Scottish local authorities have recorded more than 10,000 data breaches over the last five years, The Ferret can reveal. Incidents included the unauthorised access of data by staff, stolen data, procedural failures, theft of hardware, personal data put on websites, and the disclosure of personal information to third parties. Police Scotland has been informed of data breaches at least 12 times and at least 47 people faced internal disciplinary sanctions. Freedom of information requests sent to Scotland’s 32 local authorities also found that thousands of staff across Scotland have yet to complete data protection training. While the vast majority of the 10,194 data breaches were for relatively minor issues such as emails being sent to the wrong recipient, concerns have been raised over measures in place to protect sensitive pieces of personal information. The Scottish Conservatives said it was “quite staggering” that so many breaches could have occurred in just a few years and that The Ferret’s findings will “deeply alarm” the public. The Scottish Lib-Dems described the breaches as a “serial problem”. Councils said the rising number of breaches is due to an increased awareness of the need to report data breaches internally. Local authorities are expected to collect, store, use, share and dispose of personal information, or data about individuals, in line with General Data Protection Regulation (GDPR) and the Data Protection Act (DPA). The Information Commissioner’s Office — an independent authority set up to uphold information rights in the public interest — has wide powers and can serve enforcement notices on data controllers and fine them heavily. Breaching the DPA can also, in certain circumstances, be a criminal offence. These figures must serve as an urgent wake-up call for ministers Miles Briggs MSP, Scottish Conservatives We asked councils to provide details of data breaches since 2017. Glasgow City Council (GCC) recorded 1,718 incidents — the highest in Scotland — but said none involved any “significant loss of data”. Eight employees faced disciplinary action with one staff member sacked. GCC said: “We would point out that the council has very well established and internally-publicised data breach reporting processes, and previous exercises have indicated that we report a significantly higher number of data breaches than other public sector bodies.” The City of Edinburgh Council recorded 1,103 breaches and said the majority were “breaches of confidentiality”. They included the loss or theft of hardware, the disclosure of personal data to a third party, personal data on a public website, the misuse of data, and passwords being accessed or shared. The council said it was “not aware of disciplinary action being taken against staff” and refused to say how many of its 18,000 staff had not completed GDPR training, stating it would be too costly to find out. People have the right to expect that all organisations handling personal data should do so safely and securely ICO spokesperson South Lanarkshire Council had 224 incidents with the ICO notified on four occasions. Police Scotland were informed of 12 breaches, the council said. Incidents included a laptop stolen from an employee’s car, a work phone stolen, bank details disclosed in error, and sensitive information being discussed in a public setting. Dumfries and Galloway Council had 231 breaches including “sensitive information” being disclosed 47 times. One case involved “no parental permission sought to discuss child”. Last year Scottish Borders Council apologised after a data breach. The council had been in the process of alerting 1,300 residents they were eligible for a payment due to their receipt of free school meals, but it sent three emails with all recipient email addresses visible to multiple individuals. In 2012 the ICO fined Midlothian Council £140,000 for disclosing sensitive personal data about children and their carers to the wrong people on five separate oc...