Police Scotland Fined £66,000 After Serious Data Mishandling

Share this Article:

The Information Commissioner’s Office (ICO) has issued a £66,000 fine to Police Scotland after serious failures in the handling of sensitive personal information.

The case highlights the importance of data minimisation, privacy by design and robust internal procedures when dealing with personal data, particularly where highly sensitive information is involved.

Although the fine relates to a public sector organisation, the underlying compliance failures are issues that many organisations could face if data protection processes are not carefully managed.

What Happened?

The ICO’s investigation found that Police Scotland extracted the entire contents of a person’s mobile phone after the individual reported an alleged crime.

This extraction included a large amount of highly sensitive personal information that was unrelated to the investigation.

The regulator determined that this approach was excessive and did not comply with the data minimisation principle, which requires organisations to only collect information that is strictly necessary for a specific purpose.

The situation worsened when the full, unredacted data was later shared with a third party as part of a misconduct disclosure bundle.

Because appropriate review and redaction procedures were not in place, sensitive personal information was disclosed that should never have been shared.

Key Failings Identified by the ICO

The investigation found several significant compliance failures. Police Scotland failed to:

  • Implement appropriate measures to protect sensitive personal data

  • Limit data collection and sharing to what was strictly necessary

  • Report the personal data breach to the ICO within the legally required 72-hour timeframe

Together, these failures led to the unlawful disclosure of highly sensitive information and caused significant distress to the individual affected.

Why Data Minimisation Matters

This principle requires organisations to only collect and process the personal data that is genuinely necessary for a specific purpose.

Extracting the entire contents of a device, database or system without properly assessing what information is actually required can quickly create unnecessary risk.

Once excessive data is collected, it becomes harder to control how it is accessed, reviewed, shared and protected.

The Role of Policies and Procedures

The ICO also highlighted the lack of clear organisational controls.

Staff were not sufficiently guided by policies or supported by procedures designed to prevent inappropriate access or disclosure of sensitive information.

Effective data protection is not just about having policies written down. Organisations must check that staff understand them, follow them and have the tools needed to apply them in practice.

A Reminder for Organisations

Although the £66,000 penalty may appear relatively modest, it is important to recognise that the fine was issued to a public sector organisation.

The ICO specifically noted that the amount was reduced to avoid disproportionate impact on public services.

For private sector organisations, financial penalties for similar breaches could be significantly higher.

More importantly, enforcement action like this highlights how quickly poor data practices can escalate into serious regulatory issues.

Practical Questions for Organisations

Cases like this should prompt organisations to review their own data handling processes. Key questions to consider include:

  • Are we collecting more personal data than we actually need?

  • Do our systems limit access to sensitive information appropriately?

  • Do staff have clear procedures for reviewing and redacting data before it is shared?

  • Are our policies practical and properly followed in day-to-day operations?

  • Do we have a clear process for identifying and reporting data breaches within the 72-hour requirement?

If the answer to any of these questions is unclear, it may be time to review your current processes.

Need Support Reviewing Your Approach?

At Privacy Helper, we support organisations in reviewing their data protection frameworks, strengthening internal procedures and ensuring practical compliance with ICO expectations.

Our expert team has experience supporting organisations through thousands of real-world data protection cases and understands the operational challenges businesses face when managing personal data.

Contact us today to discuss how we can help you reduce risk and strengthen your approach to data protection.

About the Author:

Explore More Articles