Privacy Notice - Complaint Handling Review applicants
Using Your Personal Data – Complaint Handling Reviews
General Processing under Part 2 Data Protection Act 2018 and UK GDPR
Who we are
The Police Investigations and Review Commissioner (PIRC) is appointed by Scottish Ministers under the Police, Public Order and Criminal Justice (Scotland) Act 2006 (2006 Act) as amended (the 2006 Act). The role of the PIRC is to provide independent oversight of policing bodies in Scotland; investigating incidents involving the police and reviewing the way the police handle complaints from the public.
About this notice
This notice explains how your personal data (also referred to as ‘personal information’) will be dealt with (processed) by the PIRC and your rights in relation to that processing. The PIRC is known as the ‘controller’ of the personal data we collect.
Data protection law in the United Kingdom (UK) is governed by the Data Protection Act 2018 (DPA), the UK General Data Protection Regulation (UK GDPR) and the Law Enforcement Directive (LED). Part 2 of the DPA covers general processing under the UK GDPR. Part 3 of the DPA covers law enforcement processing under the LED. For PIRC complaint handling reviews processing is under Part 2.
This notice covers information processed for complaint handling reviews under Part 2 of the DPA and provides you details of:
- what is personal data
- why we need your personal data
- what is our lawful basis is for processing
- the types of personal data we hold
- what we do with your personal data
- who we will share your personal data with
- the length of time we will keep your personal data.
What is personal data
Personal data is information that can identify you, for example, name, address, date of birth.
Special category personal data
There is an additional category of personal data called ‘special category personal data’. This is information which relates to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data (where used for identification purposes), health data, sex life or sexual orientation.
Why we need your personal data
One of our functions is to review the manner in which the police have handled complaints made about them. These reviews are called ‘Complaint handling Reviews’ (CHRs). We need information, including your personal data, to allow us to assess and carry out your CHR. Our functions are explained in the Police, Public Order and Criminal Justice (Scotland) Act 2006, as amended.
We only ask you for the information that we need to carry out our CHR function and / or to improve the service we provide.
What is our lawful basis for processing
PIRC must have a legal basis for processing your personal and special category data. The legal bases, that may be relied upon are listed below:
- Article 6 (1)(c) necessary to comply with a legal obligation. PIRC would require to comply with Court Orders to provide your personal data to others.
- Article 6 (1)(d) necessary to protect the vital interests of yourself or another, in extreme circumstances PIRC may have to release personal data to protect your interests or the interests of others, for example, medical emergencies.
- Article 6 (1)(e) necessary for the performance of a task carried in the public interest or in the exercise of official authority. Part of PIRC’s function is to maintain public confidence in the police complaints system and provide effective oversight: this activity in a public interest including your interest and the interest of others.
- Article 6(1)(f) ‘legitimate interests’ is generally the interest of PIRC for example, undertaking surveys to improve the service provided to the public.
Where special category data such as health information is processed a legal basis for this will be within Article 9 of UK GDPR or Schedule 1 of the Data Protection Act 2018 (check this in special category policy). Examples included:
- Article 9(1)(a) processing “special categories” of data where you have given explicit consent.
- Article 9(1)(g) processing “special categories” of data where necessary for reasons of substantial public interest.
- Article 9(1)(f) processing “special categories” of data in connection with legal claims.
The types of personal data we hold
We need you to provide information such as your name, address, and contact details. We also need to ask you for information about the complaint you made to the relevant policing body. We will then ask the policing body for the information they hold relating to your complaint.
We may also hold sensitive personal data and/or biometric data of the type described above.
In order to carry out our CHR functions, we process information relating to a variety of individuals including:
- Victims and / or family members
people suspected of committing, or who have committed, an offence
- police officers and police staff
- consultants and other professional experts
- members of the public who have complained to police and are dissatisfied with the response.
What we do with it
We use your personal data to conduct our review function and report out findings to you and the relevant policing body. We will hold your personal information securely whether in paper or electronic format.
Who we will share your personal data with
We may share your information with other public bodies. We will only do this when it is necessary to carry out our complaint handling review functions, or to allow the public body concerned to carry out its own functions.
We may disclose your personal information in exceptional circumstances. For example, where we are required by law to do so or where the health and safety of you or others is at risk.
We may use your information for statistical, research, training and development purposes. In these circumstances the processing is necessary for us to pursue our legitimate interests1. Information will not be used for these purposes where this would interfere with your fundamental rights. Processing these circumstances will be undertaken in terms of Part 2 of the DPA.
We may also ask you to complete an equality monitoring questionnaire. This is an optional questionnaire used for statistical purposes and to inform and allow us to meet our obligations in terms of the Public Sector Equality Duty and will not have an impact on the review process in any way. Processing these circumstances will also be undertaken in terms of Part 2 of the DPA.
A summary of your complaint handling review may be published on our website. It may also be featured in a press release. These documents are anonymised and will not contain your name. They will not contain information that could identify you or any other person involved in the complaint being reviewed. When we have finished your review, we will let you know if a summary will be published. If you do not wish a summary of your complaint to be published, please let us know and we will consider this request.
How long we keep it
We will not hold your information for longer than is necessary. The timescales involved are explained in our Records Management Policy.
What are your rights?
Right of access
You have the right to confirmation as to whether or not we are processing your personal data and to be given information on how we use the data, what type of data we have, who we will share it or have shared it with, how long we will keep it for, and what your rights are regarding your data. You can also request to see the personal information we hold about you.
Right to rectification
If you believe that information we hold on you is incorrect, you can request that it is corrected or deleted.
Right to erasure
You can request that we delete the personal information we hold on you if, we no longer require it, you object to us processing it and we have no overriding legitimate grounds for us to retain it, your data has been unlawfully processed, it needs to be erased for legal reasons.
Right to restrict processing
You can request that we temporarily restrict the processing of your personal data if, we are checking the accuracy of your data, our processing is unlawful and you do not want your data erased, we no longer need your data but need to retain it for legal reasons, or you object to us processing it and confirmation is awaited regarding our overriding legitimate grounds to retain it.
Right to withdraw consent
Where we process your personal information for a particular purpose on the basis of your consent you have the right to withdraw that consent. You can inform us of your wish to withdraw consent by contacting us at the address below. The relevant personal data will be destroyed on receipt of the withdrawal of consent unless there is an overriding purpose for continued processing.
Right to data portability
This only applies where the legal basis for us to collect your personal data is consent and where the processing is by automated means, neither of which are relevant to how we process your data. This right is therefore not applicable.
Right to object
If the lawful basis for processing your personal data is that processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, or it is necessary for the purposes of legitimate interests which we pursue.
Rights in relation to automated decision making and profiling
Where applicable, you have the right to object to your data being subject to automatic decision making and profiling, however the PIRC will not use your data in this manner.
It is important to note that these rights detailed above are not absolute. In some cases, exemptions can apply and we may not be able to provide you with all of the information you are looking for or comply with your request to exercise your rights.
If you have a request regarding your rights or if you want to complain about how we have handled your personal data, you can contact us at:
Phone: 01698 542 900
Post: Police Investigations and Review Commissioner
Hamilton Business Park
If you are not satisfied with our response, or believe that we are processing your data not in accordance with the law, you can complain to the Information Commissioner’s Office at:
Post: Wycliffe House
Phone: 01625 54 57 45
Any complaints about the use of biometric data, and an organisation’s non compliance with the Code of Practice should be made to the Scottish Biometrics Commissioner. They can be contacted as follows:
Scottish Biometrics Commissioner
99 McDonald Road
Tel: 0131 202 1043
Date of completion of this notice – November 2023
1. Article 6(1)(f)