Publication - FOI/EIR release

Disclosure Scotland - data retention policy questions: FOI release

Published: 4 Dec 2020
Part of:
Public sector

Information request and response under the Freedom of Information (Scotland) Act 2002.

Published:
4 Dec 2020
Disclosure Scotland - data retention policy questions: FOI release
FOI reference: FOI/202000102872
Date received: 25 Oct 2020
Date responded: 18 Nov 2020
Information requested

You asked for:

  1. Your data retention policy in relation to emails submitted in relation to applications
  2. Your data retention policy in relation to emails that contain personal identifiable information, such as name , date of birth , place of birth etc
  3. If you are fully compliant with your policy
  4. The last date prior to this email you audited your compliance
Response

I enclose a copy of all of the information you requested.

The answer to your questions are:

1. Information on how long Disclosure Scotland retains personal information can be found on our Privacy Statement. I have provided the relevant portion below:

"Retaining your personal information

We retain personal information in line with the Data Protection Act 2018. This involves only retaining the personal information we need for business, regulatory or legal reasons. Once personal information is no longer needed, it is securely destroyed.

DS have a requirement to retain records of applications and applicants for several reasons, the key ones being:

  • the ongoing monitoring of PVG Scheme members
  • the validation of identity of applicants and information in relation to previous applications
  • a separate requirement to maintain personal information for the PVG Scheme barred lists"

The data retention policy which applies to e-mails in Outlook containing personal information is three months, unless the e-mail is required for business or other reasons. This includes e-mails submitted in relation to applications. A one month data retention period applies to specific Outlook inboxes with data restrictions. A five year data retention period applies to e-mails stored on the Scottish Government filing system, eRDM, for business or legal reasons.

2. I refer to the answer above.

3. Disclosure Scotland was compliant at the last e-mail audit conducted on 10th August 2020. Further audits will be conducted procedurally in order to ensure compliance in all inboxes.

4. The last audit was conducted on 10th August 2020.

About FOI
The Scottish Government is committed to publishing all information released in response to Freedom of Information requests. View all FOI responses at http://www.gov.scot/foi-responses.

Contact

Please quote the FOI reference
Central Enquiry Unit
Email: ceu@gov.scot
Phone: 0300 244 4000

The Scottish Government
St Andrews House
Regent Road
Edinburgh
EH1 3DG