Data Protection & Retention Policy
Adopted 07.07.2025
1. Purpose
St Agnes Parish Council (the Council) is committed to managing personal and sensitive information lawfully, transparently and securely. This policy explains how we collect, use, store and dispose of data in line with the UK GDPR, the Data Protection Act 2018 and other applicable legislation, thereby promoting public confidence in our governance. In fulfilling our statutory duties and delivering services, we handle:
- Public information – material we are legally required or choose to place in the public domain.
- Pre-publication or policy drafts – working documents that remain confidential until approved.
- Commercially sensitive data – information supplied by partner organisations under a duty of confidence.
- Employment data – personal information about current, former and prospective employees, Councillors, contractors and volunteers.
- Resident and service-user data – personal details provided by individuals who contact us, use our services or submit complaints.
The Document Retention Schedule (Appendix 4) forms part of this policy and sets clear rules for information retention and disposal. Except for information that is personal or commercially confidential, we operate on a principle of openness and make routine material available through the Publication Scheme.
2. Scope
This policy applies to:
- All Councillors, employees, contractors, volunteers, and agents handling personal data on behalf of the Council.
- All forms of data: electronic, paper, verbal, audio/visual.
- All individuals whose data we collect, including residents, employees, Councillors, suppliers, and service users.
3. Terminology
- Data subject: The person whose personal data is being collected or used.
- Personal data: Any information that can identify a living person, either on its own or with other details (names, photos, addresses, dates of birth, email addresses, bank details, social media posts, IP addresses).
- Special category data: More private information that needs extra protection (see section 8).
- Data controller: The person or organisation (e.g. the Council) that decides why and how personal data is used.
- Data processor: A person or organisation that uses or manages personal data on behalf of the data controller.
- Processing data: Any action taken with personal data, including collecting, storing, organising, changing, using, sharing, or deleting it – manually or electronically.
4. Protecting Confidential or Sensitive Information
The Council acknowledges it must hold and process personal and sensitive data about employees, Councillors, and the public. The UK GDPR and Data Protection Act 2018 balance individual rights with the Council’s legitimate need to use such information. This policy is based on the seven legal principles that personal data must be:
- Processed fairly, lawfully and in a transparent manner in relation to the data subject.
- Collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.
- Adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
- Accurate and as far as possible kept up to date.
- Retained only for as long as necessary.
- Processed securely, with protection against unauthorised or unlawful processing, loss, destruction or damage, using appropriate technical and organisational measures.
- Accountability: The Council shall take responsibility for, and be able to demonstrate, compliance with these principles by maintaining appropriate policies, records and evidence.
5. Purposes for Processing
The Council processes personal data to:
- Meet its obligations as an employer
- Deliver statutory and community services, let contracts and manage finances
- Monitor equality of opportunity and service quality
- Manage premises and security (including CCTV)
- Assist regulators and law-enforcement bodies
- Keep records of Councillors, staff, contractors, volunteers and service users
- Respond to enquiries, complaints and information requests
- Conduct surveys, research, audits and other administrative functions
6. Data Collection and Use
- Collect only data necessary for specified purposes
- Inform individuals via clear privacy notices
- Use data solely for the purpose it was collected
- Keep records of processing activities
7. Lawful Bases (UK GDPR, Article 6)
The Council will ensure that at least one of the following conditions is met for personal information to be held and processed:
- Consent
- Performance of a contract or agreement
- Legal obligation
- To protect the vital interests of the individual
- Public task / official authority, or the Council’s legitimate interests (when not performing a public task)
8. Special Category Data
The Council may need to collect and process special-category data. When it does, it shall:
- Have a lawful basis
- Meet one of the additional conditions under UK GDPR, Article 9 (Appendix 1)
- Have an Appropriate Policy Document (APD) in place, as required under Schedule 1 of the DPA 2018
9. Data Subject Rights
Under the UK GDPR, individuals have the following rights regarding their personal data:
- Right to be Informed – provided through privacy notices and this policy.
- Right of Access – request access to personal data via Subject Access Request to the Clerk.
- Right to Rectification – correct inaccurate or incomplete data.
- Right to Erasure (“Right to be Forgotten”) – request deletion where there is no legal reason to retain it.
- Right to Restrict Processing – stop use temporarily (e.g., while a correction or objection is considered).
- Right to Object – object if data is used for a different purpose than collected.
- Right to Data Portability – request a copy of data where processing is based on consent or contract and automated (unlikely in Council functions).
- Rights in Relation to Automated Decision-Making and Profiling – not undertaken by the Council.
10. Subject Access Requests
The Council will respond to Subject Access Requests within one calendar month. The Council will:
- Identify the requester via ID if necessary
- Search all data locations and formats
- Apply exemptions as necessary
- Redact personal information about others
- Provide supplementary information (e.g., data source if not provided directly by the subject)
- Provide information securely (encryption / registered post)
No fee will be charged unless the request is manifestly unfounded or excessive. If charges apply, they will follow the Council’s Freedom of Information Policy.
11. Responsibility
The Council, as a corporate body, is responsible for compliance with data protection laws. The Clerk is the designated Data Protection Officer (DPO).
12. Data Sharing
Data will only be shared:
- When there is a lawful basis
- Under a Data Sharing Agreement or contract, with prior notice to subjects where possible
- With safeguards in place (e.g., redaction, pseudonymisation)
13. Data Security
- Password protection and access controls
- Secure storage (physical and digital)
- Regular software updates and security monitoring
- Staff training and data handling procedures
14. Data Breaches
In the event of a personal data breach, the Clerk (DPO) will:
- Assess the breach promptly and determine risks
- Report to the ICO within 72 hours if required
- Inform affected individuals if the risk is high
- Log all breaches in the Data Breach Register
15. Data Processors Outside the UK
The Council will only transfer data internationally where safeguards are in place (e.g., UK adequacy regulations, IDTA, UK Addendum to EU SCCs). Transfers are permitted only if lawful, necessary, and protective of individual rights.
16. Complaints
Complaints can be raised with the Clerk or the Information Commissioner’s Office: casework@ico.org.uk | 0303 123 1113
17. Data Retention and Disposal
The Council retains and disposes of data per its Document Retention Schedule (Appendix 4). Data is:
- Kept only as long as necessary
- Reviewed regularly
- Securely destroyed when no longer needed
18. Policy Review
This policy will be reviewed every four years, or earlier if required by legislation, ICO guidance, data breaches, or feedback.
19. Legal Framework
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Freedom of Information Act 2000
- Environmental Information Regulations 2004
- ICO Guidance
