ScotAccount hosting infrastructure and jurisdictional risk assessment: FOI release
- Published
- 21 July 2026
- Directorate
- Digital Directorate
- Topic
- Public sector
- FOI reference
- FOI/202600516387
- Date received
- 11 May 2026
- Date responded
- 8 June 2026
Information request and response under the Freedom of Information (Scotland) Act 2002.
Information requested
1. The cloud infrastructure provider(s) and data centre location(s) used to host the ScotAccount service (manage.scotaccount.service.gov.scot), including whether any component of the service runs on infrastructure owned or operated by a company subject to United States jurisdiction.
2. Whether a Data Protection Impact Assessment (DPIA) under Article 35 of the UK GDPR has been conducted for ScotAccount that specifically identifies and assesses the risk of extraterritorial data access under the US CLOUD Act 2018 or the UK-US Data Access Agreement. If so, a copy of that assessment.
3. The current number of registered ScotAccount users, and whether the service stores or processes any data classified as special category data under Article 9 of the UK GDPR.
4. Whether the Scottish Government has assessed the operational continuity risk to ScotAccount in the event that a hosting provider is subject to international sanctions, ownership change, or service withdrawal, and if so, a copy of or summary of that assessment.
5. Whether any exit plan or migration strategy exists for ScotAccount's hosting infrastructure, and if so, a summary of that plan including estimated timeline and cost.
Response
1. The cloud infrastructure provider(s) and data centre location(s) used to host the ScotAccount service (manage.scotaccount.service.gov.scot), including whether any component of the service runs on infrastructure owned or operated by a company subject to United States jurisdiction.
The cloud infrastructure provider is Amazon Web Services (AWS), UK regions only. The data for ScotAccount is processed and stored within the UK. Amazon Web Services (AWS) is subject to United States jurisdiction.
2. Whether a Data Protection Impact Assessment (DPIA) under Article 35 of the UK GDPR has been conducted for ScotAccount that specifically identifies and assesses the risk of extraterritorial data access under the US CLOUD Act 2018 or the UK-US Data Access Agreement. If so, a copy of that assessment.
Data Protection Impact Assessments (DPIA) are not intended to be a comprehensive assessment of international legal regimes that could theoretically apply to cloud suppliers. They are assessments against UK GDPR and therefore the ScotAccount DPIA does not specifically identify and assesses the risk of extraterritorial data access under the US CLOUD Act 2018 or the UK-US Data Access Agreement.
3. The current number of registered ScotAccount users, and whether the service stores or processes any data classified as special category data under Article 9 of the UK GDPR.
At 1 June 2026 ScotAccount had just over 768,000 registered accounts.
ScotAccount processes biometric data derived from official documentation and a selfie image of the user; this constitutes special category data under Article 9 of the UK GDPR. Biometric images are processed solely to complete an identity verification check and are fully deleted once the check is completed. They are not retained, stored or processed further within ScotAccount for any other purpose.
4. Whether the Scottish Government has assessed the operational continuity risk to ScotAccount in the event that a hosting provider is subject to international sanctions, ownership change, or service withdrawal, and if so, a copy of or summary of that assessment.
The following is a summary of our position. No operational continuity risks specific to ScotAccount have been identified that are materially different from those managed for other digital services using public cloud infrastructure. We do not hold a separate, ScotAccount specific document assessing these risks in isolation.
5. Whether any exit plan or migration strategy exists for ScotAccount's hosting infrastructure, and if so, a summary of that plan including estimated timeline and cost.
ScotAccount, through the Scottish Government, applies standard exit and portability considerations through its procurement and management approach of all suppliers. While high-level exit considerations exists as part of general governance, there is no ScotAccount specific plan that includes defined timelines or cost estimates.
About FOI
The Scottish Government is committed to publishing all information released in response to Freedom of Information requests. View all FOI responses at https://www.gov.scot/foi-responses.
Contact
Please quote the FOI reference
Central Correspondence Unit
Email: contactus@gov.scot
Phone: 0300 244 4000
The Scottish Government
St Andrew's House
Regent Road
Edinburgh
EH1 3DG