The UK Information Commissioner’s Office (ICO) fined Police Scotland £66,000 and issued a reprimand after finding “serious” data protection failures tied to the handling of an alleged victim’s mobile phone data. Investigators extracted the entire contents of the phone when only specific communications were needed for a criminal inquiry, resulting in the collection of a substantial volume of highly sensitive “special category” data unrelated to the investigation.
The ICO found that the unredacted full extraction was later mishandled during internal processes: the complete phone dump was included in a professional standards/misconduct disclosure bundle and shared with a third party who should not have received it, exposing sensitive victim information. Reporting emphasized the case as a governance and controls failure around data minimisation, secure handling of digital evidence, and staff training within policing and criminal justice organizations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The UK Information Commissioner's Office fined Police Scotland £66,000 and issued a reprimand after finding infringements of the Data Protection Act 2018. The ICO also noted the force failed to self-report the personal data breach within the required 72-hour period.
The ICO opened a formal investigation into Police Scotland in response to the complaint and the handling of the victim's mobile phone data. The probe examined both the excessive extraction and the later unlawful disclosure.
The affected victim filed a complaint with the UK Information Commissioner's Office over Police Scotland's handling and disclosure of her phone data. This complaint triggered regulatory scrutiny of the force's actions.
Following the incident and regulatory scrutiny, Police Scotland said it updated its processes, staff training, and oversight arrangements to prevent similar data handling failures. The force also acknowledged shortcomings and apologized.
Police Scotland's Professional Standards Department later included the victim's complete extracted phone data in a misconduct disclosure bundle and shared it with the accused police employee, an unauthorized recipient. The disclosure exposed highly sensitive and special category personal data.
During a criminal investigation, Police Scotland carried out a full mobile phone extraction on an alleged victim's device. The ICO later found this collection was excessive and unfair because it captured sensitive data unrelated to the investigation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.