Agenda item
The General Data Protection Regulation
Minutes:
RESOLVED:
That Cabinet:
1. Notes the contents of the report.
2. Approves the Data Protection Policies and Procedures as set out in Appendices 1-12.
3. Delegates authority to the Borough Solicitor, in consultation with the Leader of the Council and the Cabinet Member for Finance Property and Business Services, to introduce any new Data Protection Policies and Procedures which are necessary to ensure that the Council is at all times fully compliant with the General Data Protection Regulation and the Data Protection Act 2018.
4. Agrees that all Members of the Council should receive training from the Borough Solicitor on the General Data Protection Regulation and the Data Protection Act 2018.
5. Requests that the Chairman of the Executive Scrutiny waives the scrutiny call-in period so that any decisions can take immediate effect. This will ensure that the Council's Data Protection Policies and Procedures are in place and published on the Council's Website ahead of the new Data Protection Laws coming into force.
Reasons for decision
Cabinet noted that the laws on data protection had been overhauled by European and Domestic Legislation and the Council needed to ensure that it was fully compliant with them and to evidence its compliance by having a set of robust policies and procedures in place by 25 May 2018. Cabinet noted the steps the Council had taken to prepare for this and gave its approval to the new policies and procedures introduced as part of this preparatory work, whilst also requesting they take immediate effect.
Alternative options considered and rejected
Cabinet noted that the Council had no option other than to fully comply with the new set of laws.
Officer to action:
Raj Alagh, Borough Solicitor - Chief Executive’s Office
Classification: Public
The report and any background papers relating to this decision by the Cabinet are available to view on the Council's website or by visiting the Civic Centre, Uxbridge.
Supporting documents:
-
07 - REPORT RA GDPR Cabinet Report May 2018 Word Version (2), item 7.
PDF 110 KB
-
Appendix 1 Draft GDPR Data_Protection_Policy, item 7.
PDF 125 KB
-
Appendix 2 GDPR Golden Rules, item 7.
PDF 113 KB
-
Appendix 3 Information Governance Policy, item 7.
PDF 117 KB
-
Appendix 4 Lawful Basis for Processing of Personal Data Policy, item 7.
PDF 140 KB
-
Appendix 5 Data Protection Individuals' Rights Policy, item 7.
PDF 155 KB
-
Appendix 6 Subject Access Policy and Procedure, item 7.
PDF 147 KB
-
Appendix 7 Procedure for Undertaking a Data Protection Impact Assessment, item 7.
PDF 144 KB
-
Appendix 8 Data Protection Privacy Notice, item 7.
PDF 139 KB
-
Appendix 9 GDPR Record of processing activities, item 7.
PDF 188 KB
-
Appendix 10 Managing an Information Security Breach Policy and Procedure, item 7.
PDF 210 KB
-
Appendix 11 ICT Acceptable Usage Policy, item 7.
PDF 109 KB
-
Appendix 12 Document Retention and Destruction Policy, item 7.
PDF 304 KB