ICO prosecutes company employees for unlawfully accessing client data

A former employee of Lex Autolease Ltd has been prosecuted and fined under section 55 of the Data Protection Act 1998. The employee illegally accessed personal data records of 551 customers of the Company which related to road traffic accidents. The employee accessed the records on his employer's computer and then emailed them to his private email address, which he then sold to a third party as personal leads.

Section 55 covers the unlawful obtaining, disclosing or procuring of personal data, which is a criminal offence. The ICO has warned that employees should “be aware that documents containing personal data they have produced or worked on belong to their employer and are not theirs to take with them when they leave.”

Currently the offence is punishable by way of a fine only, but the ICO continues to call for more effective deterrent sentences, including the threat of prison, to be available to the courts to stop the unlawful use of personal information.

The employee pleaded guilty to two charges under section 55 of the DPA at Manchester Magistrates' Court. He was fined £500 and ordered to pay prosecution costs of £364 and a £25 victim surcharge.

Employers should notify the ICO if they are concerned that an individual is misusing personal data, especially if those individuals have access to customer data or are moving to competitors. Informing the ICO will assist in the company avoiding any criticism for covering up or not taking proper action to remedy a data breach.

It is important that employees who have access to commercially sensitive information are employed on strict contractual terms. Such terms should include express confidentiality provisions applying during and after termination of employment and obligations to return all company property and information when leaving the company.

This case demonstrates that the consequences of an employee taking any confidential or customer information can be a criminal offence, in addition to any other consequences arising from a breach of their employment obligations. Whilst the threat of a criminal sentence may be a deterrent, employers should also have in place appropriate security measures supported by policies, procedures and well-trained staff in order to minimise the risk of personal data being compromised. These protections should not only seek to prevent confidential information being stolen in the first place, but also from being used subsequently.


If you would like more information or advice relating to this article or an Employment law matter, please do not hesitate to contact Chris Cook on 01727 798089.

© SA LAW 2019

Every care is taken in the preparation of our articles. However, no responsibility can be accepted to any person who acts on the basis of information contained in them alone. You are recommended to obtain specific advice in respect of individual cases.
Read the latest Employment Views & Insights
The team at SA Law LLP has ‘excellent knowledge of employment law’. Practice head Chris Cook is recommended.
The Legal 500
SA Law Work Life red mug and glasses
Stained glass window Employment SA Law
Views & Insights
Proposed changes to NDA rules 'not enough to end workplace harassment'

Partner Keely Rushmore comments in People Management about the government's announcement.

Stained glass window Employment SA Law
Views & Insights
Smart Exits: Protected Conversations and Termination Payments

Chris Cook addresses the most appropriate ways of reaching a settlement when managing an employee's exit from a company.

Stained glass window Employment SA Law
Views & Insights
Increased rights for agency and zero-hours workers

The ‘Good Work Plan’ aims to address the rights of those with atypical worker statuses, including agency workers and those on zero-hours contracts.

Chris Cook handles the full range of employment law for both individuals and organisations. He receives particular recognition for his strong TUPE expertise.…
Chambers & Partners
Phone Box with Man in a Bowler Hat
Stained glass window Employment SA Law
Views & Insights
Consultation into extending redundancy protection for pregnant women and new parents

New consultation for redundancy protection while on or shortly after maternity leave or shared parental leave.

Stained glass window Employment SA Law
Views & Insights
A guide to flexible working & flexible working requests

Flexible working can assist employers in attracting and retaining talented candidates and staff. Our guide covers the key questions and considerations…

SA Law Red arrow neon light image
Views & Insights
Google issued with £44m fine over GDPR breach

Head of Employment and Data Protection, Chris Cook, explains Google's GDPR breach that led to landmark £44 million fine.

Stained glass window Employment SA Law
Views & Insights
CEO and average worker pay gap reporting launches

Latest comment in HR Magazine: Keely explains what HR teams should know about the CEO and average worker pay gap regulations, which come into force in…

Stained glass window Employment SA Law
Views & Insights
Deliveroo riders’ lose latest challenge to their employment status

The latest development in the Deliveroo gig-economy case sees riders appeal for trade union representation denied