Privacy Notice – Professional Standards Department – Lawful Business Monitoring
Date of completion of this notice – May 2026
Who we are
The Police Service of Scotland (“Police Scotland”) is a constabulary established under the Police and Fire Reform (Scotland) Act 2012. Police Scotland Headquarters is located at Tulliallan Castle, Kincardine, United Kingdom, FK10 4BE. Any enquiries can be made by contacting our Data Protection Officer by post at this address, or by email at: dataprotection@scotland.police.uk, and by telephone on 101.
About this notice
This notice is to advise you (you are also referred to as the data subject) of how your personal data (information) will be dealt with (processed) by Police Scotland and your rights in relation to the processing. This notice covers information processed for both crime and non-crime purposes.
The Chief Constable of Police Scotland is the controller of your personal information and decides the purposes for which your personal information will be processed. Police Scotland can be contacted by telephoning 101.
The tables below provide you with details of:
- Why we process your personal information
- What our lawful basis is for processing it
- The information provided by you
- The types of personal information we hold if not provided by you
- The source of the information if not provided by you
- The length of time we will keep your information
- Who we will share it with.
In addition to the details below, your information may also be used by Police Scotland for administrative purposes such as testing new information technology systems, training and audit purposes. Where this is the case, the processing will be in accordance with the UK GDPR and Data Protection Act 2018.
Lawful Business Monitoring
Lawful Business Monitoring (LBM) is an auditing tool used to assist in the protection of staff, information assets and data. It is intended to assist in the investigation of criminal and corrupt activity. The tool is to mitigate the threat of internal corruption and to safeguard the reputation of Police Scotland and the Scottish Police Authority (SPA). LBM monitoring is systematic and carried out through automated software across devices and systems and records all computer-based actions, including screenshots and keystroke activity. However, the retained data is not routinely viewed, searched or interrogated. The data remains inaccessible unless and until the defined authorisation threshold is met and access is approved as necessary and proportionate for a specified purpose.
LBM is used on a reactive basis and, for defined high-risk indicators, on a proactive basis.
Reactive use includes historical audits to view activity within the remit of intelligence-led investigations. Proactive use is limited to identifying corruption-related behaviour, including inappropriate language and work avoidance tactics linked to defined corruption categories. It is not used for routine productivity measurement or day-to-day performance monitoring. Any proactive alert is only considered for review where pre-defined thresholds or patterns are met, and any subsequent access by Anti-Corruption Unit (ACU) staff must be separately justified, authorised, time-bounded and recorded.
Monitoring for inappropriate language is intended to identify indicators of corruption, abuse of position, discriminatory behaviour, sexual misconduct, misuse of police systems, or other conduct creating a serious risk to individuals, the organisation or public confidence. It is not designed to identify isolated undesirable language for performance action. Unless a genuine and proportionate risk is identified, no further action will be taken. Any case progressed beyond an initial alert must be justified, recorded and handled in accordance with ACU governance, authorisation requirements and data protection obligations.
LBM will proactively monitor for use of language which falls within the remit of corruption categories, allowing an assessment to be made as to the context around such language being used. The monitoring applied is strictly predicated by high risk, proportionate to the identified threat and designed to detect indicators of corruption. Corruption categories include Misuse of Force Systems and Sexual Misconduct, such as abuse of power for a sexual purpose, and racist and discriminatory behaviour.
LBM can also identify work avoidance tactics, such as Key Jamming. Key jamming, and indeed other work avoidance tactics, risk compromise as users are leaving computers unlocked and accessible in order to misrepresent being online.
LBM may be configured to identify activity falling within defined corruption-related categories, such as misuse of police systems, unauthorised disclosure of information, sexual misconduct, theft and fraud, and other high-risk behaviours. The monitoring applied is intended to be risk-based, necessary and proportionate to the identified threat. Less intrusive measures, such as reliance solely on application logs or targeted manual audit, may not provide the full content, context or cross-system visibility required for evidential reconstruction where serious indicators only emerge later. For that reason, access to retained LBM data is tightly controlled.
LBM can also identify indicators associated with deliberate misuse of Police Scotland ICT, including key jamming or similar automated activity. The purpose of reviewing such activity is not to measure productivity, but to protect the integrity of Police Scotland systems and information assets, including where behaviour may indicate dishonest misuse, attempts to create a false appearance of activity, or an increased risk of unauthorised access or disclosure because devices are left unlocked or otherwise accessible contrary to security requirements. Any review will only take place where objective indicators and repeat thresholds are met, and where authorised access is considered necessary and proportionate on a case-by-case basis.
Lawful Business Monitoring allows Police Scotland to monitor, without consent, and to keep records of communications:
- In order to establish the existence of facts
- In the interest of national security
- For the purposes of preventing or detecting criminal and corrupt activity
- For the purposes of investigating or detecting the unauthorised use of that or any other Police Scotland systems
- In order to secure, or as an inherent part of, the effective operation of the system.
Where authorised ACU staff access LBM data, information may in some circumstances be further processed where this is necessary and proportionate and where a separate lawful basis applies. If material indicates possible conduct, welfare or other non-crime concerns, any onward handling will be considered on a case-by-case basis under the relevant legal framework and governance process. LBM is not authorised for routine performance management. Any referral beyond the original criminality or corruption purpose must be justified, limited to the minimum necessary information, and recorded through the applicable authorisation and case-recording arrangements. This will only be done so when it is necessary and proportionate to do so. If personal data is further processed, it is done so because it reveals information that no employer could reasonably be expected to ignore. This includes behaviour that falls short of our standards of Professional Behaviour or Code of Conduct, and which is likely to impact public trust and confidence.
Police Scotland devices and ICT systems are provided for policing purposes and are subject to monitoring and audit in accordance with law, policy and this notice. Integrity Matters, Whistleblowing and Optima Health are excluded from LBM to protect confidentiality, and further systems may be excluded where appropriate. Even where technical collection is continuous, LBM records are not routinely viewed and remain inaccessible unless and until the defined authorisation threshold is met. This notice is intended to ensure that workers are informed about the nature, purpose and safeguards of the monitoring.
Further information regarding Lawful Business Monitoring can be found within the Lawful Business Monitoring Guidance.
What is personal data?
“Personal data” is information that can be used to identify someone. For example, names, addresses or dates of birth. This also includes alleged or actual offending information when processed for non-crime purposes.
There is also another type of personal data which is called “special category personal data”. This is information which relates to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation.
Purpose and Lawful Basis for Processing etc.
Why we process your personal information
To investigate complaints against the police
Our lawful basis under the UK General Data Protection Regulation (UK GDPR) for processing
A legal obligation – Article 6(1)(c)
Public Task - For the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (referred to as the public task) – Article 6(1)(e)
Substantial public interest – UK GDPR Article 9(2)(g)
Obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security– UK GDPR Article 9(2)(b)
Personal and/or special category data provided by the data subject when relevant
Name, gender, address, date of birth, phone numbers, email addresses, details of complaint
When required/provided: racial/ethnic origin, religious beliefs, sex life/sexual orientation, health information.
Types of personal data when not provided by the person to whom it relates
Officer(s) involved: name, rank, shoulder number, division
Officer(s)/Staff involved: when known/required/provided: racial/ethnic origin, religious beliefs, sex life/sexual orientation, health information.
Source of personal data when not provided by the person to whom it relates
Person making complaint
Police systems
Length of time we keep your information
Record Retention Standard Operating Procedure (SOP) (Professional Standards – PST-001 to PST-003)
Organisations or individuals we may share your information with
Police Investigations and Review Commissioner (PIRC) for independent investigation of incidents
Scottish Police Authority (SPA) to audit the complaints handling procedures
Crown Office and Procurator Fiscal Service (COPFS) for independent investigation of criminal matters where required.
Why we process your personal information
To investigate allegations of corruption or criminality
Our lawful basis under the UK General Data Protection Regulation (UK GDPR) for processing
Investigating allegations of corruption/criminality or conduct), the purpose will vary between the following:
A legal obligation – Article 6(1)(c)
Public Task – For the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller – Article 6(1)(e)
Part 2 Data Protection Act 2018 (General Processing)
Part 3 Data Protection Act 2018 (Law Enforcement Purposes)
Section 17(2)(b) of the Police and Fire (Reform) Scotland Act 2012
Section 20(1) of the Police and Fire (Reform) Scotland Act 2012
Section 32 of the Police and Fire (Reform) Scotland Act 2012
Section 36(A) Police and Fire (Reform) Scotland Act 2012
The Investigatory Powers Act 2016 (Section 46)
In the case of Lawful Business Monitoring usage:
The Investigatory Powers (Interception by Businesses etc for Monitoring and Record-keeping purposes) Regulations 2018
Personal and/or special category data provided by the data subject when relevant
Name, gender, address, date of birth, phone numbers, email addresses, details of complaint
When required/provided: racial/ethnic origin, religious beliefs, sex life/sexual orientation, health information
Types of personal data when not provided by the person to whom it relates
Relating to person(s) against whom concerns expressed: name, gender, department, phone number, email address, details of alleged concerns, rank, shoulder number, PSI and when required/provided: date of birth.
Source of personal data when not provided by the person to whom it relates
Police Systems
Audit Trail Appliance (LBM)
Person making complaint
Length of time we keep your information
Record Retention SOP (Crime and Productions – CRP001-CRP006)
Organisations or individuals we may share your information with
See Privacy Notice – Law Enforcement for details.
Why we process your personal information
To investigate allegations of conduct disciplinary matters*
Our lawful basis under the UK General Data Protection Regulation (UK GDPR) for processing
*Data collated through existing criminality/corruption investigations where LBM has been authorised, may be repurposed when necessary and proportionate to do so, to investigate conduct/disciplinary matters*
A legal obligation – Article 6(1)(c)
Public Task – For the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller – Article 6(1)(e)
Substantial public interest – UK GDPR Article 9(2)(g)
Obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security– UK GDPR Article 9(2)(b)
Part 2 Data Protection Act 2018 (General Processing)
Part 3 Data Protection Act 2018 (Law Enforcement Purposes)
The Investigatory Powers Act 2016 (Section 46)
The Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping purposes) Regulations 2018
Police Service of Scotland (Conduct) Regulations 2013
Police Service of Scotland (Conduct) Regulations 2014
Personal and/or special category data provided by the data subject when relevant
Name, gender, address, date of birth, phone numbers, email addresses, details of complaint
When required/provided: racial/ethnic origin, religious beliefs, sex life/sexual orientation, health information
Categories of personal data when not provided by the person to whom it relates Source of personal data when not provided by the person to whom it relates
Officer(s)/Staff allegedly involved: name, gender, address, date of birth, phone number, email address, details of alleged misconduct
When required/provided: racial/ethnic origin, religious beliefs, sex life/sexual orientation, health information
Source of personal data when not provided by the person to whom it relates
Person making complaint
Police systems
Length of time we keep your information
Record Retention SOP (Professional Standards – PST-001 to PST-003)
Organisations or individuals we may share your information with
Police Investigations and Review Commissioner (PIRC) for independent investigation of incidents
Scottish Police Authority (SPA) to audit the complaints handling procedures
Crown Office and Procurator Fiscal Service (COPFS) for independent investigation of criminal matters where required.
Why we process your personal information
To proactively investigate police officers/police staff flagged to Anti-Corruption Unit (ACU) through both the risk matrix tool and corruption behavioural triggers. More information can be found here.
Our lawful basis under the UK General Data Protection Regulation (UK GDPR) for processing
*Data collated through existing criminality/corruption investigations where LBM has been authorised, may be repurposed when necessary and proportionate to do so, to investigate conduct/disciplinary matters*
Substantial public interest – UK GDPR Article 9(2)(g)
Obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security – UK GDPR Article 9(2)(b)
Section 17(2)(b) of the Police and Fire (Reform) Scotland Act 2012
Section 20(1) of the Police and Fire (Reform) Scotland Act 2012
Section 32 of the Police and Fire (Reform) Scotland Act 2012
Section 36(A) Police and Fire (Reform) Scotland Act 2012
Part 2 Data Protection Act 2018 (General Processing)
Part 3 Data Protection Act 2018 (Law Enforcement Purposes)
The Investigatory Powers Act 2016 (Section 46)
The Investigatory Powers (Interception by Businesses etc for Monitoring and Record-keeping purposes) Regulations 2018
Police Service of Scotland (Conduct) Regulations 2013
Police Service of Scotland (Conduct) Regulations 2014
Personal and/or special category data provided by the data subject when relevant
PSI, Sex, Full Name, Previous Names, Date of Birth, Police Scotland Start Date, Description, Posting Rank, Post Title, Post Number, Division, Subdivision, Section, Station, Department, Master Department, Work Telephone, Work Email
Categories of personal data when not provided by the person to whom it relates
Officer(s)/Staff involved: name, rank, shoulder number, division
Relating to person(s) against whom concerns expressed: name, gender, department, phone number, email address, details of alleged concerns, rank, shoulder number, PSI and when required/provided: date of birth
Source of personal data when not provided by the person to whom it relates
Audit Trail Appliance (LBM)
Length of time we keep your information
Record Retention SOP (Professional Standards – PST-001 to PST-003)
Organisations or individuals we may share your information with
Police Investigations and Review Commissioner (PIRC) for independent investigation of incidents
Scottish Police Authority (SPA) to audit the complaints handling procedures
Crown Office and Procurator Fiscal Service (COPFS) for independent investigation of criminal matters where required.
Why we process your personal information
Wellbeing and safeguarding concerns
Our lawful basis under the UK General Data Protection Regulation (UK GDPR) for processing
Substantial public interest – GDPR Article 9(2)(g)
Health & Safety at Work etc. Act 1974 – S.2(1) – employer is to ensure the health, safety and welfare at work of all his employees
Health & Safety at Work etc. Act 1974 – S.3(1) - employer is to ensure the health, safety and welfare at work of persons not in his employment (contractors, subcontractors)
Obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security– GDPR Article 9(2)(b)
Part 2 Data Protection Act 2018 (General Processing)
Part 3 Data Protection Act 2018 (Law Enforcement Purposes)
The Investigatory Powers Act 2016 (Section 46)
The Investigatory Powers (Interception by Businesses etc for Monitoring and Record-keeping purposes) Regulations 2018
Common law duty of care (Donoghue V Stevenson) – reasonable care to avoid foreseeable injury to employees
Right to life – Article 2 ECHR – If any identified thoughts of self-harm/suicide – Police Scotland have an actively positive duty to act and save life
Personal and/or special category data provided by the data subject when relevant
PSI, Sex, Full Name, Previous Names, Date of Birth, Police Scotland Start Date, Description, Posting Rank, Post Title, Post Number, Division, Subdivision, Section, Station, Department, Master Department, Work Telephone, Work Email
Categories of personal data when not provided by the person to whom it relates
Officer(s)/staff allegedly involved: name, gender, address, date of birth, phone number, email address, details of alleged misconduct
When required/provided: racial/ethnic origin, religious beliefs, sex life/sexual orientation, health information
Source of personal data when not provided by the person to whom it relates
Audit Trail Appliance (LBM)
Length of time we keep your information
Record Retention SOP (Professional Standards – PST-001 to PST-003)
Organisations or individuals we may share your information with
Optima Health
National Health Service (NHS)
Scottish Ambulance Service (SAS)
If required, details could be supplied to emergency services/Optima/third sector agencies with consent of the data subject, or if extreme circumstances to safeguard someone’s immediate health – for example SAS/NHS, under usual information sharing channels in existence for statutory purposes.
Why we process your personal information
Specialist investigations including reports of conduct or integrity concerns (whistleblowing)
Our lawful basis under the UK General Data Protection Regulation (UK GDPR) for processing
A legal obligation – Article 6(1)(c)
Personal and/or special category data provided by the data subject when relevant
Relating to person making complaint – name, department, phone number, email address, details of alleged concerns
And when required/provided date of birth, address, ID number
Categories of personal data when not provided by the person to whom it relates
Relating to person(s)against whom concerns expressed: name, department, phone number, email address, details of alleged concerns
And when required/provided: date of birth, address, ID number
Source of personal data when not provided by the person to whom it relates
Person making complaint
Police systems
Length of time we keep your information
Record Retention SOP (Professional Standards – PST-001 to PST-003)
Organisations or individuals we may share your information with
Police Investigations and Review Commissioner (PIRC) for independent investigation of incidents
Scottish Police Authority (SPA) to audit the complaints handling procedures
Crown Office and Procurator Fiscal Service (COPFS) for independent investigation of criminal matters where required
Why we process your personal information
*To provide the Divisional Commander/Head of Department with information to aid their decision making in relation to applications for business interests/secondary employment.
Our lawful basis under the UK General Data Protection Regulation (UK GDPR) for processing
A legal obligation – Article 6(1)(c)
Personal and/or special category data provided by the data subject when relevant
Name, rank, PSI, current posting, contact details. Full details of proposed business interest/secondary employment
Categories of personal data when not provided by the person to whom it relates
Personal and/or special category data held on police systems
Source of personal data when not provided by the person to whom it relates
Police systems
Length of time we keep your information
Record Retention SOP (Professional Standards – PST-004 and PST-005)
Organisations or individuals we may share your information with
None
Why we process your personal information
To determine whether Police Scotland needs to take any further action against officers who receive Fixed Penalty Notices (FPN)
Our lawful basis under the UK General Data Protection Regulation (UK GDPR) for processing
A legal obligation – Article 6(1)(c)
Personal and/or special category data provided by the data subject when relevant
Name, rank, PSI, division, details of the reason the FPN was accepted
Categories of personal data when not provided by the person to whom it relates
Personal and/or special category data held on police systems
Source of personal data when not provided by the person to whom it relates
Police systems
Length of time we keep your information
Record Retention SOP (Professional Standards – PST-006)
Organisations or individuals we may share your information with
None
General processing within Lawful Business Monitoring will be undertaken in accordance with the conditions set out at Article 9(g) of the UK GDPR, substantial public interest on the basis of law, where one of the following conditions from Part 2, Schedule 1 of the Data Protection Act 2018 (DPA 2018) is met:
- Prevention/detection of unlawful acts
- Protecting the public against dishonesty
- Regulatory activity
- Safeguarding of children and adults at risk
Or
- Article 9(2)(b) obligations of an employer…field of employment
*Failure to declare a Business Interest or Secondary Employment (BISE) may be dealt with under The Police Service of Scotland (Conduct) Regulations 2013 or The Police Service of Scotland (Conduct) Regulations 2014 for Police Officers and the Disciplinary (Authority/Police Staff) SOP for SPA/Police.
Your Rights
You have certain rights in relation to how we process your personal information. These are listed below.
1. Right of access – you can make what is called a subject access request to us.
You are entitled to, amongst other things, a copy of the information we hold on you, although there are exceptions to this. For further information and details on how to make a subject access request please visit the Police Scotland website at www.scotland.police.uk/access-to-information/data-protection/subject-access-requests.
2. Right to rectification (correction)
We must correct without delay, any personal information we hold on you which is not accurate. If you think anything is wrong, you should contact us by post or e mail, where possible by completing the form on our website at https://www.scotland.police.uk/access-to-information/data-protection/your-rights telling us what you think is wrong and why. There are exceptions to when we have to correct the information, and you will be advised if we have to apply them. If it is not possible to establish the accuracy of the personal information, we will restrict how we process it, for example restrict who can see your information, or who we disclose it to.
3. Right to erasure or restriction of processing
You have a right to request that we delete your personal information, but this will only be done when we are not legally required to keep it. On occasion it may be more appropriate to restrict how we process it, for example restrict who can see your information, or who we disclose it to. You can find more information on our website at https://www.scotland.police.uk/access-to-information/data-protection/your-rights
For more information about any of these rights, go to www.scotland.police.uk/access-to-information/data-protection/your-rights or email information.assurance@scotland.police.uk.
If we refuse to carry out your requests in full under paragraphs 1 to 5 above, you have the right to ask the Information Commissioner to check whether our decision is correct.
If you are unhappy in any way with how we have dealt with your information, you have the right to complain to the Information Commissioner.
The Information Commissioner can be contacted at:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Tel: 0303 123 1113 (local rate)
Date of next review of this document – January 2027.