Some of the language used in privacy notices can be specialised. The Information Commissioner's website provides a useful introduction to key terms and concepts.
We process and store any personal data for the purpose(s) of delivering and maintaining Scottish Parliamentary Corporate Body (SPCB) contracts and in order to comply with public procurement regulations in Scotland.
Normal category data, including:
Personal data can be provided to us via a number of sources including
Personal data is provided to us directly from an economic operator or a person who has powers of representation, decision or control in relation to an economic operator for the purpose of taking part in a procurement procedure.
Personal data is provided to us via a third party (e.g. credit check via access to an online portal or Police Scotland’s SOCG / Police Check).
Data protection law states that we must have a legal basis for handling your personal data.
The processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) UK GDPR).
Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) UK GDPR is necessary to ascertain whether an organisation, or an individual representing an organisation, has been convicted of any criminal offences. In terms of regulation 8 of the Procurement (Scotland) Regulations 2016 a contracting authority must exclude an economic operator from participation in a procurement procedure where the contracting authority has established or is otherwise aware that the economic operator or a person who has powers of representation, decision or control in relation to an economic operator has been convicted of any of the offences listed in sub paragraphs (a) – (k) of the regulation. The SPCB, as the contracting authority, is therefore required to process information relating to certain criminal convictions under regulation 8 of the Procurement (Scotland) Regulations 2016. The processing is necessary to comply with a statutory obligation to which the SPCB is subject (Article 6(1)(c) UK GDPR).
The legal basis for sharing personal data as part of the procurement process is that it is necessary for the purposes of a legitimate interest of the SPCB (Article 6(1)(f) UK GDPR). The legitimate interest is to receive professional specialist advice in order to achieve best value for money in the procurement process.
The legal basis for sharing information relating to certain criminal convictions is to ensure that the SPCB complies with the Procurement (Scotland) Regulations 2016. The sharing is insofar necessary to comply with a statutory obligation to which the SPCB is subject (Article 6(1)(c) UK GDPR).
Finally, the legal basis for sharing personal data with other public sector bodies involved in the procurement process as referred to below is that sharing is necessary for the performance of a contract (Art 6(1)(b) UK GDPR).
Not processing this information would make it impossible for the SPCB to conclude and manage contracts and compromise the SPCB’s full compliance with public procurement regulations in Scotland.
The personal data is shared with other public sector bodies involved in the procurement process where necessary. For example:
The personal data is shared with third party advisers involved in the procurement process where necessary. For example:
Supplier names and contract details are published on the Scottish Parliament website for all SPCB contracts with a value above £5,000 as part of our Contracts Register. Regulated contracts (contracts with a value above £50,000) are also published on the Public Contracts Scotland website. This is in order for the SPCB to meet the obligations of Section 35 of the Procurement Reform (Scotland) Act 2014.
The personal data is shared with Police Scotland to facilitate a SOCG / Police Check, where necessary.
Criminal offence data received from Police Scotland is shared internally with other departments within the Scottish Parliament, where necessary.
The personal data is retained for 5 years after contract expiry in accordance with the Scottish Parliament records management policy.
In line with the principles underlying the National Guidance for Child Protection in Scotland (2014), published by the Scottish Government, our staff may report a concern to the relevant authorities if they come across an issue during their work which causes them to think that a child may be at risk of abuse or harm.
Data protection legislation sets out the rights which individuals have in relation to personal data held about them by data controllers. Applicable rights are listed below. You can exercise your data subject rights in particular circumstances depending on the purpose for which the data controller is processing the data and the legal basis upon which the processing takes place.
The following rights may apply:
You have the right to request a copy of the personal information about you that we hold.
Further information on how to make a data protection 'subject access request'.
You have the right to ask us to correct the personal data we hold about you. We want to make sure that your personal information is accurate, complete and up to date and you may ask us to correct any personal information about you that you believe does not meet these standards.
You have the right at any time to require us to stop using your personal information for direct marketing purposes. In addition, where we use your personal information to perform tasks carried out in the public interest then, if you ask us to, we will stop using that personal information unless there are overriding legitimate grounds to continue.
You have the right to ask us to delete personal information about you where:
In some cases, you may ask us to restrict how we use your personal information. This right might apply, for example, where we are checking the accuracy of personal information about you that we hold or assessing the validity of any objection you have made to our use of your information. The right might also apply where there is no longer a basis for using your personal information, but you don't want us to delete the data. Where this right is validly exercised, we may only use the relevant personal information with your consent, for legal claims or where there are other public interest grounds to do so.
Where we use your personal information with your consent, you may withdraw that consent at any time and we will stop using your personal information for the purposes for which consent was given.
Please contact us in any of the ways set out below if you wish to exercise any of these rights.
We keep this privacy statement under regular review and will place any updates on this website. Paper copies of the privacy statement may also be obtained using the contact information below.
This privacy statement was last updated on 27 January 2021.
If you have any further questions about the way in which we process personal data, or about how to exercise your rights, please contact the Head of Information Governance at:
The Scottish Parliament
Edinburgh
EH99 1SP
Telephone: 0131 348 6913
(Calls are welcome through the Text Relay service or in British Sign Language through contactSCOTLAND-BSL.)
Email: dataprotection@parliament.scot
Please contact us if you require information in another language or format
We seek to resolve directly all complaints about how we handle personal information but you also have the right to lodge a complaint with the Information Commissioner's Office online at: https://ico.org.uk/make-a-complaint.
Or by phone at: 0303 123 1113