Skip to additional navigation Skip to content

4087198

Response to request for information

Reference

4087198

Response date

8 September 2026

Request

I am seeking recorded information concerning the data protection impact assessments, risk assessments and safeguards relating to the Council’s processing of changes of address and the updating/linking of council tax accounts. Please provide:

  1. The current Data Protection Impact Assessment (DPIA) relating to the Council’s council tax system and, in particular, the processing of changes of address.
  2. Any previous versions of that DPIA which remain within the Council’s retention period, together with their dates/version numbers.
  3. Any DPIA specifically relating to the Council’s online change-of-address form, portal or associated software through which members of the public notify the Council of a change of address.
  4. Any data protection risk assessment, privacy risk assessment, data protection screening assessment or equivalent document undertaken where the Council determined that a DPIA was not required for the above processing.
  5. Any recorded assessment concerning the risks arising where a person has more than one council tax account or property associated with their details, including the risk that a change of address submitted through the Council’s system may update one account but fail to update another relevant account.
  6. Any recorded assessment of the risks associated with automated or semi-automated matching, linking, updating or processing of council tax accounts following a change-of-address notification.
  7. Any recorded assessment concerning the possibility of incorrect or incomplete personal data being retained or used as a result of a change-of-address notification not being applied to all relevant council tax accounts.
  8. Any recorded information identifying the technical, procedural or human safeguards specified in the DPIA or equivalent assessment to mitigate the risks identified above.
  9. Any recorded information showing whether those safeguards include: 
    • automated checks for other council tax accounts associated with the same person;
    • alerts or exceptions requiring manual intervention;
    • staff review where a person has multiple properties/accounts;
    • verification of whether a change-of-address notification should be applied to other council tax accounts;
    • any other mechanism intended to prevent an incorrect or incomplete update. 
  10. Any subsequent review, audit, reassessment or update of the above DPIA or risk assessment following an incident, complaint, identified system weakness or change to the Council’s council tax processing system. 
  11. If the Council considers that no DPIA was required for any of the processing described above, please provide the recorded information documenting that decision and the reasons for determining that a DPIA was unnecessary. 
  12. Please also provide the job title of the person or role responsible for approving or signing off the relevant DPIA or equivalent assessment. I am not requesting the individual’s personal contact details.

For clarity, this request concerns the Council’s general processing systems, procedures and safeguards and is not a request for my own personal data. If any information is considered exempt, please provide the non-exempt portions and identify the specific exemption relied upon, together with the reasons for applying it. Please provide the information in electronic form where possible.

Response

We have considered your request under the Freedom of Information Act 2000 (FOIA). Under section 1(4) of FOIA, the Council is required to provide recorded information that it held at the date of the request. 

A reasonable search has been undertaken of the relevant records in service areas responsible for Council Tax administration and information governance.  The Council has not identified any DPIAs relating to the Council Tax system or changes of address within that system. Searches were also undertaken for risk assessments, screening assessments, reviews, audits and other recorded information falling within the scope of your request. No recorded information of this nature was identified. Accordingly, no information falling within the scope of this aspect of the request can be disclosed.

In relation to question 12, as no DPIA or equivalent assessment has been identified, there is no specific sign-off recorded for such a document. In general, responsibility for determining whether a DPIA is required rests with the Council's Data Protection Officer (DPO), Chief Information Officer (CIO) and Senior Information Risk Owner (SIRO).
  
Advice and Assistance under section16 of the FOIA.

Under section 16 of FOIA, the Council has a duty, so far as it would be reasonable to expect it to do so, to provide advice and assistance to a person who has made, or proposes to make, a request for information. Data protection impact assessments were introduced by the General Data Protection Regulation (EU GDPR), which applied from 25 May 2018 alongside the Data Protection Act 2018. Following the end of the EU transition period, the relevant regime became the UK GDPR and the Data Protection Act 2018. Article 35 of the UK GDPR requires a DPIA where a new type of processing is likely to result in a high risk to the rights and freedoms of individuals. The use of new technology is one factor to consider, but it does not by itself determine whether a DPIA is required.  For pre-existing processes, a DPIA is only likely to be required where it is intended to introduce:

  • New technology: Adding AI, automated decision-making, or algorithmic banding/profiling tools;
  • Data sharing expansion: Integrating new external data-matching initiatives (like cross-matching data with HMRC or DWP under the Digital Economy Act); or 
  • Large-scale changes: Altering how personal data is collected, handled, or scaled across departments.

The Council does not hold a DPIA for the Council Tax system or a DPIA specific to changes of address within that system. Having reviewed the processing activities concerned, the Council has not identified any requirement under the UK GDPR or Data Protection Act 2018 for a DPIA to have been undertaken in relation to those activities.

We can further advise that, in general here Council Tax accounts are linked, a change in contact information will be applied in the default setting to all linked accounts. Where accounts are not linked, for example, because an individual is recorded in different capacities, such as a resident for one property and a landlord for another, the individual would need to notify the Council of the change in contact information in relation to each account. Any use of personal information across accounts must comply with the data protection principles, including purpose limitation and accuracy.