Skip to main content
Guidance

Privacy Notice for the Covid Fraud Reporting Site

Published 12 September 2025

This notice sets out how we will use your personal data, and your rights. It is made under Articles 13 and/or 14 of the UK General Data Protection Regulation (UK GDPR). 

1. YOUR DATA 

1.1 Purpose

The purpose(s) for which we are processing your personal data is(are): 

The Counter Fraud Reporting Site (CFRS) is a GOV.UK hosted platform that allows members of the public or organisations to report suspicions of COVID-19 related fraud cases.
The site uses a structured webform to guide the type of information submitted. However, submissions may include any type of information relevant to suspected fraud, including details about third parties such as names (incl aliases), addresses, business details, COVID-19 support scheme, financial information, or other identifying information. This data may be needed to positively identify offenders or clarify the nature of the suspected fraud. The project is law enforcement - related, focusing on identifying fraud cases, not general fraud prevention as agreed by HMT.

1.2 The data

We will process the following personal data: 

  • Name
  • Email address
  • Address
  • Health information 
  • What type of COVID-19 spending the suspected fraud was on (e.g. Bounce Back Loans) 
  • The estimated value of the suspected fraud and the date (or dates) it took place

The legal basis for processing personal data is that it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. 

The legal basis for processing law enforcement personal data is that processing is necessary for the performance of a task carried out for the prevention and detection of unlawful acts by a competent authority. The Cabinet Office is a Competent Authority as defined in Section 1 of Schedule 7 of the DPA 2018

Sensitive personal data is personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation.

The legal basis for processing your sensitive personal  data is:

That it is necessary for reasons of substantial public interest (para 6, sch.1): 

This applies to the PSFA counter fraud activity as it is necessary public funds, maintain the integrity of government services, and ensure resources are used as intended. The processing supports fraud prevention, detection, investigation, prosecution, and recovery in the effective exercise of statutory and governmental functions., 

Preventing or detecting crime (para 10 & 14, sch.1)

1.4 Recipients

Your personal data will be shared by us with our website service provider. As your personal data will be stored on our IT infrastructure it will also be shared with our data processors who provide email, and document management and storage services. 

The information you provide by using this form will be processed by the Cabinet Office, as part of the Public Sector Fraud Authority activities. 

Please see the Privacy Notice for the Public Sector Fraud Authority Intelligence Hub for more details regarding how they will process the personal data you provide. 

1.5 Retention 

Any personal data you provide using this site is assessed as being relevant to suspected or confirmed fraud, it will be retained in an identifiable format for up to five years following the resolution of the action for which it was received or until the conclusion of any related investigation, whichever is later

Where personal data has not been provided directly by you, it will have been provided by another user as part of their use of CFRS.

2. YOUR RIGHTS 

You have the right to request information about how your personal data are processed, and to request a copy of that personal data. 

You have the right to request that any inaccuracies in your personal data are rectified without delay. 

You have the right to request that any incomplete personal data are completed, including by means of a supplementary statement. 

You have the right to request that your personal data are erased if there is no longer a justification for them to be processed. 

You have the right in certain circumstances (for example, where accuracy is contested) to request that the processing of your personal data is restricted. 

You have the right to object to the processing of your personal data

3. INTERNATIONAL TRANSFERS

As your personal data is stored on our Corporate IT infrastructure, and shared with our data processors, it may be transferred and stored securely outside the UK. Where that is the case it will be subject to equivalent legal protection through an adequacy decision, reliance on Standard Contractual Clauses, or reliance on a UK International Data Transfer Agreement.

4. COMPLAINTS 

If you consider that your personal data has been misused or mishandled, you may make a complaint to the Information Commissioner, who is an independent regulator.  The Information Commissioner can be contacted at:  Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, or 0303 123 1113, or icocasework@ico.org.uk.  Any complaint to the Information Commissioner is without prejudice to your right to seek redress through the courts. 

5. CONTACT DETAILS 

The data controller for your personal data is the Cabinet Office. The contact details for the data controller are: Cabinet Office, 70 Whitehall, London, SW1A 2AS, or 0207 276 1234, or you can use this webform

The contact details for the data controller’s Data Protection Officer are: dpo@cabinetoffice.gov.uk

The Data Protection Officer provides independent advice and monitoring of Cabinet Office’s use of personal information.