L

Lord Clement-Jones (LD)

Speaking in the House of Lords on 10 February 2025

Debate

Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) (Amendment) Regulations 2024

Contribution

My Lords, I thank the noble Lord, Lord Leong, for his introduction, but I am slightly baffled by this SI. I looked up whether the Commons had had its debate on it and found that it took place on 21 May 2024. Then I looked at the impact assessment, which seems to be dated 2023. I do not quite know why we are dealing with a historic SI almost a year later. What has happened in the intervening period? The Minister did not mention anything to do with that. Is this some oversight by the department? Has something happened? Was somebody ill and could not deal with this in the House of Lords? It is a rather peculiar situation. The second rather strange aspect of this is that, when the Automated Vehicles Bill was going through, my noble friend the late Baroness Randerson, who was mentioned by my noble friend Lady Smith—it is rather coincidental that this was one of her big issues: automated vehicles and the data relating to them—raised questions about protection of personal privacy and the national security implications of the data being retained by manufacturers of automated vehicles. She also raised the possibility of a cyberattack that could paralyse traffic over a considerable area. Those concerns were also raised by my honourable friend Wera Hobhouse in the Commons at the same time. I think the noble Lord, Lord Sharpe, might be interested in this: we were assured at that time by Ministers in the previous Government that GDPR was good enough protection in respect of automated vehicles, despite the concerns expressed by my late noble friend Baroness Randerson. Now it turns out, as set out in the Explanatory Memorandum, that special provisions are needed. Again, this is rather baffling. We seem to be hearing either that we have an administrative problem or that there was a misunderstanding about the intended policy. In some respects, I should be pleased that the Explanatory Memorandum sets out more safeguards, because if we are going to exempt these three areas—in particular, automated vehicles—we need to know that those safeguards will be in place through other mechanisms. I will go through what those might be and put questions to the Minister about them. How will the collection, storage and use of personal data by automated vehicles be regulated to ensure compliance with data protection laws? What specific criteria must be met for a person or body to be authorised as a self-driving entity, particularly concerning data protection? Do they need to obtain a certificate of compliance with data protection legislation from the ICO, for instance? How can the public be reassured that their personal data will be protected? How will the regulations ensure that personal data is protected, not only during vehicle operation but after the ownership of a vehicle has ended? What are these robust personal data practices that need to be in place for companies to be authorised as self-driving entities? What information about the data for the authorisation of automated vehicles must be provided and to whom? Will the Secretary of State consult the Information Commissioner’s Office before making regulations relating to the provision of personal data in automated vehicles, and will the ICO be including elements to do with personal data and automated vehicles in its annual report to Parliament? How will the Government protect against potential cyberattacks on automated vehicle systems? Specifically, how do the regulations for consumer connectable products under the Product Security and Telecommunications Infrastructure Act interact with those that apply to automated vehicles and their components? Does this exempt the whole of the automated vehicle or, rather, particular connectable items in automated vehicles that would in fact be covered by the PSTI Act? How will the regulations prevent anti-competitive practices by vehicle manufacturers who might use data to restrict competition between them and independent operators? The Explanatory Memorandum talks about the CAVPASS programme, which provides some information that is relevant. Currently, however, it does not deal directly with these specific questions regarding data handling in automated vehicles. We are promised, I think, that something is coming down the track in 2025. There is mention of a staged approach to regulations, which suggests that future measures will be introduced. When can we expect more information of the kind that I have raised? Is it not long overdue, given the speed of development of these vehicles? They are already in pilot form and we need to know that our data is secure. We are still left with questions, despite all that. I doubt whether CAVPASS is necessarily going to cover how data is collected in relation to cybersecurity and how they will be protected in that respect. There are quite a lot of questions here, and it is rather peculiar that we were not in a position to ask these questions at the same time as the House of Commons last May. I am therefore looking forward to what the Minister has to say in reply.

More from Lord Clement-Jones (LD)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.