Local Council Toolkit

The Local Council Data Protection Toolkit

A complete 12-month support package for parish and town councils.

Stay compliant with UK GDPR and the Data Protection Act, without the stress and headaches.

Just £695 + VAT per year. 60-day money-back guarantee.

An Open Letter to Clerks, Council Officers and Local Councillors

Dear Local Council,

If there is one thing we hear more than anything else from the clerks and officers we work with, it is this: there simply is not enough time to do everything you have to do.

Time to stay on top of ever-changing information compliance rules. Time to figure out which of it really applies to parish and town councils. Time to learn or refresh key skills. And now, there is something new to add to the list.

From the 2025/26 AGAR, parish and town councils must confirm their compliance with UK GDPR and the Data Protection Act.

Data protection compliance is not new. Parish and town councils, together with other data controllers, have had to comply with their legal and statutory data protection obligations for years. But, with the introduction of Assertion 10, information compliance has now come into clear focus.

This may mean refreshing outdated policies and providing relevant training for staff and councillors. It may mean mapping out the personal data processed by the council, including why you hold it, who has access, and your lawful basis for processing. It may also involve conducting data protection risk assessments and ensuring key documents and policies reflect how your council works today, and not how the council operated back in 2018 when GDPR first came into law.

That is why we created the Local Council Data Protection Toolkit service.

It is designed to take the pressure off. Giving your council a clear, supported pathway to information compliance, with relevant tools and templates, step-by-step guidance, council-specific training, and year-round support through live clinics and events.

Information compliance does not stand still, and neither does your council. Your council is growing, taking on new services and assets. Breakthrough Communications is here to support your council on that journey. You do not need more on your "to do" list.

You need the right tools at the right time, so compliance does not become a last-minute scramble. Join us today.

Daniel Purchese
Breakthrough Communications
01903 299000 | hello@breakthroughcomms.co.uk
Daniel Purchese

Every council has to declare its compliance with UK GDPR

Assertion 10 means that as part of your councils Annual Governance Statement every parish and town council will have to confirm that they are compliant with their legal obligations under UK GDPR and the Data Protection Act.

What Assertion 10 expects from councils

UK GDPR
Comply with the regulation
Comply with the UK General Data Protection Regulation and the Data Protection Act 2018.
Lawful
Process personal data fairly
Process personal data lawfully, fairly, and in line with UK GDPR principles.
Roles
Controller and Processor
Recognise the council's roles as both a Data Controller and a Data Processor.
Audits
Of personal data processed
Carry out council-wide audits of the personal data your council processes, why you hold it and who has access.
Risk
Risk assessments
Risk assess all personal data processed and identify mitigations to reduce risk to the council and to data subjects.
Training
For staff and councillors
Put in place regular and relevant data protection training for council staff and councillors.

The compliance gap

2018
Many policies have not been updated since GDPR first came into law
2026
Assertion 10 requires policies that reflect how your council works today

The Local Council Data Protection Toolkit is built to close that gap.

There is a lot to take care of, which is why acting now can help avoid unnecessary stress, frustration and headaches further down the line.

Breakthrough Communications proudly introduces

The Local Council Data Protection Toolkit

A supportive pathway to compliance, with guidance and clarity every step of the way. On-demand training, customisable templates, regular bulletins, drop-in clinics and live virtual Masterclasses, all built around how parish and town councils actually work.

On-Demand, Bite-Sized Training Modules
Bespoke data protection training and guidance for clerks and lead council officers, comprehensively covering the journey to confident compliance.
Regular Refresher Training
Councillors and staff get regular data protection training at no extra cost, with certificates of completion for all delegates.
Regular Drop-in Clinics
Join us on Zoom to troubleshoot issues, get answers, and hear from colleagues across the country as we share and discover best practices.
Templates, Resources and Checklists
We have done the hard work for you. Council-specific templates designed to save you time and effort, so you do not have to start from scratch.
Best Practice Bulletins
Helping your council stay up to date with the latest data protection and information compliance developments affecting parish and town councils.
Monthly Masterclasses
Practical advice on key topics such as CCTV, photography at events, councillor data, SARs, FOI and EIR management.

A unique six-stage pathway to compliance

The Toolkit will support your council through every stage of its data protection compliance journey, giving you peace of mind and confidence at AGAR.

1
Foundations
The building blocks of data protection

A thorough understanding of council information compliance essentials, so the rest of the journey makes sense from the start.

Includes:
  • UK GDPR principles explained for councils
  • The Data Protection Act 2018 in plain English
  • Roles: Data Controller and Data Processor
  • What "personal data" actually means in council life
2
Data Mapping
Map out the personal data your council processes

Our experts will guide you to map out all of the personal data your council processes, and document the purposes for which it is being processed.

Includes:
  • Council-wide personal data audit template
  • Purpose of processing register
  • Who has access guidance
  • Worked examples for parish and town councils
3
Lawful Basis
Confirm a lawful basis for each purpose

Explore the lawful basis your council has for each purpose you have identified, and document it in a way that stands up to scrutiny.

Includes:
  • Lawful basis decision guide
  • Public task and legitimate interests in council settings
  • Special category data scenarios
  • Documentation templates
4
Risk Assessment
Risk assess personal data from a practical perspective

A practical approach to identifying and mitigating data protection risks, including the risks to the council and to data subjects.

Includes:
  • Council data protection risk register
  • Practical mitigation library
  • DPIA template and worked example
  • CCTV, photography and event risk guidance
5
Policies and Documentation
Create the essential policies your council needs

Step-by-step guidance to create essential policies and documentation, written for how your council operates today and not in 2018.

Includes:
  • Data Protection Policy template
  • Privacy Notice template
  • Records Retention schedule
  • Subject Access Request (SAR) procedure
6
Review and Future-Proof
Confidence at AGAR and beyond

A final review of everything you have done, giving you confidence to declare Assertion 10. We will also keep your council future-proofed as guidance evolves.

Includes:
  • Assertion 10 readiness checklist
  • Annual review prompts
  • Updates whenever new guidance is released
  • Ongoing access to live clinics and Masterclasses
Risk-Free Guarantee

60-day money-back guarantee

If your council completes all of the training modules and attends at least one live clinic or Masterclass, but is still not satisfied, we will refund your council in full. No hassle. No risk.

Who is the Data Protection Toolkit for?

Clerks and council officers

A clear, supported pathway through compliance, with bite-sized training built around how your council actually works. Sign off Assertion 10 with confidence.

Councillors

Refresher training and certificates of completion for every councillor, with a unique subscription that covers everyone in the council.

Councils preparing for Assertion 10

A practical roadmap to data audits, lawful basis, risk assessments, and the policies your council needs in place to declare compliance.

Councils tackling SARs, FOI, CCTV or events

Practical guidance on subject access requests, FOI and EIR, CCTV, photography and videography at events, councillors using personal data, and more.

Save time, reduce stress and prevent information compliance headaches

Or call us on 01903 299000

What is included and what it costs

12 months of unlimited access for everyone in the council. One simple price.

What is included

On-demand, bite-sized training modules for clerks and council officers
Regular refresher training with certificates of completion for all delegates
Council-specific templates, resources and checklists, including a UK GDPR and Data Protection Compliance Checklist
Monthly Masterclasses on CCTV, photography at events, SARs, FOI and EIR, and more
Regular Zoom drop-in clinics for real-time troubleshooting
Best practice bulletins as guidance evolves
Whole-council subscription: clerks, officers and councillors all included

Need to take this to council first?

The Toolkit sits comfortably within communications, training or governance budgets. If you need a short delay while the decision goes through council, call us on 01903 299000 and we will hold the price for you.

Give your council a clear, supported pathway to UK GDPR compliance

Or call us on 01903 299000

Frequently asked questions

Our Toolkit service is an optional service for councils. However, the Assertion 10 requirements are not optional, and neither are the legal and statutory data protection requirements that have been placed on councils for years. The Toolkit is here to guide and support your council through that journey and to ease the stress.
Data protection policies and other documents, such as a Privacy Notice, must reflect current council practice, be actively followed, and regularly updated to align with the latest guidance, legislation and best practice. Out-of-date or off-the-shelf policies may not reflect the way your council processes personal data.
Compliance involves having a clear sense of where your council is now, where it needs to be, and how to bridge any gap. That can take time. We would advise not delaying your compliance journey, regardless of whether or not you use our service.
Personal data covers staff records, councillor contact details, resident correspondence, planning documents, consultation and survey responses, live and recorded CCTV footage, photographs from council and community events, and details in allotment or burial registers. Even routine documents such as GDPR and FOI requests, complaint emails or youth club sign-up forms often contain identifiable personal information.
Breakthrough Communications is the only organisation that provides data protection and information compliance advice to NALC, many County Associations, and directly to parish and town councils. Our team specialises exclusively in the parish and town council sector, combining expert knowledge of UK GDPR and FOI with a practical understanding of how councils operate.
We update the Toolkit every month and add important updates right away whenever new guidance is released.
Yes. Your council's subscription covers everyone. Councillors, clerks and staff can all access the materials and join training sessions.
If your council completes the training and attends a live session but is not satisfied, we will refund you in full within 60 days.

The right tools at the right time, so compliance does not become a last-minute scramble

Join the councils already using the Local Council Data Protection Toolkit to take the pressure off and get Assertion 10 ready.

Register for the Local Council Data Protection Toolkit

Stay in the loop