Human resources at a click

ICO prosecutes employee under the Data Protection Act for forwarding client data to his personal email address

The Information Commissioner’s Office (ICO) has recently prosecuted an employee who transferred information about his company’s clients before moving to a new job. The employee worked at a waste management company and, before leaving to work at a rival company, emailed the details of 957 clients to his personal email address. The documents contained commercially sensitive information, as well as personal information including the contact details of customers and their purchase history.

The employee pleaded guilty to the offence of unlawfully obtaining data and was fined £300, ordered to pay £405.98 costs and a £30 victim surcharge. This follows on from a similar case in April 2016 where a former employee of the insurance company LV= was also fined £330 for attempting to get an existing employee to sell customer data to him.

Chambers and Partners

The Clarkslegal team are commercial and good to work with. They get what our business needs and tell me what I need to hear.

The Courts are currently limited to imposing a fine for these offences (albeit the fine is unlimited). Although the Criminal Justice and Immigration Act 2008 makes unlawfully obtaining personal data punishable by up to 2 years in prison, this is yet to be enacted and it is not known when this will come into force. Earlier this year, the ICO called for tougher sentencing powers for people convicted of stealing personal data but, for the time being, it seems that the ICO is following through in its warning that “anyone who tries to unlawfully obtain, disclose or sell personal data should expect to see themselves hauled before the courts”.

Employmentbuddy.com 

Disclaimer This information is for guidance purposes only and should not be regarded as a substitute for taking professional and legal advice. Please refer to the full General Notices on our website.
Monica Atwal
Monica Atwal
Managing Partner

Related Articles

Data Subject Access Requests (DSARs) are very rarely the subject of litigation, rarer still in the High Court, so the...

If you have employees who bring their own devices into the workplace and use said devices to deal with company...

In our article, Data Use and Access Bill – how will it impact business and their dealings with Data Protection,...

Related Resources

Generative AI policy

This Policy covers the use of generative artificial intelligence (generative AI). Generative AI is a type of artificial intelligence technology...

Data Protection – An Overview

This factsheet provides and brief overview of data protection legislation. Introduction Data Protection legislation aims to protect and safeguard individual’s...

What is Personal Data?

This factsheet provides an overview of what is personal data. Introduction The Data Protection Act 2018 (DPA) applies to ‘Personal...

Human resources at a click