24/07/2026

The Information Commissioner’s Office (ICO) has recently highlighted an important reminder for all organisations that handle personal information: having access to a system does not mean you are entitled to access every record within it.
A former Herefordshire Council employee has received a suspended prison sentence after unlawfully accessing approximately 490 personal records and downloading 94 documents over a four-day period. The records contained highly sensitive information relating to children and adults, including medical records, social worker reports and child and family assessments.
The employee pleaded guilty to an offence under section 1 of the Computer Misuse Act 1990, which makes it a criminal offence to intentionally access computer material without authorisation.
Why is this significant?
Many people assume that data protection offences only arise where information is stolen, sold or shared with others. This case demonstrates that simply accessing information without a legitimate business reason can have serious consequences.
The employee had access to the council’s systems as part of his role. However, that access was limited to carrying out his work. Viewing records relating to family members or people known to him was entirely outside the scope of his authorised duties.
In other words, authorisation is about purpose, not just permissions.
The Computer Misuse Act and Data Protection
Interestingly, this prosecution was brought under the Computer Misuse Act 1990 rather than the Data Protection Act 2018.
The Computer Misuse Act focuses on unauthorised access to computer systems. It is often the most appropriate legislation where an individual knowingly accesses information they are not entitled to view, even if they already have valid login credentials.
By contrast, the Data Protection Act 2018 contains criminal offences relating to the unlawful obtaining, disclosure or retention of personal data. Depending on the facts, there can be overlap between the two pieces of legislation, but prosecutors will generally pursue the charge that most accurately reflects the offending and provides the clearest route to conviction.
Lessons for employers
This case provides several important reminders for organisations:
- Ensure role-based access controls are regularly reviewed.
- Monitor audit logs and investigate unusual access patterns.
- Make it clear that staff must only access information where there is a genuine business need.
- Deliver regular data protection and information security training.
- Reinforce that misuse of personal data can result in disciplinary action, dismissal and, in serious cases, criminal prosecution.
Password sharing is not a shortcut
This case also serves as a timely reminder about password security.
Employees should never share usernames or passwords, even with trusted colleagues. Password sharing undermines audit trails, makes it difficult to identify who carried out particular actions and increases the risk of unauthorised access to personal information. It is also likely to breach an organisation’s information security policies and may expose both individuals and organisations to significant risk.
Building a culture of accountability
Technical controls are only one part of effective information governance.
Organisations should foster a culture where employees understand that access to personal data is granted solely for legitimate purposes and that curiosity is never a lawful reason to view someone’s information.
The vast majority of employees act appropriately. However, this case demonstrates that organisations should have robust monitoring arrangements, clear policies and regular training in place to identify and deter misuse before significant harm occurs.
At JH Data Protection, we help organisations develop practical, proportionate data protection and information governance arrangements that protect individuals, support staff and reduce organisational risk. If you would like advice on strengthening your data protection compliance or delivering engaging staff training, we’d be happy to help.
Email: dpo@jhdataprotection.com
Leave a comment