How to Keep Your Personal Data Safe While Exploring Scotland

How to Keep Your Personal Data Safe While Exploring Scotland

I spend a good part of every year on the road around Scotland with a bag full of gear – phones, a laptop, camera cards, and a drone that carries its own little cache of footage and flight logs. Over the years I’ve become a lot more careful about the digital side of travelling than I used to be, and not because I’m especially paranoid. It’s just that the things we carry now hold our whole lives: banking, photos, work files, passwords, the lot. Losing a phone on a Highland hillside is bad enough. Handing your bank details to a scammer because you scanned the wrong sticker in a car park is a different kind of misery altogether.

This is a practical guide to keeping your personal data safe while you’re out exploring Scotland – whether you’re driving the NC500, wandering round Edinburgh, or parked up at a caravan site in Moray like I often am. Some of it is universal common sense that applies anywhere in the world. But a fair bit is specific to the realities of travelling here: patchy mobile signal, cafe and campsite Wi-Fi, contactless-everything car parks, and a recent wave of scams that have genuinely turned up in Scottish towns and villages over the past year or two.

Why bother? A quick reality check

There’s a lazy assumption that cybercrime is something that happens to other people, or only to big companies. It isn’t. Ordinary travellers are targeted constantly, precisely because we’re distracted, tired, using unfamiliar networks, and in a hurry to pay for parking or check into a room. A holiday is when your guard is down, and criminals know it.

The good news is that the vast majority of this stuff is preventable with a handful of habits that take almost no effort once you’ve set them up. You don’t need to be technical. You just need to know what to look out for and to do a bit of preparation before you set off. I’ll walk through it in the rough order you’d actually deal with it: before you leave, while you’re connecting to networks, when you’re paying for things, and what to do if the worst happens.

Before you leave home

Most of your security is won or lost before you’ve even packed the car. Ten minutes at the kitchen table saves a world of grief later.

Update everything

Software updates are boring and they always seem to want installing at the worst possible moment. But those updates are largely security patches – they close the holes that criminals rely on. Update your phone, tablet and laptop operating systems, and update your apps too, before you leave. Doing it at home on your own broadband is far better than trying to download a large update over a flaky campsite connection halfway up the west coast.

Lock your devices properly

Every device you take should have a screen lock – a PIN, a strong passcode, or biometrics like a fingerprint or face unlock. A six-digit passcode is vastly better than a four-digit one, and both are better than the shockingly common “no lock at all”. If your phone is lost or stolen, this is the single thing standing between a stranger and your email, your banking apps and your photos. Turn it on.

Sort out your passwords and turn on two-factor authentication

If you’re still reusing the same password across multiple accounts, this is your nudge to stop. The single most useful thing most people can do for their online security is start using a password manager, which generates and stores a unique, strong password for every account so you only have to remember one master password. The UK’s National Cyber Security Centre also recommends the “three random words” approach for passwords you do need to remember – something like coffee-heron-tractor is both strong and memorable.

Then turn on two-factor authentication (sometimes called 2FA or two-step verification) on your important accounts – email first and foremost, then banking, then social media. It adds a second check, usually a code from an app or a text, so that even if someone gets your password they still can’t get in. An authenticator app is more secure than receiving codes by text, which matters more than you’d think when you’re somewhere with poor signal and texts don’t always arrive.

Back up before you go

Back up your phone and laptop before you travel. If a device is lost, stolen or damaged, a recent backup turns a catastrophe into an inconvenience. I speak from experience here – the thought of losing a card full of drone footage from a shoot is enough to make me back everything up religiously. Cloud backups are convenient; a separate physical backup left safely at home is belt-and-braces.

Enable “find my device” and know how to wipe it remotely

Both Apple and Android have built-in tools to locate a lost device on a map, lock it, or erase it entirely from afar. Switch this on before you leave and make sure you know your login details for it. If your phone vanishes, being able to remotely lock or wipe it is enormously reassuring.

Wi-Fi, mobile signal and the realities of connecting in Scotland

Here’s where travelling in Scotland throws up its own particular quirks. Mobile coverage in the Highlands and Islands is patchy at best. Drive the NC500 or head into the glens and you’ll lose signal for long stretches, which pushes people towards whatever Wi-Fi they can find – the cafe, the pub, the campsite, the visitor centre. And that’s exactly where you need to be a bit careful.

The trouble with public Wi-Fi

Public Wi-Fi networks in cafes, hotels, airports and campsites are convenient but usually unsecured, which means the data travelling between your device and the network can potentially be intercepted. Criminals also occasionally set up fake hotspots with innocent-looking names – “Free Cafe WiFi” – hoping you’ll connect and hand over your browsing without realising. The practical rules are simple:

  • Avoid doing anything sensitive – online banking, shopping, entering card details – while connected to public Wi-Fi.
  • If you must connect, check the exact network name with a member of staff rather than guessing.
  • Tell your device to “forget” public networks after you’ve used them, so it doesn’t automatically reconnect to a network with the same name somewhere else.
  • Turn off the setting that automatically joins open Wi-Fi networks.

Use a VPN – or just use your mobile data

A VPN (Virtual Private Network) encrypts your internet connection so that even on an unsecured network, what you’re doing stays private. If you regularly use public Wi-Fi, a reputable VPN is well worth having. On a Mac, for example, dedicated security software such as Moonlock bundles a VPN alongside malware protection and a tool that flags suspicious scam messages, which is a tidy way to cover several bases at once if you’re an Apple user.

Honestly though, the simplest safe option is often to skip public Wi-Fi entirely and use your own mobile data via 4G or 5G for anything sensitive. Your mobile connection is encrypted by default and far harder to snoop on. Where you have signal, tethering your laptop to your phone’s hotspot is a genuinely secure way to work. The catch, of course, is that in the more remote corners of Scotland you may not have any signal at all – which is all the more reason to do your important admin before you head into the hills.

Turn off Bluetooth and location services when you don’t need them

Both can be exploited and both drain your battery, which matters when you’re out all day. Switch Bluetooth off when you’re not actively using it, and be selective about which apps you allow to track your location. You almost certainly don’t need every app knowing where you are at all times.

Paying for things – and the QR code scam you really need to know about

This is the section I’d most want a visitor to Scotland to read, because it’s the scam that has genuinely spread across the country recently and it catches out sensible, careful people.

The car park “quishing” scam

Over the past couple of years, criminals have been sticking fake QR code stickers onto parking machines and signs. You scan the code expecting to pay for parking, you’re taken to a convincing but fraudulent website, you enter your card details – and the money goes straight to the scammers rather than the council. Worse, some victims have had repeated payments taken from their accounts afterwards. This trick has a name now: “quishing”, short for QR-code phishing.

This is not a distant, big-city problem. Edinburgh City Council warned drivers in 2026 about sabotaged parking machines carrying fake QR stickers, stressing that the council doesn’t use QR codes for parking at all. Stirling Council issued similar warnings, and fake codes have even been reported in places as remote as Ardnamurchan on the west coast. If you’re driving around Scotland and paying for parking as you go, this is a live risk in exactly the kind of scenic spots you’ll be stopping at.

How to protect yourself:

  • Be suspicious of any QR code on a parking machine, especially if it looks like a stuck-on sticker or sits over the top of other text.
  • Most Scottish councils do not use QR codes for parking payment. If a code takes you anywhere other than the official app or website, back out immediately and don’t enter card details.
  • Prefer paying at the machine directly, or use the official parking app (RingGo, PayByPhone and similar) downloaded from your phone’s official app store – not via a scanned code.
  • Check the web address carefully after scanning. Fraudulent sites often mimic the real thing with a slightly-off address.

Fake parking fine texts and emails

Alongside the sticker scam, there’s been a wave of fake “you have an unpaid parking fine” texts and emails doing the rounds across the UK, complete with links to pay. Genuine penalty charge notices are fixed to your vehicle, handed to you, or posted – they don’t arrive by text out of the blue. Treat any such message with deep suspicion and never click the link. If you’re worried a fine might be real, go directly to the council’s official website yourself rather than following any link.

Contactless and card sense

Contactless payment is genuinely one of the safer ways to pay – your actual card details aren’t shared with the retailer, and there are limits on contactless amounts. Using your phone’s wallet (Apple Pay or Google Pay) is more secure still, because each transaction uses a one-time token rather than your real card number. When you’re travelling, paying by phone is a solid default.

Phishing, scam messages and staying sceptical on the move

When you’re tired and distracted on a trip, a well-timed scam message is easy to fall for. Be wary of unexpected texts and emails, particularly anything that creates urgency – a delivery you need to reschedule, a fine to pay, a “suspicious login” to your bank that needs immediate action. That urgency is the trap. Scammers want you to react before you think.

A few habits that serve you well anywhere:

  • Never enter passwords or card details via a link in a message. Go to the official app or type the web address yourself.
  • Your bank will never ask you to move money to a “safe account” or read out a security code. That’s always a scam.
  • If a message seems even slightly off, it probably is. Take a breath. Genuine organisations don’t mind you calling them back on their official number to check.

A word on watching what you share

It’s tempting to post the holiday photos in real time – I’m as guilty as anyone of wanting to share a cracking sunset from a Moray beach the moment I’ve got it. But broadcasting that your house is empty for a fortnight is an open invitation, and criminals do use social media to work out when homes are unoccupied. Consider holding the best photos back until you’re home. The sunset will look just as good next Tuesday.

A note for Mac and Apple users

There’s a long-standing myth that Macs and iPhones can’t get malware. They can, and Mac-specific malware in particular has been climbing sharply, often disguised as fake installers for popular apps or delivered through phishing links and fake “security alert” pop-ups. Apple’s built-in protections are genuinely good, but they only help if they’re switched on and kept up to date.

If you’re a Mac user who wants an extra layer, dedicated security software like Moonlock (from the MacPaw team) is built specifically for macOS – combining real-time malware protection, a scam-message checker and a VPN for safer browsing on public networks. For travelling, that combination is quite well suited to the risks I’ve described above. As ever, treat any single tool as one layer among several rather than a magic shield – good habits matter more than any app.

If the worst happens

Even careful people get caught out sometimes. Knowing what to do quickly limits the damage.

  • Lost or stolen device: use “find my device” to lock or wipe it remotely, then change the passwords on your important accounts and contact your mobile provider to block the SIM.
  • You’ve entered card details on a scam site: contact your bank immediately using the number on the back of your card, and ask them to block the card and raise a fraud claim. Speed matters.
  • Reporting a scam in Scotland: report fraud to Police Scotland by calling 101, and to Advice Direct Scotland’s consumer service on 0808 164 6000. If you spot a fake QR sticker on a parking machine, photograph it and report it to the council and the police so it can be removed before it catches someone else.

Frequently asked questions

Is public Wi-Fi in Scottish cafes and hotels safe to use?

It’s fine for casual browsing, but avoid anything sensitive like banking or entering card details on it. Public Wi-Fi is usually unsecured, so use your mobile data or a VPN for anything important, and double-check the exact network name with staff before connecting.

What is the QR code parking scam I keep hearing about?

Criminals stick fake QR code stickers onto parking machines. Scanning them leads to a fraudulent payment website that steals your card details. Most Scottish councils don’t use QR codes for parking at all, so be very wary of any code on a machine and pay at the machine or via an official app instead.

Do I need a VPN to travel around Scotland?

You don’t strictly need one, but it’s useful if you regularly connect to public Wi-Fi. The simplest alternative is to use your own mobile data for anything sensitive, since that connection is encrypted by default. Bear in mind mobile signal is patchy in remote areas, so do important admin before heading into the hills.

Can iPhones and Macs really get viruses?

Yes. The idea that Apple devices are immune is a myth, and Mac-specific malware has been rising. Apple’s built-in protections help a great deal when kept up to date, and Mac users wanting extra cover can add a dedicated security tool. Good habits – updates, strong passwords, scepticism about links – matter most.

What should I do if I lose my phone while travelling?

Use Apple’s or Android’s “find my device” feature to locate, lock or wipe it remotely. Change the passwords on your key accounts, and contact your mobile provider to block the SIM. Having a screen lock and a recent backup in place beforehand makes all of this far less painful.

How do I report a scam or fraud in Scotland?

Call Police Scotland on 101 to report fraud, and contact Advice Direct Scotland’s consumer helpline on 0808 164 6000. If you’ve lost money, phone your bank immediately using the number on your card. Report fake QR stickers to the relevant council so they can be removed.

Is contactless payment safe when I’m out and about?

Yes, contactless is one of the safer ways to pay because your full card details aren’t shared with the retailer. Paying with your phone’s wallet is safer still, as each transaction uses a one-time token rather than your real card number.

Explore Scotland with a bit more peace of mind

None of this should put you off. Scotland is a wonderful place to explore and the overwhelming majority of trips pass without any bother at all. The point isn’t to travel nervously – it’s to travel prepared, so that a lost phone or a dodgy sticker in a car park is a minor hiccup rather than a holiday-ruiner.

Get the boring bits done before you leave – updates, backups, a password manager, two-factor authentication switched on – and the rest is mostly a matter of staying a little sceptical when something feels off. Do that, and you can give your full attention to the things that actually matter out here: the glens, the coastlines, the castles and the long light of a Highland evening. If you’re planning your route, our Scotland road trip planner and NC500 fuel stop guide will help you get the practicalities sorted before you go – leaving you free to enjoy the drive.

All information was correct at the time of writing, please check things like entry costs and opening times before you arrive.

Leave a comment below

Loading map...