Image Source: Pixabay, copyright free
Donations keep this site going. If you like what I’m doing here and think this work is important to the independence movement, consider a donation. One-off or monthly; as little or as much as you want. Click the links below, or full details are available here.
What Happens Now?
The modern data protection system stems largely from the EU‘s General Data Protection Regulation (GDPR). This was enshrined in UK law via the Data Protection Act 2018 and hasn’t been affected by Brexit.
There were plans for a new UK-only law in 2022, but these plans were withdrawn in 2023.
The key principles of the UK’s data protection rules are1:
- Data is used “fairly, lawfully and transparently” and only for specific purposes.
- Data is used “in a way that is adequate, relevant and limited to only what is necessary”.
- Responsibility to ensure personal data is accurate, up to date and not kept for longer than is necessary.
- Responsibility to ensure data is kept secure – including protection from “unauthorised processing, access, loss, destruction or damage”.
The main authority responsible for enforcing data protection is the Information Commissioner’s Office (ICO). They play a similar role in policing freedom of information.
The ICO handles data protection complaints and investigates breaches. Organisations that handle personal data pay an annual fee to the ICO.
Does This Work for Wales?
In principle, yes. In practice, there are issues – though they’re not confined to Wales.
No serious action has been taken against big tech companies when they’ve breached GDPR rules. The tech industry, particularly Artificial Intelligence (AI), is often evolving too fast for regulators to keep pace.
Organisations such as Privacy International2 have raised concerns that data brokers and tech companies are increasingly looking to “grey areas”. This includes data that isn’t given directly, but can be “observed, derived and inferred” in order to manipulate people in ways that aren’t obvious (called “microtargeting”).
Some Wales-specific issues include the collection of biometric data (i.e. fingerprint scans) from students in order to pay for school meals3. In 2023, the Senedd agreed to a backbench motion calling for biometric data collection in schools to be halted4.
What Would Be the Pros & Cons of Independence?
Given the global nature of data collection, there’s probably very little Wales could do in isolation.
The default is that the current system continues (Data Protection Act 2018). Wales could also take a rights-based approach and include clauses relating to personal and biometric data in a written Welsh Constitution or Bill of Rights.
The main downside is that we would be taking on the role of policing and funding data protection enforcement ourselves.
What Do Other Countries Do?
![]()
Ireland has implemented the GDPR via its own Data Protection Act. Data protection monitoring and enforcement is undertaken by the Data Protection Commission. The Commission is an independent body separate from the country’s Information Commissioner.
![]()
The Data Protection Agency is responsible for enforcement and monitoring. As an EU member state, the GDPR has been integrated into Danish law via its own Data Protection Act. The procedures are similar to those in the UK and Ireland, though a government-appointed Data Protection Council decides matters of “fundamental importance in the field of data protection”.
![]()
The Swedish Authority for Privacy Protection is the agency responsible for the enforcement and monitoring of data protection rights. Again, the GDPR forms most of the legislative framework, enshrined in Swedish law via its own Data Protection Act.
![]()
New Zealand has nothing to do with the GDPR, so it has its own legislative and regulatory framework for data protection. Yet despite that, it’s remarkably similar to Europe. The Privacy Act 2020 outlines how personal data is to be used and managed, but it’s broadly similar to the provisions of the GDPR and is deemed to be compatible with the GDPR by the EU.
Data protection is overseen by the Office of the Privacy Commissioner, whose main role is to issue guidance and a code of practice to organisations liable under the 2020 Act. One of the main differences is that the fines are capped at a much lower level than in the UK.
What Options Does Wales Have?
As mentioned, the default option is that the current system continues: the EU’s GDPR is enshrined in Welsh law through the Data Protection Act 2018.
After independence, Wales could – if the Senedd wanted to – introduce a new data protection law.
Also, as mentioned, there’s the possibility of taking a more rights-based approach to data protection, and enshrining some rights over personal and biometric data in a written Welsh Constitution.
What's at Stake?
The overall score (out of 20) is the total of the scores for the four mini-categories (out of 5 each).
How Would This Be Run?
The options are likely to be similar to any system we put in place for freedom of information.
Wales establishes a separate post of Information Commissioner modelled on the current ICO. The Commissioner would be responsible for policing and enforcing the Freedom of Information Act and data protection laws.
This is similar to New Zealand. Instead of creating a separate office, the current Ombudsman would be responsible for policing data protection (and freedom of information).
A tribunal would need to be set up to hear appeals against decisions, regardless of whether it’s a stand-alone Information Commissioner or the Public Services Ombudsman making them. This is currently the responsibility of the General Regulatory Chamber first-tier tribunal (in EnglandandWales).
How Much Will This Cost?
Headline: Potentially cost-neutral due to income from fees and fines; any shortfall covered by the Welsh Government, any surplus returned to them.
The current Information Commissioner’s office raises most of its income from data protection fees paid by organisations that handle personal data.
If a Welsh Information Commissioner had an office similar in size to Scotland’s Information Commissioner, it would have running costs of around £2.1 million per year5. But that would be offset by income from data protection fees and fines.
The Ombudsman’s annual budget would need to be increased to cover the cost of the additional role (extra staff, etc.). This is likely to be in the same ballpark as a stand-alone Commissioner, though possibly slightly less, as you wouldn’t need to cover the cost of appointing a Commissioner and/or senior managers/deputies.
There’s a debate over whether fees should be introduced to partially cover the cost of data protection appeals. At the moment, it’s free.
Would any new taxes need to be introduced?
No, though whichever authority is responsible for enforcing data protection rules would be able to set registration fees and issue fines.
Who will pay for this?
Any company, organisation or public body which handles personal data and is required by law to be registered.
How Long Would This Take?
The default option – continue with the Data Protection Act – would happen instantly.
Establishing a stand-alone Information Commissioner for Wales would likely take up to a year. Folding the role into that of the Public Services Ombudsman might take the same amount of time. Both options would probably need a change to the law, which might take up to a year to get through the Senedd.
People & Work
Technically, everyone, as it’s about personal data. Professionally, it would have more of an impact on anyone handling or storing personal data: IT managers, the police, the NHS, other major public bodies, etc.
A stand-alone Information Commissioner’s office (similar in size to Scotland’s) may create up to 30 jobs. Most of these would likely be filled from the current Information Commissioner’s office in Cardiff.
More senior posts – currently based in London, including the Commissioners themselves – would be created from scratch.
You Might Also Like....
UK Government. “Data protection”.
Privacy International. “General Data Protection Regulation“.
Welsh Government (13th August 2009). “Protection of biometric information in schools and colleges”.
Senedd Cymru, Plenary (8th March 2023). “Motion NDM8131 – Biometric data in schools”.
Scottish Information Commissioner (October 2024) “Annual Report 2023-24“. (p76).
No AI tools were used to draft this post.









