Information Management - Data Protection & Freedom of Information privacy notice

The Information Management Team handles requests under Freedom of Information (FOI) and Environmental Information Regulations (EIR). We also handle all aspects of data protection legislation, such as making a subject access request (SAR), ensuring our services meet legal requirements, and responding to data protection incidents and complaints.

Each of these services involves all types of personal information held by the council, although some requests/complaints may only involve small amounts of information, and some of them much larger amounts of sensitive information.

Our FOI requests and responses are published on our website, but we don’t publish the identity of requesters. As part of the response that the council issues, we often publish names of staff members or contractor staff where it is reasonable to do so, for example, if the staff member is in a public facing or senior role.

We work with the Information Commissioner’s Office (ICO) on any complaints or incidents, and sometimes use our Legal Services.

For data protection work we access a wide range of personal information held by council services or by organisations that we are sharing information with, such as the police, the government or other local authorities. This means that at one time or another we access all types of information that the council holds.

It is the relevant council service itself that usually shares or discloses information, with the advice of the Information Management Team. The Information Management Team only shares information directly with a smaller number of organisations.

Personal information collected

  • Name
  • Address & contact details
  • DOB
  • Financial information
  • Equalities Information
  • Property information
  • Criminal/Prosecution Information
  • Health/Medical Information
  • Social Services Records
  • Human Resources Records
  • Other Agencies Involved
  • Education Information
  • Housing Information
  • Employment
  • Information from the Local Authority from where you live and previously lived
  • Family/Relationship Information
  • NHS Number
  • Support Network
  • Referees
  • Referral/Assessment Information
  • Images in photographs or film/CCTV

Who we share the information with

  • Individuals (data subjects)
  • Requestors
  • Information Commissioner’s Office (ICO)
  • Police
  • Judicial Agencies eg Courts
  • DfE
  • Legal representatives
  • Council services
  • Professional regulatory bodies
  • Council legal service
  • Insurance companies
  • Other local authorities
  • The Barnet Group, including Your Choice Barnet and Barnet Homes
  • Trade Unions

Legislation that applies

  • Freedom of Information Act 2000 (FOI)
  • Environmental Information Regulations 2004 (EIR)
  • General Data Protection Regulation 2016 (GDPR)
  • Data Protection Act 2018 (DPA)
  • Privacy & Electronic Communications (EC Directive) Regulations 2003 (PECR)

Because we work with information from all council services, we also comply with any of the legislation that affects each of the services, such as the Children Act or Care Act.

How long we keep your information

  • Records of our handling of requests, incidents and complaints (excluding SARs) for 5 years, with some records retained for longer periods as necessary, such as complex requests or significant incidents
  • Subject Access Requests (SARs) are kept for 2 years plus the current year