Data Protection Breaches – Personal Liability for Employees
- 11 September 2026
- Privacy and Data Protection
It is well known that employers have obligations under the Data Protection Act 2018 (the “Act”) but, perhaps lesser known, is that employees can be held personally liable for certain actions amounting to criminal offences under the Act.
The ICO has made several successful prosecutions resulting in suspended prison sentences and/or fines. It is also able to recover financial benefits obtained by offenders with proceedings under the Proceeds of Crime Act 2002. In 2026 so far, the ICO has reported 7 prosecutions against individuals involving the unlawful accessing and sale of personal data demonstrating its willingness to prosecute in these areas.
A recent example of this occurred in May 2026, when two former RAC employees were handed suspended prison sentences and ordered to complete 150 hours of unpaid work, for unlawfully copying and selling over 29,500 lines of personal information. The two individuals worked as customer service specialists at one of the RAC’s call centres. The RAC discovered that the employees had been accessing and copying personal data relating to people involved in road traffic accidents and had evidence (via WhatsApp messages between the two) that a third party was paying for this information. The employees were found to have committed offences under the Computer Misuse Act 1990 and Data Protection Act 2018. At the Proceeds of Crime Act Hearings that followed, orders were made for them to repay just over £118,000 (in total) plus legal costs.
There are a number of criminal offences that individuals can be prosecuted for under the Data Protection Act 2018. Some of the key ones being:
In the employment context, these often arise from disgruntled employees unlawfully taking client/customer data without consent when they leave employment, though they also occur in situations like the above where employees unlawfully access data during their employment for personal gain.
There are also other offences which can arise in the employment context, such as altering, defacing, blocking, erasing, destroying or concealing information with the intention of preventing disclosure of all or part of the information as part of a Data Subject Access Request (“DSAR”) where the person making the request would have been entitled to receive this, which the ICO has also pursued.
In September last year, the ICO secured a conviction against the Director of a Care Home for failing to comply with a DSAR made by one of the resident’s daughters, who was enquiring about her father’s care. The Director was found guilty of this offence and ordered to pay a fine of £1,100 and additional costs. The ICO said that this case highlighted the human impact that an organisation’s deliberate non-compliance with requests for information access can have on people and families, and the importance of its work to target offences that undermine public confidence in the data protection regime.
Employees can be held personally liable for certain actions amounting to criminal offences under the Act.
In the ICO’s annual report 2025/26 it says that it continues to focus on interventions that raise data protection standards across the board including leading criminal prosecutions.
Whilst employers cannot fully prepare for rogue employees, these cases are reminders of the importance of remaining vigilant to risks and taking steps to address these including:
Our data protection team assist organisations with dealing with potential and actual data protection breaches and DSAR compliance including assisting organisations in updating their policies and training. Please do not hesitate to get in contact with a member of the team.
Keep up to date with the latest tips, analysis and upcoming events by our legal experts, direct to your inbox.
Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.