24/07/2026

The Information Commissioner’s Office (ICO) has recently highlighted an important reminder for all organisations that handle personal information: having access to a system does not mean you are entitled to access every record within it.

A former Herefordshire Council employee has received a suspended prison sentence after unlawfully accessing approximately 490 personal records and downloading 94 documents over a four-day period. The records contained highly sensitive information relating to children and adults, including medical records, social worker reports and child and family assessments.

The employee pleaded guilty to an offence under section 1 of the Computer Misuse Act 1990, which makes it a criminal offence to intentionally access computer material without authorisation.

Why is this significant?

Many people assume that data protection offences only arise where information is stolen, sold or shared with others. This case demonstrates that simply accessing information without a legitimate business reason can have serious consequences.

The employee had access to the council’s systems as part of his role. However, that access was limited to carrying out his work. Viewing records relating to family members or people known to him was entirely outside the scope of his authorised duties.

In other words, authorisation is about purpose, not just permissions.

The Computer Misuse Act and Data Protection

Interestingly, this prosecution was brought under the Computer Misuse Act 1990 rather than the Data Protection Act 2018.

The Computer Misuse Act focuses on unauthorised access to computer systems. It is often the most appropriate legislation where an individual knowingly accesses information they are not entitled to view, even if they already have valid login credentials.

By contrast, the Data Protection Act 2018 contains criminal offences relating to the unlawful obtaining, disclosure or retention of personal data. Depending on the facts, there can be overlap between the two pieces of legislation, but prosecutors will generally pursue the charge that most accurately reflects the offending and provides the clearest route to conviction.

Lessons for employers

This case provides several important reminders for organisations:

  • Ensure role-based access controls are regularly reviewed.
  • Monitor audit logs and investigate unusual access patterns.
  • Make it clear that staff must only access information where there is a genuine business need.
  • Deliver regular data protection and information security training.
  • Reinforce that misuse of personal data can result in disciplinary action, dismissal and, in serious cases, criminal prosecution.

Password sharing is not a shortcut

This case also serves as a timely reminder about password security.

Employees should never share usernames or passwords, even with trusted colleagues. Password sharing undermines audit trails, makes it difficult to identify who carried out particular actions and increases the risk of unauthorised access to personal information. It is also likely to breach an organisation’s information security policies and may expose both individuals and organisations to significant risk.

Building a culture of accountability

Technical controls are only one part of effective information governance.

Organisations should foster a culture where employees understand that access to personal data is granted solely for legitimate purposes and that curiosity is never a lawful reason to view someone’s information.

The vast majority of employees act appropriately. However, this case demonstrates that organisations should have robust monitoring arrangements, clear policies and regular training in place to identify and deter misuse before significant harm occurs.

At JH Data Protection, we help organisations develop practical, proportionate data protection and information governance arrangements that protect individuals, support staff and reduce organisational risk. If you would like advice on strengthening your data protection compliance or delivering engaging staff training, we’d be happy to help.

Email: dpo@jhdataprotection.com

Leave a comment

  • Council officer convicted for unlawfully accessing personal data

    24/07/2026 The Information Commissioner’s Office (ICO) has recently highlighted an important reminder for all organisations that handle personal information: having access to a system does not mean you are entitled to access every record within it. A former Herefordshire Council employee has received a suspended prison sentence after unlawfully accessing approximately 490 personal records and…

  • Why Smart Companies Keep Getting Data Protection Wrong

    12/07/2026 The biggest data protection risk? It’s certainty. The organisations most likely to get into difficulty with data protection are rarely the ones asking difficult questions. They’re the ones convinced they’re already compliant. Whether it’s a multinational or a start-up, the mistakes are remarkably similar: Collecting data because they can, not because they need to.…

  • The Rise of the Cake Shed

    When Home Business CCTV Stops Being “Purely Personal or Household” 05/07/2026 Have you noticed the increase of “cake sheds” in your area? It seems every week another one pops up on local social media groups. Home businesses are booming. Whether it’s a side hustle or the start of something much bigger, garden bakeries, honesty shops,…

  • University of Nottingham Cyber Attack Exposes Student and Alumni Data

    12/06/2026 The University of Nottingham has confirmed that a significant amount of personal data relating to current students and alumni has been accessed following a cyber attack on its student records system. In a statement issued on 10 June 2026, the University said it had identified unauthorised activity within its Campus Solutions system and immediately…