Some of the language used in privacy notices can be specialised. The Information Commissioner's website provides a useful introduction to key terms and concepts.
We collect, store and use personal data for the purposes of making ticket and tour bookings, facilitating meetings and appointments at the Scottish Parliament and responding to general enquiries. We also collect information for the purposes of identifying the demographics of where people are visiting the Scottish Parliament from. This information asks for your postcode and includes details about where you are visiting from with the following options: Edinburgh, Rest of Scotland, Rest of UK and Rest of World. Submission of this information is voluntary and further information is set out in the section on Legal Basis.
Normal category data such as your name, address and telephone number.
Depending on the nature of your request/enquiry, we may receive and temporarily store special category data about you to facilitate access to the Scottish Parliament building and your visit here. We may also receive and temporarily store other special category data that you provide to us either by way of a booking request or a general enquiry.
Special category personal data consists of information revealing:
Personal data is provided to Visitor Services directly from individuals (data subjects) or other individuals or organisations on their behalf, employees of the Scottish Parliamentary Corporate Body (SPCB) or other Parliament passholders, including elected Members of the Scottish Parliament (in their constituency, regional or ministerial capacity) or their staff via emails, written communications, telephone calls, welcome or other visit advisory apps and/or verbally in person.
Data protection law states that we must have a legal basis for handling your personal data.
The legal basis for processing personal data (including normal and special category data) for the purposes of handling ticket and tour booking requests, facilitating meetings and appointments and responding to general enquiries that relate to the core functions of the Scottish Parliament is that it is necessary for a task carried out in the public interest (Article 6 (1)(e) UK General Data Protection Regulation (UK GDPR) and section 8(e) of the Data Protection Act 2018 (DPA)). The task is engagement with the public and facilitating visitors to come and experience the Parliament and to facilitate meetings between visitors and parliamentary staff and other building users.
For special category information that you provide to us when making a ticket or tour booking or in the context of a general enquiry, the processing is necessary for a task carried out in the substantial public interest (in accordance with Article 9(2)(g) UK GDPR and section 10(3) and paragraph 6(1)(b), part 2, schedule 1 DPA 2018).
If you provide us with any health-related information for accessibility purposes, the processing is necessary for a task carried out in the substantial public interest (in accordance with Article 9(2)(g) UK GDPR and section 10(3) and para 6(2)(b) part 2, schedule 1 DPA). Facilitating access to the Scottish Parliament for members of the public with additional access requirements is a core task of the SPCB and in the substantial public interest.
The legal basis for processing personal data which includes your postcode and where you are visiting the Scottish Parliament from is consent of the data subject in terms of Article 6(1)(a) of the UK GDPR. The software used by Eventbrite for processing this information will ask you to indicate your consent to the provision of this information and explain your right to withdraw consent at any time.
We use a US based third-party provider, Eventbrite, as a data processor to manage some tours and events ticketing.
Information is stored in its system on secure servers. Access to the system is restricted to a limited number of Parliament staff and may only be accessed by the provider with the authorization of Parliament staff if required to resolve a technical issue.
Data may also be shared internally where necessary with other departments and employees of the SPCB or other parliament passholders, elected Members of the Scottish Parliament or their staff. Data may be shared externally with the emergency services such as the police and with other government security agencies, where necessary, to ensure the safety and security of the building and its users.
Personal data in relation to ticket and tour bookings is retained in either electronic or paper form and then destroyed 3 months after the date of the booking request, our reply, or the date for which the booking is made, whichever is the latest.
Personal data in relation to general enquiries is retained in either electronic or paper form and then destroyed 3 months after the date of the enquiry or the date of the event to which the enquiry relates, whichever is the latest.
Personal data in relation to facilitating meetings and appointments or provided by Welcome or other visit advisory apps will be retained in either electronic or paper form and then destroyed the first working day after the meeting or appointment or the date of the visit to which the advisory app relates.
In line with the principles underlying the National Guidance for Child Protection in Scotland (2014), published by the Scottish Government, our staff may report a concern to the relevant authorities if they come across an issue during their work which causes them to think that a child may be at risk of abuse or harm.
Data protection legislation sets out the rights which individuals have in relation to personal data held about them by data controllers. Applicable rights are listed below. You can exercise your data subject rights in particular circumstances depending on the purpose for which the data controller is processing the data and the legal basis upon which the processing takes place.
The following rights may apply:
You have the right to request a copy of the personal information about you that we hold.
Further information on how to make a data protection subject access request'.
You have the right to ask us to correct the personal data we hold about you. We want to make sure that your personal information is accurate, complete and up to date and you may ask us to correct any personal information about you that you believe does not meet these standards.
You have the right at any time to require us to stop using your personal information for direct marketing purposes. In addition, where we use your personal information to perform tasks carried out in the public interest then, if you ask us to, we will stop using that personal information unless there are overriding legitimate grounds to continue.
You have the right to ask us to delete personal information about you where:
In some cases, you may ask us to restrict how we use your personal information. This right might apply, for example, where we are checking the accuracy of personal information about you that we hold or assessing the validity of any objection you have made to our use of your information. The right might also apply where there is no longer a basis for using your personal information, but you don't want us to delete the data. Where this right is validly exercised, we may only use the relevant personal information with your consent, for legal claims or where there are other public interest grounds to do so.
Where we use your personal information with your consent, you may withdraw that consent at any time and we will stop using your personal information for the purposes for which consent was given.
Please contact us in any of the ways set out below if you wish to exercise any of these rights.
We keep this privacy statement under regular review and will place any updates on this website. Paper copies of the privacy statement may also be obtained using the contact information below.
This privacy statement was last updated on 16 February 2024.
If you have any further questions about the way in which we process personal data, or about how to exercise your rights, please contact the Head of Information Governance at:
The Scottish Parliament
Edinburgh
EH99 1SP
Telephone: 0131 348 5281
(Calls are welcome through the Text Relay service or in British Sign Language through contactSCOTLAND-BSL.)
Email: dataprotection@parliament.scot
Please contact us if you require information in another language or format
We seek to resolve directly all complaints about how we handle personal information but you also have the right to lodge a complaint with the Information Commissioner's Office at: https://ico.org.uk/make-a-complaint.
Or by phone at: 0303 123 1113