Privacy notice
Brighton & Hove City Council is committed to protecting your personal information. As a data controller, we have a responsibility to make sure you know why and how your personal information is being collected, following relevant data protection laws.
The primary laws that govern how Brighton & Hove City Council collects and uses personal information (known as Data) about you are:
General Data Protection Regulation (GDPR)
Data Protection Act (DPA) (2018)
Our service privacy notices include details on how our teams collect, store and process your data.
Overview and purposes
We need you to give us your personal information so we can provide services to you as a local authority.
To deliver our services, meet our legal obligations and protect public funds, we need to collect, store, use, share and dispose of personal information. This is known as data processing.
We use your information to:
- verify your identity where required
- contact you by post, email or telephone
- maintain our records
We also receive and share information with third parties. This is usually with other public authorities or government departments, like:
- the police and court service
- the NHS
- HM Revenue and Customs
- the Department for Work and Pensions
We may also share information with other local authorities, contractors who provide services for us and members of the public.
Details of when information is shared and who it's shared with can be found in service-specific privacy notices.
We collect different categories of personal information, depending on the service we provide to you. In most cases, we'll need your name and contact details.
What personal data is
Personal data is specific information about a person that can be used to identify that person on its own or when put together with another piece of information.
Personal data about you is information like your:
- name
- address
- phone number
- date of birth
- National Insurance number
- NHS number
- gender
- email address
- IP address
- location-based data
- financial/bank details
Some types of personal information are more sensitive than others. This information is known as 'special category data' and includes information like:
- race
- ethnic origin
- religious or political beliefs
- trade union membership
- physical and mental health data
- biometric and genetic data, like photographs, fingerprints, facial recognition, and DNA
- sexual orientation
Stricter controls are in place to control when and how we can collect, use and store special category data.
Details of why and how we collect, use and store your personal and special category data can be found in the specific privacy notices for each service.
How we use your personal information
We use your personal information for the purpose it was collected and hold it centrally to ensure we maintain accurate records across the organisation. We also process personal data to prevent fraud.
We will not keep your personal information any longer than needed and will dispose of it securely. The length of time we need to keep information will depend on the purpose for which it's collected.
Our service-specific privacy notices give further information on how long we keep your information.
How we protect your data and keep it secure
Examples of the security measures we use are the following:
- training for our staff, making them aware of how to handle information securely and how and when to report when something goes wrong
- using encryption when data is being sent, meaning that information is scrambled so that it cannot be read without access to an unlock key
- pseudonymising data where possible, meaning that your identity will be removed, so that work can be done without your identity being known by the people doing that work
- controlling access to systems and networks allows us to stop people who are not allowed to view your personal information from getting access to it
- regular testing of our technology and ways of working, including keeping up to date on the latest security updates (commonly called patches)
Who we share your personal information with
To provide services and to meet our legal obligations as a local authority, we sometimes need to share your personal information with external organisations.
We'll only share your personal information where necessary, either to comply with the law or where permitted under data protection legislation.
Examples of organisations we may share your personal information with include:
- NHS
- HMRC
- police
- UK government departments and related agencies
- other local authorities
- Ombudsmen, like the Information Commissioner’s Office, The Care Inspectorate
- care providers and voluntary organisations
For more information about who we share your personal data with and why, see the section ‘Service Related Privacy Notices’.
We only share your information with partners or contractors who agree, through information-sharing agreements, to protect your information.
Sharing information outside of the UK
Almost all personal data we use is stored and processed in the UK. Some information may also be stored within the EU.
If we need to transfer your personal information outside of these areas for a particular activity, this will be explained in the relevant service-specific privacy notice. This will include a description of the protective measures in place to keep it safe.