Community Resilience Groups and GDPR
We want to ensure that by working in partnership with other statutory agencies and voluntary sector organisations that we are able to maximise our collective ability to respond and support the needs of our communities.
The following advice has been prepared to assist Community Resilience Group's to take appropriate measures should there be a requirement for you to collect and store personal data during an emergency.
Considerations when handling sensitive data
All information should be captured and stored in line with General Data Protection Regulations (GDPR) Legislation and any guidance provided by the Information Commissioners Office (ICO).
We would recommend that you consider a leaflet drop to households in your community which has useful contact numbers and emails, including those for members of your resilience team or community group. Prior to doing this, or distributing the HELP leaflet, approval and consent should be sought from team members that they are happy for their contact information to be shared.
The responsibility then lies with individuals to make contact direct with their local resilience team or any other relevant organisation and ask for support, this negates the need for local resilience teams to hold any personal or sensitive data unnecessarily.
If required, we strongly recommend that you keep to a minimum, any data that you may need to support people and that any information you do hold is held securely. This information could be captured at the point of contact to ensure you can fulfil the support requested (name, address, telephone number or email) and by no other means. No medical or further personal details should be captured or stored