Photo of Marshals Sports Field Pavilion
  1. Home
  2.  » 
  3. Policy
  4.  » Appropriate Policy Document

Appropriate Policy Document

Adopted by Council – 7 July 2026

1. Introduction

Gainsborough Town Council processes personal data relating to customers of its facilities, Councillors, and current and former employees in order to carry out its statutory and corporate functions. As part of these activities, the Council may also process special category personal data and criminal offence data.

Special category personal data is defined under Article 9 of the UK General Data Protection Regulation (UK GDPR) and includes personal data revealing:

  • Racial or ethnic origin;
  • Political opinions;
  • Religious or philosophical beliefs;
  • Trade union membership;
  • Genetic data;
  • Biometric data for the purpose of uniquely identifying a natural person;
  • Data concerning health;
  • Data concerning a natural person’s sex life or sexual orientation.

Article 10 of the UK GDPR applies to the processing of personal data relating to criminal convictions, offences, and related security measures. Section 11(2) of the Data Protection Act 2018 (DPA 2018) clarifies that criminal offence data includes information relating to the alleged commission of offences, criminal proceedings, and sentencing. Information relating to victims and witnesses of crime may also fall within the scope of criminal offence data.

This Appropriate Policy Document has been adopted in accordance with Schedule 1 of the DPA 2018. It sets out the lawful bases and conditions relied upon by Gainsborough Town Council when processing special category and criminal offence data, together with the safeguards in place to protect such information.

In accordance with paragraph 39 of Schedule 1 to the Data Protection Act 2018, this Appropriate Policy Document will be retained for at least six months after the Council ceases carrying out the processing to which it relates.

2. Description of Data Processed

Further information regarding the categories of personal data processed by the Council, the lawful basis for processing, and the purposes for which information is used can be found in the Council’s General Privacy Notice.

3. Special Category Data

Gainsborough Town Council processes special category personal data under the following conditions set out in Article 9 of the UK GDPR:

Article 9(2)(a) – Explicit Consent
Processing is carried out with the explicit consent of the data subject. For example, health information provided by employees or Councillors who require additional support or workplace adjustments.

Article 9(2)(b) – Employment, Social Security and Social Protection
Processing is necessary for the purposes of carrying out obligations or exercising rights under employment, social security, or social protection law. Examples include managing employee sickness absence and occupational health matters.

Article 9(2)(c) – Vital Interests
Processing is necessary to protect the vital interests of an individual. For example, using health information about an employee or Councillor during a medical emergency.

Article 9(2)(f) – Legal Claims
Processing is necessary for the establishment, exercise, or defence of legal claims. Examples include employment tribunal proceedings and other forms of litigation.

Article 9(2)(g) – Substantial Public Interest
Processing is necessary for reasons of substantial public interest, including compliance with legal obligations arising from the Council’s role as a public authority, such as duties under equality legislation.

Article 9(2)(i) – Public Health
Processing is necessary for reasons of public health. For example, processing undertaken in response to public health emergencies such as the COVID-19 pandemic.

Section 10(3) of the DPA 2018 provides that processing under Article 9(2)(g) must satisfy one of the substantial public interest conditions set out in Part 2 of Schedule 1 to the DPA 2018.

The Council processes special category and criminal offence data where the following conditions apply:

  • Paragraph 6 – Statutory and Government Purposes;
  • Paragraph 8 – Equality of Opportunity or Treatment;
  • Paragraph 10 – Preventing or Detecting Unlawful Acts;
  • Paragraph 12 – Regulatory Requirements Relating to Unlawful Acts and Dishonesty;
  • Paragraph 18 – Safeguarding of Children and Individuals at Risk;
  • Paragraph 19 – Safeguarding the Economic Well-being of Certain Individuals.

4. Criminal Offence Data

Gainsborough Town Council processes criminal offence data in accordance with Article 10 of the UK GDPR and only where a condition in Parts 1, 2 or 3 of Schedule 1 to the Data Protection Act 2018 is met and appropriate safeguards are in place.

Examples of such processing include:

  • Pre-employment vetting and Disclosure and Barring Service (DBS) checks, where appropriate, where permitted by law and relevant to the role;
  • Employee declarations relating to criminal convictions where required by contractual or legal obligations;
  • Investigations relating to safeguarding, fraud, misconduct, or other unlawful activities.

The Council may also process special category personal data in circumstances where an Appropriate Policy Document is not legally required. In all cases, the Council will ensure that the processing respects the rights and freedoms of data subjects and complies with the principles of data protection legislation.

5. Compliance with the Data Protection Principles

In accordance with the accountability principle, the Council maintains records of processing activities in accordance with Article 30 of the UK GDPR and Section 61 of the DPA 2018.

Where required, the Council carries out Data Protection Impact Assessments (DPIAs) in accordance with Articles 35 and 36 of the UK GDPR and Section 64 of the DPA 2018 to ensure that data protection is embedded by design and by default.

6. Accountability

The Council complies with the data protection principles set out in Article 5 of the UK GDPR.

The Council has implemented appropriate technical and organisational measures to demonstrate compliance with data protection legislation. These measures include:

  • The Council acts as the Data Controller for the personal data it processes and has designated the Town Clerk to oversee day-to-day compliance with data protection requirements;
  • Adopting a ‘data protection by design and default’ approach;
  • Maintaining records of processing activities;
  • Implementing and regularly reviewing data protection policies and procedures;
  • Entering into contracts with data processors where required;
  • Applying appropriate technical and organisational security measures;
  • Providing regular data protection and information governance training to employees and Councillors;
  • Undertaking Data Protection Impact Assessments where necessary; and
  • Regularly reviewing and monitoring compliance arrangements.

Principle (a): Lawfulness, Fairness, and Transparency
The Council provides clear and transparent information about how personal data is processed, including the lawful basis for processing, through its General Privacy Notice, Data Map, and associated policies.

Principle (b): Purpose Limitation

  • Personal data is processed only for specified, explicit, and legitimate purposes;
  • Processing carried out in the substantial public interest is limited to what is necessary for the Council to perform its statutory and corporate functions;
  • Where personal data is shared with another organisation, the Council will document the sharing arrangement and implement a Data Sharing Agreement where appropriate;
  • Personal data will not be used for purposes that are incompatible with the original purpose for which it was collected.

Principle (c): Data Minimisation

  • The Council only collects and processes personal data that is necessary and proportionate for the relevant purpose;
  • Any personal data that is not relevant to the Council’s stated purposes will be securely deleted or destroyed.

Principle (d): Accuracy

  • The Council takes reasonable steps to ensure that personal data is accurate and kept up to date;
  • Where inaccurate or outdated information is identified, the Council will rectify or erase it without undue delay where appropriate;
  • Where a decision is made not to rectify or erase data, the rationale for that decision will be documented.

Principle (e): Storage Limitation
All special category and criminal offence data processed by the Council will be retained only for as long as necessary and in accordance with the Council’s Record Retention Policy.

Retention periods are reviewed regularly and updated where required to reflect legislative, regulatory, and operational requirements.

Principle (f): Integrity and Confidentiality (Security)
The Council ensures that appropriate security measures are applied to all personal data, including:

  • Secure electronic systems and networks;
  • Controlled access to information based on business need;
  • Secure storage and handling of paper records;
  • Appropriate procedures for updating, correcting, and deleting personal data; and
  • Measures designed to prevent unauthorised access, disclosure, loss, alteration, or destruction of personal data.

7. Retention and Erasure

The Council will ensure that:

  • Its Data Map and Records of Processing Activities are kept up to date;
  • Special category and criminal offence data is disposed of securely when no longer required;
  • Appropriate retention periods are determined by considering:
  • The amount, nature, and sensitivity of the personal data;
  • The potential risk of harm arising from unauthorised use or disclosure;
  • The purposes for which the data is processed and whether those purposes can be achieved through other means; and
  • Any legal, statutory, or regulatory requirements.

In accordance with paragraph 39 of Schedule 1 to the Data Protection Act 2018, this Appropriate Policy Document will be retained for at least six months after the Council ceases carrying out the processing to which it relates.

8. Related Policies and Documents

This Appropriate Policy Document should be read in conjunction with the following Council policies and guidance:

  • Data Protection Policy;
  • Retention of Documents and Records Policy;
  • Data Breach Guidance;
  • General Privacy Notice; and
  • Information Security procedures and guidance.

Copies of these policies and procedures are available from the Council and can be accessed via the Council’s website.

9. Policy Review

This document will be reviewed at least annually and updated where necessary.