Subheading Police Scotland says it has taken ‘organisational learning from this incident’

ICO fines Police Scotland £66,000 after multiple mistakes handling data from a crime victim’s mobile phone.
The UK’s data protection regulator has fined Police Scotland £66,000 after an investigation found the force mishandled highly sensitive personal data belonging to a woman who had reported a crime.
The Information Commissioner’s Office (ICO) said the country’s second-largest police force committed a “serious failure” when officers extracted and later shared the entire contents of the woman’s mobile phone during an internal misconduct case.
According to the watchdog, investigators initially sought to retrieve text messages exchanged between the woman and a man accused of an offence during an incident in 2021 involving two Police Scotland employees.
However, instead of extracting only the relevant messages, officers conducted a full download of the phone’s contents.
The senior investigating officer deemed the approach proportionate and argued that carrying out a complete extraction would allow the device to be returned more quickly.
The ICO said this decision resulted in police collecting a “substantial volume” of unrelated and highly sensitive material from the woman’s device.
Among the information obtained was “special category data,” a classification under UK data protection law covering particularly sensitive personal details such as health information, religious beliefs, ethnicity, political views and sexual orientation.
The exact nature of the data involved has been redacted from official documents.
Because the allegation concerned two police staff members, the case was referred to Police Scotland’s professional standards department (PSD) for review. As part of that process, the PSD received all documentation associated with the investigation, including the full dataset extracted from the phone.
The department concluded that one of the employees accused in the case may have committed gross misconduct and arranged a disciplinary hearing.
But in a further error, the officer facing the allegation was mistakenly provided with documents that included the victim’s phone data in its entirety, including the sensitive information that had been collected during the full extraction.
The woman later complained to the ICO in September 2022, saying the force had not clearly explained what personal information had been disclosed during the misconduct proceedings.
The ICO opened a formal investigation in May 2023.
In its findings, Information Commissioner John Edwards said Police Scotland had breached the Data Protection Act 2018 by failing to ensure that the scale of the data collection was lawful and proportionate, and by not adequately safeguarding the data once it had been gathered.
The ICO also found that the force failed to report the breach within the required 72-hour window after becoming aware of the mistake.
Sally-Anne Poole, the ICO’s head of investigations, said the case demonstrated how poor data protection practices could directly harm individuals.
“At its heart, data protection is about people, and this incident is a stark example of the devastating consequences of poor data protection practices on individuals,” she said.
The ICO said the £66,000 fine reflected both the seriousness of the failings and the need to avoid causing disproportionate harm to public services.
Deputy Chief Constable Alan Speirs said the force had acknowledged the shortcomings identified by the regulator.
“The organisation did not meet expectations and regulations relating to data handling in regard to this matter,” he said. “Police Scotland has taken organisational learning from this incident.”
He added that the force had already introduced new measures to strengthen data-handling procedures, including additional staff training, improved oversight and revised processes designed to reduce the risk of similar breaches occurring in future