Customer Experience and Digital privacy notice

How the Customer Experience and Digital service area collects and uses your data, and your rights regarding your information.

General information

Customer Experience and Digital is responsible for providing members of the public with the option to register for an online customer account, referred to as “myAccount”. This account enables customers to carry out specific online transactions, such as applying for a Blue Badge, and subsequently log in and monitor the progress of their application.

To deliver this service effectively, we are required to collect and process personal data.

The processing of personal data is governed by the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Data (Use and Access) Act 2025 (DUAA) collectively referred to as data protection law.

This privacy notice explains how Customer Experience and Digital uses information about you when you contact us to create an account, and how we protect your privacy.

Suffolk County Council is the controller for the personal information that is being processed. If you have any queries about how Customer Experience and Digital is collecting or using your personal data, you can contact the service by email at: digitalservicedelivery@suffolk.gov.uk

Contact details for the council’s Data Protection Officer and Compliance Manager can be found in the council’s corporate privacy notice, which is available on the council’s website.

What is personal data?

Personal data includes information about you, which can be used to identify you as an individual. Examples include:

  • Your name
  • Your date of birth
  • Your contact details
  • Your image

Special category data is the most sensitive type of personal data and includes:

  • Information about your health or any social care services that you may use
  • Information that could identify your racial or ethnic origins
  • Information that could identify your political beliefs
  • Information that could identify your religious or philosophical beliefs
  • Information that could identify your trade union membership
  • Genetic data
  • Biometric data (where used to identify you, e.g. use of fingerprints to access online services)
  • Information about your sex life, or sexual orientation

The types of personal data that we process and where it comes from

In order to provide your myAccount services, we collect the following personal data from you:

  • Name
  • Contact details including email address and telephone number
  • Any other personal information that you provide that is relevant to your online account

Why do we process your personal data?

Customer Experience and Digital offers members of the public the opportunity to register for an online account, known as myAccount. This account enables individuals to access a range of online services, such as applying for a Blue Badge and, to securely track the progress of their requests.

To create and manage myAccount, we need to collect certain personal details. This ensures we can verify your identity, link your account to you, and provide access to the services and information you require.

When you register for myAccount, you can:

  • Log in to update your personal details
  • Carry out online transactions
  • Check for updates on submitted requests
  • Communicate securely with us
  • Delete your account if it is no longer needed

Our legal basis for processing your information

Personal data

Under data protection law, Customer Experience and Digital can only process your personal data if it is lawful to do so. Please see the details below of the lawful bases that we rely on for processing different types of personal data.

For processing personal data, we rely on the following lawful basis:

  • UK GDPR Article 6(1)(a) – where you have provided consent for us to process your information for a specific purpose

Special category data

When we process special category data, we rely on the following additional lawful basis:

  • UK GDPR Article 9(2)(a) – where you have provided us with explicit consent to process your information for a specific purpose

N.B. The lawful bases identified above for both personal and special category data apply only to the information that you provide in relation to the opening of your online account. Any information that you provide via your account for the purpose of accessing a service will be processed in accordance with the privacy notice of the relevant service and can be accessed via the council’s website.

For example, applications made to the Blue Badge team, will be processed in line with those lawful bases as identified in the Blue Badge privacy notice.

Right to withdraw consent 

When we rely on consent to process your personal and special category data, you have the right to withdraw that consent at any time.

If you would like to withdraw your consent for us to process your personal data for your online account, you can log into your myAccount at any time to request the account is deleted, alternatively you can contact digitalservicedelivery@suffolk.gov.uk to delete your account for you. All personal details that we hold for your myAccount will be deleted within 72 hours of your account deletion request.

Please note that the withdrawal of consent only applies to the information that is collected for the purposes of opening your online account. It will not apply to any personal or special category data that you provide in order to access a specific service (such as Blue Badge), where the service relies on a different lawful basis than consent.

Sharing your information

The Customer Experience and Digital team does not share your information with anyone outside of the council, however the information that you input to access a service will be shared with the relevant team so that they can provide you with the service you have requested/need.

The supplier of the platform that hosts myAccount has access to the system for the purposes of system administration and support.

Whether we intend to transfer your information to another country

We do not transfer any personal data to any countries or international organisations outside of the EU, the EEA (European Economic Area), or any other country that does not have an equivalent level of data protection to the UK.

How long we keep your information

We will retain your myAccount details for as long as your account remains active. An account is considered active when you log in or interact with it. If your account becomes inactive, for example, you do not log in for a period of 37 months, we will notify you of our intention to delete your account.

If you choose to close your account yourself, you can do so at any time by logging into myAccount and requesting deletion. Once submitted, your account information will be permanently deleted within 72 hours.

Please note, the retention periods outlined above apply solely to the personal information you provide to create your myAccount profile. Any personal data associated with specific service transactions carried out using myAccount, such as a Blue Badge application, will be governed by the Privacy Notice of the relevant service team. These transactions may involve additional or more sensitive data, and their retention periods will be determined by the policies and statutory requirements of the individual service.

For example, while your myAccount profile may be deleted after 37 months of inactivity, your Blue Badge application data may be retained for a longer period in accordance with the Blue Badge service’s own retention schedule.

Automated decision-making and profiling

Customer Experience and Digital does not use automated decision-making processes or profiling in respect of your information.

Your rights under data protection law

Under data protection law, you have the right to request access to the information that we hold about you. If you would like to make a request to access your personal information, please contact data.protection@suffolk.gov.uk.

You also have other rights regarding your personal data. You can find out more information about these rights by looking at the council’s corporate privacy notice.

Your right to independent advice

If you would like independent advice on this privacy notice or other matters about how Suffolk County Council processes your personal data, including how to make a complaint, you can contact the Information Commissioner's Office at:

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

Telephone: 0303 123 1113

Email: casework@ico.org.uk