The Animal Health (Fixed Penalty Notices) (Scotland) Regulations 2026: Data Protection Impact Assessment
Data protection impact assessment (DPIA) considering the potential impacts of the implementation of the Animal Health Fixed Penalty Notice (Scotland) Regulations 2026
6. Risk Assessment
6.1 Risk to individual rights:
- right to be informed
- right of access
- right to rectification
- right to erasure
- right to restrict processing
- right to data portability
- right to object
- rights in relation to automated decision making and profiling
Solution or mitigation: The Regulations do not impose any requirements to collect new or additional personal data. The data will continue to be collected as necessary for the enforcement action determined by the enforcement authority.
Data controllers must ensure they apply suitable consideration to individual rights within privacy statements and give due consideration to these when conducting operational DPIA’s and setting up Data Sharing Agreements.
Likelihood: Low
Severity: Green
Result: No new impact
6.2 Privacy risks: purpose limitation
Solution or mitigation: The Regulations do not impose any requirements to collect new or additional data. The data will continue to be collected as necessary for the relevant enforcement action determined by the enforcement authority.
Likelihood: Low
Severity: Green
Result: No new impact
6.3 Privacy risks: transparency
Solution or mitigation: The Regulations do not impact on the way data subjects are informed about the purpose and lawful basis for the processing, and their rights.
Likelihood: Low
Severity: Green
Result: No new impact
6.4 Privacy risks: minimisation and necessity
Solution or mitigation: There will be no change to the way in which data is collected and processed by data controllers as a result of the Regulations.
Likelihood: Low
Severity: Green
Result: No new impact
6.5 Privacy risks: accuracy of personal data
Solution or mitigation: The Regulations provide that a person may be required to provide their name and address to an authorised officer for the purpose of issuing a FPN. There is a possibility that incorrect information could be provided to the authorised officer. However, failing to provide these details, or giving a false name or address is an offence under the Regulations.
Enforcement authorities have clear processes in place for verifying a persons identity and address. Data controllers will be responsible for ensuring the information they hold about person issued a FPN is accurate.
The Regulations require that a FPN be withdrawn if it is found to have been issued in error, for example if it has been issued to the wrong person.
Likelihood: Medium
Severity: Amber
Result: Reduced
6.6 Security risks: retention and security of data
Solution or mitigation: Data controllers are responsible for ensuring the necessary safeguards are in place to manage data securely and to ensure appropriate data sharing agreements are in place to comply with UK GDPR and the Data Protection Act 2018.
The Regulations require the retention of certain data by enforcement authorities for a period of 3 years from the date a FPN is issued.
Likelihood: Low
Severity: Green
Result: Reduced
6.7 Security risks: data transfer
Solution or mitigation: Risks surrounding loss of data and information transfers occur at an operational level and therefore are not subject to this risk assessment.
Likelihood: N/A
Severity: N/A
Result: N/A
6.8 Other risks: impact on children
Solution or mitigation: A Children’s Rights and Wellbeing Impact Assessment (CRWIA) has been conducted and has been published alongside the Regulations and the impact on children’s rights was assessed to be neutral. A section will be incorporated within enforcement guidance which advises enforcement authorities to consider alternative enforcement approaches in the first instance for individuals aged 16 and 17, and advising that FPNs should not be issued to under 16s.
Likelihood: Low
Severity: Green
Result: Mitigated