Written and maintained by Chris Haycock, GDPRQuick.com/CliqTo Ltd
Last reviewed August 2026
GDPR for local authorities
Local authorities handle personal data across many different services: residents, applicants, service users, elected members, complaints, consultations, enforcement, licensing, payments, grants, suppliers, contractors and staff. This draft page explains the GDPR records a local authority needs, and how GDPRQuick can help turn those decisions into practical documentation.
Let's begin.
Download and use this checklist in your business.
Use it as a practical hand-off for owners, managers, and staff who need to understand the GDPR points covered on this page.
What personal data local authorities handle
Local authority data is broad because councils and public bodies deliver many different services. A single organisation may hold information for housing, planning, licensing, environmental health, benefits, waste, libraries, leisure, community services, complaints, consultations, elections, grants and employment.
Typical personal data includes:
- Resident contact details, addresses and service requests
- Application, eligibility, complaint and case records
- Payment, grant, invoice and supplier details
- Inspection, enforcement, licensing and public register information
- Consultation responses, elected member correspondence and democratic services records
- Contractor, volunteer, employee and worker records
- Safeguarding, vulnerability or support information where relevant
The main GDPR challenge is not simply listing data. It is explaining which service uses it, what legal power or public task applies, who it is shared with and how long it is kept.
Public task, legal obligation and lawful basis
Local authorities often rely on public task or legal obligation rather than consent. Services may be delivered under statutory powers, public duties, regulatory functions, contractual arrangements or legitimate administrative needs.
Your documentation should avoid treating consent as the default. Consent may still be relevant in specific voluntary contexts, but many council services cannot function if lawful processing depends on consent that can be withdrawn at any time.
Record the basis service by service
A practical record should explain the lawful basis for each main activity, such as service delivery, case management, inspections, complaints, public consultations, employment, procurement, enforcement, grants or payments.
Special category, safeguarding and vulnerable-person data
Some local authority services involve sensitive information about health, disability, social care, housing need, safeguarding, education, vulnerability, equality monitoring or support needs.
Where special category data is used, the authority needs an Article 9 condition as well as an ordinary lawful basis. Safeguarding and support records also need tight access controls and clear retention rules.
- Only collect sensitive information where it is necessary for the service or duty involved
- Restrict access to staff or partners who genuinely need it
- Keep case notes factual, relevant and proportionate
- Record why sensitive information is shared with another body
Not sure what applies to your local authorities?
Take the quick risk check before you get too deep into the detail.
Take the 2-minute checkSharing data with partners and processors
Local authorities regularly share personal data with other public bodies, contractors, commissioned services, software providers, enforcement partners, auditors, funders, emergency services and regulators.
Some sharing is controller-to-controller sharing between public bodies. Other sharing involves processors acting under contract. Your records should distinguish between the two and explain the purpose, data types, safeguards and legal gateway where relevant.
Contracts and data sharing agreements
Contractor and processor relationships should have suitable data protection terms. Regular controller-to-controller sharing may need a data sharing agreement, especially where several bodies work together on a service or case.
Public registers, transparency and publication
Some information held by local authorities is published because the law requires or permits it. Planning registers, licensing registers, election information, decision records and committee papers can all raise GDPR questions.
Publication should be deliberate. The authority should document what is published, why publication is lawful, whether redaction is needed and how long published information remains available.
Subject access requests and mixed case files
Subject access requests can be complex in local authority records because files may include information about several people, professional opinions, third-party reports, legal correspondence, safeguarding details and statutory decision-making.
Your process should explain who receives requests, where searches are carried out, how third-party information is reviewed, how exemptions are considered and how deadlines are tracked.
- Search service systems, case management tools, email, document stores and archived records
- Review third-party personal data before disclosure
- Keep a record of searches, redactions and decisions
- Escalate complex requests to trained staff
Retention and archiving across services
Different council services need different retention periods. Some records are short-lived enquiries. Others may be needed for statutory, financial, audit, safeguarding, employment, contract, legal or historical archive reasons.
A single vague retention statement is rarely enough. The authority should keep a schedule that covers service areas and explains when data is deleted, anonymised, archived or transferred to a formal archive.
What GDPR documents does a local authority need
A practical GDPR pack for a local authority should reflect the range of public services and statutory functions it performs.
- A public-facing privacy notice structure covering major services
- A Record of Processing Activities for service delivery, public task, employment, procurement, payments, casework and statutory duties
- A processor and supplier list covering software, contractors, outsourced services, cloud systems and support providers
- A data sharing record for partner bodies and joint services
- A retention schedule covering service areas, public registers, finance, employment and archives
- A subject access request process for complex mixed records
- A breach response process for misdirected emails, lost files, portal errors, supplier incidents and unauthorised access
Build local authority GDPR documents from your own answers
GDPRQuick guides you through questions about the services you deliver, what data you collect, which lawful bases apply, who you share data with, what suppliers you use and how long records are kept.
Your answers become the wording for your GDPR statement, processing records, action plan and supporting forms. You can update the documents later when services, suppliers, sharing arrangements or retention rules change.
Check your GDPR risk first.
Use the GDPRQuick risk calculator to get an indicative view of where your local authorities data protection work may need attention.
Start the risk calculatorQuestions about GDPR for local authorities
Do local authorities need GDPR documentation?
Yes. Local authorities should keep clear GDPR documentation because they handle personal data across statutory services, public tasks, employment, procurement, complaints, payments, enforcement and community services.
Do councils always need consent to use resident data?
No. Many local authority activities rely on public task, legal obligation, contract or legitimate administrative purposes. Consent is not usually the default for statutory or public service processing.
Is public register information still personal data?
It can be. Information may be published under a legal requirement or public function, but the authority should still document why publication is lawful and whether redaction or retention limits apply.
Can local authorities share data with partner organisations?
Yes, where there is a lawful basis and appropriate safeguards. The authority should document who receives the data, why it is shared, what legal gateway applies and whether a sharing agreement or processor contract is needed.
Are safeguarding records special category data?
They may include special category data and other highly sensitive information. Access, sharing, retention and disclosure should be controlled carefully and documented clearly.
How should a council handle subject access requests?
It should have a process for searching systems, reviewing mixed files, considering third-party data, applying exemptions where appropriate and responding within the required deadline.
What if personal data is sent to the wrong resident or contractor?
That is a personal data breach in principle. The authority should contain the issue, assess the risk, record the incident and decide whether it must be reported to the ICO or affected people.
Does using a software supplier make GDPR the supplier's responsibility?
No. Suppliers may be processors, but the authority remains responsible for choosing appropriate suppliers, setting instructions, documenting the processing and checking contractual safeguards.
Is GDPRQuick a replacement for legal advice?
No. GDPRQuick helps you create and maintain practical documentation. It does not certify compliance, and your organisation remains responsible for its own policies, processes, security measures, and legal decisions.
