ICO fines Police Scotland £66k and issues reprimand over failures in handling sensitive personal information
The Information Commissioner’s Office (ICO) has fined Police Scotland £66,000 and issued it with a reprimand after finding serious failures in its handling of sensitive personal information. It concluded that the force failed to apply basic safeguards when extracting and disclosing highly sensitive data. The ICO found that Police Scotland extracted the entire contents of a person’s mobile phone after they reported an alleged crime, without putting in place adequate safeguards to prevent access to irrelevant material. The download ran to 39,233 pages, including more than 10,000 pages of images and included private and special category data wholly unrelated to the investigation. The ICO concluded that the extraction was not ‘strictly necessary’ for law enforcement purposes and was excessive and unfair, in breach of sections 35 and 37 of the Data Protection Act 2018 (DPA 2018).