41 Data Protection Policy
PDF 270 KB
To receive a report from the Head of Digital Transformation and Customer Engagement to review the existing policy to ensure compliance with the Data Protection Act (DPA) 2018, the General Data Protection Regulations and the impact of the new Data Use and Access Act 2025 (DUAA) which gained royal assent June 2025.
Additional documents:
Decision:
The Cabinet had before it a report * from the Head of Digital Transformation and Customer Engagement to review the existing policy to ensure compliance with the Data Protection Act (DPA) 2018, the General Data Protection Regulations and the impact of the new Data Use and Access Act 2025 (DUAA) which gained royal assent June 2025.
RESOLVED that:
1. The revised Data Protection Policy be APPROVED.
2. Delegation of the Data Protection Policy to the Head of Digital Transformation & Customer Engagement, in consultation with the IT & Information Governance (ITIG) board and Legal Services to ensure that the policy remained current and reflected any legislative changes or regulatory guidance be APPROVED.
Minutes:
The Cabinet had before it a report * from the Head of Digital Transformation and Customer Engagement to review the existing policy to ensure compliance with the Data Protection Act (DPA) 2018, the General Data Protection Regulations and the impact of the new Data Use and Access Act 2025 (DUAA) which gained Royal Assent in June 2025.
The Cabinet Member for Quality of Living, Equalities and Public Health outlined the contents of the report with particular reference to the following:
Discussion took place with regard to:
RESOLVED that:
(Proposed by Cllr D Wulff and seconded by Cllr J Lock)
Reason for Decision:
Not complying with the Data Protection Act 2018 and GDPR would expose MDDC to enforcement action by the Information Commissioner’s Office (ICO).
Note:* Report previously circulated