INFORMATION AND DATA PROTECTION POLICY

INTRODUCTION

In order to conduct its business, services and duties Old Hunstanton Parish Council processes a wide range of data relating to its own operations and some which it handles on behalf of partners.  In broad terms, this data can be classified as:-

Old Hunstanton Parish Council will adopt procedures and manage responsibly all data which it handles and will respect the confidentiality of both its own data and that belonging to partner organisations it works with and members of the public.  In some cases, it will have contractual obligations towards confidential data but in addition will have specific legal responsibilities for personal and sensitive information under data protection legislation.

The Parish Council will periodically review and revise this policy in the light of experience, comments from data subjects and guidance from the Information Commissioners Office.

The Council will be as transparent as possible about its operations and will work closely with public, community and voluntary organisations.  Therefore, in the case of all information which is not personal or confidential, it will be prepared to make it available to partners and members of the Parish’s communities.

PROTECTING CONFIDENTIAL OR SENSITIVE INFORMATION

Old Hunstanton Parish Council recognises it must, at times, keep and process sensitive and personal information about both employees and the public.  It has, therefore, adopted this policy not only to meet its legal obligations but to ensure high standards.

The General Data Protection Regulation (GDPR) which became law on the 25th May 2018 will, like the Data Protection Act 1998, seek to strike a balance between the rights of individuals and the sometimes competing interest of those such as the Parish Council with legitimate reasons for using personal information.

THE POLICY IS BASED ON THE PREMISE THAT PERSONAL DATA MUST BE:

OLD HUNSTANTON PARISH COUNCIL PROCESSES PERSONAL DATA IN ORDER TO:

Where appropriate and governed by necessary safeguards we will carry out the above processing jointly with other appropriate bodies from time to time.

THE PARISH COUNCIL WILL ENSURE THAT AT LEAST ONE OF THE FOLLOWING CONDITIONS IS MET FOR PERSONAL INFORMATION TO BE CONSIDERED FAIRLY PROCESSED:-

Particular attention is paid to the processing of any sensitive personal information and the Parish Council will ensure that at least one of the following conditions is met:-

WHO IS RESPONSIBLE FOR PROTECTING A PERSON’S PERSONAL DATA

The Parish Council, as a corporate body, has ultimate responsibility for ensuring compliance with the Data Protection legislation. The Parish Council has delegated this responsibility day to day to the Parish Clerk.

E-mail:  clerk.oh@gmail.com

Phone:  07917 757328

Correspondence: The Parish Clerk

Hayman Lodge, Ploughmans Piece, Thornham, Norfolk PE36 6NE

DIVERSITY MONITORING

Old Hunstanton Parish Council monitors the diversity of its employees and Councillors in order to ensure that there is no inappropriate or unlawful discrimination in the way it conducts its activities.  It undertakes similar data handling in respect of prospective employees.  This data will always be treated as confidential.  It will only be accessed by authorised individuals within the Council and will not be disclosed to any other bodies or individuals.  Diversity information will never be used as selection criteria and will not be made available to others involved in the recruitment process.  Anonymised data derived from diversity monitoring will be used for monitoring purposes and may be published and passed to other bodies.

The Parish Council will always give guidance on personal data to employees, Councillors, partners and volunteers through a Privacy Notice and ensure that individuals on whom personal information is kept are aware of their rights and have easy access to that information on request.

Appropriate technical and organisational measures will be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.  Personal data shall not transferred to a country or territory outside the European Economic Areas unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.

INFORMATION PROVIDED TO THE PARISH COUNCIL

The information provided (personal information such as name, address, email address, phone number) will be processed and stored so that it is possible for us to contact, respond to or conduct the transaction requested by the individual.  By transacting with Old Hunstanton Parish Council individuals are deemed to be giving consent for their personal data provided to be used and transferred in accordance with this policy.  However, where ever possible specific written consent will be sought.  It is the responsibility of those individuals to ensure that the Parish Council is able to keep their personal data accurate and up-to-date.  Their personal information will not be shared or provided to any other third party or be used for any purpose other than that for which it was provided.

THE PARISH COUNCIL’S RIGHT TO PROCESS INFORMATION

General Data Protection Regulations (and Data Protection Act) Article 6 (1) (a) (b) and (e)

Processing is with consent of the data subject or Processing is necessary for compliance with a legal obligation.

Processing is necessary for the legitimate interests of the Parish Council.

INFORMATION SECURITY

The Parish Council cares to ensure the security of personal data.  We make sure that your information is protected from unauthorised access, loss, manipulation, falsification, destruction or unauthorised disclosure.  This is done through appropriate technical measures and appropriate policies.  We will only keep your data for the purpose it was collected for and only for as long as is necessary after which it will be deleted.

CHILDREN

The Parish Council will not process any data relating to a child under 13 without the express parental/guardian consent of the child concerned.

RIGHTS OF THE DATA SUBJECT

ACCESS TO INFORMATION.  An individual has the right to request access to the information we have on them.  They can do this by contacting our Parish Clerk.

INFORMATION CORRECTION.  If they believe that the information we have about them is incorrect, they may contact us so that we can update it and keep their data accurate. Please contact the Parish Clerk.

INFORMATION DELETION.  If the individual wishes the Parish Council to delete the information about them they can do so by contacting the Parish Clerk.

RIGHT TO OBJECT.  If an individual believes their data is not being processed for the purpose it has been collected for they may object by contacting the Parish Clerk.

The Parish Council does not use automated decision making or profiling of individual personal data.

COMPLAINTS.  If an individual has a complaint regarding the way their personal data has been processed they may make a complaint to the Parish Clerk or the Commissioners Office casework@ico.org.uk or telephone 03031231113.

The Parish Council will ensure that individuals on whom personal information is kept are aware of their rights and have easy access to the information on request.

MAKING INFORMATION AVAILABLE

The Publication Scheme is a means by which the Council can make a significant amount of information available routinely without waiting for someone to specifically request it.  The scheme is intended to encourage local people to take an interest in the work of the Parish Council and its role within the community.

In accordance with the provisions of the Freedom of Information Act 2000, this Scheme specifies the classes of information which the Council publishes or intends to publish.

All formal meetings of the Parish Council and its Committees are subject to statutory notice being given on notice boards and the website.  All formal meetings are open to the public and press and reports to those meetings and relevant background papers are available for the public to see.  The Parish Council welcomes public participation and has a public participation session on each Council and Committee meeting.  Details can be seen in the Parish Council’s Standing Orders which are available from the Parish Clerk and on the website.

Occasionally, the Parish Council or Committees may need to consider matters in private. Examples of this are matters involving personal details of staff or a particular member of the public or where details of commercial/contractual sensitivity are to be discussed.  This will only happen after a formal resolution has been passed to exclude the press and public and reasons for the decision are stated. Minutes from all formal meetings, including the confidential parts, are public documents.

The Openness of Local Government Bodies Regulation 2014 requires written records to be made of certain decisions taken by officers under delegated powers. These are not routine operational and

administrative decisions such as giving instructions to the workforce or paying an invoice approved by the Parish Council but would include urgent action taken after consultation with the Chairman such as responding to a planning application in advance of Council.

The 2014 Regulations also amend the Public Bodies (Admission to Meetings) Act 1960 to allow the public or press to film, photograph or make an audio recording of Parish Council and Committee meetings normally open to the public.  The Parish Council will, where possible, facilitate such recording unless it is being disruptive.  It will also take steps to ensure that children, the vulnerable and members of the public who object to being filmed are protected without undermining the broader purpose of the meeting.

The Parish Council will be pleased to make special arrangements on request for persons who do not have English as their first language or those with hearing or sight difficulties.

DATA TRANSPARENCY

The Parish Council has resolved to act in accordance with the Code of Recommend Practice for Local Authorities on Data Transparency (Sept 2011). This sets out the key principles for local authorities in creating greater transparency through the publication of public data and is intended to help them meet obligations of the legislative framework concerning information.

‘Public Data’ means the objective, factual data on which policy decisions are based and on which public services are assessed or which is collected or generated in the course of public service delivery.

The Code will, therefore, underpin the Parish Council’s decisions on the release of public data and ensure it is proactive in pursuing higher standards and responding to best practice as it develops.

The Principles of the Code are:

DEMAND LED: new technologies and publication of data should support transparency and accountability.

OPEN: the provision of public data will be integral to the Parish Council’s engagement with residents so that it drives accountability to them.

TIMELY: data will be published as soon as possible following publication.

Government has all issued a further Code of Recommended Practice on Transparency, compliance of which is compulsory for Parish Councils with turnover not exceeding £25,000 per annum.

Old Hunstanton  Parish Council will have an external audit each year even if its gross income or expenditure does not exceed £25,000.

The Parish Council will ensure that the following information is published on the website:-

DATA PROTECTION TERMINOLOGY

Data Subject – means the person whose personal data is being processed.

Personal data – means any information relating to a natural person or data subject that can be used directly or indirectly to identify the person.

It can be anything from a name, a photo, an address, date of birth, e-mail address, bank details and posts on social networking sites or a computer IP address.

Sensitive personal data – includes information about racial or ethnic origin, political opinions, religious or other beliefs, trade union membership, medical information, sexual orientation, genetic and biometric data or information related to offences or alleged offences where it is used to uniquely identify an individual.

Data Controller – means a person who (either alone or jointly e.g. Parish Council) determines the purposes for which and the manner in which any personal data is to be processed.

Data processor – in relation to personal data, means any person who processes the data on behalf of the data controller.

Processing information or data – means obtaining, recording or holding the information or data or carrying out any operation or set of operations on the information or data including:

21st June 2018.