Scotland’s Crown Office and Procurator Fiscal Service disclosed on August 13 that a third-party supplier used to run an internal staff survey suffered a data security incident, exposing employment information for roughly 300 COPFS employees. The exposed data covers names, roles, and work email addresses collected through a Scottish Government data maturity assessment. COPFS said the supplier first detected suspicious activity on August 5 and began investigating immediately.

Why it matters: COPFS was careful to draw a line between its own systems, which were not touched, and the third-party platform that was. “There is no evidence that the incident has had any impact on confidential casework or the operational work of the Service,” the agency said, adding there is no indication that case, victim, or witness information was affected. For a prosecution service, that distinction is the whole story: a breach of HR-adjacent survey data is a serious but contained incident, while a breach touching casework would be a different category of problem entirely. The gap between those two outcomes was decided entirely by how the supplier had scoped and segmented the data it was allowed to hold.

The original insight here is about assessment fatigue. Government agencies increasingly outsource routine internal surveys, from engagement scores to, in this case, data-maturity self-assessments, to outside platforms that were never designed to hold anything more sensitive than opinions. COPFS staff supplied real names, roles, and work emails to a tool built for benchmarking, not for handling records that later needed the same security scrutiny as case files. Public bodies evaluating any third-party survey or assessment vendor should ask what data classification the platform was actually built for, not just what data it happens to collect, a lesson that also applies to software supply chains further down the stack.

Source: Crown Office and Procurator Fiscal Service