Decoding the world of cybersecurity

78 missing devices, no ICO reports in Scotland

The Scottish Government says encryption and remote-wipe controls meant 78 lost or stolen work devices did not create a personal-data risk requiring notification to the ICO.

78 missing devices, no ICO reports in Scotland
Summary
  • FOI-derived figures show 78 Scottish Government-issued phones and laptops were recorded lost or stolen between January 2025 and June 2026.
  • The government says full-device encryption and remote-wipe capabilities meant none crossed the ICO reporting threshold.
  • UK GDPR requires organisations to document the reasoning behind decisions that a personal-data breach does not require notification.

The Scottish Government says none of 78 work phones and laptops recorded lost or stolen over an 18-month period created a personal-data risk requiring notification to the Information Commissioner’s Office, citing encryption and remote-wipe controls.

Figures obtained through freedom-of-information requests and reported in the Scottish press cover the period from January 2025 to June 2026. They comprise 57 mobile phones, 14 lost laptops, and seven stolen laptops, with only one of the missing devices reportedly recovered.

The Scottish Government said none of the incidents met the threshold for reporting to the ICO. It pointed to security procedures including full encryption throughout a device’s life and remote-wiping capability, adding: “Together these measures prevent unauthorised data access.”

No evidence has emerged that information was obtained from any of the missing devices, so the figures do not establish 78 separate data breaches.

UK GDPR also does not require every lost device containing personal information to be reported. An organisation must assess the likelihood and severity of risk to people’s rights and freedoms, with notification required where the breach is likely to create such a risk.

Encryption can be decisive in that assessment because physical loss of a laptop does not necessarily expose the information stored on it. Remote management adds another control layer where an organisation can lock, disable, or wipe a managed device after loss.

The strength of the assessment depends on evidence relating to the particular device. A general policy requiring encryption does not by itself establish that the missing endpoint was encrypted, centrally managed, correctly configured, and incapable of exposing accessible information when it disappeared.

Remote wipe has similar limitations. An organisation may be able to issue a wipe instruction without being able to guarantee that an offline device ever reconnects and receives it. The security state at the point of loss, combined with encryption and access controls, carries more weight than the availability of the wipe function alone.

The ICO’s breach guidance requires organisations to consider whether an incident creates a likely risk and to retain records of their assessment. A decision not to notify therefore remains part of the organisation’s accountability record.

Repeated losses also create a separate asset-management issue even where individual devices remain protected. Custody, recovery rates, configuration evidence, user behaviour, and recurring loss patterns can influence the organisation’s broader control environment without turning every missing endpoint into a reportable privacy incident.

The reported figures include devices associated with bodies including Transport Scotland, Social Security Scotland, and the Scottish Children’s Reporter Administration, bringing several types of public-sector work within the same endpoint-management problem.

Nothing in the available evidence establishes that the Scottish Government failed to meet an ICO notification obligation. The record instead rests on repeated assessments that encryption and management controls prevented the device losses from becoming reportable personal-data incidents.

×