This section provides a summary of personal data processing activities undertaken by the Council.

Record of Processing Activity

Show all parts of this guide

8. Technical and Organisational Security Measures

The Council has a robust suite of security controls in place to protect the records we hold about you (on paper and electronically).  We meet stringent Public Sector Network (PSN) security controls, and strict Payment Card Industry Data Security Standards (PCI-DSS).  We have also recently completed the local government Cyber Assessment Framework which is the UK government cyber security scheme.

Access to your records is only available to those who have a right to see them.  Examples of further security include:

  • Access controls, controlling access to systems and networks using multi factor authentication, allows us to stop people who're not allowed to view your personal information from getting access to it.
  • Encryption, meaning that information is hidden so that it can't be read without special knowledge (such as a password). This type of technology is applied to a number of our systems including our email system.
  • Regular testing of our technology and ways of working including keeping up to date on the latest security updates (patches).
  • Training for our staff allows us to make them aware of how to handle information and how and when to report when something goes wrong.