Social Security Scotland privacy measures and personal data breaches: FOI release

Information request and response under the Freedom of Information (Scotland) Act 2002

FOI Reference: FOI/202500456060
Date received: 6 March 2025
Date responded: 1 April 2025

Information requested

Request for information 1: Confirmation of the standard privacy measures which you implement in fraud investigations in order to prevent privacy infringements taking place as of February 2025.

Request for information 2: Confirmation of if there have been cases in which privacy infringements have occurred due to a fraud investigation, as of February 2025.

Request for information 3: Confirmation on the number of cases in which privacy infringements have occurred due to a fraud investigation, as of February 2025.

Response

We have interpreted the term “privacy infringement” to mean personal data breaches arising from noncompliance with UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Request for information 1:

All of the information you have requested is available from the below links. Under section 25(1) of FOISA, we do not have to give you information which is already reasonably accessible to you. If, however, you do not have internet access to obtain this information from the website(s) listed, then please contact me again and I will send you a paper copy.

Fraud investigations are carried out in line with the Social Security Scotland - Code of Practice for Investigations, The Social Security Assistance (Investigation of Offences) (Scotland) Regulations 2020 and the Social Security Scotland - Counter Fraud Strategy.

Data protection is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

For information on how we process our clients’ personal data, please see the following privacy information: Privacy notice and data protection - Social Security Scotland - mygov.scot

Request for information 2 and 3:

We hold record of one case where a personal data breach has arisen during the course of a fraud investigation. To be helpful, we can advise that this was risk assessed as a non-reportable personal data breach.

About FOI

Social Security Scotland is committed to publishing all information released in response to Freedom of Information requests. The Scottish Government also publishes responses to requests. You can view the responses at http://www.gov.scot/foi-responses.



Sign up to our newsletter

If you are an organisation or individual who works with people who may need information or support on any of our benefits, sign up to our stakeholder newsletter.

We'll never send you content you haven’t asked for and you can opt out at any time.

Please enter a valid email address

Read our privacy policy