Toggle menu

Element (15): Public Records Created or Held by Third Parties

Where the council make use of third parties to provide services on our behalf, appropriate contractual arrangements are in place that define the responsibilities of the third party in keeping with the requirements of the Public Records (Scotland) Act 2011, Data Protection Act 2018, UK GDPR and Freedom of the Information (Scotland) Act 2002. Third parties are required to agree to appropriate contractual controls including standard contractual terms and conditions. Terms and conditions are reviewed and updated where changes to legislation require us to do so.

Data Processing Information Handling Standards are supplied to third parties to provide guidance on the standards appropriate to the handling of public records. Third parties engaged in providing a service on behalf of the council are required to provide evidence of the appropriate handling of records, such as, policies, procedures, guidance and training as well as any compliance or certification to standards, such as, BS ISO 270001. End of contract clauses are included to ensure that ongoing controls are applied to records, such as, transfer back to the authority.