Internal audit, risk management and insurance privacy notice - Privacy notices

Why we collect information about you
  • to provide services related to internal audit, risk management and insurance to the council and other public sector organisations
  • to undertake investigations into fraud involving public assets, services and resources
  • to undertake activities designed to prevent and detect fraud
  • to undertake investigations into fraudulent claims
  • to support human resources in the investigation of internal disciplinary matters
  • to investigate referrals made under whistleblowing policy
  • to process and manage insurance claims 
What type of information we may collect
  • name, date of birth, address and contact information
  • financial information such as bank details, claims and payments
  • employment details
  • other personal information required to support investigations
  • details of alleged and prosecuted criminal convictions and offences

We may also process some special category (sensitive) data such as:

  • physical or mental health details
  • racial or ethnic origin
  • sex life or sexual orientation
  • religious or philosophical beliefs
  • trade union membership
Lawful bases for processing information about you
  • necessary to comply with a legal obligation
  • necessary to perform a task carried out in the public interest or in the exercise of official authority
  • necessary for reasons of substantial public interest
How we may collect your information
  • provided to us directly by you
  • provided by another individual such as a work colleague or a manager
  • provided by another individual such as a family member or carer
  • provided by another organisation involved in the provision of audit, risk management and insurance support and services, and intelligence 
Who we may share your information with
  • government bodies and regulators such as the Department or Work and Pensions, the Cabinet Office and HM Revenue and Customs.
  • other local and district authorities
  • other regulatory bodies and enforcement organisations
  • organisations providing audit, risk management and insurance services to the council
  • police forces and other law enforcement and prosecution agencies
How long we hold your information for

We are required to retain your information for as long as is necessary, after which it will be securely destroyed.

Further information on retention periods is available through our customer privacy notice.

Your information rights

You have several rights in relation to the information that the council holds about you. For information about your rights, when they might apply and how to make a request to exercise them, please see our customer privacy notice.

You may also be interested in