Suggested Privacy Policy for your website

Suggested Privacy Policy for your website

How to use this privacy policy template

This is a template website privacy policy for councils using Parish Online. Copy the HTML content below this box and paste it into your website page editor (use the HTML or source code view in your CMS). Then work through the following steps before publishing:

  1. Replace every [HIGHLIGHTED PLACEHOLDER] with your council's specific details.
  2. Read each amber ⚠ INSTRUCTION box, act on it, then delete the entire box from your page.
  3. Remove any bullet points or whole sections that do not apply to your council.
  4. Do not publish until every [PLACEHOLDER] has been replaced and all ⚠ INSTRUCTION boxes have been deleted.

Privacy Policy

Last updated: [DATE, for example 1 June 2026]

[COUNCIL NAME] is committed to protecting your privacy and handling your personal data fairly, lawfully and transparently.

This Privacy Policy explains how we collect, use, store and protect personal information when you use our website or contact the Council. This website is operated on our behalf by Parish Online.

This policy should be read alongside our Accessibility Statement and any service-specific privacy notices published by the Council.

Data Controller

For data protection purposes, [COUNCIL NAME] is the data controller.

  • [Council address, line 1]
  • [Council address, line 2]
  • Email: [council email address]
  • Telephone: [council telephone number]

Data Protection Contact

⚠ INSTRUCTION – DELETE THIS BOX BEFORE PUBLISHING: Choose one of the two options below depending on your council's arrangements, then delete the other option and this instruction box.

Option A – use if your council has appointed a dedicated Data Protection Officer (DPO), typically larger town councils.
Option B – use if data protection enquiries are handled by the Clerk, as is common for smaller parish councils and parish meetings.

Option A – Data Protection Officer

The Council has appointed a Data Protection Officer (DPO).

  • [DPO name or organisation]
  • Email: [DPO email address]
  • Telephone: [DPO telephone number]

The DPO can be contacted regarding any matter relating to the processing of personal data or to exercise your rights under data protection law.


Option B – Clerk to the Council

Data protection enquiries should be directed to the Clerk:

  • [Clerk name]
  • Email: [Clerk email address]
  • Address: [Clerk postal address]

Data Protection Legislation

This Privacy Policy is provided in accordance with:

⚠ INSTRUCTION – DELETE THIS BOX BEFORE PUBLISHING: Add any further legislation specific to your council's activities, for example the Localism Act 2011 or relevant regulations applicable to services you provide. Remove this box when done.

Personal Data We Collect

Depending on how you interact with the Council, we may collect:

Contact information

  • Name
  • Postal address
  • Email address
  • Telephone number

Correspondence information

  • Details of enquiries, complaints or requests
  • Information supplied in forms, emails, letters or telephone conversations

Website information

When you visit our website, we may automatically collect:

  • IP address
  • Browser type and version
  • Device type and operating system
  • Referring website
  • Date, time and pages visited

Council service information

Where relevant, we may collect information necessary to provide council services or carry out statutory functions.

How We Collect Personal Data

We collect personal data:

  • Directly from you through website forms, email, telephone, post or meetings
  • From government bodies, public authorities, contractors and service providers acting on behalf of the Council
  • From publicly available sources where permitted by law

Why We Use Personal Data

We use personal data to:

  • Respond to enquiries and correspondence
  • Deliver council services and process requests and applications
  • Manage consultations and community engagement
  • Maintain council records and administer meetings and council business
  • Comply with legal obligations and exercise the Council's statutory functions
  • Improve website performance and security
  • Prevent fraud and misuse of services

Lawful Basis for Processing

Under UK GDPR, the Council must have a lawful basis for processing personal data.

Public task – Article 6(1)(e)

Most Council processing is necessary for the performance of tasks carried out in the public interest or in the exercise of official authority vested in the Council.

Legal obligation – Article 6(1)(c)

We process personal data where necessary to comply with legal obligations, including those arising under local government, audit, electoral and transparency legislation.

Consent – Article 6(1)(a)

Where required, we will obtain your consent before processing your information. You may withdraw consent at any time by contacting us.

Legitimate interests – Article 6(1)(f)

Where appropriate, we may process personal data for legitimate interests, provided those interests are not overridden by your rights and freedoms.

Who We Share Information With

We may share personal data where necessary with:

  • Council employees and councillors
  • Professional advisers, auditors and inspectors
  • Government departments, public bodies and regulators
  • Law enforcement agencies
  • Contractors and service providers
  • Website hosting and IT support providers

Information is shared only where there is a lawful basis for doing so. The Council does not sell personal data.

This website is hosted and operated on behalf of the Council by Parish Online, acting as a data processor. Parish Online processes website data only on the Council's instructions and in accordance with a data processing agreement.

Freedom of Information and Environmental Information Requests

As a public authority, the Council is subject to the Freedom of Information Act 2000 and the Environmental Information Regulations 2004. Information provided to the Council may be disclosed where required by law.

When considering requests for information, the Council will balance its legal obligations with its responsibilities under data protection legislation. Personal data will only be disclosed where permitted by law.

International Transfers

The Council primarily stores and processes information within the United Kingdom. Where personal data is transferred outside the UK, we will ensure that appropriate safeguards are in place in accordance with UK GDPR, including adequacy regulations, International Data Transfer Agreements or approved contractual clauses.

How Long We Keep Information

The Council retains personal data only for as long as necessary. Retention periods are determined by statutory requirements, business needs, audit requirements and legal obligations, and by guidance issued by the National Association of Local Councils (NALC) and relevant records management standards.

When information is no longer required it will be securely deleted or destroyed.

Security of Personal Data

The Council uses appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration or disclosure. These include secure systems and servers, access controls, password protection, staff training, and regular review of security arrangements.

Your Rights

Under UK GDPR you have the following rights. To exercise any of these rights, please contact the Council or Data Protection contact listed above. We will respond within one month of receiving your request.

Right to be informed

To know how your personal data is used.

Right of access

To obtain a copy of personal data held about you (a Subject Access Request).

Right to rectification

To have inaccurate or incomplete information corrected.

Right to erasure

To request deletion of personal data where there is no longer a lawful basis to hold it.

Right to restrict processing

To request limitations on how your data is used.

Right to data portability

To obtain and reuse your personal data in certain circumstances.

Right to object

To object to processing carried out under certain lawful bases, including the public task basis.

Rights relating to automated decision-making

To challenge decisions made solely by automated means where applicable.

Automated Decision-Making and Profiling

The Council does not carry out automated decision-making or profiling that produces legal or similarly significant effects on individuals.

Complaints

If you are dissatisfied with how your personal data has been handled, you should first contact the Council or the Data Protection contact listed above.

You also have the right to complain to the Information Commissioner's Office (ICO):

Website Cookies

Cookies are small text files placed on your device when you visit a website. The Council uses cookies to ensure the website functions correctly, improve website performance and understand how visitors use the website.

Some cookies are essential and do not require consent. Non-essential cookies, including analytics cookies, will only be placed after you have provided consent through the website's cookie banner. You may change your cookie preferences at any time through your browser settings or the website's cookie controls.

Cookies used on this website

⚠ INSTRUCTION – DELETE THIS BOX BEFORE PUBLISHING: The table below lists the standard cookie categories used on Parish Online websites. If you have added any third-party tools or scripts to your website (such as Google Analytics, embedded maps or social media widgets), you may need to add rows for those cookies. Parish Online can advise on what cookies your site uses.

Cookie typePurposeConsent required?
Strictly necessaryEnable core website functionalityNo
PreferencesRemember user settings and choices, such as cookie consentNo
AnalyticsMeasure website usage and performance to help improve the siteYes
SecurityProtect website functionality and users from malicious activityNo

A current list of cookies is available through the website's cookie management tool.

Third-Party Websites

This website may contain links to external websites. The Council is not responsible for the content, privacy practices or security of third-party websites. You should read the privacy notices of any external websites you visit.

Changes to this Privacy Policy

The Council may update this Privacy Policy from time to time. Any changes will be published on this page and will take effect immediately upon publication. We encourage you to review this policy periodically.


    • Related Articles

    • Suggested Terms and Conditions for your website

      If you choose to add Terms and Conditions to your website, here's a template you may wish to use and adapt. This document is provided with no warranty. Terms and Conditions 1. Introduction Welcome to [Local Council Name] (“the Council”) website. By ...
    • Setting up Default Signature Template

      Overview You can set signatures to be consistent across all staff and councillors. this essentially forces a signature policy on all users. To do this: Go to the Email Admin Panel Go to Organisation Go to Signature Template Give it a name Enter the ...
    • Suggested Accessibility Statement for your website

      How to use this accessibility statement template Copy the HTML content below this box and paste it into your website page editor (use the HTML or source code view in your CMS). Then work through the following steps before publishing: Replace every ...
    • Amending a policy document

      Overview Once you've loaded a policy document to the website you may wish to change the title or details associated with the document. Method Go to the page where your policy document is and move your cursor to the top right hand of the box of the ...
    • Removing a policy document

      Overview When you update the Council's policies you will need to remove or replace the old ones on your website. These will likely be on a page entitled policies or governance depending on how you've chosen to set this up. Method Go to the page where ...