Search

How can we help?

Icon

Data Protection Breaches – Personal Liability for Employees

It is well known that employers have obligations under the Data Protection Act 2018 (the “Act”) but, perhaps lesser known, is that employees can be held personally liable for certain actions amounting to criminal offences under the Act.

The ICO’s approach to employee prosecutions

The ICO has made several successful prosecutions resulting in suspended prison sentences and/or fines. It is also able to recover financial benefits obtained by offenders with proceedings under the Proceeds of Crime Act 2002. In 2026 so far, the ICO has reported 7 prosecutions against individuals involving the unlawful accessing and sale of personal data demonstrating its willingness to prosecute in these areas.

A recent example of this occurred in May 2026, when two former RAC employees were handed suspended prison sentences and ordered to complete 150 hours of unpaid work, for unlawfully copying and selling over 29,500 lines of personal information. The two individuals worked as customer service specialists at one of the RAC’s call centres. The RAC discovered that the employees had been accessing and copying personal data relating to people involved in road traffic accidents and had evidence (via WhatsApp messages between the two) that a third party was paying for this information. The employees were found to have committed offences under the Computer Misuse Act 1990 and Data Protection Act 2018. At the Proceeds of Crime Act Hearings that followed, orders were made for them to repay just over £118,000 (in total) plus legal costs.

There are a number of criminal offences that individuals can be prosecuted for under the Data Protection Act 2018.  Some of the key ones being:

  • Obtaining, disclosing or retaining personal data without the consent of the Data Controller
  • Selling data obtained without the controller’s consent (or offering to sell data that has been obtained in this way)

In the employment context, these often arise from disgruntled employees unlawfully taking client/customer data without consent when they leave employment, though they also occur in situations like the above where employees unlawfully access data during their employment for personal gain.

There are also other offences which can arise in the employment context, such as altering, defacing, blocking, erasing, destroying or concealing information with the intention of preventing disclosure of all or part of the information as part of a Data Subject Access Request (“DSAR”) where the person making the request would have been entitled to receive this, which the ICO has also pursued.

In September last year, the ICO secured a conviction against the Director of a Care Home for failing to comply with a DSAR made by one of the resident’s daughters, who was enquiring about her father’s care. The Director was found guilty of this offence and ordered to pay a fine of £1,100 and additional costs. The ICO said that this case highlighted the human impact that an organisation’s deliberate non-compliance with requests for information access can have on people and families, and the importance of its work to target offences that undermine public confidence in the data protection regime.

Employees can be held personally liable for certain actions amounting to criminal offences under the Act.

The ICO’s ongoing focus on enforcement

In the ICO’s annual report 2025/26 it says that it continues to focus on interventions that raise data protection standards across the board including leading criminal prosecutions.

Practical steps for employers to mitigate risks

Whilst employers cannot fully prepare for rogue employees, these cases are reminders of the importance of remaining vigilant to risks and taking steps to address these including:

  • Having a clear data protection policy setting out expectations on employees, including that they should not be accessing personal data unless required for their role;
  • Providing training on expected standards and personal liability;
  • Having clear guidance and training on dealing with DSARs and what should/should not be done as part of these;
  • Ensuring adequate security measures are in place to reduce the risks of incidents occurring.  This includes making sure that information is only available to those who genuinely require this as part of their role but could also include wider security measures such as mechanisms for detecting unusual behaviour (such as mass downloads of data);
  • Having clear data breach reporting measures in place and IT support to assist with mitigating the risks connected to these; and
  • Ensuring personal data received from other sources is subject to proper due diligence checks

How our data protection team can help

Our data protection team assist organisations with dealing with potential and actual data protection breaches and DSAR compliance including assisting organisations in updating their policies and training.  Please do not hesitate to get in contact with a member of the team.

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

employmentboddy logo
clipboard logo HR Resources

Data Protection – An Overview

This factsheet provides and brief overview of data protection legislation.

Read, listen and watch our latest insights

art
  • 30 September 2026

Clarkslegal celebrates strong results in the Legal 500 UK 2027

Clarkslegal would like to thank its clients for the outstanding feedback that contributed to the firm’s recognition in the Legal 500 UK Solicitors 2027 Guide. We are proud to be recognised across five key practice areas: Litigation, Property, Corporate & Commercial, Employment, and Immigration.

art
  • 29 September 2026
  • Employment

New bereavement leave rights for pregnancy loss

The Government have announced that in April 2027 they will be introducing a new right to bereavement leave to include those who suffer pregnancy loss before 24 weeks. This has been announced in their response to their consultation on bereavement leave “Make Work Pay: Leave for bereavement including pregnancy loss”.

art
  • 25 September 2026
  • Employment

Consultation response on duty to inform workers of right to join a union

The Employment Rights Act 2025, makes it a requirement for employers to inform workers of their right to join a trade union at the same time as the Section 1 particulars are issued to them and at subsequent times. The details of this new duty are to be provided in regulations.

art
  • 24 September 2026
  • Public Procurement

Procurement challenges: What documents and information are bidders entitled to?

A tricky feature of public procurement challenges for unsuccessful bidders is that contracting authorities usually hold all the cards. When the outcome of a tender conducted under the Procurement Act 2023 has been decided, authorities must provide bidders with an Assessment Summary containing their scores for each of the award criteria and those of the successful bidder and an explanation for those scores.

art
  • 23 September 2026
  • Corporate and M&A

GDPR Privacy Policies: Key requirements for organisations

When an organisation is creating a website or app to reach users or potential customers drafting a Privacy Policy may be an afterthought. However, failure to write a Privacy Policy, which complies with the relevant legislation, can have serious consequences.

Pub
  • 17 September 2026
  • Employment

Employment law changes in 2026: What you need to know

Stay ahead of the latest UK employment law changes. Watch our on demand webinar with Monica Atwal and Harry Berryman covering key HR developments and employment law updates for 2026.