Internal audit - Privacy Notice
Who the council is and what the council does
West Oxfordshire District Council is a data controller under the Data Protection Legislation as the council collects and processes personal information about you in order to provide services and meet their statutory and regulatory obligations.
The council’s internal audit function is outsourced to the South West Audit Partnership (SWAP) who provide an independent function to provide the council with assurance on its internal control, fraud and governance processes. SWAP’s Privacy Notice can be found on their website https://www.swapaudit.co.uk/
https://www.swapaudit.co.uk/_files/ugd/c35ae1_d1bb561586c94e088ff5e1d25a5fca53.pdf
The following notice explains why the council asks for your personal information, how that information will be used and how you can access your records.
Any questions regarding our privacy practices should be sent to:
Data Protection Officer (DPO)
West Oxfordshire District Council
Council Offices, Witney, OX28 1NB
Email: data.protection@westoxon.gov.uk
Tel: 01993 861194
Why the council needs your information and how the council uses it
Under Section 151 of the Local Government Act 1972 we are required to hold or have access to information from systems and processes across the council. Access to this information is securely provided to SWAP in order to fulfil the legal requirement to provide an internal audit function and to prevent, detect and deter fraud and / or corruption, thus safeguarding the public purse and providing assurance of safe stewardship of public funds.
The council does not sell your personal information to anyone else.
What is the legal process for collecting and processing this data
Under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, the lawful bases we rely on for processing this information are:
- UK GDPR Article 6 (1) (c) Legal Obligation – processing is necessary for compliance with legal obligation to which the council is subject
- UK GDPR Article 6 (1) (e) Public Task – processing is necessary for the performance of a task carried out in the public interest in the exercise of official authority vested in the council.
The following acts and regulations provide the primary bases on which the internal audit function operates:
- Section 151 of the Local Government Act 1972 requires that authorities ‘make arrangements for the proper administration of their financial affairs'
- The Accounts and Audit Regulations 2015 require that ”a relevant body must undertake an effective internal audit to evaluate the effectiveness of its risk management, control and governance processes, taking into account public sector internal auditing standards or guidance. Any officer or member of that body must if the body requires:
- a) make available such documents and records (including those in electronic form), and
- b) supply such information and explanation.
as are considered necessary by those conducting the internal audit”
What type of information is collected from you
Personal details, which may include:
- Name, date of birth, address
- Other contact details – email address and telephone number
- Employment Details e.g. National Insurance Number
- Financial Details e.g. Bank Account information
- Information gathered during the course of an investigation.
The above list is not exhaustive. The council will only ask for personal information that is appropriate to enable us to deliver our services. In some cases you can refuse to provide your details if you deem a request to be inappropriate. However, you should note that, that this processing is governed by Legal Obligation and Public Task.
We collect this information by:
- telephone, email, social media, writing or in person
Who your information may be shared with (internally and externally)
Your data is shared internally only with the appropriate staff where it is necessary for the performance of their roles; within the council or SWAP.
Sometimes the council has a legal duty to provide your personal information to other organisations, for example the court service or HMRC.
The council may also share your personal information with government departments, agencies and third party contractors such as, but not limited to, the Police.
We will not normally share your information with organisations without your consent. However the council will use the information for the purpose of performing any of its statutory enforcement duties. It will make any disclosures required by law and may also share this information with other bodies responsible for detecting/preventing fraud or auditing/administering public funds.
Your information will not be disclosed to any other organisations, except where the council is required and allowed to by law, to safeguard public safety and in risk of harm or emergency situations.
The council will not share your information with third parties for marketing purposes.
How long the council keeps your information (retention period)
We will only retain your personal information for as long as we are required to do so by law and the purpose, we collected it for.
Once your data is no longer needed it will be securely and confidentially destroyed or disposed of the data in line with retention schedules.
How the council protects your information
Your data is stored securely on our systems and accessed only by authorised officers using their own username and password created in line with pre-defined user credentials. Personal data is also held in electronic files on the council’s network drives. These are only accessible through personal logon credentials and access privileges to specific drives. Access to our council sites require a personal electronic pass to access staff only areas. The council has strict procedures for the way this is done. Any and all information about you is treated as confidential and with respect. There are also clear rules and guidance about storing, recording and sharing information which staff receive training on.
If you use your credit or debit card to make payments, the council passes your card details securely to our payment processing partner as part of the payment process. The council does this in accordance with the Payment Card Industry Security Standard and does not store the details on its website. The information you give to the council when using our online payment system will only be used for the recording of your payment
The council will not transfer your personal data outside the EU without your consent.
The council have implemented generally accepted standards of technology and operational security in order to protect personal data from loss, misuse or unauthorised alteration or destruction.
Please note however that where you are transmitting information to us over the internet this can never be guaranteed to be 100% secure.
The council will notify you promptly in the event of any breach of your personal data which might expose you to serious risk.
Your rights
You have the following rights under the Data Protection Legislations:
- To access your personal data
- To be provided with information about how your personal data is processed
- To have your personal data corrected
- To have your personal data erased in certain circumstances
- To object to or restrict how your personal data is processed
- To have your personal data transferred to yourself or to another business in certain circumstances
- To be told if the council have made a mistake whilst processing your data and the council will self-report breaches to the Commissioner.
How you can access, update or correct your information
The Data Protection law gives you the right to apply for a copy of information about yourself. This is called a ‘Subject Access Request'.
If you wish to see a copy of your records you should contact the Data Protection Officer. You are entitled to receive a copy of your records free of charge, within a month.
In certain circumstances access to your records may be limited, for example, if the records you have asked for contain information relating to another person.
The accuracy of your information is important to us to be able to provide relevant services more quickly. The council is working to make our record keeping more efficient. In the meantime, if you change your address or email address, or if any of your circumstances change or any of the other information the council holds is inaccurate or out of date, please email us or write to us at:
Data Protection
West Oxfordshire District Council
Council Offices, Witney, OX28 1NB
Email: data.protection@westoxon.gov.uk
Further information
If you would like to know more about how the council uses your information, or if for any reason you do not wish to have your information used in any of the ways described in this privacy notice, please contact the Data Protection Officer at data.protection@westoxon.gov.uk
For more information about data protection please visit: www.westoxon.gov.uk/about-the-council/council-data-and-information/data-protection/
If you are concerned about the way the council is handling your personal information you can contact the Information Commissioner (ICO): https://ico.org.uk/make-a-complaint/
The council reserve the right to update this privacy notice from time to time by publishing a new version on our website.