Human resources at a click

Data Protection Breaches – Personal Liability for Employees

_Professional Office Specialist Working on Desktop Computer in Modern Technological Monitoring Control Room

It is well known that employers have obligations under the Data Protection Act 2018 (the “Act”) but, perhaps lesser known, is that employees can be held personally liable for certain actions amounting to criminal offences under the Act.

The ICO’s approach to employee prosecutions

The ICO has made several successful prosecutions resulting in suspended prison sentences and/or fines. It is also able to recover financial benefits obtained by offenders with proceedings under the Proceeds of Crime Act 2002. In 2026 so far, the ICO has reported 7 prosecutions against individuals involving the unlawful accessing and sale of personal data demonstrating its willingness to prosecute in these areas.

A recent example of this occurred in May 2026, when two former RAC employees were handed suspended prison sentences and ordered to complete 150 hours of unpaid work, for unlawfully copying and selling over 29,500 lines of personal information. The two individuals worked as customer service specialists at one of the RAC’s call centres. The RAC discovered that the employees had been accessing and copying personal data relating to people involved in road traffic accidents and had evidence (via WhatsApp messages between the two) that a third party was paying for this information. The employees were found to have committed offences under the Computer Misuse Act 1990 and Data Protection Act 2018. At the Proceeds of Crime Act Hearings that followed, orders were made for them to repay just over £118,000 (in total) plus legal costs.

There are a number of criminal offences that individuals can be prosecuted for under the Data Protection Act 2018.  Some of the key ones being:

  • Obtaining, disclosing or retaining personal data without the consent of the Data Controller
  • Selling data obtained without the controller’s consent (or offering to sell data that has been obtained in this way)

In the employment context, these often arise from disgruntled employees unlawfully taking client/customer data without consent when they leave employment, though they also occur in situations like the above where employees unlawfully access data during their employment for personal gain.

There are also other offences which can arise in the employment context, such as altering, defacing, blocking, erasing, destroying or concealing information with the intention of preventing disclosure of all or part of the information as part of a Data Subject Access Request (“DSAR”) where the person making the request would have been entitled to receive this, which the ICO has also pursued.

In September last year, the ICO secured a conviction against the Director of a Care Home for failing to comply with a DSAR made by one of the resident’s daughters, who was enquiring about her father’s care. The Director was found guilty of this offence and ordered to pay a fine of £1,100 and additional costs. The ICO said that this case highlighted the human impact that an organisation’s deliberate non-compliance with requests for information access can have on people and families, and the importance of its work to target offences that undermine public confidence in the data protection regime.

Employees can be held personally liable for certain actions amounting to criminal offences under the Act.

The ICO’s ongoing focus on enforcement

In the ICO’s annual report 2025/26 it says that it continues to focus on interventions that raise data protection standards across the board including leading criminal prosecutions.

Practical steps for employers to mitigate risks

Whilst employers cannot fully prepare for rogue employees, these cases are reminders of the importance of remaining vigilant to risks and taking steps to address these including:

  • Having a clear data protection policy setting out expectations on employees, including that they should not be accessing personal data unless required for their role;
  • Providing training on expected standards and personal liability;
  • Having clear guidance and training on dealing with DSARs and what should/should not be done as part of these;
  • Ensuring adequate security measures are in place to reduce the risks of incidents occurring.  This includes making sure that information is only available to those who genuinely require this as part of their role but could also include wider security measures such as mechanisms for detecting unusual behaviour (such as mass downloads of data);
  • Having clear data breach reporting measures in place and IT support to assist with mitigating the risks connected to these; and
  • Ensuring personal data received from other sources is subject to proper due diligence checks

How our data protection team can help

Our data protection team assist organisations with dealing with potential and actual data protection breaches and DSAR compliance including assisting organisations in updating their policies and training.  Please do not hesitate to get in contact with a member of the team.

Disclaimer This information is for guidance purposes only and should not be regarded as a substitute for taking professional and legal advice. Please refer to the full General Notices on our website.
Louise Keenan
Louise Keenan
Associate

Related Articles

It is well known that employers have obligations under the Data Protection Act 2018 (the “Act”) but, perhaps lesser known,...

Artificial intelligence is changing the data protection landscape, but perhaps not in the way many organisations expected. Much of the...

What is personal data? Personal data refers to any information related to an identifiable living individual. That individual has to...

Related Resources

Internet and email policy

Policy covering the use of the internet and email by employees. Purpose and scope This Policy covers the use of...

Generative AI policy

This Policy covers the use of generative artificial intelligence (generative AI). The use of generative AI is transforming the way...

Telephone policy

Purpose & Scope This Policy covers the use of the Company’s telephone systems and mobile phones by employees for both...

Human resources at a click