Source · Select Committees · Digital, Culture, Media and Sport Committee

Tenth Report - Connected tech: smart or sinister?

Digital, Culture, Media and Sport Committee HC 157 Published 7 August 2023
Government response
Second Special Report - Connected tech: smart or sinister?: Government and the Information Commissioner’s Office Response to the Committee’s Tenth Report of Session 2022–23 · published 24 Nov 2023
Read the government response ↗ Response on the Index

Recommendations & Conclusions

20 items
1 Conclusion
Para 35

Significant barriers prevent individuals from effectively exercising data rights with connected tech.

Conclusion
Data rights are an important tool for empowering data subjects and balancing data processing against users’ rights and freedoms. However, there are many barriers to individuals being able to exercise these rights when using or interacting with connected tech, ranging from product design to digital literacy and resources. Users must be given clear information about, and a fair chance to understand, the basis on which their data is used, the implications for their digital rights, the benefits and risks, and how to consent, object and how to exercise these rights.

Link to this item

Department for Culture, Media and Sport
View Details →
2 Recommendation
Para 36

Introduce measures to standardise intuitive privacy interfaces for connected devices, empowering users.

Recommendation
The Government should introduce appropriate measures to standardise privacy interfaces for connected devices as a first step, which will help users learn how to control connected devices in their homes and exercise data rights. Privacy interfaces should be appropriately accessible, intuitive and flexible enough so users of a reasonable level of digital literacy and privacy expectations can use them, without requiring them to go through complex dashboards with long lists of terms and conditions and settings. Interfaces should also provide information on how devices are connecting to other devices and networks, to provide transparency about data flows.

Link to this item

Department for Culture, Media and Sport
View Details →
3 Recommendation
Para 41

Clarify Online Safety Bill obligations for connected devices and voice assistants surfacing harmful content.

Recommendation
The Government should clarify the obligations in the Online Safety Bill for voice assistants, connected devices (like smart speakers) and other emerging technologies that can surface harmful content, to ensure that those that integrate search services in particular fall in-scope of the duties. It should also set out in its response to this report how the online safety regime will categorise voice assistants and connected devices that integrate internet search so that they do not service harmful content like hate speech and other harms.

Link to this item

Department for Culture, Media and Sport
View Details →
4 Recommendation
Para 51

Urge ICO to proactively engage manufacturers on child-friendly privacy settings for connected tech.

Recommendation
The use of connected tech in schools and by children in homes raises concerns, including the harvesting and third-party use of children’s data and their lack of control over what technology is used and when. The Government and ICO were quick to dismiss our concerns about this issue. We urge the ICO to take a more proactive approach in engaging with manufacturers of connected toys and education technology. It should ensure that all products include: terms and conditions that are age-appropriate; privacy settings that are intuitive for children and help them exercise data rights; and fully explain the benefits and risks of data processing. Industry should be supported in this through comprehensive guidance, independent research and user- testing.

Link to this item

Department for Culture, Media and Sport
View Details →
5 Recommendation
Para 52

Commit to strengthening the Age-Appropriate Design Code and laying revised version promptly.

Recommendation
The Government should commit to ensuring that the Age-Appropriate Design Code is strengthened rather than undermined by data protection reform and to laying the revised code as soon as is practicable.

Link to this item

Department for Culture, Media and Sport
View Details →
6 Recommendation
Para 59

Review incentives for piloting data institutions in smart cities to boost citizen control.

Recommendation
Though smart cities provide a range of opportunities, such as more efficient management of resources, there are also additional risks to confidence in privacy and data protection, making it harder for individuals to exercise data rights. The Government should review how it can incentivise and actively pilot the creation of data institutions, in partnership with local government and other local stakeholders, Connected tech: smart or sinister? 67 in smart cities to address issues of data protection and ensure that citizens can have greater control over, and directly participate in the benefits from, the use of their data.

Link to this item

Department for Culture, Media and Sport
View Details →
7 Recommendation
Para 64

Commission research on automated workplace monitoring and clarify HSE's role in AI regulation.

Recommendation
The monitoring of employees in smart workplaces should be done only in consultation with, and with the consent of, those being monitored. The Government should commission research to improve the evidence base regarding the deployment of automated and data collection systems at work. It should also clarify whether proposals for the regulation of AI will extend to the Health and Safety Executive (HSE) and detail in its response to this report how HSE can be supported in fulfilling this remit.

Link to this item

Department for Culture, Media and Sport
View Details →
8 Conclusion
Para 65

Develop ICO guidance on employment monitoring into a principles-based code for workplace tech.

Conclusion
The Information Commissioner’s Office should develop its existing draft guidance on “Employment practices: monitoring at work” into a principles-based code for designers and operators of workplace connected tech.

Link to this item

Department for Culture, Media and Sport
View Details →
9 Recommendation
Para 72

Keep data protection reforms under review to avoid undermining existing adequacy agreements.

Recommendation
The Government has not yet made a compelling case for reform of data protection. While we understand that some companies do not share data outside the UK, we are concerned that differing expectations between those companies and companies that do share data outside the UK may give the impression of “lesser” protections for processing personal data in the UK overall. This could be perceived as undermining our existing data adequacy arrangements and ultimately harm companies that share data between the UK and other jurisdictions. To maintain the UK’s reputation as a world-class technology hub, the Government should keep its data reforms under review so as not to undermine its existing data adequacy agreements.

Link to this item

Department for Culture, Media and Sport
View Details →
10 Conclusion

Reject executive overreach by preventing ICO powers without full parliamentary oversight.

Conclusion
We agree that reforming the governance and accountability structures of the Information Commissioner’s Office will be a positive step. We have previously recommended against executive overreach in the case of Ofcom and the Online Safety Bill; these concerns apply with respect to the Information Commissioner’s Office and the Data Protection and Digital Information (No. 2) Bill. Powers to veto codes of practice and to set strategic priorities without parliamentary oversight should not be adopted. (Paragraph 78) Product security

Link to this item

Department for Culture, Media and Sport
View Details →
11 Recommendation

Produce an implementation plan and commit to codifying remaining IoT security guidelines.

Recommendation
The introduction of the product security regime, which codifies three of the original thirteen guidelines set out in the Government’s internationally recognised 2018 Code of Practice for Consumer IoT Security, is an important first step in improving cybersecurity for connected devices. However, the remaining ten guidelines retain considerable support among stakeholders. We recommend that the Office for Product Safety and Standards (OPSS), as the national regulator, should produce an implementation plan so policymakers can measure the impact of the product security regime. The OPSS should continue to promote the guidelines not included in the Product Security and Telecommunications Infrastructure Act 2022 and the Government should commit to codifying these remaining guidelines in phases as the regime matures and industry adapts, in order to stay ahead of emerging cyber threats. (Paragraph 101) 68 Connected tech: smart or sinister?

Link to this item

Department for Culture, Media and Sport
View Details →
12 Conclusion
Para 102

Work with OPSS to promote data protection and security guidelines for IoT devices.

Conclusion
As the guidelines set out in the 2018 Code of Practice for Consumer IoT Security imply, cybersecurity and data protection are mutually reinforcing. Without cybersecurity, data cannot be meaningfully protected, while data protection can manage the risk and impact of cyberattack. The Information Commissioner’s Office, either bilaterally or through the Digital Regulation Co-operation Forum, which helps co-ordinate regulation of digital platforms and services, should work with the Office for Product Safety and Standards as it promotes the guidelines pertaining to data protection and data security in the 2018 Code of Practice.

Link to this item

Department for Culture, Media and Sport
View Details →
13 Recommendation
Para 108

Require providers to adopt network, storage, and cloud security standards for connected tech.

Recommendation
Improving cybersecurity of consumer connected devices is an important and positive step, but the proliferation of connected tech in enterprise settings and the gap in the regime regarding network, storage and cloud security still present likely attack vectors that will continue to allow devices to be compromised. The Government should close the gaps for both consumer and enterprise connected tech in the product security regime by requiring that providers adopt network-level, storage and cloud-based security to the same standards as it requires for connected devices.

Link to this item

Department for Culture, Media and Sport
View Details →
14 Recommendation
Para 116

Support free courses, educators, and improve industry hiring to address cyber skills shortage.

Recommendation
We are concerned about the ongoing skills shortage, as recognised in both the Government and industry’s regular reporting on cybersecurity skills in the labour market, and believe that the shortage will be exacerbated further as the product safety regime comes into force. We support industry’s calls for the Government to do more to address this issue. The Government should also take steps to support the availability of free courses across the country, encourage more professionals to become cybersecurity educators, improve the provision of core professional skills among the existing workforce and incentivise industry to improve hiring practices and retention rates.

Link to this item

Department for Culture, Media and Sport
View Details →
15 Recommendation
Para 117

Improve gender and ethnic diversity in cyber workforce through new schemes and support.

Recommendation
We are particularly concerned that, despite the shortage of cyber skills in the UK, there are stubborn and significant disparities in the cyber workforce based on gender and race and ethnicity. The Government should reflect on the significant disparities in gender and race/ethnicity in the cyber workforce and take steps to improve these divides, such as by introducing additional schemes and funding to widen the talent pool, improving the culture of and attitudes to the cyber profession both in education and work, and considering how to provide professional support for people during their career.

Link to this item

Department for Culture, Media and Sport
View Details →
16 Recommendation
Para 120

Ensure DSIT coordinates cyber policy and establish clear ministerial accountability for delivery.

Recommendation
The creation of the Department for Science, Innovation and Technology is an opportunity to ensure a comprehensive, joined up approach to cyber policy. We recommend that responsibilities for cyber policy is co-ordinated by the dedicated Department for Science, Innovation and Technology and that government ensures collaboration between the Department and other cyber-focused teams distributed across Whitehall. Ministers in the Department for Science, Innovation and Technology should be ultimately responsible and accountable for developing and delivering cyber policy except for national security measures.

Link to this item

Department for Culture, Media and Sport
View Details →
17 Recommendation

Ensure National Cyber Security Centre has capacity to meet growing demands for services

Recommendation
As the prevalence of connected technology grows, so too will the demand for the National Cyber Security Centre’s services. The Government should ensure that the National Cyber Security Centre has the capacity to meet demands for its services. It should explicitly consider and address capacity issues as part of its regular reporting Connected tech: smart or sinister? 69 on cybersecurity skills in the UK. (Paragraph 121) Technology-facilitated abuse

Link to this item

Department for Culture, Media and Sport
View Details →
18 Recommendation
Para 131

Make tackling technology-facilitated abuse a priority across law enforcement and justice system

Recommendation
The Government must make tackling technology-facilitated abuse, or “tech abuse”, a priority. There is little evidence to suggest that our law enforcement and criminal justice system has been equipped to deal with the problems caused by tech abuse now, let alone as connected devices become even more prevalent in future. While there is no “silver bullet” for dealing with tech abuse, the Government can do more to tackle it.

Link to this item

Department for Culture, Media and Sport
View Details →
19 Recommendation
Para 132

Upskill law enforcement and improve crime data to enhance response to tech abuse

Recommendation
The Government’s response to tech abuse should involve upskilling law enforcement to improve the criminal justice response and increasing law enforcement’s and victims’ and survivors’ awareness of specialist services tackling violence against women and girls. The Government should also reflect on how official crime data on tech abuse can be improved to expand the evidence base for specialists, academics and policymakers in order to develop a more comprehensive, co-ordinated response.

Link to this item

Department for Culture, Media and Sport
View Details →
20 Conclusion

Convene cross-sector tech abuse working group to produce guidance and code of practice

Conclusion
We want to see words from cross-sector stakeholders on tech abuse now leading to positive actions. The Office for Product Safety and Standards should, at the earliest opportunity, convene a “tech abuse working group” with stakeholders, bringing industry together with researchers, specialist support services and public services. This group should be more than just a talking shop, and draw on research to produce guidance and a code of practice that establishes best practice for manufacturers, vendors and law enforcement. The working group should report publicly through the OPSS on its progress at regular intervals. (Paragraph 138) 70 Connected tech: smart or sinister?

Link to this item

Department for Culture, Media and Sport
View Details →
Report Status
Response document linked

Missing links do not establish that no response was published. A linked document does not verify responses to individual findings.

Conclusions & Recommendations
20 items (15 recs)

No response data available yet.