30 Jul 2026
by Sachin Agrawal

When councils merge, who's responsible for the data? The compliance challenge hiding inside LGR

Amid the rush to reorganise, a question that's sadly little front of mind is what happens to the data these councils hold

By Sachin Agrawal, Managing Director of Zoho UK

Local Government Reorganisation (LGR) is fast approaching, marking the largest restructuring of English local government since the 1970s, reshaping 134 councils into new unitary authorities. Amid the rush to reorganise, a question that's sadly little front of mind is what happens to the data these councils hold. Resident records, social care files and housing histories will all need migrating to new systems. However, how councils will handle their data gets far less attention than the political and structural side of LGR.

The data ownership question

The Local Government Secretary has confirmed reorganisation decisions for 14 more areas of England, meaning a further 134 existing councils will become 38 new unitary authorities, affecting around 15 million people. That's a lot of data to manage, with most two-tier councils on track to restructure by April 2028. No two councils operate the same way, each with its own systems and records. The challenge is making sense of it all quickly, without disrupting services to residents.

This is more than an IT migration problem, it's a compliance and governance one, and it starts well before vesting day. The District Councils' Network has urged councils to establish early whether they are a data controller, joint controller or processor for each dataset. Councils will need to outline who decides the purpose and means of processing data, not simply who holds the files. A shadow authority jointly shaping policy with predecessor councils before vesting day may already be a joint controller. Social care, housing, law enforcement and HR data often carry their own legal gateways, so a single "lift and shift" won't work. Get this wrong, or leave it unresolved, and a council can find itself exposed under UK GDPR and the Data Protection Act 2018 when it can least afford it.

The opportunity hiding inside LGR

There's opportunity in the wider policy backdrop too: the Cyber Security and Resilience Bill, raising the baseline for how critical data and infrastructure are protected, is moving through the House of Lords now. The bill shows the direction of travel, and councils that build data residency, access and provable compliance into procurement are future-proofing their systems.

Because new unitary authorities are procuring fresh, mostly via G-Cloud, they have a rare chance to start with the right processes rather than inheriting inconsistent practices from predecessor councils. Retrofitting compliance onto a legacy estate is expensive and slow; specifying it at procurement costs nothing extra. LGR programme and procurement teams should be pushing suppliers on these questions well before go-live:

  • Who is the data controller for each dataset during the shadow period, and does that change on vesting day?
  • Where does the data reside, and under which legal jurisdiction - UK, EU or elsewhere?
  • Does the vendor monetise customer data, and what does the contract say about that?
  • What certifications back up their compliance claims - ISO/IEC 27001, SOC 2 Type II, Cyber Essentials Plus?
  • Is the platform already G-Cloud listed?

When a council hands over resident data, it isn't just a procurement decision, it's a trust decision on behalf of the communities it serves. Data belongs to the council and its residents; a good partner won't monetise it or move it without authorisation. That should be the baseline for every public sector technology contract, but it isn't always the baseline councils are getting.

The technology decisions made over the next 18 months will shape how well-governed these new authorities are for a decade or more. Data governance rarely gets the attention org charts and service redesigns do during a reorganisation this size, but it's one of the few parts of LGR where doing it properly from the outset is no harder, and no more expensive, than doing it badly.



techUK - Transforming Public Services

public_sector_icon_badge_stroke 2pt_final.png

techUK members are transforming public services in the UK. Our community help to shape a smarter, digitally empowered public sector.

techUK drives public sector digital transformation by uniting the public sector and tech industry. Through early market engagement, efficient procurement, and innovative technology adoption, we help to modernise legacy IT, and enable efficient, secure, and personalised services.  

Get involved: We run a busy calendar of activity including events, reports, and insights that demonstrate some of the most significant digital transformation opportunities for the sector. Our Transforming Public Services Hub is where you will find details of all upcoming activities. We also send a monthly public services newsletter to which you can subscribe here.

Upcoming 'Transforming Public Services' events

Latest news and insights

More resources

 

 

Authors

 Sachin Agrawal

Sachin Agrawal

Director, Zoho UK