Local Government Lawyer

 

GLD Vacancies

GLD Vacancies


Ben Pumphrey explains why a pause in local government reorganisation is an opportunity when it comes to local authority data management.

The announcement earlier this month around the pausing of local government reorganisation (LGR) was a surprise to many local authorities, some of which were well into progressing plans for proposals in their area.

While LGR is under review, the local authorities affected must now focus on ‘business as usual’ in their day-to-day activity. Any preparation for LGR must be paused until the review is completed by Government and next steps are outlined.

The unexpected halt on LGR may in fact give local authorities some much needed breathing space, particularly when it comes to planning future data management and effective storage and usage practices.

Local authorities hold a significant amount of data about their constituents. Much of this data is personal or sensitive, often relating to services they have engaged with in the past or currently. Many local authorities have systems that are clunky, difficult to use, and there is often a patchwork of systems that can make data management and security more challenging.

For people living and working in areas affected by the decision to pause LGR, there is likely to be some concern about continuity of services and how the council might respond. Depending on how progressed plans for LGR were in their area, particularly with regard to data migration, it is possible that data management gaps could arise, increasing data security risks.

A robust data management plan is critical to help local authorities work in a secure and efficient way across all services. Local authorities need to have clearly defined data controller roles and responsibilities, to ensure that every piece of data is accounted for, recorded, and accessible to the correct parties.

This pause in LGR plans could provide a window of time for local authorities to conduct a thorough data audit. Regardless of if LGR proceeds, it is a useful task to help understand where data sits and with whom.

A thorough data audit of all records is non-negotiable for any government body that holds records and should include an assessment of who owns what data, where it is stored (whether digital or physical), who will own it going forward, who has access to it, and who is responsible for archival records. It is therefore an ideal time for local authorities to reflect on current data management practices and find better, more secure ways of handling, storing, and using data, as well as ensuring that it identifies information that it no longer needs to retain, and securely destroys such information.

Where personal data is going to be transferred to other bodies, local authorities, as controllers, should document the transfer. Ideally in the form of a data sharing or data transfer agreement, so as to document what information has been transferred, as well as ensuring which organisation remains responsible for upholding data subject rights under the GDPR.  

As part of any data review, security and protection are a must and should be considered at every stage. Even though LGR has been paused and is under review, councils may still need to ensure they have a plan in place for data migration at some point in the future. Weak security or uncontrolled access to data could result in serious data governance breaches, potentially exposing the organisation (or its partners) to a risk of a cyberattack.

Interoperability of systems and data protection should be considered to ensure local authorities are ready for data migration. Systems need to be able to communicate for an effective handover of data, to preserve operational continuity and ensure efficient and effective services for constituents. Any systems holding personal data should be checked for any compatibility issues ahead of migration. Training on new systems should also be carried out in advance of new systems being introduced, in order to reduce disruption and guarantee staff can use them confidently and access the data they need.

As service users’ needs will not stop during any migration process, it is important to develop a migration plan to ensure that as much of the data that needs to be transferred is done well ahead of time, both to ensure that the data integrity is maintained, and to minimise the amount of data that needs to be transferred immediately on or immediately prior to the transfer date.

Involving staff in a data audit exercise is crucial too – your staff are your key asset in understanding what data you will need for continuity of service and what data can be archived as and when the new organisations emerge. Board-level decision makers, along with the Data Protection Officer, should run Data Protection Impact Assessments (DPIAs). Individual heads of service, including IT/security leads, should also be involved in a data mapping process, to correctly assign roles and responsibilities around data – something that is essential in the event of any security issues or future system migrations. As supplier contracts novate, it is also a good opportunity to consider supplier assurances around data security and whether updated due diligence checks are required to protect service user data going forwards.

With LGR currently on hold and under review, local authorities should make best use of the time available to them by ensuring their data handling and security processes are robust and well managed, and that they are not holding any information they no longer need to retain.

Taking a proactive approach to looking at how data is stored, used, and accessed and adopting a best practice approach to data management is important and will ensure they are ready to proceed with LGR as necessary in the future.  

Ben Pumphrey is a legal director and data governance specialist at Anthony Collins.


Related Articles

Jobs

Directory

Events

Newsletter signup