Minutes:
Click here to view the recording of this item on YouTube
The Interim Corporate Governance Manager presented the revised Data Protection Policy, highlighting statutory changes from the Data (Use and Access) Act 2025, new requirements for data protection complaints procedures, expanded definitions, and the introduction of training and transparency measures, with the panel agreeing to recommend its approval and ongoing monitoring.
The revised policy incorporates changes from the Data (Use and Access) Act 2025, including the statutory requirement for a published data protection complaints process by 19 June 2026, updates to the legal framework, and clearer definitions of roles and responsibilities, especially for elected members.
The policy sets out four SMART objectives: establishing a clear complaints process, improving information governance performance, increasing competence and awareness through training, and enhancing transparency and record keeping. Training for both staff and elected members is planned, along with the publication of performance data.
The Vice – Chair, Councillor Long requested guidance from the Monitoring Officer if this policy was to be approved by Full Council and not only Cabinet. The Chief of Staff and Monitoring Officer referred to the Constitution and confirmed the policy was to be agreed by Cabinet not Full Council.
The Vice – Chair, Councillor Long questioned what steps were being taken to achieve 100% compliance and further questioned if it was known of any Council’s that had been fined.
The Interim Corporate Governance Manager confirmed she was unaware of any Council’s which had been fined. She added the ICO considers complaints on case-by-case basis and the enforcement actions and notices were published on the website of the ICO.
Councillor Sayers requested that future reports to the panel include detailed statistics on data protection complaints, compliance with statutory timeframes, and outcomes. The panel agreed to monitor these metrics annually, with the Interim Corporate Governance Manager confirming that service-specific KPIs would be developed.
The Leader, Councillor Beales endorsed the request of future reports to the Panel to monitor data protection complaints, compliance with statutory timeframes, and outcomes
Councillor Nash raised concerns about Councillors being directed to use FOI requests instead of their rights of access to information. The Chief of Staff and Monitoring Officer clarified that member inquiries should be handled through the appropriate channels and announced upcoming training to clarify access rights.
Councillor Morley referred to Local Government Reorganisation and recognised the importance of data and included in the capital programme was funds for a hardware refresh. He highlighted the importance of having a common platform in preparation to migrate systems.
The Interim Corporate Governance Manager confirmed the system used was the same as Breckland District Council and further enquires would be made with Norfolk County Council in preparation.
The panel agreed to recommend the policy for cabinet approval, noted the statutory publication deadline, and authorised the Data Protection Officer to update the policy as required by changes in ICO guidance or legislation, with updates to be reported to cabinet.
RESOLVED: The Panel supported the recommendations to Cabinet
Cabinet Recommendation:
Supporting documents: