Data controller name: Scottish Ministers
St Andrew's House
This privacy notice details how the Scottish Government applies data protection principles when processing personal data in the course of providing information to the Scottish coronavirus (COVID-19) Inquiry (“the Inquiry”).
If you used to work for the Scottish Government, or if you have shared your personal data with the Scottish Government regarding an issue associated with the COVID-19 pandemic or in relation to the issue of pandemic planning before then, this notice will be relevant to you.
The Inquiry may ask Scottish Government to release to it any of your personal data that is relevant to the Inquiry’s investigations. The full Terms of Reference are available for reference on the Scottish Government website.
This notice sets out your privacy rights and how we gather, use and share personal data about you, when providing information to the Inquiry, in accordance with current data protection legislation.
It is important that you read this notice, so that you are aware of how and why we are using personal data.
This privacy notice will be regularly reviewed and may be subject to revision. Any significant changes on how we process and share your personal data will be clearly indicated on any subsequent versions. This is the first version of the privacy notice (03 May 2022).
The Scottish Government is providing information to the Inquiry, which has a remit to investigate the strategic elements of handling of the COVID-19 response in Scotland. Over the lifespan of the Inquiry, the Scottish Government will gather information held which has been sought by the Inquiry; review and prepare that information for secure sharing with the Inquiry and then implement that sharing.
The lawful basis for sharing data with the Inquiry is:
Article 6(1)c of the UK GDPR:
‘‘processing is necessary for compliance with a legal obligation to which the Ministers are subject’’.
The lawful basis for gathering, reviewing and collating data in preparation to respond to the Inquiry is:
Article 6(1)e of the UK GDPR
“processing is necessary for the performance of a task carried out in the public interest”
Data collection and processing
We will only collect and transfer personal data held by the Scottish Government which we are required to provide to the Inquiry. In the course of our working relationship with you and the Inquiry, we may collect, store, and use the following categories of personal data:
- information contained in your email signature, such as: name, job title, telephone numbers, and email addresses
- consultants or contractors’ names and contact details
- information that details your involvement in the COVID-19 response as an employee of the Scottish Government
This data will be processed by means of collecting, storing, recording, retrieval, reviewing and sharing with the Inquiry.
Your data will be collected from the Scottish Government’s internal document management systems
Who we will share your data with
We will share your data with the Inquiry in order to comply with any section 21 Inquiries Act notices served by the Inquiry on the Scottish Government (as set out in the further information section below). There are clear processes in place which govern the protection of your personal data.
The records and information identified for sharing with the Inquiry are retained in accordance with the Scottish Government’s records management policy. Those records will be retained for as long as they are required to support Scottish Government in its legal obligations.
Where we are processing your personal data due to a legal obligation, you:
- have the right to obtain confirmation that your data is being processed, and access to your personal data
- are entitled to have personal data rectified if it is inaccurate or incomplete
Where we are processing your personal data as part of our public task you also have:
- a right to have personal data erased and to prevent processing, in specific circumstances
- the right to ‘block’ or suppress processing of personal data, in specific circumstances
- the right to object to the processing, in specific circumstances
These rights are not absolute, and where there are legal requirements for us to process personal data we may not be able to action an erasure request.
For more information on the rights you have over how your personal data is handled, please visit Your data matters | ICO
Please email email@example.com if you wish to raise a concern.
If you are dissatisfied with the way we handle your personal data, you can raise your concerns with our Data Protection Officer in the first instance. You can do this by e-mail to DataProtectionOfficer@gov.scot or write to:
Data Protection Officer
If you feel we have been unable, or unwilling to resolve your complaint, you have the right to lodge a complaint with the Regulator for data protection in the UK, the Information Commissioner's Office (ICO).
The Information Commissioner
Tel: 08456 30 60 60
Where the Inquiry serves a notice under section 21 of the Inquiries Act 2005 on the Scottish Ministers for the provision of relevant information, this creates a legal obligation on the Scottish Ministers to comply. Relevant information may include personal data. This legal obligation on the Scottish Government as the data controller permits the lawful processing of personal data under UK GDPR.
The Scottish Government must provide the relevant personal data to the Inquiry to comply with the section 21 notice. Failure to comply with a section 21 notice may constitute contempt of court by the Scottish Government.
In accordance with the Inquiries Act 2005, the Inquiry cannot make any determination as a matter of civil or criminal law but it will make findings about facts and recommendations. Its remit, set out in its terms of reference, is to review the strategic handling, including by the Scottish Government, of the COVID-19 pandemic response.
There is a problem
Thanks for your feedback