Data Protection Policy
On this page
1. Introduction
2. Purpose
3. Definitions
4. Roles and responsibilities
5. Data Protection Officer (DPO)
6. Data subject rights
7. Complaints
8. Data protection principles
9. Processing personal data
10. Data protection by design and default
11. Data protection impact assessments
12. Personal data breaches and near misses
13. Biometric Recognition Systems
14. Destruction of records
15. Training
16. Monitoring arrangements
17. Legislation and guidance
18. Links with other policies
19. Appendix 1
20. Appendix 2
1. Introduction
1.1 This policy provides the West of England Combined Authority’s (The Authority) standards which must be maintained to comply with the UK Data Protection Act 2018 (DPA) and the UK General Data Protection Regulation (GDPR). The policy also refers to further legislation where appropriate.
1.2 This document will be available to all elected members, employees, partners, third party contractors, agency workers, volunteers and temporary staff.
1.3 Key Messages
- The Authority is defined as a data controller and all employees, elected members, partners, contractors and volunteers have a responsibility to comply with GDPR and DPA.
- You must read, understand and adhere to this policy.
- GDPR and DPA apply to all the personal data and special category data processed by, and/or on behalf of the authority. This information must be processed lawfully and fairly, and the legal basis for processing must be recorded.
- You must only access personal data and special category data which is necessary to carry out your job. Unauthorised access is a breach of data protection and may be subject to disciplinary action.
- You must report any suspected breaches to the Information Governance Team immediately and no later than 24 hours after becoming aware of the breach.
- You must complete all mandatory training.
2. Purpose
2.1 The Authority issues this policy to meet its requirements under The GDPR and The Data Protection Act 2018 as a public authority responsible for the handling of personal data in the role of Data Controller or otherwise, and for the control and release of data under the Freedom of Information Act 2000, the Environmental Information regulations 2004 and Local Government (Access to Information) Act 1985.
2.2 This policy is also intended to serve as the Appropriate Policy Document for the processing of special category data and criminal record data (where applicable).
2.3 This policy applies to all personal data for which West of England Combined Authority is the data controller, regardless of whether it is in paper or electronic format.
3. Definitions
3.1 Personal data - ‘Personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
3.2 The term personal data covers both facts and opinions about an individual. We process a wide range of personal data of staff (including councillors and volunteers) and residents as part of our operations. A non-exhaustive list of examples of the types of personal data that we process may be found in our privacy notices.
3.3 Special category personal data - Formerly known as “sensitive personal data”, special category data is information that is more sensitive and requires additional consideration when processing. These are:
- racial or ethnic origin
- political opinions
- religious / philosophical beliefs
- trade union membership
- genetic data
- biometric data (for identification purposes)
- health data (mental and physical)
- sex life or sexual orientation
Examples of the types of special category data we process can be found at Appendix 2.
3.4 Our Record of Processing Activities (RoPA) details the types of information we hold and the grounds upon which we process it, as do our privacy notices which can be found on our website or relevant websites.
3.5 Data Subject(s) - The data subject is the person about whom the personal data relates or identifies.
3.6 Data Processing - Data processing is an over-arching term that means “doing something” with personal data. This commonly includes:
- Collecting or collating the data
- Analysing the data
- Sharing the data
- Storing the data
- Destroying the data
3.7 Data Controller - The data controller is occasionally the person or more commonly the organisation with overall responsibility for determining the purposes of processing of personal data. They will make all the decisions about what is captured, how it’s used and the purpose for it, as well as deciding what controls need to be in place.
3.8 Data Processor - is occasionally a person, but more commonly an organisation commissioned by a data controller to carry out data processing on behalf of the data controller. These are often software providers such as Microsoft or contracted out services such as an insurance company. Essentially, a data processor is acting as an extension of the data controller, so must operate under the data controller’s instructions, and under the terms of a data processing agreement.
3.9 Data Sharing - means giving data to another data controller, for them to use for their own purposes. In this context, once you have shared personal data, the recipient becomes the data controller of that information and therefore makes the decisions over what they will do with it.
Note, we do NOT share data with our data processors, as they are processing it under our data controllership.
3.10 Data Breach - The most common type of data breach is the accidental or unlawful loss, alteration, destruction, disclosure of or access to personal data, for example sending an email to the wrong recipient, losing a file containing personal data, or sharing passwords enabling someone else to access your account.
3.11 However, we consider any failing of one of the data protection principles (Article 5 of UK GDPR) as a breach of data protection legislation, so could include examples such as not having the necessary paperwork in place, not providing the data subject with clear privacy information, retaining personal data for longer than is necessary or processing personal data without an identified lawful basis (Article 6 of UK GDPR).
3.12 Data Processing Agreement – a legally binding contract between the data controller and its data processor. This contract defines exactly how the data controller expects the data processor to process its personal data.
3.13 Data Sharing Agreement - a written agreement between data controllers where there is regular sharing of personal data. The data sharing agreement should define who is involved in the agreement, what data is being shared, why the recipient needs the data, how this is lawful, how the data will be shared.
4. Roles and responsibilities
4.1 The scope of this policy applies to all employees of West of England Combined Authority including contract, agency and temporary staff, volunteers and employees of partner organisations working for West of England Combined Authority.
4.2 In addition, this policy applies to all personal data processed by Elected Members as part of official duties. Members processing personal data in respect of their party or ward duties are not covered by this policy and must make their own arrangements as individual Data Controllers.
4.3 More detail regarding the roles and responsibilities of Information Governance staff is covered in the Information Governance Framework. The following is a brief description of those roles and responsibilities.
4.4 Information Governance Board - The IG Board is composed of the Director of Legal Services (Chair), Senior Information Risk Owner (SIRO), Legal Representative, Information Governance Manager, Data Protection Officer, IT Representative and is responsible for the following.
- The creation and maintenance of an IG strategy.
- The balance of IG priorities against corporate priorities.
- The coordination of resources to meet Corporate IG responsibilities.
- The approval of Policy relating to IG.
- Ensuring the execution of IG tasks by representatives within their relative service areas.
- The identification and representation of needs and risks within the service areas represented.
- The facilitation of intra-service data sharing.
- The reduction of data breaches through technical and organisational means.
- The ethical considerations of data processing within the Authority.
4.5 Information Governance Team - The IG Team has overall responsibility for supporting the IG Board to comply with all relevant data protection obligations and providing the single point of specialist knowledge in relation to information governance matters including data protection, information asset management, freedom of information, and general legal matters relating to the processing of data.
4.6 Information Asset Owners and Custodians (IAOs & IACs) - Information Asset Owners (IAOs) are accountable for their respective information assets; this includes a clear understanding of the information asset. IAOs must understand any risks (and mitigations) associated with their information asset, the security measures in place, compliance requirements (including any internal audit findings and recommendations), and agreeing any classification or categorisation.
4.7 Information Asset Custodians (IACs) are responsible for capturing, storing and disposing of data in line with the IAO’s requirements for technical tools for data-provisioning and delivery of business requirements. If the IAO’s are the accountable “business owner” of the information, then the IACs are the operational guardians who implement the controls, manage the systems, and ensure day to day protection of the asset.
4.8 All other staff (as defined in scope) - All staff are responsible for:
- Familiarising themselves with and complying with this and related policies. The learning culture within the Authority seeks the avoidance of blame and is key to allowing individuals the confidence to report genuine mistakes. However, staff should be aware, that a deliberate or reckless disregard of this policy could result in disciplinary action being taken;
- The safe keeping of personal data, minimising the risk of its loss or misuse at all times. All staff should adopt the approach that they should treat the personal data of others with the same care with which they would treat their own;
- Only using computers and other devices authorised by the Authority for accessing and processing personal data ensuring that they are properly “logged-off” at the end of any session in which they are using personal data; and locking devices when they are temporarily left unattended at any point.
- Storing, transporting and transferring data using encryption and secure password protected devices.
- Not transferring personal data offsite or to personal devices.
- Deleting any data they hold in line with this policy, the Records Management Policy, and the retention schedule;
- Informing their manager or HR of any changes to their personal data, such as a change of address.
- Reporting to the IG Team in the following circumstances:
- Any questions about the operation of this policy, data protection law, retaining or sharing personal data or keeping personal data secure;
- If they have any concerns that this policy is not being followed;
- If they are unsure whether they have a lawful basis upon which to use personal data in a particular way;
- If they need to rely on or capture consent, deal with data protection rights invoked by an individual, or transfer personal data outside the UK and European Economic Area;
- The discovery of a data breach or near miss (immediate action is required).
- Whenever they are engaging in a new activity that may affect the privacy rights of individuals;
- If they are to share personal data with a data processor, for example a contractor or someone offering a service, in which case a contract is likely to be required and potentially a data protection impact assessment (DPIA).
5. Data Protection Officer (DPO)
5.1 The Authority’s Data Protection Officer (DPO) role is responsible for informing and advising the Authority on its obligations under data protection legislation. The DPO will delegate some of its responsibilities to the Information Governance Officer but will still hold accountability for the DPO role.
5.2 The DPO will hold the necessary level of expert knowledge and perform their tasks in an independent manner. The DPO will not be dismissed or penalised by the Authority for performing their DPO tasks.
6. Data Subject Rights
6.1 In all aspects of its work, the Authority will ensure that the rights of the data subject are protected by all practicable measures associated with the conduct of our work. Subject to exceptions, the rights of the data subject as defined in law are:
6.2 Right to be informed.
We advise individuals how we will use their data with transparent privacy notices and other documentation, such as data capture and consent forms where appropriate.
6.3 Right of access.
An individual when making a subject access request (SAR) is entitled to the following;
- Confirmation that their data is being processed;
- Access to their personal data;
- Other supplementary information – this largely corresponds to the information that should be provided in a privacy notice.
We must respond to such a request within one calendar month unless the request is complex, in which case it may be extended by up to a further two calendar months, with requesters informed of the extension within the first calendar month.
6.4 Right to Rectification.
Individuals have the right to ask us to correct information they think is inaccurate or incomplete. We have a duty to investigate any such claims and rectify the information where appropriate within one calendar month, unless an extension of up to a further two calendar months can be justified.
6.5 Right to Erasure.
Individuals have a right to request that their personal information is erased but this is not an absolute right. It applies in circumstances including where:
- The information was given voluntarily; consent is now withdrawn and no other legal basis for retaining the information applies;
- The information is no longer required;
- The data was collected from a child for an online service; or
- We have processed the data on the basis that it is in their legitimate business interests to do so, and having conducted a legitimate interests test, we conclude that the rights of the individual to have the data erased outweigh those of the Authority to continue to process it.
We will consider such requests as soon as possible and within one month, unless it is necessary to extend that timeframe for a further two months based on the complexity of the request or if several requests have been received from the individual.
6.6 Right to Restrict Processing.
This is not an absolute right. An individual may ask us to temporarily limit the use of their data (for example, storing it but not using it) when we are considering:
- A challenge made to the accuracy of their data, or
- An objection to the use of their data.
An individual may also ask us to restrict the destruction of a record, if they wish it to be retained beyond the normal retention period.
In addition, we may be asked to limit the use of data rather than delete it:
- If the individual does not want West of England Combined Authority to delete the data but does not wish it to continue to use it;
- If the data was processed without a lawful basis;
- To create, exercise or defend legal claims.
6.7 Right to Data Portability.
An individual can make a request for data held in an electronic format to be transferred to themselves or to another data controller in a commonly used format or appropriate machine readable and interoperable format. The data must be held in a structured electronic format and processed under the lawful basis of consent, or in performance of a contract for this right to apply.
6.8 Right to Object.
Individuals have a right to object in relation to the processing of data in respect of:
- a task carried out in the public interest except where personal data is processed for historical research purposes or statistical purposes;
- a task carried out for the exercise of official authority;
- a task carried out in its legitimate interests;
- scientific or historical research, or statistical purposes, or
- direct marketing.
Only the right to object to direct marketing is absolute, other objections will be assessed in accordance with data protection principles. We will advise of any decision to refuse such a request within one month, together with reasons and details of how to complain and seek redress.
6.9 Right to Complain.
Individuals have the right to complain about the way in which the Authority processes their personal data. This is the first stage, before the Information Commissioner will consider a personal data complaint.
See section 8 for complaint handling.
6.10 Rights Related to Automated Decision Making.
This right applies to two distinct forms of processing; firstly, where there is an automated decision being made and no human involvement or consideration of the resulting impact on data subjects, and, secondly, profiling a data subject using an automated process for the purpose of evaluation, such as finding out about their preferences, predicting behaviour, or making decisions about them.
Such processing may only be undertaken in the following circumstances;
- Necessary for entering a contract with that data subject,
- authorised by specific legislation,
- With the explicit consent of the data subject.
Such processing activities must be assessed using a DPIA with the consultation of the IG Team.
7. Complaints
7.1 The Authority is always seeking to implement best practice and strives for the highest standards. We operate an “open door” policy to discuss any concerns about the implementation of this policy or related issues.
7.2 Individuals have the right to make a complaint to us about the way in which we process personal data. Our data protection complaints policy is set out on our website. There is also a right to make a complaint to the Information Commissioner, but complaints should be raised with us first by contacting the IG Team insert email address. We will acknowledge all complaints within 30 days and respond without undue delay.
7.3 If a complainant remains dissatisfied with the Authority’s handling of the complaint, the ICO is contactable at:
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
8. Data Protection Principles
8.1 Data protection legislation is based on seven key data protection principles with which the Authority complies.
- The principles say that personal data must be:
8.3 Processed lawfully, fairly and in a transparent manner – we will explain to individuals why we need their data and why we are processing it – for example on consent forms (where consent is used as the basis for processing), and in our Privacy Notice(s). We review our documentation and the basis for processing data on a regular basis.
8.4 Collected for specified, explicit and legitimate purposes – we explain these reasons to the individuals concerned when we first collect their data.
If we wish to use personal data for reasons other than those given when the data was first obtained, we will inform the individuals concerned before doing so and will review the lawful basis for processing unless the new purpose is compatible with that in respect of which consent was given, or there is another lawful basis for sharing the information in which case, we will document the basis for processing.
8.5 Adequate, relevant and limited to what is necessary to fulfil the purposes for which it is processed - we must only process the minimum amount of personal data that is necessary to undertake our work.
8.6 Accurate and where necessary kept up to date – we will check the details of individuals on our databases at appropriate intervals and maintain the databases. We will consider and respond to requests for inaccurate data to be rectified in accordance with the Data Protection Act 2018.
8.7 Kept for no longer than is necessary for the purposes for which it is processed – we review what data we hold at appropriate intervals for example upon the annual review of the Record of Processing Activities (or sooner if needed).
- When we no longer need the personal data we hold, we will ensure that it is deleted or anonymised in accordance with the retention schedule. We only keep personal data, including special category data, in an identifiable form for as long as is necessary for the purposes for which it was collected, or where there is a legal obligation to do so;
- We have a retention and disposal/records management policy which governs how long all data including special category data shall be retained for. This policy is complied with and reviewed regularly;
- Once the data is no longer needed, we delete it, securely destroy it in line with our retention and disposal policy, or render it permanently anonymous.
8.8 Processed in a way that ensures it is appropriately secure – the Authority implements appropriate technical measures to ensure the security of data and systems for staff and all users.
- We adopt a risk based approach to taking data offsite. Unless necessary, hard copies of personal data will not be removed from our premises.
- Any decision to remove the information must be based on the business need of the Authority or in the best interests of the individual, rather than for the convenience of the individual member of staff. It is always preferable for any special category data to be accessed via appropriately encrypted means rather than hard copy when off-site.
- If there is no reasonable alternative to removing hard copies from the office, the following procedure will apply:
- Information will be transported in a secure case;
- Wherever possible, information that is removed from site will be pseudonymised by using a “key” held by the office on site;
- We adopt a risk-based approach, for example hard copy personal data with lower sensitivity (e.g. notebooks) may be taken off site, but if left in a vehicle must be locked in the boot, never left in a visible place, only for the shortest period and never overnight. Special category data must be always kept on the staff member’s person.
- Special category data must be returned to our premises at the end of the working day. If this is not practicable and a staff member needs to retain the information in their personal possession this must be discussed in advance with the service lead including what measures will be taken to safeguard the information, given the risks that are beyond a staff member’s control in so doing and the potential consequences ensuing. The service lead must record their decision.
- Data will be tidied away when not in use (e.g. when staff undertake working at home, it must be out of sight of family members, not left out, and tidied away).
- Only those who have need to access the data concerned will be granted permission and access to it.
- Our Information Security Policy and Acceptable Usage Policy describe the requirements around remote working and password protection.
8.9 Accountability – the Authority complies with its obligations under data protection law and can demonstrate this via the measures set out in this policy including:
- completing data protection impact assessments (DPIAs);
- integrating data protection into internal documents including this policy, any related policies and privacy notices;
- regularly training members of staff on all relevant data protection law, including this and any related policies;
- reviewing and auditing privacy measures and compliance;
- maintaining and reviewing records of its processing activities for all personal data that it holds;
- reviewing and ensuring familiarity of policies related to the handling of data;
- reviewing reasons for data breaches;
- and ensuring stakeholders manage risks and compliance using their risk register.
9. Processing Personal Data
9.1 In order to ensure that the Authority’s processing of personal data is lawful; we will always identify one of the following seven grounds for processing before starting the processing:
- The data subject or their proxy has freely given clear consent. We will seek consent (where appropriate) to process data from the individual or parent, depending on their mental capacity to understand what is being asked for.
- The data needs to be processed so that we can fulfil a contract with the individual, or the individual has asked us to take specific steps before entering a contract;
- The data needs to be processed so that we can comply with a legal obligation;
- The data needs to be processed to ensure the vital interests of the individual, i.e. to protect someone’s life;
- The data needs to be processed so that we, as a public authority, can perform a task in the public interest, or carry out our official functions;
- The data needs to be processed for the purposes of a recognised legitimate interest (see Appendix 1);
- The data needs to be processed for our legitimate interests or those of a third party where necessary, balancing the rights of the individual (unless the processing is necessary for a ‘recognised’ legitimate interest). However, the Authority may only use this lawful basis where processing does not constitute a public task.
9.2 Processing Special Categories of Personal Data - In addition to the legal basis to process personal data, special categories of personal data also require an additional condition for processing under Article 9 of the UK GDPR. The grounds that we may rely on include:
a) The individual has given explicit consent to the processing of those special categories of personal data for one or more specified purposes;
b) Processing is necessary for the purposes of carrying out the obligations and exercising specific rights under employment and social security and social protection law and research;
c) Processing is necessary to protect the vital interests of the individual or of another natural person where the individual is physically or legally incapable of giving consent;
d) Processing relates to personal data which are manifestly made public by the individual;
e) Processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity;
f) Processing is necessary for reasons of substantial public interest but must be clearly demonstrated and assessed as part of the public interest test and evidenced throughout the decision making process.
These grounds include the following (the full list of defined purposes may be found in Schedule 1 Part 2 of the Data Protection Act 2018):
- Statutory and government purposes
- Safeguarding of children or individuals at risk
- Legal claims
- Equality of opportunity or treatment
- Counselling
- Occupational pensions
g) Processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3;
h) Processing is necessary for reasons of public interest in the area of public health;
i) Processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes.
9.3 Deciding upon the correct legal basis for processing data can be difficult and more than one ground may be applicable, when in doubt please consult with the Information Governance Team.
9.4 Legal basis for processing criminal offence data - Criminal offence data includes information about criminal allegations, criminal offences, criminal proceedings and criminal convictions. We do not maintain a register of criminal convictions.
9.5 When processing this type of data, we are most likely to rely on one of the following bases:
- The processing is necessary for the purposes of performing or exercising obligations or rights which are imposed or conferred by law on the controller or the individual in connection with employment, social security or social protection;
- The processing is necessary for the purposes of protecting the physical, mental or emotional well-being of an individual;
- The processing is necessary for statutory purposes; or
- Consent where freely given. We acknowledge because of the potential for the imbalance of power that it may be difficult for consent to be deemed valid as a result, we will only rely on this where no other valid option is available to the Authority.
9.6 Third Parties with Access to Personal Data - Please refer to our privacy notices for details of who, aside from the Authority, has access to the personal data processed.
9.7 Data Sharing - The West of England Combined Authority will only share personal data under limited circumstances when there is a lawful basis to do so and will be stated clearly in the relevant Privacy Notice(s). The following principles apply:
- We will share data if there is an issue with an individual that puts the safety of staff or others at risk.
- We will document a legal gateway (which is a legal power to share personal data) and a lawful basis for processing in consultation with the Information Governance Team.
- When a central government or local government initiative requires sharing for the purpose or purposes of achieving its stated aims and objectives.
- We will share data where there is a need to liaise with other agencies.
- The Authority will put in place a Data Sharing Agreement when necessary in accordance with guidance from the ICO.
9.8 We may also disclose personal data to law enforcement and government bodies without consent, where there is a lawful requirement / basis for us to do so, including:
- For the prevention or detection of crime and/or fraud;
- For the apprehension or prosecution of offenders;
- For the assessment or collection of tax owed to HMRC;
- In connection with legal proceedings;
- For research and statistical purposes, as long as personal data is sufficiently anonymised, or consent has been provided or it is otherwise fair and lawful to do so.
9.9 We may also share personal data with emergency services and local authorities to help them to respond to an emergency situation.
9.10 Third-Party Processors - The Authority’s suppliers and contractors may need access to data to provide services. When third parties are processing personal data on behalf of us, we will:
- Only appoint suppliers or contractors who can provide sufficient guarantees that they comply with data protection law;
- Establish a data processing agreement with the supplier or contractor, either in the contract or as a standalone agreement, to ensure the fair and lawful processing of any personal data disclosed;
- Only provide access to data that the supplier or contractor needs to carry out their service, and information necessary to keep them safe while working.
10. Data Protection by Design and Default
10.1 The Authority has a legal obligation to integrate appropriate technical and organisational measures into all of its processing activities, and to consider this aspect before embarking on any new type of processing activity.
10.2 It is a statutory requirement that any activity involving a high risk to the data protection rights of the individual when processing personal data be assessed by a data protection impact assessment. Prior to the commencement of any such activity, the Authority’s Information Governance Team must be consulted, and an initial screening be conducted assessing risk.
10.3 Any activity involving the processing of personal data must be registered on the Register of Processing Activity (RoPA) and reviewed at the very least annually or upon significant change to the nature of processing.
11. Data Protection Impact Assessments
11.1 A Data Protection Impact Assessment (DPIA) is conducted when processing is likely to result in a high risk to individuals. Where there is potential for processing to result in a high risk to individuals or is a major project involving personal data the authority will screen the processing activity under consideration.
11.2 Project leads, or Information Asset Owners will consult with the Information Governance Team regarding the possible requirement for a DPIA to be conducted prior to processing any personal data. The Information Governance Team must be involved at the earliest feasible stage of any project that considers the use of personal data.
12. Personal Data Breaches and Near Misses
12.1 A personal data breach is defined as “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed in connection with the provision of a public electronic communications service.” It may be deliberate or accidental.
12.2 Wherever it is believed that a security incident has occurred, or a “near-miss” has occurred, the staff member must inform the Information Governance Team immediately so that an assessment may be made as to whether the ICO should be informed within 72-hours as is legally required, and / or those data subjects affected by the breach.
12.3 Further details on security incidents and data breaches can be found in the Information Security Policy.
13. Biometric Recognition Systems
13.1 Biometric data is personal information about an individual’s physical or behavioural characteristics which may be used to identify that person. It may take the form of fingerprint, voice, or facial recognition.
13.2 We will undertake a Data Protection Impact Assessment (DPIA) before implementing any new biometric system to assess the impact on individuals.
13.3 In the case of adults, for example staff members, we will seek their consent direct from them before processing any biometric data, unless an alternative lawful basis applies.
13.4 Where consent has been relied upon to process biometric data, if the individual concerned does not agree to proceed or wishes to withdraw their consent to the use of the biometric system, we will consider providing an alternative means of achieving the same aim.
14. Destruction of Records
14.1 We adhere to our retention policy and will permanently securely destroy both paper and electronic records securely in accordance with these timeframes.
14.2 We will ensure that any third party who is employed to perform this function has the necessary accreditations and safeguards.
14.3 Where we delete electronic records and our intention is to put them beyond use, even though it may be technically possible to retrieve them, we will follow the Information Commissioner’s guidance on deleting data and this information will not be made available on receipt of a subject access request.
15. Training
15.1 To meet our obligations under data protection legislation, we will ensure that all staff, volunteers, and councillors receive an appropriate level of data protection training as part of their induction.
15.2 Permanent members of staff will receive data protection training on a regular basis. Those who have a need for specialist training will be provided with it.
15.3 Data protection also forms part of continuing professional development. Staff members undertake regular informal discussions on data protection to ensure key updates are provided when there are changes to legislation. Staff are provided with guidance on data protection matters through regular awareness updates.
16. Monitoring Arrangements
16.1 The IG Team will monitor compliance with this policy and associated policies and procedures; where it is found that standards are not being met the Information Governance Board will be notified and remedial action will be taken.
16.2 This policy will be reviewed biennially, unless an incident or change to regulations dictates an earlier review.
17. Legislation and Guidance
17.1 This policy considers the following:
- The UK General Data Protection Regulation (UK GDPR)
- The Data Protection Act (DPA) 2018
- The Data (Use and Access) Act 2025 (DUAA)
- The Protection of Freedoms Act 2012
- Guidance published by the Information Commissioner’s Office
- Information Sharing – Advice for Practitioners – DfE July 2018
- Freedom of Information Act 2000
- Environmental Information Regulations 2004
- Local Government (Access to Information) Act 1985
18. Links with Other Policies
18.1 This Data Protection Policy is linked to policies in the Information Governance Framework.
Appendix 1
Lawfulness of Processing: Recognised Legitimate Interests
When relying on Article 6(1)(ea) to process personal data (recognised legitimate interests), the following reasons can be considered:
- Disclosure to a third party, where the requesting organisation can demonstrate a recognised legitimate interest
- Where processing is necessary for national security, public security and / or defence
- Where the processing is necessary for responding to an emergency, in accordance with the Civil Contingencies Act 2004
- Where the processing is necessary for the purpose of detecting, investigating or preventing crime, or apprehending or prosecuting offenders
- Where processing is necessary to safeguard vulnerable individuals.
Appendix 1
Lawfulness of Processing: Recognised Legitimate Interests
When relying on Article 6(1)(ea) to process personal data (recognised legitimate interests), the following reasons can be considered:
- Disclosure to a third party, where the requesting organisation can demonstrate a recognised legitimate interest
- Where processing is necessary for national security, public security and / or defence
- Where the processing is necessary for responding to an emergency, in accordance with the Civil Contingencies Act 2004
- Where the processing is necessary for the purpose of detecting, investigating or preventing crime, or apprehending or prosecuting offenders
- Where processing is necessary to safeguard vulnerable individuals.