Top Tips for Local Authority Lawyers advising on Data Protection Matters
Charlotte Smith and Hannah Peto set out some of their top tips to consider when advising on data protection matters.
- Details
Local authority legal teams deal with a range of issues and data protection matters can occur on a day-to-day basis, whether as a stand-alone issue or as part of a wider piece of advice, such as part of a contract negotiation. We have set out below some of our top tips to consider when advising on data protection matters.
1. Check if the Supplier is a Controller or Processor
In many services contracts, the supplier will be a processor for local authorities, however, sometimes the supplier is a controller (or even a joint controller) and therefore the data protection clauses in template contracts may need to be adapted for that scenario.
2. Ensure Contracts Reflect GDPR Requirements
Art.28 GDPR sets out the requirements for controller to processor contracts and must be complied with in all controller-processor scenarios. Also, ensure any amendments to data processing provisions still comply with Art.28 GDPR and that required provisions are not omitted in error.
3. Comply with the ICO Data Sharing Code of Practice
Art.26 GDPR requires joint controllers to set out their responsibilities “by means of an arrangement”. A data-sharing agreement between individual controllers is also good practice. When drafting data sharing clauses and agreements, consider the ICO Data Sharing Code of Practice.
4. Update Contracts to Reflect Brexit Changes
If you are using template data protection provisions, be mindful that there have been some changes to data protection law as a result of Brexit. For example, the GDPR has been updated to reflect language we use in the UK (“Supervisory Authority” is amended to be the “ICO” and/or “foreign designated authority”).
5. Get Ready for the International Data Transfer Agreement
Earlier this year, the ICO’s new International Data Transfer Agreement and SCC Addendum came into force. These will replace the current EU standard contractual clauses (SCCs). The SCCs can still be used for contracts concluded on or before 21 September 2022 and you will have until 21 March 2024 to get the new IDTA in place.
6. Diarise GDPR Deadlines
Timescales are a key part of GDPR compliance and the ICO can exercise its enforcement powers if timescales are not complied with. Key timescales include the time to respond to Subject Access Requests which is one month (this can be extended for up to 3 months in certain circumstances). And if you suffer a personal data breach, you have 72 hours to report to the ICO if it meets the threshold for reporting, including weekends and bank holidays.
7. Know Your Lawful Basis
You can only process personal data if you can meet an Art.6 lawful basis and so this should be identified before any processing begins. In addition, you may only process special category personal data if Art.9 conditions are met. There are also additional Data Protection Act 2018 conditions for special category and criminal conviction data.
8. Be Careful of the Consent Lawful Basis
Consent is one of the Article 6 lawful bases you can use. However, the standard of GDPR consent is high – it must be “freely given, specific, informed and unambiguous” and made “by a statement or by a clear affirmative action”. Therefore, it may not always be the most appropriate lawful basis to use. It can also be difficult for public bodies to rely on the lawful basis of consent if there could be an imbalance of power and consent is not freely given (see GDPR Recital 43).
Charlotte Smith is a Senior Associate and Hannah Peto is a Trainee Solicitor at Sharpe Pritchard LLP.
For further insight and resources on local government legal issues from Sharpe Pritchard, please visit the SharpeEdge page by clicking on the banner below.
This article is for general awareness only and does not constitute legal or professional advice. The law may have changed since this page was first published. If you would like further advice and assistance in relation to any issue raised in this article, please contact us by telephone or email enquiries@sharpepritchard.co.uk
Click here to view our archived articles or search below.
|
OUR RECENT ARTICLES
Jul 03, 2025
IPA guidance 2025: Managing PFI distress and preparing for expiryAanya Gujral and David Owens dive into the recent guidance published on managing the risks associated with Private Finance Initiative (“PFI”) projects.
Jul 03, 2025
Data (Use and Access) Act – Updating Data Protection Law and moreOn the 19th June 2025, the Data Use and Access Bill (“DUA Bill”) received Royal Assent to become the Data Use and Access Act 2025 (“DUA Act”).
Jun 24, 2025
Modifying subsidies: What is permitted and what is not?Beatrice Wood and Oliver Slater explore recent developments and discuss the process of awarding subsidies.
Jun 24, 2025
Getting new PPP right: Smarter tools for smarter infrastructureNicola Sumner, Steve Gummer and Roseanne Serrelli discuss the 'dos and don'ts' of Public-private Partnerships in their new form.
Jun 19, 2025
Zones/RABs and heat networks: The path to an investible infrastructure asset class?The UK’s new heat network zoning framework (the outlines for which were drawn by the Energy Act 2023) is set to redefine how low‑carbon heating is delivered by creating geographic zones, where district heat networks are the mandated, optimal solution.
Jun 17, 2025
Partial debt guarantees- Reviving Investment in UK Water InfrastructureIs it Time for a Public Sector Major Infrastructure Debt Guarantor?
|
ABOUT SHARPE PRITCHARD We are a national firm of public law specialists, serving local authorities, other public sector organisations and registered social landlords, as well as commercial clients and the third sector. Our team advises on a wide range of public law matters, spanning electoral law, procurement, construction, infrastructure, data protection and information law, planning and dispute resolution, to name a few key specialisms. All public sector organisations have a route to instruct us through the various frameworks we are appointed to. To find out more about our services, please click here. |
OUR NEXT EVENT
|
OTHER UPCOMING EVENTS
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |