| AREA OF RISK | RISK | LEVEL H/M/L | MANAGEMENT OF RISK | ACTION |
| Email security | Unauthorised access to council emails | L | Emails accounts all within the Leven PC domain and are password protected. Use of bcc to send wider mail shots to external parties. Delete emails from residents when issues have been resolved. | Do not forward emails from residents cut and paste information into a new email. |
| General internet security | Unauthorised access to council computers and files | L | Computer password protected and has up to date anti virus software. Operating system is hosted remotely through a host organisation that manages storage in line with GDPR requirements. | Remind Councillors to ensure their security systems are up to date and installed correctly. |
| Use of Whatsapp | Access to whatsapp group data | M | Never refer to personal data when using the Leven PC whatapp group | Continue to remind councillors |
| Website SM security | Personal information or photographs of individuals published | M | Ensure written consent is secured for photographs of individuals including parental consent for those under 17. Security is provided on the website by the host organisation (Getextra) including statements regarding GDPR. | Provide a proforma for consent for events |
| Financial Risks | Financial loss following a data breach | L | The council has funds in reserve for contingencies related to fines | Ensure insurance policy covers liability cover for data breaches |
| Filming | Filming and recording at meetings | L | If a meeting is closed to discuss confidential information ensure no phones or other devices are able to record the session. If filming of public meeting is enabled ensure all filmed give consent if not ensure those not giving consent are not recorded | Chair to issue a statement on recording at the beginning of all meetings |