The Chief Fire Officer of North Yorkshire Fire and Rescue Service is committed to protecting your personal information.
Who we are?
Your personal data – what is it?
“Personal data” is any information about a living individual which allows them to be identified. Identification can be directly using the data itself, or by combining it with other information which helps to identify a living individual. The processing of personal data is governed by legislation relating to personal data which applies in the United Kingdom including the General Data Protection Regulation (the “GDPR”) and the Data Protection Act 2018, and other legislation relating to personal data and rights, such as the Human Rights Act.
The data we may collect about you:
Personal Data that we may collect includes, but is not limited to:
- Name of owner and/or responsible person
- Contact details
- All correspondence and documentation completed for the purposes of an audit or managing a fire safety complaint
- Details of any person providing information
Special category personal data may include personal data revealing:
- Racial or ethnic origin;
- Political opinions;
- Religious or philosophical beliefs;
- Trade Union membership;
- Physical or mental health;
- Sex life or orientation;
- Genetic or biometric data.
North Yorkshire Fire and Rescue will use the minimum amount of personal information necessary to carry out a particular activity.
What is the legal basis for processing your personal data?
The Chief Fire Officer of North Yorkshire Fire and Rescue Service may process personal data for the following reasons:
- To meet a legal obligation
- The Regulatory Reform (Fire Safety) Order 2005 gives us the authority to go into non-domestic buildings to check the fire safety provisions and procedures. Further action may be taken if we consider the responsible person has failed to comply with any provision of the Order. Find out more about the Order, our and your regulatory responsibilities as the responsible person and the consequences of not complying.
- Under the Fire and Rescue Services Act 2004, we have a duty to extinguish fires and protect life and property in the event of fires and road traffic collisions, and a power to respond to other eventualities that causes or likely to cause death, injury, illness or harm to the environment. Section 45 to 48 of the Act empowers us to obtain information and investigate what caused a fire or why it progressed as it did.
- To allow us to perform our public task of providing a Fire and Safety Rescue Service in the interest of the public.
Where we process special categories of personal data, we will do so for one or more of the following reasons:
- It is necessary to protect individuals’ vital interests;
- The processing relates to personal data which have been manifestly made public by the data subject;
- It is necessary for the establishment, exercise or defence of legal claims, or for courts acting in their judicial capacity;
- It is necessary for reasons of substantial public interest and occurs on the basis of a law that is proportionate to the aim pursued and protects the rights of data subjects;
- The processing is required for the purpose of medical treatment undertaken by health professionals;
- The processing is necessary for reasons of public interest around public health; and
- The processing is necessary for archiving purposes in the public interest, for historical, scientific, research or statistical purposes, subject to appropriate safeguards.
The Data Controller will comply with data protection law. This says that the personal data we hold about you must be:
- Used lawfully, fairly and in a transparent way, as appropriate.
- Collected only for valid purposes that we have clearly explained to you and not used in any way that is incompatible with those purposes;
- Relevant to the purposes we have told you about and limited only to those purposes;
- Accurate and kept up to date;
- Kept only as long as is necessary for the purposes we have told you about;
- Kept and destroyed securely, including ensuring that appropriate technical and security measures are in place to protect your personal data and to protect personal data from loss, misuse, unauthorised access and disclosure.
Sharing your personal data:
We may share your personal data internally with relevant departments for the purpose of fulfilling one or more of the above stated legal bases. We may also engage the services of other agencies to meet legal requirements or fulfil another lawful basis.
Where we have arrangements to share your personal data, there is a contract, memorandum of understanding or information sharing agreement in place to ensure that the requirements of the Data Protection legislation on handling personal information are met. Where we are required to disclose information by law, for example for safeguarding purposes, we may do so without these arrangements.
We engage with third party processors who handle some, or all, of the above-mentioned information on our instruction.
NYFRS will take steps to ensure any disclosures of personal data are necessary and proportionate, as required by law. Whenever we share your personal information, sharing options will be evaluated to ensure that your data is shared in the most secure manner.
How do we keep your personal information secure?
We are committed to ensuring that your personal data is safe and processed securely. In order to prevent your personal data from being accidentally lost, used or accessed in an unauthorised manner, altered or disclosed, we have put in place suitable physical, electronic and managerial measures. These include information security awareness training for our staff. We have also compiled procedures to safeguard and secure the information that we hold about you which our staff adhere to.
We limit the access to your personal information to those employees who have a business need to know, for instance through secure work areas and access controls on all our systems. Employees, contractors and other third parties who handle personal data will only process your personal information in line with our direct instructions.
How long do we keep your personal information?
North Yorkshire Fire and Rescue keeps your personal information as long as is necessary for the particular purpose, or purposes, for which it is held.
Records that contain your personal information processed for “general data” purposes will be managed in accordance with the Service’s Retention Schedule.
Your rights and personal data:
A key area of change in the new Data Protection Act relates to individuals’ rights. The law refreshes existing rights by clarifying and extending them and introduces new rights.
However, your information rights will be dependent on the reason why the data was collected, how the data was collected and why it is being used.
Further information about your rights can be found on the “Your Information Rights” page.
Details as to how we can be contacted as well as how you can submit a complaint is available on our website: Your Information Rights – North Yorkshire Fire & Rescue Service (northyorksfire.gov.uk)