General Data Protection Regulation (GDPR) Policy
Reviewed July 2026 – Next Review July 2028
1. Introduction
Leven Parish Council is committed to protecting the rights and freedoms of individuals whose personal data it collects and processes. This policy ensures that all personal data is handled lawfully, fairly, and transparently, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The Council recognises that data protection safeguards the privacy of individuals and supports public trust in how information is managed.
The Information Commissioner’s Office (ICO) oversees compliance and promotes good practice. Leven Parish Council is registered with the ICO as a data controller.
2. Roles and Responsibilities
- The Parish Clerk acts as the Council’s designated contact for data protection
matters.
- All councillors, employees, and volunteers are responsible for complying with data protection legislation.
- The Council will ensure that all staff and councillors receive appropriate training and guidance.
- The Council will maintain a record of processing activities and review it annually.
Although parish councils are not required to appoint a formal Data Protection Officer,
the Clerk will act as the Council’s lead for data protection compliance.
3. Data Collection and Use
The Council collects and processes personal data to fulfil its statutory duties and public functions. This includes information about:
- Employees and councillors
- Residents and service users
- Contractors and suppliers
- Volunteers and community partners
Data may be collected:
- To comply with legal obligations
- To perform tasks in the public interest
- With the consent of the individual
The Council will only collect data that is necessary for its legitimate purposes and will not retain it longer than required.
4. Data Protection Principles
All processing of personal data by Leven Parish Council will follow the seven principles of the UK GDPR:
- Lawfulness, fairness and transparency – data must be processed lawfully and openly.
- Purpose limitation – data must be collected for specified, legitimate purposes.
- Data minimisation – data must be adequate, relevant and limited to what is necessary.
- Accuracy – data must be accurate and kept up to date.
- Storage limitation – data must not be kept longer than necessary.
- Integrity and confidentiality – data must be processed securely.
- Accountability – the Council must be able to demonstrate compliance with all principles.
5. Data Subject Rights
Individuals have the following rights under the UK GDPR:
- To access their personal data (Subject Access Request)
- To have inaccurate data corrected
- To have data erased (“right to be forgotten”)
- To restrict or object to processing
- To data portability (receive their data in a structured format)
- To object to automated decision-making or profiling
- To lodge a complaint with the ICO
Requests will normally be processed free of charge within one month, extendable by up to two months for complex cases.
Complaints relating to data handling will be managed under the Council’s Complaints Policy.
6. Data Sharing and Disclosure
The Council will not disclose personal data to unauthorised third parties, including family members, friends, suppliers or other organisations, except where:
- The individual has given consent
- Disclosure is required by law
- Disclosure is necessary to perform a public task
All councillors and staff must exercise caution when handling personal data and ensure that any sharing is lawful and documented.
7. Data Security
The Council will take appropriate technical and organisational measures to protect personal data, including:
- Secure storage of electronic and paper records
- Password protection and encryption where appropriate
- Regular updates to antivirus and firewall software
- Controlled access to data based on role and necessity
- Secure disposal of data when no longer required
Data breaches will be treated seriously and investigated promptly.
8. Data Breaches and Incidents
If a data breach occurs or is suspected:
- The Clerk will investigate immediately.
- Serious breaches will be reported to the ICO within 72 hours of discovery.
- Affected individuals will be notified where required.
- The Council will record all breaches and lessons learned.
9. Risk Assessment and Review
The Council will maintain a GDPR Risk Register identifying potential risks and
mitigation measures. This will be reviewed annually alongside the Council’s data audit.
10. Training and Awareness
All councillors and staff will receive periodic training on data protection responsibilities. New members and employees will be briefed during induction.
11. Policy Review and Accountability
This policy will be reviewed every two years or sooner if legislation or guidance changes. The Clerk will report annually to the Council on compliance and any data protection issues.
12. Contact
For data protection enquiries or Subject Access Requests, contact: □ •
clerk@levenparishcouncil.gov.uk 07725 301557
