Some of the language used in privacy notices can be specialised. The Information Commissioner's website provides .
The purposes of processing personal data which is subject to a data breach is to enable the SPCB to report any data breach to the Office of the UK Information Commissioner and to communicate, if appropriate, with the data subjects involved.
Normal category data, such as names, addresses and telephone numbers.
Special Category data, as defined by the UK General Data Protection Regulation (UK GDPR).
Special category personal data includes information revealing an individual’s:
Depending on the nature of the data breach, the source of the data can be internal and relate to employees of the Scottish Parliament Corporate Body (SPCB) or it could be provided directly or indirectly to us by an external party.
Data protection law states that we must have a legal basis for handling your personal data.
The legal basis of processing is that it is a legal requirement for data controllers to report on any data breach within 72 hours of first becoming aware of a data breach. The processing is therefore necessary to comply with a statutory obligation to which the SPCB is subject in accordance with Article 6(1)(c) of the UK GDPR. The processing of special category data is necessary for reasons of substantial public interest in accordance with Article 9(2)(g) UK GDPR. Being able to investigate data breaches and review and respond to the breach to its full extent is in the substantial public interest.
The consequences of not processing the personal data in the event of a data breach would mean that the requirement to inform the ICO and affected data subjects could not be undertaken.
The data may be shared with the Information Commissioner’s Office.
Any normal or special categories of personal data involved in a data breach will be securely deleted immediately after reporting to the ICO or to data subjects – i.e. within 72 hours of an incident taking place unless the data needs to be held for different purposes.
Data protection legislation sets out the rights which individuals have in relation to personal data held about them by data controllers. Applicable rights are listed below. You can exercise your data subject rights in particular circumstances depending on the purpose for which the data controller is processing the data and the legal basis upon which the processing takes place.
The following rights may apply:
You have the right to request a copy of the personal information about you that we hold.
Further information on how to make a data protection 'subject access request'.
You have the right to ask us to correct the personal data we hold about you. We want to make sure that your personal information is accurate, complete and up to date and you may ask us to correct any personal information about you that you believe does not meet these standards.
You have the right at any time to require us to stop using your personal information for direct marketing purposes. In addition, where we use your personal information to perform tasks carried out in the public interest then, if you ask us to, we will stop using that personal information unless there are overriding legitimate grounds to continue.
You have the right to ask us to delete personal information about you where:
In some cases, you may ask us to restrict how we use your personal information. This right might apply, for example, where we are checking the accuracy of personal information about you that we hold or assessing the validity of any objection you have made to our use of your information. The right might also apply where there is no longer a basis for using your personal information, but you don't want us to delete the data. Where this right is validly exercised, we may only use the relevant personal information with your consent, for legal claims or where there are other public interest grounds to do so.
Where we use your personal information with your consent, you may withdraw that consent at any time and we will stop using your personal information for the purposes for which consent was given.
Please contact us in any of the ways set out below if you wish to exercise any of these rights.
We keep this privacy statement under regular review and will place any updates on this website. Paper copies of the privacy statement may also be obtained using the contact information below.
This privacy statement was last updated on 3 March 2021.
If you have any further questions about the way in which we process personal data, or about how to exercise your rights, please contact the Head of Information Governance at:
The Scottish Parliament
Edinburgh
EH99 1SP
Telephone: 0131 348 6913
(Calls are welcome through the Text Relay service or in British Sign Language through contactSCOTLAND-BSL.)
Email: [email protected]
Please contact us if you require information in another language or format
We seek to resolve directly all complaints about how we handle personal information but you also have the right to lodge a complaint with the Information Commissioner's Office online at: .
Or by phone at: 0303 123 1113