Privacy Policy
Version 6, Date: 23/5/18
The processing of personal data is governed by legislation relating to personal data which applies in the United Kingdom including the General Data Protection Regulation (the GDPR) and other local legislation relating to personal data and rights such as the Human Rights Act.
- This Privacy Policy is provided by Beenham Parish Council which is the data controller for Parish Council data.
- The personal data collected:
- Contact information (such as email) and other personal information (names and addresses)
- Where activities are paid for, such as use of parish council facilities, financial identifiers such as bank account numbers.
- For a full list of data collected, see appendix B for more details
- The council will comply with data protection law. This says that the personal data held must be:
- Used lawfully, fairly and in a transparent way.
- Collected only for valid purposes that we have clearly explained and not used in any way that is incompatible with those purposes.
- Relevant to the purposes specified and limited only to those purposes.
Accurate and kept up to date. - Kept only as long as necessary for the purposes specified.
- Kept and destroyed securely including ensuring that appropriate technical and security measures are in place to protect personal data to protect personal data from loss, misuse, unauthorised access and disclosure.
- Personal data is used for some or all of the following purposes:
- To contact by email (for example, about community activities)
- To maintain Parish Council accounts and records;
- To send communications which parishioners have requested and that may be of interest.
- To process relevant financial transactions including grants and payments for goods and services supplied to the council
- The legal basis for processing personal data is described in more detail in appendix B.
- The council will implement appropriate security measures to protect personal data. It is likely that personal data will be shared with some or all of the following (but only where necessary):
- The Parish Council may need to keep some other records for an extended period of time. For example, it is legal requirement to keep financial records for a minimum period of 8 years to support HMRC audits or provide tax information. Personal data will be deleted the as soon as is practically possible. See appendix B for more details
- Rights affecting personal data include:
- The right to access personal data we hold on you
- The right to correct and update the personal data we hold on you
- The right to have your personal data erased
- The right to object to processing of your personal data or to restrict it to certain purposes only
- The right to withdraw your consent to the processing at any time for any processing of data to which consent was obtained
- You can contact the Information Commissioners Office on 0303 123 1113 or via email ( https://ico.org.uk/global/contact-us/email/ ) or at the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
- If we wish to use your personal data for a new purpose, not covered by this Privacy Policy, then we will provide you with a Privacy Notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent to the new processing.
- We keep this Privacy Policy under regular review and we will place any updates on this web page, https://beenham-pc.gov.uk/privacy-policy/
- Please contact us if you have any questions about this Privacy Policy or the personal data we hold about you or to exercise all relevant rights, queries or complaints at:
- The Data Controller, Beenham Parish Council, care of the Parish Clerk
- Email: clerk@beenham-pc.gov.uk
APPENDIX A: GDPR – Data held by the Parish Council and GDPR Roles
This table identifies data held by Beenham Parish Council in April 2018, where the data originates, with whom it is shared, the basis for processing the data and the proposed retention period for the data. It has been compiled as part of the implementation of GDPR
| Data held | Where it came from | Shared with whom | Basis for processing data | Data Retention |
| Register of Councillors’ interests: Councillor contact details, name, address, telephone, mobile, email, personal profile etc. including ‘declaration of Interest’ form | Application to be a Parish Councillor | Parish Notes (name, tele and address) Parish web site (photo, name, address, brief personal profile, telephone / mobile number) Parish Clerk | Public Interest | While Councillor is in office. To be removed from Parish Notes and web site within 3 months of leaving office; plus held by Parish Clerk for up to 15 months after leaving office. |
| Email address for information distribution list; first name, surname and email | Application by email address holder | Webmaster only (plus Host for server) | Consent | Individuals can request removal |
| Correspondence from public; name, address, potentially email address and telephone number | Unsolicited correspondence from members of the public | Parish Councillors and Clerk; minimal data only to be shared, and only if necessary to resolve topic. | Public Interest | No more than 15 months after resolution. Parish Councillors to remove information from personal files as soon as possible. |
| Staff information: Name, address, DOB, Renumeration, NI, tax code, bank account, sickness, disciplinary, training records etc. | Employees as part of usual employment procedures. Job applicants during recruitment process. | Statutory authorities as legal requirement. Parish Councillors for job recruitment process. | Legal Requirement | Throughout period of employment, as per legal obligations. After employment data will be retained in line with statutory requirements. Non-statutory information from job applicants deleted within 12 months. |
| Volunteers; name, address, email, telephone number. | Volunteers | N/A | Public Interest | While volunteer is performing the task; deleted within 15 months of leaving role. |
| Hirers of Community facilities. Name, address, tele, email address. | Information provided by Hirer. | Name shared with cleaner who unlocks the facilities. | Contractual necessity | Deleted within 15 months after contract. |
| Web site information for Clubs and Societies. Contact name, email, tele for further information | Information provided by contact individual | Publicly available on the Parish web site. | Public Interest | Deleted from web site and processing emails within 3 months when requested by individual. |
Roles
The following list defines roles within the Parish Council which will support the implementation of GDPR. Some of the roles are obligatory:
- Data Controller (Obligatory) – Full Parish Council, represented by the Chairman. Overall responsible for Data Processing activities and compliance with GDPR
- Data Processors – Parish Clerk, Booking Clerk, Webmaster. This is any person or organisation which processes personal data on behalf of the Data Controller.
- Data Protection Officer (Recommended for a Parish Council) – named Parish Councillor; must have appropriate knowledge of GDPR and will advise on internal compliance, particularly when new processes are introduced.
- Data Protection Compliance Officer (day to day central support and guidance in respect of compliance with processes that cover GDPR). – Parish Clerk