Data Matching Privacy Notice

Data Controller

Mole Valley District Council (“the Council”) is the data controller for the personal information processed for the purposes described in this privacy notice.

The Council is committed to protecting public funds and ensuring that personal information is processed lawfully, fairly and transparently in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other applicable legislation.

Why we process your personal information

The Council has a responsibility to protect the public funds it administers and to ensure public resources are used appropriately.

We use personal information to:

  • prevent and detect fraud;
  • identify and investigate potential fraud, error and financial irregularities;
  • verify information supplied to the Council;
  • protect public funds;
  • support the administration of public services;
  • participate in data matching exercises designed to identify potentially fraudulent or incorrect claims, payments or applications.

We may share information provided with other bodies responsible for:

  • auditing
  • administering public funds
  • undertaking a public function
  • in order to prevent and detect fraud.

Data matching involves comparing records held by one organisation against records held by the same organisation or another organisation to identify anomalies, inconsistencies or matches that may require further investigation.

A data match does not automatically indicate fraud, error or wrongdoing. Where a match is identified, appropriately authorised officers will undertake further enquiries before any conclusions or decisions are made.

We participate in the Department for Work and Pensions (DWP) National Fraud Initiative: a data matching exercise operated by the Public Sector Fraud Authority to assist in the prevention and detection of fraud.

We are required to provide particular sets of data to the Minister for the DWP for matching for each exercise.

The use of data by the Public Sector Fraud Authority in a data matching exercise is carried out with statutory authority under Part 6 of the Local Audit and Accountability Act 2014. It does not require the consent of the individuals concerned under data protection legislation, including the UK GDPR and the Data Protection Act 2018, where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

Data matching by the Public Sector Fraud Authority is subject to a Code of Practice.

See the National Fraud Initiative privacy notice on the Gov.uk website. The notice is made under Article 14 of the UK GDPR and explains how personal data is used and what rights individuals have.

We may also share information with other councils, government agencies and associated partners, in order to prevent and detect fraud.

In particular, we will share data with Surrey County Council and any successor authority, other councils and partner organisations.

Our lawful basis for processing

The use of data for this project is carried out under our legal obligations:

  • Section 151 of Local Government Act 1972 requires every authority to make arrangements for the proper administration of their financial affairs
  • The Accounts and Audit Regulations 2015 – Part 2 Internal Control:
    • ‘The financial control systems … must include … measures …to enable the prevention and the detection of inaccuracies and fraud…’.
      • Further, the project may involve data processing where exemptions under data protection legislation are relevant. Any reliance on an exemption must be assessed against the purpose and circumstances of the processing:
  • a) Schedule 2, Part 1, paragraph 2 of the Data Protection Act 2018 – crime and taxation exemptions may apply where the relevant conditions are met;
  • Fraud Act 2006;
  • Other legislation relevant to the services being provided.

Personal data processed for any of the following purposes may be subject to the crime and taxation exemption, to the extent that applying the relevant UK GDPR provisions would be likely to prejudice those purposes:

  • The prevention, investigation or detection of crime
  • The assessment or collection of any tax or duty or of any imposition of a similar nature.

Where the exemption applies, certain UK GDPR rights and obligations may be restricted. Any exemption should be considered, justified and documented on a case-by-case basis, and the Council should comply with the UK GDPR as normal where no exemption applies.

For further information, email investigations@molevalley.gov.uk.

Categories of personal information processed

The categories of personal information processed will vary depending on the relevant data matching exercise but may include:

  • name;
  • previous names;
  • address and address history;
  • date of birth;
  • National Insurance number;
  • employee number;
  • payroll information;
  • pension information;
  • Council Tax information;
  • housing records;
  • tenancy information;
  • housing benefit and welfare support records;
  • electoral registration information;
  • financial information;
  • service user records;
  • business rates information;
  • contact details;
  • other information held by the Council that is necessary for fraud prevention, detection or investigation activities.

We will only process information that is necessary and proportionate for the relevant purpose.

Where we obtain information from

Information may be obtained:

  • directly from you;
  • from information you provide when applying for services;
  • from Council records;
  • from central government departments and agencies;
  • from other local authorities;
  • from public sector bodies;
  • from audit bodies;
  • from law enforcement agencies;
  • from organisations participating in lawful data matching exercises;
  • from publicly available sources where it is lawful to do so.

Who we share information with

Where lawful and necessary, the Council may share information with:

  • the Public Sector Fraud Authority;
  • Department for Work and Pensions;
  • HM Revenue and Customs;
  • Surrey County Council and any successor authority;
  • district, borough, county and unitary councils;
  • government departments and executive agencies;
  • audit bodies;
  • the police and other law enforcement agencies;
  • regulatory bodies;
  • organisations carrying out public functions;
  • organisations responsible for administering public funds;
  • contractors acting on behalf of the Council where appropriate safeguards are in place.

We will only share information where there is a lawful basis for doing so and suitable security measures are in place.

International transfers

The Council does not normally transfer personal information outside the United Kingdom.

If an international transfer becomes necessary, appropriate safeguards will be implemented in accordance with UK GDPR requirements.