Search

How can we help?

Icon

Data Protection Breaches – Personal Liability for Employees

It is well known that employers have obligations under the Data Protection Act 2018 (the “Act”) but, perhaps lesser known, is that employees can be held personally liable for certain actions amounting to criminal offences under the Act.

The ICO’s approach to employee prosecutions

The ICO has made several successful prosecutions resulting in suspended prison sentences and/or fines. It is also able to recover financial benefits obtained by offenders with proceedings under the Proceeds of Crime Act 2002. In 2026 so far, the ICO has reported 7 prosecutions against individuals involving the unlawful accessing and sale of personal data demonstrating its willingness to prosecute in these areas.

A recent example of this occurred in May 2026, when two former RAC employees were handed suspended prison sentences and ordered to complete 150 hours of unpaid work, for unlawfully copying and selling over 29,500 lines of personal information. The two individuals worked as customer service specialists at one of the RAC’s call centres. The RAC discovered that the employees had been accessing and copying personal data relating to people involved in road traffic accidents and had evidence (via WhatsApp messages between the two) that a third party was paying for this information. The employees were found to have committed offences under the Computer Misuse Act 1990 and Data Protection Act 2018. At the Proceeds of Crime Act Hearings that followed, orders were made for them to repay just over £118,000 (in total) plus legal costs.

There are a number of criminal offences that individuals can be prosecuted for under the Data Protection Act 2018.  Some of the key ones being:

  • Obtaining, disclosing or retaining personal data without the consent of the Data Controller
  • Selling data obtained without the controller’s consent (or offering to sell data that has been obtained in this way)

In the employment context, these often arise from disgruntled employees unlawfully taking client/customer data without consent when they leave employment, though they also occur in situations like the above where employees unlawfully access data during their employment for personal gain.

There are also other offences which can arise in the employment context, such as altering, defacing, blocking, erasing, destroying or concealing information with the intention of preventing disclosure of all or part of the information as part of a Data Subject Access Request (“DSAR”) where the person making the request would have been entitled to receive this, which the ICO has also pursued.

In September last year, the ICO secured a conviction against the Director of a Care Home for failing to comply with a DSAR made by one of the resident’s daughters, who was enquiring about her father’s care. The Director was found guilty of this offence and ordered to pay a fine of £1,100 and additional costs. The ICO said that this case highlighted the human impact that an organisation’s deliberate non-compliance with requests for information access can have on people and families, and the importance of its work to target offences that undermine public confidence in the data protection regime.

Employees can be held personally liable for certain actions amounting to criminal offences under the Act.

The ICO’s ongoing focus on enforcement

In the ICO’s annual report 2025/26 it says that it continues to focus on interventions that raise data protection standards across the board including leading criminal prosecutions.

Practical steps for employers to mitigate risks

Whilst employers cannot fully prepare for rogue employees, these cases are reminders of the importance of remaining vigilant to risks and taking steps to address these including:

  • Having a clear data protection policy setting out expectations on employees, including that they should not be accessing personal data unless required for their role;
  • Providing training on expected standards and personal liability;
  • Having clear guidance and training on dealing with DSARs and what should/should not be done as part of these;
  • Ensuring adequate security measures are in place to reduce the risks of incidents occurring.  This includes making sure that information is only available to those who genuinely require this as part of their role but could also include wider security measures such as mechanisms for detecting unusual behaviour (such as mass downloads of data);
  • Having clear data breach reporting measures in place and IT support to assist with mitigating the risks connected to these; and
  • Ensuring personal data received from other sources is subject to proper due diligence checks

How our data protection team can help

Our data protection team assist organisations with dealing with potential and actual data protection breaches and DSAR compliance including assisting organisations in updating their policies and training.  Please do not hesitate to get in contact with a member of the team.

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

employmentboddy logo
clipboard logo HR Resources

Data Protection – An Overview

This factsheet provides and brief overview of data protection legislation.

Read, listen and watch our latest insights

Pub
  • 07 September 2026
  • Corporate and M&A

Frequently Asked Questions About Shareholders’ Agreements – Episode 1

Join Emma Docking and Jonathan Hayes as they explore some of the most frequently asked questions about shareholders’ agreements, including what they are, how they work alongside articles of association, and the risks of operating without one.

art
  • 03 September 2026
  • Employment

Employment Rights Act – October Changes

We are well and truly underway with implementation of the Employment Rights Act 2025 (“ERA 2025”) and October brings the next tranche of changes that employers will need to be ready for.

art
  • 02 September 2026
  • Immigration

Mandatory MFA for Sponsor Management System Users: What Sponsors Need to Know

The Home Office is introducing a significant security change to the Sponsor Management System (SMS). From 3 September 2026, the Home Office will begin a phased rollout of mandatory Multi-Factor Authentication (MFA) for SMS users.

art
  • 01 September 2026

Orwins continues growth with investment in Milners and Acquisition of Roe Lawyers

Clarkslegal is pleased to share the news that Orwins, the legal services group we joined earlier this year, has announced a significant investment in Yorkshire law firm Milners and the acquisition of London-based specialist practice Roe Lawyers.

Pub
  • 28 August 2026
  • Immigration

Right to Work and Sponsor Licence Changes 2026: Key dates for businesses

In this podcast, immigration solicitors Ruth Karimatsenga and Monica Mastropasqua discuss the key immigration compliance changes coming into force in September and October 2026 and what employers, HR teams, sponsors and individuals should do to prepare.

art
  • 28 August 2026
  • Commercial Real Estate

Modernising security of tenure: The Law Commission’s follow up consultation paper

On 16th June 2026, the Commission published its second consultation paper: Business Tenancies: the right to renew – modernising security of tenure.