Employees Who Drive as Part of Their Role

The proper handling of personal information by Carmarthenshire County Council is very important to the delivery of our services and maintaining public confidence.

Personal data is any information that relates to a person who can be directly or indirectly identified from the information. The terms ‘information’ and ‘personal data’ are used throughout this privacy notice and have the same meaning.

To ensure that the Council treats personal information correctly, we seek to adhere in full to the requirements of Data Protection legislation.

This privacy notice has therefore been produced to explain as clearly as possible what we do with your personal data.

1. The purpose for which we use your personal data

We process driver-related personal data for the following purposes:
•    Effectively respond to service demands.
•    Effectively configure employees (e.g. working patterns, locations) to provide an efficient and responsive service.
•    Reduce wear and tear on vehicles, thus reducing maintenance costs.
•    Reduce fuel wastage.
•    Lower insurance costs.
•    Ensuring compliance with legal obligations (e.g. drivers’ hours, licensing, road safety) 
•    Managing driver safety and risk to include safeguarding employees that may be vulnerable or at risk due to lone working issues.
•    Monitoring vehicle use and preventing misuse 
•    Investigating incidents, collisions, claims and complaints.
•    Maintaining vehicle roadworthiness and defect reporting systems 
•    Managing training, qualifications, and competency 
•    Protecting employees, the public, and company assets 
•    Supporting disciplinary and performance management processes
•    Enhance the security of our vehicles

The relevant legislation includes:
•    The Management of Health & Safety at Work Act 1999
•    The Health & Safety at Work Act 1974
•    Road Traffic Act 1988
•    Employment Practices Code (Information Commissioner’s Office – ICO)
•    Human Rights Act 1998 (Article 8 – Right to Privacy)
•    The Road Vehicles (Construction and Use) Regulations 1986
•    The Goods Vehicles (Licensing of Operators) Act 1995
•    Traffic Management Act 2004
•    Regulation (EC) No 561/2006 (Drivers’ Hours Rules) 
•    The Transport Act 1968 
•    The Drivers’ Hours and Tachographs (Amendment etc.) (EU Exit) Regulations 2019
•    Vehicle Drivers (Certificates of Professional Competence) Regulations 2007

Public task/work - the other basis for processing this data is that it is necessary to do so to perform a task carried out in the public interest, or in the exercise of official authority vested in the controller (on the basis of the legislation listed above).
Therefore, the processing of this data is not based on consent.

2. What type of information do we use?

We collect and process the following categories of information/personal data relating to the driver:
•    Driver CPC (DCPC) qualification records
•    Training and Competency Records
•    Driving Licence Checks
•    Driver Declaration Forms
•    Drivers Hours/Working Time
•    Driver Record Scoring/Risk Rating
•    Vehicle CCTV Recordings
•    Depot CCTV Recordings
•    Fuel Card Usage Data
•    Fuel Key Usage Records
•    Pool Car Booking Entries
•    Vehicle Spot Hire Records
•    Driver Defect Book Entries
•    Defects reported via Microsoft Forms
•    Motor Incident/Accident Claim
•    Vehicle Overloading Reports
•    The location and movement of the driver, and in some circumstances its passengers when using the vehicle. The speed, driving style and associated data (harsh braking/acceleration), Fuel consumption and other data related to vehicle telematics/information
•    Vehicle Compliance Check Book

3. Do we use information received from other sources?

We don’t routinely obtain information about you from any other sources.

4. Transferring your information abroad

Almost all information about you is stored within the UK.  The only information stored outside of the UK is Fleetclear vehicle CCTV recordings, which is held in the AWS datacentre in Dublin, Ireland.  Where hosting is outside the UK, hosting will be restricted to jurisdictions providing equivalent protection (e.g., EU under GDPR), in line with corporate arrangements.

5. Who has access to your information?

The Council will use your personal data only when there is a need for us to do so and to the extent that is necessary in each case. An example of who might use the data is set out below:
•    The Council’s Fleet Management team and service managers.
•    The employee’s Line Manager/Management Team.
•    Health & Safety team.
•    Human Resources (only in the event of disciplinary action where appropriate).
•    Training team.
•    Fleet team.
•    Risk Management (Insurance Section) – in the event of damage to a vehicle. Where there is a third party claim relevant information may be shared with the third party’s representative for example, an insurer.
•    Regulatory bodies, such as DVSA, Police, Traffic Commissioner.
•    Quartix, the supplier of our Telematics system as detailed in 2 above.
•    Jaama, the fleet management system as detailed in 2 above.
•    CWM Environmental, who supply us with the weighbridge data.
•    Vision, the tachograph and working time management system as detailed in 2 above.
•    Triscan, the system used to manage our fuel deliveries and dispensing.
•    Fleetclear, the system used to manage or vehicle CCTV.
•    Aviva , our insurance company
•    Velocity, is the system used to monitor our Fast Fuel Cards.

There are also other specific situations where we may be required to disclose information about you, such as:
•    Where we are required to provide the information by law.
•    Where disclosing the information is required to prevent or detect a crime.
•    Where disclosure is in the vital interests of the person concerned.

Staff who have access to monitor these systems will have to comply with the following:
•    No "live" monitoring of staff unless there is an active operational need.
•    Strict prohibition of inappropriate use, such as personal curiosity regarding employee whereabouts or any non-work-related surveillance.
•    A clear requirement to notify staff when data is being used in relation to any formal investigation concerning them.
 
Access permissions to the these systems will be reviewed on a 6 monthly basis. There will be annual audits to monitor the use of the systems to ensure it is being used as per this policy. Anyone who does have access will be required to undertake annual refresher training to make sure they fully understand data protection rules, their responsibilities that come with handling this kind of data, and the privacy rights of employees.
If you have concerns regarding staff misusing the systems, please contact the Council’s Data Protection Officer as detailed in Section 8 of this notice. 

6. How long we will keep your information

The Council maintains Retention Guidelines which set out how long records are retained and when they should be securely disposed of. Information will only be retained for as long as there is a lawful purpose to do so and will be securely deleted, destroyed or anonymised when no longer required.

The Retention Guidelines are subject to regular review and may be updated from time to time to reflect changes in legislation, statutory guidance and service requirements.  You can find these guidelines here:

How long we keep records - Carmarthenshire County Council

Please note where data is used as evidence in a disciplinary or insurance claim or similar, system reports may be held longer for that purpose.

 

7. Your Data Protection rights

You have the right to:

  • Obtain access to the personal data that Carmarthenshire Council is processing about you
  • Have any inaccurate or incomplete information rectified (corrected)
  • Withdraw your consent to processing, where this is the only basis for the processing
  • Make a complaint to the Information Commissioner’s Office (ICO), the independent body in the UK which protects information rights

In some circumstances, you may have the right to:

  • Object to the processing of your personal information
  • The erasure of your personal data
  • Restrict the processing of your personal information
  • Data portability

8. Contact details

For more information regarding this privacy notice and your rights, please contact:

Data Protection Officer
Carmarthenshire County Council
County Hall
Carmarthen
SA31 1JP

Email: dataprotection@carmarthenshire.gov.uk

Contact details for the Information Commissioner’s Office along with further guidance on Data Protection legislation can be found on the ICO website .

Council & Democracy

The Council

Councillors, AM's and MP's

Council departments

Have your say

Committees & Meetings

Strategies, plans and policies