Select Page
Author: Adrian Ramdat (Director of Training & Consultancy)

April 2026

On 11 March 2026, the Information Commissioner's Office fined Police Scotland £66,000 for mishandling sensitive personal data belonging to a victim. The specifics matter: this wasn't a case of sloppy record-keeping or an accidental disclosure. The entire contents of a victim's mobile phone were extracted and then shared with a third party who had no legitimate reason to see any of it.

That sequence of events is worth considering for a few minutes.

This wasn't overreach. It was a failure of control.

What makes this case uncomfortable isn't the fine. It's the questions it raises about how these decisions get made in practice.

Everything was taken, not what was needed for the investigation, but the entirety of someone's digital life. Messages, images, personal data, the private details of people connected to the victim who had no involvement whatsoever. And at no point in that process does it appear anyone meaningfully asked: why are we taking all of this?

That question should have been the starting point. It wasn't.

The law isn't ambiguous. The application is.

The Police, Crime, Sentencing and Courts Act 2022 permits data extraction, but within clear boundaries: it must be necessary, proportionate, and tied to a specific purpose. In many cases, informed consent is also required and the person should be aware of how far the extraction will go. These aren't aspirational standards; they're the legal threshold.

UK GDPR reinforces the same expectations. Collect only what you need. Protect it properly. Limit its use. This framework applies well beyond policing. It equally applies to regulatory bodies, enforcement agencies, and any organisation with investigative powers is operating within the same boundaries.

None of this is new law. Which is precisely what makes a failure of this kind so difficult to excuse.

A chain of poor decisions, not a single error

Cases like this rarely come down to one mistake. What the ICO's investigation revealed was a sequence: no defined scope at the outset, no serious attempt to limit intrusion, no effective filtering of the data once obtained, inadequate safeguards either by design or in practice, and ultimately no control over what happened to that data once it left the hands of those who collected it.

Each failure made the next one worse. By the time the data was shared externally, the harm was already done and in hindsight, it was foreseeable from the beginning.

The uncomfortable truth about digital evidence

Mobile devices are frequently described as rich sources of evidence, and that's true. What tends to go unacknowledged is what else they contain, conversations, relationships, health information, financial detail, the private lives of people who have nothing to do with any investigation.

Accessing a device isn't a neutral act. It's a significant intrusion, and the fact that the data exists doesn't create an entitlement to it. Convenience has never been a legal justification, even when it quietly functions as one.

Professional judgement: safeguard or weakest link

Structured frameworks and professional standards exist to guide these decisions and the expectation they create is consistent: decisions must be justified, proportionate, and capable of being accounted for. But frameworks don't make judgement calls. People do.

When those calls are rushed, poorly documented, or simply not questioned by anyone in the chain, the framework becomes decoration. That's when the gap between policy and practice opens up, and that gap is where harm happens.

The real consequence: loss of trust

A victim sought help. In doing so, they handed over access to some of the most personal information that exists about them. That information was then exposed to someone with no right to see it.

The £66,000 fine will be reported in the media and it will be paid but the damage to that person's trust in the system that was supposed to protect them is harder to quantify and harder to repair. And it matters beyond the individual case, because investigative powers depend on public cooperation. That cooperation depends on trust. When trust erodes, the practical capacity to investigate effectively erodes with it.

Closing the gap between power and practice

No organisation sets out to get this wrong. But the ICO doesn't assess intentions, it assesses decisions.

The question worth asking is whether, if your organisation faced the same level of scrutiny, your decisions would hold up. Not in principle, but in practice, in the documentation, the justifications, the controls, and the oversight.

We deliver focused, bitesize training on the lawful extraction of data from digital devices, designed to challenge assumptions and strengthen decision-making in real-world scenarios. Alongside this, our Data Protection specialist works with organisations to ensure that obligations are understood, policies & processes are robust, and practice stands up to scrutiny.

Because this isn’t about regulatory fines. It’s about whether your decisions, and your organisation, can withstand being examined when it matters most.

Contact us at info@thesignaturebrand.co.uk to find out how we can help you get it right.