Parish Council GDPR
Understanding GDPR for Parish Councils
The General Data Protection Regulations (GDPR), which came into effect on 25 May 2018, is a network of principles and rights underpinned by regulations and systems that operates throughout the European Union (EU) to preserve and protect the personal data of individuals. It applies to every EU citizen. This wide-ranging legislation is designed to give the individual more rights to their data held by organisations and the key actionable points are:
- Any person has the right to ask for all the information you hold on them, both human and machine based
- Any person has the right to request deletion of all personal data held by any organisation
- Organisations must have, and state, a valid reason for collecting, processing and storing data
- Organisations must seek consent when collecting data
- Organisations must provide individuals with a route to reverse a given consent at any time
- Organisations must protect personal data that they have collected.
Online GDPR compliance
All parish councils must guarantee that their online presence is GDPR compliant. In essence this means:
Cookie policy
Consent for cookies cannot be assumed – it must be given. Cookies that track users must be inactive, or deactivated until such consent is delivered. This includes, but is not limited to, Google Analytics. It must be clear to the individual what they are consenting to and they must have an open choice and be in control of that choice. If the individual withholds consent, their online experience should be identical to that offered to a consent-giver. Consent must not be irrevocable – the individual should be able to withdraw it whenever they choose.
The UK Information Commissioner’s Office (ICO) has recommended that to ensure transparency, cookie policy should be shown to the web user as a popup or similar instrument as soon as they arrive on a site and that instrument should contain information about what a cookie is and what it does.
Privacy Policy
In terms of a parish council, a written privacy policy should tell any online visitor what policies the council is applying in relation to GDPR. Once again the ICO has some advice, including:
- Choose clear and simple language
- Express information simply in an easy to understand style
- Do not make assumptions about understanding – ensure information contains explanations and definitions
- Legalese and complex terminology should be avoided
- Do research into effectiveness when writing your privacy policy, and align it to your house style. Professional copywriters can help tailor the necessary information to meet your users’ expectations
- Use your values and principles to underpin your privacy policy – this gives people greater confidence in it, encourages them to read and understand it and respond appropriately.
- Avoid offering misleading choices
- Don’t offer people choices that are may mislead them or seem counter-intuitive
- When applying GDPR rulings, also apply any sectoral or industry specific rules like those governing advertising or the delivery of financial services
- Check that your privacy notice is the same across all platforms so that you can update it as necessary.
Sample GDPR-compliant Privacy Notice
XX PARISH COUNCIL will henceforth be referred to as the ‘Controller’ of any personal data you provide to us. We will collect only basic data – which does not include any special types of information or any location-based information. It may, however, include your name, email, telephone number and address.
The reasons we collect your data
XX PARISH COUNCIL needs access to basic data in order to provide services. We commit to not collecting any personal data that isn’t necessary to provide and oversee this service.
What we are allowed to do with your data
Our officers are allowed to process all the personal data collected, to conduct Parish Council business. We keep this information on servers that are within the European Union (EU). We confirm that no third party has access to your personal data unless they are legally allowed to do so.
XX PARISH COUNCIL has a Data Protection apparatus in place to supervise effective and secure processing of all personal data. Further information on this regime is available on our website.
How long we store your data
UK tax law requires us to keep your basic personal data for a minimum of six years. At the end of this period, it will be destroyed or deleted. Any information we use for marketing purpose is held by us until you tell us that you no longer wish to receive information from us.
Other uses we make of your data
When you contact us on a contact form or by email, we may use the data you supply to process your query. If you subscribe to updates or newsletters we continue to send them until you unsubscribe.
Your rights
Under GDPR, you have the right to see any information we hold on you and to have it corrected or deleted. If you wish to complain about our handling of your personal data, you can contact us in the first instance and ask us to investigate, on the email your-email-here@domain.com. Should you not be happy with our response, or believe we are processing your information improperly, you are free to complain to the Information Commissioner. Further information can be found at https://ico.org.uk/
SSL Certification
Possession of an SSL certificate means that any data travelling between the individual’s computer and the Parish Council’s website is secure. An SSL certificate is required even if your website merely contains a contact form or if a web user is able to subscribe to updates from your council. Most browsers regularly alert web-users to the fact that they are visiting non https websites, so most councils are choosing to ensure their websites are SSL compliant.
Do Parish Councils need to appoint a Data Protection Officer?
GDPR states that a Data Protection Officer (DPO) has to be appointed by any public authority or body processing data. Initial it was believed this would apply to Parish Councils. However the ICO has now stated that a ‘public authority’ for GDPR purposes is either one defined as such by the Freedom of Information Act 2000 or, a Scottish public authority as defined by the Freedom of Information (Scotland) Act 2002, or a body or authority described as such in regulation by the Secretary of State.
In section 7 of the Data Protection Act 2018, it clearly states that none of the following are public authorities for GDPR purposes:
- An English parish council
- A Welsh community council
- A Scottish community council
- Any parish meeting formed under section 13 of the Local Government Act 1972
- Any community meeting formed under section 27 of the Local Government Act of the same year
- Charter trustees formed under section 246 of the Local Government Act 1972, or under Part 1 of the Local Government and Public Involvement in Health Act 2007, or under the Charter Trustees Regulations 1996.
This means that a Parish Council, unless it has some other ordinance that governs its actions, does not need to appoint a DPO.
Given that a Parish Council is not a public authority for GDPR purposes, it’s important to note that this doesn’t affect the council’s status as a public authority under other forms of legislation.
Finding an effective solution to GDPR compliance
GDPR is legislation with teeth, including the risk of being fined, being prosecuted or having negative press that affects the function and reputation of the Parish Council.
GDPR is also a complex set of laws, requirements and policies that can be demanding to understand and apply. That’s why Nirvana Webstudio has defined a comprehensive package that makes GDPR compliance straightforward. Our package contains:
- An installed and configured SSL certificate that guarantees data encryption between user and website.
- A tailored privacy policy page that is fully GDPR compliant, with optional Data Protection Officer contact details.
- Simple functionality permitting users to automatically download and delete personal data
- A fully GDPR compliant cookie consent regime that gives the visitor power to allow or revoke access.
We also offer a standard package that provides SSL certification but doesn’t deliver GDPR compliance without further modification. It can publish a privacy policy and cookie policy if they are already prepared, but lacks some of the tools and functionality of the already have one ready but it doesn’t come with the same tools and functionality options as our comprehensive package
Finally, we offer a baseline package that doesn’t provide SSL certification or a contact form, as this would require SSL certification. If your website does not offer a contact mechanism, it doesn’t require an SSL certificate.
Since July 2018, most search engines have displayed a prominent ‘not secure’ message when visitors land on any site lacking SSL. This can be off-putting for genuine visitors and damage confidence in your website.
Please explore our Parish Council website packages here and contact us if you have any questions.
We'd Love To Hear From You

Rebecca

Audrius

David

Rick

Harriet

Billy

Ava
