Police Scotland Under Scrutiny: Data Failures, Unreported Breaches, and the Cost of Institutional Negligence

What is this investigation about?
Police Scotland is under formal investigation by the United Kingdom’s data protection authority over its handling of information requests from members of the public, as a pattern of systemic data failures comes into sharper focus. The probe follows what the Information Commissioner’s Office (ICO) has characterised as an “alarming” accumulation of infringements — 133 confirmed or potential violations recorded over the past four years — and a backlog of 114 unexamined complaints filed between 2025 and 2026.
The investigation is not an isolated audit. It reflects a broader accountability gap in how one of the United Kingdom’s largest police forces manages sensitive personal data — including data belonging to the very people who turn to it for protection.
What triggered the ICO’s intervention?
The most consequential case involves Detective Constable Lianne Gilbert, a serving officer who reported being raped by a colleague in 2022. In the course of the investigation, Police Scotland extracted the entire contents of her mobile phone. That data — deeply personal, extensive, and sensitive — was then handed on six unencrypted discs to the alleged attacker, his police federation representative, and his solicitor.
This was not a minor administrative error. It was a fundamental breach of the rights of a complainant who had sought the protection of the very institution that then exposed her.
The ICO fined Police Scotland £66,000 and issued a formal reprimand, announced on 11 March 2026 — three and a half years after the breach was first reported. The watchdog concluded that the force had failed to implement appropriate technical and organisational safeguards, failed to limit data sharing to what was strictly necessary, and failed to ensure that staff handling sensitive material were operating under clear, enforceable procedures.
Did Police Scotland report this breach itself?
No. A police data officer wrote at the time that the breach “did not meet the statutory notifiable requirements” for self-reporting to the ICO. Under UK law, data controllers are required to notify the ICO of serious breaches within 72 hours. Police Scotland failed to meet that threshold — a failure the ICO explicitly cited in its findings.
This is where the institutional logic becomes particularly troubling. The force’s own assessment classified the exposure of a rape survivor’s complete phone contents to her alleged attacker as not serious enough to warrant mandatory disclosure to the regulator. That judgment, and the internal framework that produced it, sits at the heart of what the ICO is now scrutinising.
How widespread is the problem?
The Gilbert case is not an outlier in volume terms — it is simply the most documented. Police Scotland determined that more than 4,700 incidents did not meet its threshold for reporting to the ICO. The force maintains, through a spokesperson, that all incidents are assessed by specialist staff and that reporting decisions are governed by “the level of risk posed to individuals’ rights and freedoms, rather than the volume of incidents, in accordance with UK GDPR requirements.”
That framing deserves scrutiny. The ICO’s own findings suggest that the force’s risk assessments have been systematically miscalibrated — producing outcomes in which serious breaches go unreported and unexamined for years.
Police Scotland is not alone in this landscape. Three Scottish councils, two schools, Prestwick Airport, the Scottish Further and Higher Education Council, NHS Tayside, and Police Scotland itself were among the public bodies subject to a “level 2” ICO intervention or higher over the past year — interventions reserved for cases where the commissioner identifies ongoing, unresolved institutional failures.
What has Police Scotland said in response?
Deputy Chief Constable Alan Speirs acknowledged receipt of the reprimand and penalty notice and stated that the force had “reflected” on its findings. “We acknowledge the organisation did not meet expectations and regulations relating to data handling in regards to this matter,” he said, adding that an apology had been issued to those involved.
The force also noted that it had undergone a voluntary ICO audit following the Gilbert incident, which has since been completed, and that steps have been taken to strengthen data-handling processes, improve staff training, and increase internal oversight.
Voluntary audits and internal reviews are a standard institutional response. Whether they produce structural change, or merely the appearance of it, is a question the ICO’s ongoing investigation will help answer.
What does this mean for data rights and accountability?
Sally-Anne Poole, the ICO’s Head of Investigations, described the Gilbert case as a “stark example of the devastating consequences of poor data protection practices.” “Police Scotland failed in its obligation to safeguard the personal information of someone who had reached out to them for help,” she said.
That framing is precise and important. Data protection law is not a bureaucratic formality. It encodes a set of rights — to privacy, to dignity, to control over one’s own information — that are especially acute when the data subject is a victim of serious crime. When a police force breaches those rights in relation to a rape complainant, and then classifies that breach as below the threshold for mandatory disclosure, it compounds the original harm with institutional concealment.
The ICO’s investigation now encompasses not just the Gilbert case but the broader question of how Police Scotland processes, assesses, and reports data incidents across its operations. With 114 complaints still awaiting review and a four-year record of 133 infringements, the scale of the accountability gap is significant — and the outcomes of this investigation will matter well beyond Scotland.
