Adopted by Full Council on 2025 Revision
mill
pg. 1
Eskdale Parish Council is committed to being transparent about how it collects and uses the personal data of staff, and to meeting our data protection obligations. This policy sets out the council’s commitment to data protection, and your rights and obligations in relation to personal data in line with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA).
This policy applies to the personal data of current and former job applicants, employees, workers, contractors, and former employees, referred to as HR-related personal data. This policy does not apply to the personal data relating to members of the public or other personal data processed for council business.
The council has appointed the clerk as the person with responsibility for data protection compliance within the council. Questions about this policy, or requests for further information, should be directed to them.
“Personal data” is any information that relates to a living person who can be identified from that data (a ‘data subject’) on its own, or when taken together with other information. It includes both automated personal data and manual filing systems where personal data are accessible according to specific criteria. It does not include anonymised data.
“Processing” is any use that is made of data, including collecting, recording, organising, consulting, storing, amending, disclosing or destroying it.
“Special categories of personal data” means information about an individual’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation and genetic or biometric data as well as criminal convictions and offences.
“Criminal records data” means information about an individual’s criminal convictions and offences, and information relating to criminal allegations and proceedings.
The council processes HR-related personal data in accordance with the following data protection principles the council:
The council will tell you of the personal data it processes, the reasons for processing your personal data, how we use such data, how long we retain the data, and the legal basis for processing in our privacy notices.
Adopted by Full Council on 2025 Revision
mill
pg. 2
The council will not use your personal data for an unrelated purpose without telling you about it and the legal basis that we intend to rely on for processing it. The council will not process your personal data if it does not have a legal basis for processing.
The council keeps a record of our processing activities in respect of HR-related personal data in accordance with the requirements of the General Data Protection Regulation (GDPR).
The Clerk of Eskdale Parish Council is responsible for ensuring adherence with the Data Protection Act.
The council will process your personal data (that is not classed as special categories of personal data) for one or more of the following reasons:
If the council processes your personal data (excluding special categories of personal data) in line with one of the above bases, it does not require your consent. Otherwise, the council is required to gain your consent to process your personal data. If the council asks for your consent to process personal data, then we will explain the reason for the request. You do not need to consent or can withdraw consent later.
The council will not use your personal data for an unrelated purpose without telling you about it and the legal basis that we intend to rely on for processing it.
Personal data gathered during the employment is held in your personnel file in hard copy and electronic format on the council’s laptop. The periods for which the council holds your HR-related personal data are contained in our privacy notices to individuals.
Sometimes the council will share your personal data with contractors and agents to carry out our obligations under a contract with the individual or for our legitimate interests. We require those individuals or companies to keep your personal data confidential and secure and to protect it in accordance with Data Protection law and our policies. They are only permitted to process that data for the lawful purpose for which it has been shared and in accordance with our instructions.
The council will update HR-related personal data promptly if you advise that your information has changed or is inaccurate. You may be required to provide documentary evidence in some circumstances.
The council keeps a record of our processing activities in respect of HR-related personal data in accordance with the requirements of the General Data Protection Regulation (GDPR).
Adopted by Full Council on 2025 Revision
mill
pg. 3
The council will only process special categories of your personal data (see above) on the following basis in accordance with legislation:
If the council processes special categories of your personal data in line with one of the above bases, it does not require your consent. In other cases, the council is required to gain your consent to process your special categories of personal data. If the council asks for your consent to process a special category of personal data, then we will explain the reason for the request. You do not have to consent or can withdraw consent later.
As a data subject, you have a number of rights in relation to your personal data.
You have the right to make a subject access request. If you make a subject access request, the council will tell you:
The council will also provide you with a copy of your personal data undergoing processing. This will normally be in electronic form if you have made a request electronically, unless you agree otherwise. If you want additional copies, the council may charge a fee, which will be based on the administrative cost to the council of providing the additional copies.
To make a subject access request, you should send the request to the Clerk or Chairman of the Council. In some cases, the council may need to ask for proof of identification before the request can
Adopted by Full Council on 2025 Revision
mill
pg. 4
be processed. The council will inform you if we need to verify your identity and the documents we require.
The council will normally respond to a request within a period of one month from the date it is received. Where the council processes large amounts of your data, this may not be possible within one month. The council will write to you within one month of receiving the original request to tell you if this is the case.
If a subject access request is manifestly unfounded or excessive, the council is not obliged to comply with it. Alternatively, the council can agree to respond but will charge a fee, which will be based on the administrative cost of responding to the request. A subject access request is likely to be manifestly unfounded or excessive where it repeats a request to which the council has already responded. If you submit a request that is unfounded or excessive, the council will notify you that this is the case and whether or not we will respond to it.
You have a number of other rights in relation to your personal data. You can require the council to:
To ask the council to take any of these steps, you should send the request to the Clerk or Chairman of the Council.
The council takes the security of HR-related personal data seriously. The council has internal policies and controls in place to protect personal data against loss, accidental destruction, misuse or disclosure, and to ensure that data is not accessed, except by employees in the proper performance of their duties.
Where the council engages third parties to process personal data on our behalf, such parties do so on the basis of written instructions, are under a duty of confidentiality and are obliged to implement appropriate technical and organisational measures to ensure the security of data.
The council have robust measures in place to minimise and prevent data breaches from taking place. Should a breach of personal data occur the council must take notes and keep evidence of that breach. If you are aware of a data breach you must contact the Clerk or Chairman of the Council immediately and keep any evidence, you have in relation to the breach.
Adopted by Full Council on 2025 Revision
mill
pg. 5
If the council discovers that there has been a breach of HR-related personal data that poses a risk to the rights and freedoms of yourself, we will report it to the Information Commissioner within 72 hours of discovery. The council will record all data breaches regardless of their effect.
If the breach is likely to result in a high risk to the rights and freedoms of individuals, we will tell you that there has been a breach and provide you with information about its likely consequences and the mitigation measures we have taken.
The Information Commissioner maintains a public register of data controllers. The Parish Council is registered as such.
The Data Protection Act 1998 requires every data controller who is processing personal data, to notify and review their notification, on an annual basis. Failure to do so is a criminal offence.
The Data Controller will review the Data Protection Register annually, prior to notification to the Information Commissioner.
Any changes to the register must be notified to the Information Commissioner, within 28 days.
To this end, any changes made between reviews will be brought to the attention of the Data Controller immediately.
You are responsible for helping the council keep your personal data up to date. You should let the council know if data provided to the council changes, for example if you move to a new house or change your bank details.
Everyone who works for, or on behalf of, the council has some responsibility for ensuring data is collected, stored and handled appropriately, in line with the council’s policies.
You may have access to the personal data of other individuals and of members of the public in the course of your work with the council. Where this is the case, the council relies on you to help meet our data protection obligations to staff and members of the public. Individuals who have access to personal data are required:
Adopted by Full Council on 2025 Revision
mill
pg. 6
Failing to observe these requirements may amount to a disciplinary offence, which will be dealt with under the council’s disciplinary procedure. Significant or deliberate breaches of this policy, such as accessing personal data without authorisation or a legitimate reason to do so or concealing or destroying personal data as part of a subject access request, may constitute gross misconduct and could lead to dismissal without notice.
The council provides training to all individuals about their data protection responsibilities.
If your roles require you to have regular access to personal data, or you are responsible for implementing this policy or responding to subject access requests under this policy, you will receive additional training to help you understand your duties and how to comply with them.
This is a non-contractual policy and procedure which will be reviewed from time to time.
Date of policy: 28 January 2025
Supersedes:
Approved by Council
Tuesday, 8 September 2026
Tuesday, 13 October 2026
Tuesday, 10 November 2026