Privacy Policy

General Privacy Notice

1. Purpose and Scope

This notice explains how Moulton Community CIO collects, uses, and protects personal information. We are required by law to handle all personal data responsibly and securely.

This policy follows the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, which together set out how organisations must use personal data fairly, lawfully, and transparently.

The Northamptonshire County Association of Local Councils (NCALC) acts as the Data Protection Officer (DPO) for Moulton Parish Council.

2. Legal Responsibility & Policy Support

This policy complies with the following legislation and controls:

Data Protection Act 2018

UK General Data Protection Regulation (GDPR)

Human Rights Act 1998

3. What is Personal Data?

Personal data means any information that can identify a living person — such as a name, address, email, photograph, or financial details.

Some types of information are more sensitive and need extra protection, such as health, race, religion, or political opinions. These are called special category data.

4. How We Protect Your Data?

We follow seven key principles to keep your data safe.

We make sure that personal data is:

  • Used lawfully, fairly, and transparently.
  • Collected only for clear and legitimate reasons.
  • Limited to what we actually need.
  • Accurate and up to date.
  • Kept only as long as necessary.
  • Stored securely and protected from unauthorised access.
  • Handled in a way that allows us to show we follow the law.

 

5. Who We Are:

This notice is issued by Moulton Community CIO, which is the data controller — meaning we decide how and why your information is used.

Sometimes we may need to share information with Partner organisations and contractors that help us deliver services

Any organisation that works for us must follow strict data protection rules.

6. What Information We Collect:

Depending on your contact with us, we may collect:

  • Names, titles, and contact details (address, phone, email)
  • Photographs or videos (for events or identification purposes)
  • Information about your age, gender, nationality, or employment (if relevant to a service)
  • Financial details such as bank account or payment information (for fees, grants, or hall hire)
  • Correspondence and communication records

 

We only collect the information we need for specific council purposes.

7. How We Use Sensitive Data

We only process sensitive (special category) data when it is strictly necessary and lawful.

This may include:

  • Monitoring equality and diversity
  • Meeting legal or safeguarding duties
  • Protecting someone’s vital interests in an emergency
  • Managing legal claims

 

We will only use such data with your explicit written consent or when required by law or the public interest.

8. Why We Use Your Information

We use personal data to:

  • Deliver services and facilities
  • Communicate with residents, staff, and volunteers
  • Process payments, contracts, and grants
  • Maintain records and accounts
  • Meet legal and safeguarding duties
  • Prevent and detect fraud or misuse of public funds
  • Carry out surveys and consultations
  • Inform you about council events, changes, or new initiatives (if you have asked to receive them)
  • Keep the community safe through CCTV or security systems where applicable

 

We will never sell your data or share it for marketing purposes.

9. Our Legal Reasons for Using Your Data

We only use your data when we have a valid legal reason to do so.

This includes:

  • Legal obligations – to meet our statutory duties as a public authority
  • Public interest or official authority – to carry out lawful council functions
  • Contract – to provide a service you have requested
  • Consent – when you agree to receive certain communications or services
  • Vital interests – to protect life or prevent harm
  • Legitimate interests – in limited cases, when it benefits the community and respects your rights

 

If we rely on your consent, you can withdraw it at any time.

10. How Long We Keep Your Data

We only keep personal information for as long as necessary.

Some records (such as legal or financial documents) must be kept for specific time periods. For example:

  • Financial records – at least 8 years (HMRC requirement)
  • Burial and legal records – permanent archive
  • Contracts and agreements – for up to 6 years after expiry (legal limitation period)

 

Once data is no longer needed, it will be securely deleted or destroyed.

11. Your Rights

You have the following rights under data protection law:

  1. Access – to see the information we hold about you.
  2. Correction – to update inaccurate or incomplete data.
  3. Erasure – to request deletion of your data (where legally possible).
  4. Objection – to stop your data being used in certain ways.
  5. Restriction – to limit how your data is used.
  6. Data portability – to transfer your data to another organisation.
  7. Withdraw consent – to stop receiving optional communications.
  8. Complain – to the Information Commissioner’s Office (ICO) if you believe we’ve mishandled your data.

 

12. Contacting the ICO

 

13. Keeping This Notice Up to Date

We regularly review this Privacy Notice and update it if our processes or the law change.

14. Contact Details

Data Controller

Moulton Parish Council

Moulton Community Centre, Sandy Hill, Reedings, Moulton, Northampton NN3 7AX
Email: info@moultonnorthants-pc.gov.uk 

Telephone: 01604 642202

15. Data Protection Officer (DPO)

Northamptonshire County Association of Local Councils (NCALC)

You can also contact the ICO via their data protection complaints tool or by calling 0303 123 1113 (Mon–Fri, 9am–5pm).