New travel booking system
On 20 January, our travel booking system will be updated. Existing bookings will remain valid but won't be viewable in the new system. Please note any current bookings before the update.
The UK General Data Protection Regulation (GDPR) gives individuals extra, or enhanced, rights in addition to the Data Protection Act 2018.
The Information Governance team have developed 10 areas of work to ensure that our council is compliant with the UK General Data Protection Regulation (UKGDPR) and all aspects of data protection.
UKGDPR is part of the Data Protection Act 2018.
We regularly publish information and guidance on in our employee news and offer training on data protection on My Learning.
Data protection officer
Revised policies and procedures
Improved risk management
Revised our privacy impact assessments
Revised our internal audit regime
Agreed an approach to third parties
Updated our standard data processing agreements
Sought assurance from third parties
Implemented a record of processing activities
Created new and update old privacy notices
Agreed when and how we capture consent
Revised and published the Essex County Council (ECC) retention periods
Agreed secure destruction standards
Launched a complaints process
Updated the access, correction, deletion and restriction processes
Agreed where data portability applies to ECC
Deployed encryption to all ECC devices
Improved incident handling (within 72 hours)
Implemented data quality controls
Made sure systems enable UKGDPR requirements
Implemented privacy by design for all new projects and systems
Refreshed e-learning for all staff
Provided training for relevant teams in ECC on UKGDPR
Updated resources for employees on their rights
Updated employee privacy notices
UKGDPR compliance is everyone’s responsibility, however there are a number of people and resources that can support and advise you.
The Information Governance team can assist you with how you can effectively manage your information.
You can contact a member of the team at informationgovernanceteam@essex.gov.uk.
The Data protection officer (DPO) has formal responsibilities to monitor compliance with the GDPR. If you believe something is wrong and want to report a breach or a concern, please email dpo@essex.gov.uk.