cross national borders, complicating


enforcement.
2. Privacy and Data Protection – Social media platforms routinely collect massive
amounts of personal data, raising compliance concerns.
3. Intellectual Property Violations – File-sharing, digital piracy, and copyright
infringement remain widespread.
4. Cybercrime – Fraud, hacking, phishing, and identity theft create ongoing threats.
5. Online Harassment and Hate Speech – The web amplifies defamatory speech,
bullying, and extremist propaganda.

Conclusion

The web magnifies legal complexity by transcending territorial boundaries, challenging


traditional legal frameworks, and forcing continual legal adaptation.

Question 4A: Definition of Compliance


Compliance in IT law refers to adhering to legal, regulatory, and ethical standards governing
digital practices. It ensures that organisations respect laws such as the GDPR, Equality Act
2010, and sector-specific rules. Compliance encompasses policies, audits, staff training, and
risk management systems.

Question 4B: Types of Compliance in IT Law


1. Accessibility Compliance

Accessibility compliance ensures digital services are inclusive for people with disabilities, in
line with equality and human rights legislation.

 Examples of measures: alternative text for images, closed captions, keyboard


navigation, screen reader compatibility.
 Case Law: Robles v. Domino’s Pizza (2019) in the US established that inaccessible
websites violate disability rights.

2. E-Discovery Compliance

Electronic discovery (e-discovery) requires organisations to preserve and provide electronic


evidence during litigation.
 Key Benefits: prevents destruction of evidence, ensures transparency, and assists in
investigations.
 Case Law: Zubulake v. UBS Warburg (2004) highlighted employer obligations to
preserve emails during litigation.

3. Cybersecurity Compliance

With rising cyber threats, compliance with standards such as ISO 27001 and frameworks like
the NIS Directive is crucial. These aim to prevent data breaches and protect critical
infrastructure.

4. Data Retention and Privacy Compliance

Organisations must manage how long personal data is stored and ensure lawful disposal.
Non-compliance risks significant penalties.

Conclusion

Compliance in IT law is not merely a regulatory burden but a safeguard for business integrity,
public trust, and individual rights.

References
 Data Protection Act 2018 (UK)
 Defamation Act 2013 (UK)
 Equality Act 2010 (UK)
 General Data Protection Regulation (GDPR) 2018 (EU)
 Google Spain v. AEPD (2014)
 Interflora v. Marks & Spencer (2014)
 ICANN Domain Name Dispute Policy (2019)
 Lloyd, I. J. (2017). Information Technology Law. Oxford: Oxford University Press.
 Murray, A. (2016). Information Technology Law. 3rd edn. Oxford: Oxford University
Press.
 Rowland, D., Kohl, U., & Charlesworth, A. (2017). Information Technology Law. 5th
edn. London: Routledge.
 Robles v. Domino’s Pizza, 913 F.3d 898 (2019).
 R v Penguin Books Ltd [1960] 3 All ER 731.
 R v Fellows & Arnold [1997] 1 WLR 593.
 Sim v Stretch [1936] 2 All ER 1237.
 McAlpine v Bercow [2013] EWHC 1342.
 Zubulake v. UBS Warburg, 220 F.R.D. 212 (2004).

You might also like