The thing is, even though the GB decides to ditch GDPR, they're still bound by it if they want to do business with the rest of Europe, just like the US is bound by it.
The thing is, even though the GB decides to ditch GDPR, they're still bound by it if they want to do business with the rest of Europe, just like the US is bound by it.
I know that some purchases of cloud services are halted for now to be sure about this. Data movement is going to be increasingly an important matter. It should have been from the begining but here we are.
https://incountry.com/blog/data-residency-laws-by-country-ov...
Organisations which receive and hold any of regulated data types to follow the GDPR requirements. According to GDPR, companies have to keep the data secure inside the EU and if the data is to be transferred outside of the UE, then it can only be transferred to countries or organisations that have signed up to equivalent privacy protection."
So the EU has all the power here to say that the UK doesn't meet their standards and require businesses to transfer their data.
However, I would guess that most international organisations would have already moved their EU customer data out of the UK.
There were years of uncertainty with the Brexit negotiations, keeping data in the UK would have too much risk.
Plus many other countries have data residency laws, so it's not like a foreign concept to international businesses.
Instead of frontloading compliance for any new venture, they can build for the UK first then work on compliance if and when they go for EU business.