What changed
The ICO has reported that a council employee received a suspended sentence after unlawfully accessing hundreds of personal records.
The case involved a Herefordshire Council employee who accessed approximately 490 records and downloaded 94 documents over a four-day period. The records included sensitive information relating to children and adults, including medical records, social worker reports and child and family assessments.
Why is staff access a data protection issue?
Staff access becomes a data protection issue when employees can view, download or use personal information without a legitimate work-related reason. Organisations must make sure access is limited, monitored and used only for authorised purposes.
Why this matters
This case is a reminder that data protection risk does not only come from hackers, lost laptops or external cyber attacks. It can also come from people inside an organisation who already have system access but use it for the wrong purpose.
Internal misuse can be especially serious where records contain sensitive or confidential information. Organisations should be able to show that access permissions are appropriate, staff understand their responsibilities, and unusual access can be detected and investigated. For wider updates across privacy, security and data protection, see our Regulatory Updates page.
What organisations should do
Organisations should review whether staff access to personal information is properly controlled, monitored and documented.
- Check whether staff only have access to the systems and records they need for their role.
- Remove or reduce access when people change roles, teams or responsibilities.
- Use audit logs to monitor unusual access, downloads or searches.
- Train staff on when they can and cannot access personal information.
- Make clear that accessing records out of curiosity, personal interest or for non-work reasons is not allowed.
- Review higher-risk areas involving special category data, children’s information or safeguarding records.
- Have a clear process for investigating suspected internal misuse quickly.
Practical takeaway
Access to personal information should never be open-ended. Organisations should make sure staff can only access what they need, that access is monitored, and that misuse can be spotted and acted on quickly.
Grounded in
ICO enforcement reporting on a Herefordshire Council employee who unlawfully accessed approximately 490 records and downloaded 94 documents, including sensitive information relating to children and adults.
Sources
- Information Commissioner’s Office: Herefordshire employee handed suspended sentence for illegally accessing personal information , 21 July 2026.
- Information Commissioner’s Office: guidance on security under UK GDPR .