Internal Audit (Central Midlands Audit Partnership) - privacy notice
Who we are?
The Central Midlands Audit Partnership is an Internal Audit partnership which consists of 6 partner organisations – Derby City Council, South Derbyshire District Council, Amber Valley Borough Council, Derby Homes, Derbyshire Fire & Rescue Service and Ashfield District Council. The Partnership is “hosted” by Derby City Council. Our address is The Council House, Corporation Street, Derby, DE1 2FS.
What types of information do we collect from you?
The team will have access to information held by service areas in order to be able to undertake their work; this may include the following types of data:
- personal, for example name, date of birth, address, sex and marital status
- employment information, for example national insurance number, details of employer, salary details, employment dates, next of kin, sickness records
- financial details, for example bank and/or building society account information including transactions & balances, mortgage accounts, insurance policies, pension information, credit history
- health information gathered to assess eligibility for benefits
- financial information regarding appraisal of financial standing of potential contractors
- written statements and recordings of interviews conducted
- other information gathered during the course of an investigation or proactive exercise.
How do we collect this information?
Information is collected in a number of ways. This includes:
- during the course of internal audit and governance reviews of council- provided services and of services provided to the council.
- in conducting an investigation, the investigator will pursue all reasonable lines of inquiry, whether these point towards or away from the suspect so each case will depend on the particular circumstances. Personal information is gathered from numerous sources such as council records, external organisations, third parties, witnesses and the suspect themselves.
How is your information used?
CMAP provides an independent function whose primary objective is to provide assurance to the partner organisations on their risk management, control, fraud and governance processes. The requirement for internal audit function is set out in legislation; Section 151 of the Local Government Act 1972. The requirement for an annual governance statement is defined in the Accounts and Audit Regulations 2015.
The team comprises two main functions:
- internal audit (including IT Audit)
- governance and fraud investigation.
These functions require us to hold or have access to information from systems and processes across the council so that we can undertake our work and in doing so:
- fulfil legal requirements to provide an internal audit function
- investigate referrals made under the corporate whistle blowing policy
- ensure the effectiveness of governance processes
- facilitate the prevention, deterrence and detection of fraud committed against the partner organisations
- investigate potential irregularities.
Where required we may publish and/or shared with key stakeholders (partners) information collected in the course of the audit work/investigation.
On what grounds do we use the information?
CMAP has a duty to protect the public purse. The following acts and regulations provide the basis on which the officers of the team operate:
- Section 151 of the Local Government Act 1972 requires that authorities ‘make arrangements for the proper administration of their financial affairs’
- The Accounts and Audit Regulations 2015 require that ”a relevant body must undertake an effective internal audit to evaluate the effectiveness of its risk management, control and governance processes, taking into account public sector internal auditing standards or guidance. Any officer or member of that body must, if the body requires:
a) make available such documents and records (including those in electronic form); and
b) supply such information and explanation.
as are considered necessary by those conducting the internal audit" - The Police and Criminal Evidence Act 1984
- Criminal Procedure and Investigations Act 1996
- Local Government Finance Act 1992.
Who has access to your information?
We may share elements of information with other internal services within partner organisations to enable the establishment of the effectiveness or otherwise of corporate systems and processes.
During the course of an investigation data may be shared with other departments within partner organisations such as human resources; with government departments and organisations such as the Cabinet Office (National Fraud Initiative), the police, HM Revenues and Customs, the department for work and pensions, the National Health Service, and the border agency etc.
Information may be shared with legal practitioners, tribunals and courts where criminal or civil action is taken against an individual.
We will not sell or rent your information to third parties. We will not share your information with third parties for marketing purposes.
What are your rights?
- Access – you can request copies of any of your personal information that is held by the Council.
- Rectification – you can ask us to correct any incorrect information.
- Deletion – you can ask us to delete your personal information. The Council can refuse to delete information if we have a lawful reason to keep this.
- Portability – you can ask us to transfer your personal data to different services or to you.
- Right to object or restrict processing – you have the right to object to how your data is being used and how it is going to be used in the future.
- Right to prevent automatic decisions – you have the right to challenge a decision that affects you that has been made automatically without human intervention, for example an online form with an instant decision.
How long will we keep your information for?
CMAP has retention schedules in place that ensure information is only held for as long as it is needed.
The partners’ IT security and confidentiality policies ensure that your information is protected, and available only to staff directly involved in your care. Details of how we keep your information secure are available on the general privacy information page.
Where can I find out more?
If you want to know more about how CMAP uses information, your rights or have a concern about the way we are collecting or using your personal data, we request that you raise your concern with us in the first instance.
You can contact our Data Protection Officer on 01332 640000 or by email at data.protection@derby.gov.uk.
For independent advice about data protection, privacy and data sharing issues, you can contact the Information Commissioner's Office (ICO):
- By post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- By phone: 0303 123 1113 (local rate) or 01625 545 745 if you prefer to use a national rate number
Alternatively, visit ico.org.uk or email casework@ico.org.uk.
IP addresses
Internet Protocol (IP) addresses are collected when our site is used:
- for statistical and analytical purposes
- to identify any malicious activity