Overview

We are committed to protecting your privacy when you use our services.

This privacy notice explains how we use information about you and how we protect your privacy.

Each of our service areas have their own individual privacy notice with more detailed information about how we handle your information for specific council services, including who we may share your information with and why.

We have also produced easy read and child friendly versions:

Our Data Protection Officer makes sure we follow the law. If you have any concerns or questions about how we look after your personal information, please contact our Data Protection Officer.

What is personal information?

Personal information is anything that identifies and relates to a living person. This can include information that when put together with other information can identify a person. For example, this could be your name and contact details. See definition of personal data on Information Commissioner’s Office.

Special category information

Some information is more sensitive and therefore needs more protection. It’s often information you would not want widely known and is very personal to you. This is likely to include anything that can reveal your:

Why we use your personal information

We may need to use some information about you to:

We only use what we need

We only collect and use personal information if we need it to deliver a service or meet a requirement.

If we don’t need personal information we’ll either keep the information anonymous if we already have it for something else or we won’t ask you for it. For example in a survey we may not need your contact details.

If we use your personal information for research and analysis, we’ll always keep your information anonymous or use a different name unless you’ve agreed that your personal information can be used for that research.

We will not sell your personal information to anyone else.

How the law allows us to use your personal information

There are a number of legal reasons why we are allowed to collect and use your personal information. The reason why we are allowed to use the information is different for each council service.

The reasons we may use your personal information are set out below. You can also see the rights you have when we use your personal information.

Article 6. Schedule: personal information

Legal basis and applicable subject rightsInformAccessRectifyEraseRestrictObjectAutomated Decisions /ProfilingPortability
ConsentYesYesYesYesYesYesYesYes
ContractYesYesYesYesYesNoYesYes
Vital InterestsYesYesNoYesYesNoNoNo
Legal ObligationYesYesYesNoYesNoYesNo
Public TaskYesYesYesNoYesYesYesNo
Legitimate InterestsYesYesYesYesYesYesYesNo

Article 9. Schedule: special category (sensitive) personal information

Legal basis and applicable subject rightsInformAccessRectifyEraseRestrictObjectAutomated Decisions /ProfilingPortability
Explicit ConsentYesYesYesYesYesYesYesYes
Employment, Social Security/Social ProtectionYesYesYesYesYesNoYesNo
Vital InterestsYesYesYesNoYesNoNoNo
Not for ProfitYesYesYesYesYesYesYesNo
Public DomainYesYesYesYesYesYesYesYes
Legal Defence/ClaimsYesYesYesNoYesNoYesNo
Substantial Public InterestYesYesYesNoYesNoNoNo
Health and Social CareYesYesYesNoYesNoYesNo
Public Interest in Public HealthYesYesYesNoYesNoYesNo
Scientific/historical Research, Statistics or Public ArchivingYesYesNoNoYesYesYesNo
Additional considerationsNoneNoneNoneWill always apply to direct marketingNoneWill always apply to direct marketingWhere it places a legal effect on an individualOnly where use of data is solely by automated means

More detail on when each legal basis may apply, please see below.

Personal information

This would apply when:

Special (sensitive) personal information

This would apply when:

What you can do with your information

The law gives you a number of rights to control what personal information is used by us and how it is used by us.

You can ask for access to the information we hold on you. We would normally share what we record about you with you when we assess your needs or provide you with services.

However, you also have the right to ask for all the information we have about you and the services you receive from us. When we receive a request from you in writing, we must give you access to everything we’ve recorded about you.

However, we cannot share any records which contain:

This applies to personal information that is in both paper and electronic records.

If you are unable to ask for your information in writing, we’ll make sure there are other ways that you can request it. If you have any queries about access to your information please contact our transparency team:

Transparency team

Telephone: 03330 139 853

Email: transparencyteam@essex.gov.uk

You can ask to change information you think is inaccurate

You should let us know if you disagree with something written about you.

We may not always be able to change or remove that information but we’ll correct factual inaccuracies and may include your comments in the record to show that you disagree with it.

Let us know if something is inaccurate.

You can ask to delete information (right to be forgotten)

In some circumstances you can ask for your personal information to be deleted, for example, where:

Where your personal information has been shared with others, we’ll tell them about your request to us for it to be deleted.

Please note that we don’t have to delete your information if:

You can ask to limit what we use your personal data for

You have the right to ask us to restrict what we use your personal information for where:

When information is restricted it can’t be used other than to securely store the data and with your consent to handle legal claims and protect others, or where it is required by law.

Where restriction of use has been granted, we’ll inform you before we carry on using your personal information.

You have the right to ask us to stop using your personal information for any council service. However, if this request is approved this may cause delays or prevent us delivering that service.

Where possible we’ll seek to comply with your request, but we may need to hold or use information because we are required to by law.

You can ask to have your information moved to another provider (data portability)

You have the right to ask for your personal information to be given back to you or another service provider of your choice in a commonly used format. This is called data portability.

However this only applies if we’re using your personal information with consent (not if we’re required to by law) and if decisions were made by a computer and not a human being.

It is unlikely that data portability will apply to most of the services you receive from the Council.

You can ask to have any computer made decisions explained to you, and details of how we may have ‘profiled’ you

You have the right to question decisions made about you by a computer, unless it’s required for any contract you have entered into, required by law, or you’ve consented to it.

You also have the right to object if you are being ‘profiled’. Profiling is where decisions are made about you based on certain things in your personal information, eg your health conditions.

If and when we use your personal information to profile you, in order to deliver the most appropriate service to you, you will be informed.

If you have concerns regarding automated decision making, or profiling, please contact the Data Protection Officer who’ll be able to advise you about how we use your information.

You can object to us sending you direct marketing

You have the right to ask us to stop sending you information about our services. If you ask us to stop we will do so.

You may have the right to object to our use of your personal information

In limited circumstances you can object to our use of your personal data, in such cases we would need to weigh your right to privacy against the wider public interest in continuing to use your information.

Who we share your information with

We use a range of organisations to either store personal information or help deliver our services to you. Where we have these arrangements there is always an agreement in place to make sure that the organisation complies with data protection law.

We’ll often complete a data protection impact assessment (DPIA) before we share personal information to make sure we protect your privacy and comply with the law. Sometimes we have a legal duty to provide personal information to other organisations. This is often because we need to give that data to courts, including:

We may also share your personal information when we feel there’s a good reason that’s more important than protecting your privacy. This doesn’t happen often, but we may share your information:

Working with fraud prevention agencies

The personal information we have collected from you will be shared with fraud prevention agencies who will use it to prevent fraud, money-laundering and to verify your identity. They will also share your information with a range of information providers to obtain documentation or information that will allow us to verify the information you have provided us is accurate. If fraud is detected, you could be refused certain services, finance, or employment.

Further details of how your information will be used by us and these fraud prevention agencies, and your data protection rights can be found on the National Anti Fraud Network (NAFN) and the National Fraud Initiative (NFI) Fraudhub privacy notices.

For all of these reasons the risk must be serious before we can override your right to privacy.

We also participate in the Cabinet Office’s National Fraud Initiative, a data matching exercise to assist in the prevention and detection of fraud. We are required to provide particular sets of data to the Minister for the Cabinet Office for matching for each exercise.

The use of data by the Cabinet Office in a data matching exercise is carried out with statutory authority under Part 6 of the Local Audit and Accountability Act 2014. It does not require the consent of the individuals concerned under the Data Protection Act 2018.

Data matching by the Cabinet Office is subject to a Code of Practice.

Read the National Fraud Initiative privacy notice for more information about the Cabinet Office’s legal powers and the reasons why it matches particular information.

We may also upload your data to the Pan Essex Data Hub as part of a data sharing agreement with other Essex authorities. The Pan Essex Hub is hosted in the UK and managed by our data processor Vigilant Apps. This exercise allows us to identify potential fraud by comparing our datasets with other local authorities. If a query is identified, we may share or receive your personal data with or from the relevant parties accordingly.

Keeping you safe

If we’re worried about your physical safety or feel we need to take action to protect you from being harmed in other ways, we’ll discuss this with you and, if possible, get your permission to tell others about your situation before doing so.

We may still share your information if we believe the risk to others is serious enough to do so.

There may also be rare occasions when the risk to others is so great that we need to share information straight away.

If this is the case, we’ll make sure that we record what information we share and our reasons for doing so. We’ll let you know what we’ve done and why if we think it is safe to do so.

How do we protect your information?

We strive to ensure that the records we hold about you (on paper and electronically) are held in a secure way, and we’ll only make them available to those who have a right to see them.

Examples of our security include:

You can find more details of our information security within our general description of security measures (113KB PDF).

Will your personal information be sent or stored in countries without the same data protection rights as the UK?

The majority of personal information is stored on systems in the UK. But there are some occasions where your information may leave the UK either in order to get to another organisation or if it’s stored in a system outside of the European Union (EU).

We have additional protections on your information if it leaves the UK ranging from secure ways of transferring data to ensuring we have a robust contract in place with that third party.

We’ll take all practical steps to make sure your personal information is not sent to a country that is not deemed ‘safe’ by the UK Government.

If we need to send your information to a location which is not on the list of locations deemed a ‘safe’ location we’ll always seek advice from the Information Commissioner (ICO) first.

How long do we keep your personal information?

For each service the schedule lists how long your information may be kept for. This ranges from months for some records to decades for more sensitive records.

Our retention schedule

There is often a legal reason for keeping your personal information for a set period of time. We try to include all of these in our Retention Schedule (PDF, 683.69 KB).

Where you can get advice

If you have any worries or questions about how your personal information is handled, please contact our Data Protection Officer.

Data Protection Officer

Telephone: 0345 743 0430 (ask to speak to the Information Governance Team)

Email: DPO@essex.gov.uk

For independent advice about data protection, privacy and data sharing issues, you can contact the Information Commissioner’s Office.

Information Commissioner’s Office

Telephone: 0303 123 1113 (local rate) or 01625 545745 (national rate)

Email: casework@ico.org.uk

Website: https://ico.org.uk/

Address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF