Data protection policy

Published 1 April 2023

Introduction

Westmorland and Furness Council as a public authority, processes large volumes of personal, sensitive personal and criminal or law enforcement data about employees, customers, clients, residents and visitors. As a result, we must comply with data protection legislation including:  

We must collect, use and dispose of personal data lawfully to deliver services and meet our legal duties. This includes information that identifies a person, such as personal data, sensitive personal data, and criminal or law enforcement data.

The purpose of this policy is to:

  • provide an explanation of the Council’s obligations under data protection legislation
  • help data subjects understand their rights and how to exercise them
  • ensure adequate consideration is given to the disclosure of person identifiable data 

The Council aims to promote greater openness, provide increased transparency of data processing and build trust and confidence in the way personal data is managed.

Read the Council's corporate privacy notice

This policy should be read alongside the:

  • Information Security Policy
  • Records Management Policy
  • Data Breach Reporting Policy, Procedure and FAQs 

Scope 

This policy applies to the processing of all data relating to identifiable, living individuals (‘data subjects’) and sets out how the council will comply with the obligations laid out in UKGDPR and DPA 2018.

UKGDPR Article 4(2) defines data processing at uk-gdpr.org

Processing is defined by UKGDPR Article 4(2) as: ‘…any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction…’ 

Policy statement  

The Council is committed to actively demonstrating compliance with core data protection principles and therefore, personal data shall be:

  1. processed lawfully, fairly and in a transparent manner in relation to the data subject 
  2. collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes
  3. adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed
  4. accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without delay
  5. kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed
  6. processed in a manner that ensures appropriate security of the personal data. This includes protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures

As a responsible Data Controller, we will:

  • publish the name of our Data Protection Officer on our website, and record it with the Information Commissioner’s Office (ICO) 
  • meet openness and transparency requirements by publishing a privacy notice that covers both general and service specific data processing
  • have a clear procedure for handling personal data breaches and security incidents
  • provide information to the public and employees about their statutory rights, including Data Subject Access
  • collect data for a clear business purpose and lawful basis
  • manage organisational records with the Records Management Policy
  • retain records with limited business use for archival and research purposes, or destroy them in accordance with our Retention and Disposal Schedule
  • inform all elected members, employees and contractors about their responsibilities through a programme of training and regular communications

We pay the fee required under the Data Protection (Charges and Information) Regulations 2018 once a year. 

Read more about the data protection fee at ico.org.uk

The registration covers our corporate activities. Separate registrations are in place for the Electoral Registration Officer, Superintendent Registrar and Returning Officer.

Roles and responsibilities 

There are a number of officers and teams across the Council that have professional expertise relating to data protection and information security. 

However, it is important that anyone with legitimate access to council data understands their responsibility to ensure information and data is held securely, processed appropriately. 

Senior Information Risk Owner (SIRO)

The Senior Information Risk Owner (SIRO) is responsible for the Council’s approach to managing information risk. This includes:

  • acting as corporate champion for information governance
  • providing a focus for the management of information governance at a senior level
  • providing advice and reports in respect of information security incidents or risks
  • assessing how the Council’s strategic priorities may be impacted by these incidents or risks, and how they can be managed, resourced and scrutinised effectively

To manage identified risks the SIRO is supported by a group of professionals, who can provide advice on the operational and technical aspects of effect data management.

Deputy Senior Information Risk Owner(s)

Authorised either jointly or alone, the Deputy Senior Information Risk Owner(s) will act in the absence of the SIRO to:

  • make decisions regarding referrals to the ICO
  • chair the weekly SIRO review meeting
  • consider the risks and activity contained in the SIRO data breach report as supplied by the Data Protection Officer

Our Chief Legal and Monitoring Officer is responsible for providing legal opinion as requested by the Chief Executive or SIRO.

Data Protection Officer(s) 

As a public authority, we must have a Data Protection Officer (DPO) who is responsible for: 

  • monitoring data protection compliance 
  • providing advice, guidance and training to employees and members
  • maintaining data protection documentation 
  • acting as the point of contact for data protection issues with the Information Commissioners Office
  • working alongside the Information Security Manager to ensure the organisational and technical requirements of the UK General Data Protection Regulation (UKGDPR) are fully implemented 

Caldicott Guardian

This role supports the SIRO and acts as the conscience of the organisation. It is responsible for protecting client and service-user confidentiality. The role holder must be registered with the Caldicott Guardian register.

View the Caldicott Guardian register at nhs.uk

Information Security Manager

The role:

  • works alongside the Data Protection Officer to fully implement the organisational and technical UKGDPR requirements
  • acts as a central point of contact on information security within the organisation, for both users and external organisations
  • implements an effective framework for the management of security
  • is responsible for the formulation, provision and maintenance of Information Security Policies
  • advises on the content and implementation of the Information Security Programme
  • supports the production of organisational standards, procedures and guidance on Information Security matters for review by the SIRO, Section 151 Officer, Data Protection Officer, Caldicott Guardian and other senior staff 
  • coordinates information security activities particularly those related to shared information systems or IT infrastructures
  • liaises with external organisations on information security matters, including representing the organisation in cross-community issues
  • ensures that contingency plans and disaster recovery plans are reviewed and tested on a regular basis 
  • represents the organisation on internal and external bodies that relate to security
  • ensures the systems, application and/or development of required policy standards and procedures in accordance with needs, policy and guidance set centrally
  • approves system security policies for the infrastructure and common services 
  • provides an incident and alert reporting system

They will also provide advice to employees on: 

  • compliance
  • incident investigation 
  • awareness and training
  • system accreditation
  • external service provision 

Records Management Service Manager 

The County Records Management Service (RMS) is responsible for providing advice and guidance for managing council records. It maintains, updates, and answers enquiries on the Retention and Disposal Schedule, which details how long to keep records. The RMS also manages paper records for services that came under Cumbria County Council prior to April 2023. This includes the storage, retrieval and disposal of records. These records are no longer needed for day-to-day business activities but still meet legal and ongoing business requirements.

Information Governance and Investigations Coordinator

The role:

  • monitors data breaches
  • supports the Senior Information Risk Owner (SIRO) in taking appropriate action

Disclosure Officer 

This role supports the Information Governance and Investigations Coordinator and the Data Protection Officer to:

  • manage or investigate data breaches
  • maintain the Council’s data breach reporting system

Information Asset Owners (IAOs) 

The nominated, senior owner of one of more organisational assets as listed in the Council’s Information Asset Register (IAR). The role: 

  • supports the SIRO to manage risks
  • identifies assets
  • manages data breaches and security incidents
  • effectively implements policies and procedures

Information Asset Administrators (IAAs) 

The nominated, administrator of one of more organisational assets as listed in the council’s Information Asset Register (IAR). The role: 

  • consults with the SIRO, IAO, DPO and ISM 
  • updates policies and procedures 
  • identifies data breaches and security incidents
  • provides advice to asset users

Executive Directors and Line Managers 

These roles:

  • ensure that all employees to complete mandatory Information Security and Data Protection eLearning on an annual basis
  • ensure that the security of the organisation’s information assets is consistent with legal and management requirements and obligations. This includes information, hardware and software used by staff and, where appropriate, by third parties
  • ensure that employees, temporary and contracted staff, contractors, elected members and third parties acting for the Council conform with System Security Policies and Security Operating Procedures
  • understand and reduce risk to information risk within the directorate
  • assign ownership to information assets
  • ensure that their employees are aware of their security responsibilities
  • ensure directorate arrangements are in place to manage information risk
  • provide assurance that information assets are protected against security risks and threats 

Employees 

All council employees, temporary and contracted staff, contractors, elected members and third parties acting for the council have a statutory duty of confidentiality to protect information and only use it for the purposes for which it was intended. 

All users have a duty to:

  • complete mandatory Information Security and Data Protection eLearning on an annual basis
  • conform to System Security Policies and Security Operating Procedures
  • be aware of their security responsibilities
  • safeguard hardware, software and information in their care
  • prevent the introduction of malicious software on the organisation’s IT systems
  • report on any suspected or actual breaches in security
  • be aware that any breach of confidentiality is a serious matter which may result in disciplinary action by the council or the appropriate professional regulatory body

Data Protection Officer (DPO)

Under UKGDPR, the Council must appoint a Data Protection Officer (DPO) because:

  • it is a public authority or body
  • core activities require large scale, regular and systematic monitoring of individuals
  • core activities consist of large-scale processing of special categories of data

Data Protection Officer
Email: dataprotection@westmorlandandfurness.gov.uk

Address:
Westmorland and Furness Council
South Lakeland House
Lowther Street
Kendal
Cumbria
LA9 4DQ 

Data Subject Access rights

UKGDPR gives you the right to access the personal, special category personal or criminal and law enforcement data that we hold about you. After receiving a valid request, we will:

  • provide you with a response within one month
  • let you know if your request is subject to an extension 
  • make reasonable efforts to comply with the format of your request
  • inform you if your request is going to be refused or a charge is payable

We will not disclose:

  • any information that relates to a third party as this will breach their rights under UKGDPR or the Data Protection Act 2018
  • where a professional thinks disclosure would cause serious harm to you or someone else
  • information that may hinder the prevention or detection of crime 

Other rights

In addition to the right of access, we must comply with the additional rights contained under UKGDPR Articles 16 to 22.

Read articles 16 to 12 at uk-gdpr.org

Rectification

You have the right to have personal data rectified if it is inaccurate or incomplete.

Erasure 

You have the right to have personal data deleted or removed where there is no compelling reason for its continued processing.

Restriction

You have a right to ‘block’ or suppress processing of personal data depending on whether the information is collected by statute or consent. When processing is restricted, the Council can store the personal data, but not further process it. Just enough information about the individual to ensure that the restriction is respected in future should be retained.

Portability

In specific situations, you can request a copy of their personal data in a format that they can take to another provider.  This is rare in local government as it relies on automated processing in which no person is involved in the processing.

Object to processing

You can object to how we process your personal data in certain situations. We will follow a process to review and respond to your objection.

Processing in the public interest or under official authority

You can object if we process your data based on legitimate interests, or to carry out a task in the public interest or under official authority, including profiling. This applies where you believe we have not correctly assessed the public interest.

Direct marketing

If you object to direct marketing, we must stop sending it to you.

Research and statistics

You can object if we process your information for scientific, historical or statistical research in certain circumstances.

You can exercise any of these rights by contacting us. 

Data Protection Officer
Email: dataprotection@westmorlandandfurness.gov.uk

Address:
Westmorland and Furness Council
South Lakeland House
Lowther Street
Kendal
Cumbria
LA9 4DQ 

Timescales and extensions 

We will respond to data subject access requests and other data rights requests within one calendar month.

We aim to respond as quickly as possible and may provide the information sooner where we can.

If a request is complex, we can extend the response time by up to a further two months under UKGDPR Article 12(3). If we need more time, we will write to you to explain why and tell you when you can expect a response. We will make sure this timescale is realistic and reflects the circumstances of your request.

If we rely on your consent to process your personal data under UK GDPR Article 6(1)(a) or Article 9(2)(a), you have the right under UKGDPR Article 7(3) to withdraw that consent at any time.

If you withdraw your consent, we must stop processing your data for that purpose unless we can rely on another lawful basis. Withdrawing consent does not affect any processing we carried out before you withdrew it. We will explain any impact this may have, especially if you receive essential services. 

To withdraw your consent, contact the service that collected your data in the first instance. 

If you have any questions or concerns, please contact us.

Data Protection Officer
Email: dataprotection@westmorlandandfurness.gov.uk

Refusing requests

We will not supply information to a data subject if:

  • the request is not clear enough for the council to conduct an effect search
  • the identity of the data subject cannot be identified
  • responding to the request will inadvertently disclose personal information relating to another individual without their consent
  • the same or similar information has been requested within the last three months, dependent on nature of data

When a valid reason exists for refusing the disclosure of information to either the data subject or a third party, the information should be withheld. The reason should be robust which can be defended legally.

We'll provide full reasoning when any information is refused. This explanation must also include the details of how you can complain about our decision. 

Verifying your identity

When exercising your rights, we can request additional information under UKGDPR Article 12(6) where the identity of data subjects cannot be confirmed. 

Additional documentation will only be needed if we cannot confirm the identity of data subjects using internal systems and/or data sources

Documentation from data subjects should be requested prior to processing requests.

The statutory deadline for responding to requests will only start when additional documentation is provided. 

Failure to provide additional documentation may lead to us rejecting requests.

Data breaches

We must legally ensure the security and confidentiality of your data under UKGDPR. We must maintain data breach detection, investigation and internal reporting procedures to ensure that risks are identified, contained and managed effectively.

We must report certain types of personal data breaches to the Information Commissioner’s Office (ICO) under UKGDPR Article 33. In the event of a significant data breach that is likely to affect your rights and freedoms, we will: 

  • report it to the ICO within 72 hours of becoming aware of it, where relevant
  • tell the individuals concerned, where required

Data breaches can be reported by email to dataprotection@westmorlandandfurness.gov.uk 

Complaints 

You can raise a complaint about the:

  • responses received to Data Subject Access Requests
  • handling of personal, special category or criminal and law enforcement data 

If you've received a response to a Data Subject Access Request and you believe it is incomplete, please raise this with us.

Complaints submitted for consideration under the Internal Review Procedure will be processed in most cases within 20 working days. If an extension is required, we'll inform you directly. 

If you're dissatisfied with the handling of your personal data, please contact the service responsible for the provision or management of your data.

In both instances, although we can address areas of concern directly, you have the right to complain to the Information Commissioner (ICO) at any time.

Information Commissioning Officer
Telephone: 0303 123 1113

Make a complaint online at ico.org.uk 

Speak to an ICO live chat agent at ico.org.uk