Data Protection Policy and Direct Marketing and Cookies Policy
July 8, 2026 Executive (Other) Approved View on council websiteFull council record
Purpose
The purpose of the report was to seek approval of the Council’s Data Protection Policy and Direct Marketing and Cookies Policy. It also requested that authority was delegated to the Council’s Senior Information Risk Owner (SIRO) to approve future substantive revisions, minor amendments and administrative updates to both policies.
Decision
ORDERED that Executive:
- Approve the Data Protection Policy
- Approve the Direct Marketing and Cookies Policy.
- Delegates authority to the senior officer designated as the Council’s Senior Information Risk Owner to approve all future substantive revisions, minor amendments and administrative updates of the Data Protection Policy and Direct Marketing and Cookies Policy.
Reasons for the decision
REASONS
Approval of both policies ensured the Council continued to meet its legal and regulatory obligations, demonstrated accountability, and reduced the risk of non-compliance, regulatory enforcement, complaints, and reputational harm.
The Direct Marketing and Cookies Policy addressed specific requirements under PECR and Information Commissioner’s Office (ICO) guidance which were not fully covered by the general Data Protection Policy.
Alternative options considered
OPTIONS
While data protection legislation did not explicitly require organisations to maintain standalone policies adopting such policies was regarded as good practice and was strongly recommended by the Information Commissioner’s Office (ICO) under its Accountability Framework.
Formal policies helped demonstrate how an organisation met its legal obligations, embedded data protection principles into everyday practice, and provided clarity on roles, responsibilities, and expectations for those handling personal data. In a public sector context, where large volumes of personal and sensitive data were processed, the absence of a policy would have made it more difficult to evidence compliance, manage risk consistently, and demonstrate accountability to regulators, service users, and the public.
Related Meeting
Executive - Wednesday, 8 July 2026 - 5.00 pm on July 8, 2026
Supporting Documents
Details
| Outcome | Recommendations Approved |
| Decision date | 8 Jul 2026 |
| Effective from | 17 Jul 2026 |
| Expected date | 8 Jul 2026 |
| Originally due | 8 Jul 2026 |
| Lead officer | Ann-Marie Johnstone |
| Subject to call-in | Yes |