New website
We're currently redeveloping our website so you may see a mix of old and new style pages while we complete this work. We'd love to hear your feedback on the new style.
Schedule 1 of the Data Protection Act 2018 requires that organisations have an Appropriate Policy Document in place for when processing special category or criminal data for specific purposes.
This document serves as the Appropriate Policy Document for Norwich City Council.
The processing of special category data is undertaken in line with the following articles of the UK GDPR:
The Council processes special category data both to fulfil our obligations as an employer and as part of our statutory duties as a Tier 2 local authority.
The Council processes special category data about our employees that is necessary to fulfil our obligations as an employer. This includes information about their health and wellbeing, ethnicity, photographs and their membership of any trade union. Further information about this processing can be found in our Human Resources privacy notice.
Our processing for reasons of substantial public interest relates to the data we receive or obtain in order to fulfil our statutory function as a Local Authority. This includes information about our tenants and service users. Further information about this processing can be found in our service specific privacy notices.
We process criminal offence data under Article 10 of the GDPR. The Council’s processing of criminal offence data includes pre-employment checks and declarations by an employee in line with contractual obligations.
The Council processes special category data for the following purposes as listed in Schedule 1:
The Council processes criminal offence data for the following purposes as listed in Schedule 1:
Article 5 of the UK General Data Protection Regulation sets out the key data protection principles. Below are the Council’s key procedures for ensuring that we comply with them.
The Council has in place appropriate technical and organisational measures to meet the requirements of accountability. These include:
The Council routinely reviews our accountability measures and update them as required.
Processing personal data must be lawful, fair and transparent. It is only lawful if and to the extent it is based on law and meets at least one of the conditions in Schedule 1 or with the data subject’s consent.
The Council provides clear and transparent information about why we process personal data including our lawful basis for processing in our service privacy notices, staff privacy notice and this Appropriate Policy Document.
The Council processes personal data for specific purposes and does not process such data for any purpose incompatible with the original purpose for which it was collected for.
The Council processes personal data necessary for the relevant purposes and strives to ensure it is not excessive. The information we process is necessary for and proportionate to our purposes. Where personal data is provided to, or obtained by, the Council but is not relevant to our stated purposes, we will erase it.
Where the Council becomes aware that personal data is inaccurate or out of date, having regard to the purpose for which it is being processed, we will take reasonable steps to ensure that it is erased or rectified without delay.
If the Council decides not to either erase or rectify it, for example because the lawful basis we rely on to process the data means these rights don’t apply, we will document our decision.
Personal data processed by the Council is retained for the periods set out in our Retention Schedule. The retention periods are determined based on our legal obligations and business needs.
Our Retention Schedule is reviewed annually and updated when necessary.
Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
The Council will ensure that there are appropriate organisational and technical measures in place to protect personal data.
This policy will be retained for the duration of our processing and for a minimum of 6 months after processing ceases.
This policy will be reviewed every two years and updated when necessary.
The last review of this policy occurred July 2024.