Site navigation

Police Scotland Fined £66K For Mishandling Data

Elizabeth Greenberg

,

police scotland ico fine
“At its heart, data protection is about people, and this incident is a stark example of the devastating consequences of poor data protection practices on individuals,” Sally-Anne Poole, ICO Head of Investigations, said.

Police Scotland is facing a £66,000 fine and a reprimand from the Information Commissioner’s Office over failures in the handling of sensitive personal information.

The ICO’s investigation into the force found that Police Scotland extracted the entire contents of a person’s mobile phone after they reported an alleged crime, without ensuring there were sufficient safeguards to prevent access to irrelevant personal information.

As a result, officers collected a substantial volume of highly sensitive information, much of which had no bearing on the investigation, the ICO found.

Police Scotland subsequently included the full unredacted content into a misconduct disclosure bundle and shared it with a third party who should not have received it.

The ICO determined that appropriate review, redaction and security procedures were not in place, and that staff were neither adequately guided nor supported by effective organisational controls.

The ICO concluded that Police Scotland failed to implement appropriate organisational and technical measures to ensure data security, as well as limit personal information sharing to what was strictly necessary.

Police Scotland was also found to not have ensured staff handling sensitive information were following clear guidance and procedures, as well as report the personal data breach to the ICO within the legally required 72-hours timeframe.


Recommended reading


“At its heart, data protection is about people, and this incident is a stark example of the devastating consequences of poor data protection practices on individuals,” Sally-Anne Poole, ICO Head of Investigations, said.

“Police Scotland failed in its obligation to safeguard the personal information of someone who had reached out to them for help. Instead, they exposed them to further risk and distress by disclosing highly sensitive information to a third party.

“People should be able to trust that organisations will treat their personal information with care, fairness and respect. When organisations fail to do so, they can expect enforcement action from us.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data