Data protection breaches

Request data on personal data breaches reported internally and to the ICO.

Data breaches at public bodies can expose personal information and erode public trust. FOI requests can reveal how often breaches happen and how serious they are.

Dear [AUTHORITY NAME], Please provide the following information for [FINANCIAL YEAR e.g. 2024-25]: 1. The total number of personal data breaches recorded. 2. A breakdown by type of breach (e.g. data sent to wrong recipient, lost or stolen device, unauthorised access, cyber incident). 3. The number of breaches reported to the Information Commissioner's Office (ICO). 4. A summary of any actions taken to prevent recurrence. I would prefer to receive this by email. Yours faithfully, [YOUR NAME]

Who to send it to#

Any Scottish public authority: council, health board, police, or government agency. Find the right authority on the Commissioner’s directory of Scottish public authorities. You can also send your request through WhatDoTheyKnow, which publishes responses online.

Tips#

  • Data breaches reported to the ICO are the most serious. The ICO publishes some enforcement data on its website, so check there for any action taken against the authority.
  • Asking for a breakdown by type helps you understand whether the problem is human error, system failures, or malicious activity.
  • If the authority refuses item 4 on the basis that it would prejudice the prevention or detection of crime, it must show that disclosing this specific information would cause real harm. The exemption can protect details of specific security measures, but it should not prevent disclosure of general process improvements.