Coronavirus (COVID-19) grant fund privacy notice
We keep this privacy notice under regular review and it was last updated on 1 June 2021.
This notice explains what personal information we hold about you, how we collect it, how we use it and how we might share information.
Who we are
Kent County Council (KCC) collects, uses and is responsible for certain personal information about you. When we do so we are regulated under the General Data Protection Regulation which applies across the European Union (including in the United Kingdom) and we are responsible as ‘controller’ of that personal information for the purposes of those laws. Our Data Protection Officer is Benjamin Watts.
The coronavirus(COVID-19) Grant Fund
The coronavirus (COVID-19) Grant Fund will support initiatives that prevent or mitigate outbreaks in Kent County Council’s (KCC) geographical area or that support the safe reintegration of groups that have been disproportionately affected by coronavirus (COVID-19).
Personal information we collect and use
Information collected by us
In order to manage the KCC coronavirus (COVID-19) Grant Fund we collect the following personal information when you provide it to us:
- names, position, job roles, contact details (email and telephone) of representatives of the successful applicants
- information related to our relationship with you e.g. agreements, correspondence, meeting notes, attendance at events.
How we use your personal data?
We use your personal information to:
- Enable us to answer questions that you have asked about the KCC coronavirus (COVID-19) Grant Fund.
- Process and assess grant applications.
- Administer and manage any grants that are awarded.
- Carry out and fulfil a grant agreement between KCC and the grantee.
- Provide you with support and assistance during the delivery of the project.
- Enable us to contact you surrounding the end of project report.
How long will your personal data be kept for?
We will hold your personal information for:
- up to six years if you contact us (by email, telephone or by letter) to keep a record of that correspondence for future reference.
- six years from the date of the last payment of the grant at which point your data will be permanently deleted. If your application is unsuccessful, your completed application will be stored for 6 years and then permanently deleted.
Reasons we collect your personal data
We rely on the following provision as the lawful basis on which we collect and use your personal information:
- You (the data subject) have given consent to the processing of your personal data for one or more specific purposes; and/or
- Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Who we share your personal information with
We require your personal information to enable us to implement the coronavirus (COVID-19) Grant Fund initiative. Without this information we are unable to process your application for funding. Additionally, we would not be able to award your organisation a grant, as processing of your personal information is required to carry out and fulfil a contract (the grant agreement) between KCC and the grantee.
Your information will be accessible by those staff working on grants and may be seen by elected members of the Council and/or panel representatives. We will also share basic information on grant recipients (amounts/name of group/purpose) but we anonymise your personal information.
We do not share any information you provide to any third parties except:
- where representatives of other organisations are part of the application assessment panel
- where it is necessary to share information with partners working on the coronavirus (COVID-19) Grant Fund Initiative
- to confirm accuracy of information you have provided in respect of your application, for example if you tell us that your project is exempt from VAT we may ask HM Revenue and Customs (HMRC) to confirm the exemption.
We will only share personal data that is relevant and necessary.
The council is required by law to protect the public funds it administers. We may use any of the information you provided for the prevention and detection of fraud. We may also share information with other bodies that are responsible for auditing or administering public funds, including the Cabinet Office. The Cabinet Office requires councils to participate in data matching exercises to assist in the prevention and detection of fraud.
Under the General Data Protection Regulation, you have rights which you can exercise free of charge that allow you to:
- withdraw your consent at any time
- know what we are doing with your information and why we are doing it
- ask to see what information we hold about you
- ask us to correct any mistakes in the information we hold about you
- object to direct marketing
- make a complaint to the Information Commissioners Office.
Depending on our reason for using your information you may also be entitled to:
- ask us to delete information we hold about you
- have your information transferred electronically to yourself or to another organisation
- object to decisions being made that significantly affect you
- object to how we are using your information
- stop us using your information in certain ways.
We will always seek to comply with your request but we may be required to hold or use your information to comply with legal duties. Please note that your request may delay or prevent us from considering your application for a loan.
Who to contact
Please contact the Information Resilience and Transparency Team at firstname.lastname@example.org to exercise any of your rights, or if you have a complaint about why your information has been collected, how it has been used or how long we have kept it for.
You can contact our Data Protection Officer, Benjamin Watts, at email@example.com or by writing to the Data Protection Officer, Sessions House, Maidstone, Kent ME14 1XQ.
For further information about your rights, including the circumstances in which they apply, see the guidance from the UK Information Commissioner's Office (ICO) on individuals’ rights under the General Data Protection Regulation.
The General Data Protection Regulation also gives you right to lodge a complaint with a supervisory authority. The supervisory authority in the UK is the Information Commissioner who may be contacted at 03031 231113.