← Back to Regulatory Updates

Regulatory Update • July 2026

Employee Sentenced After Illegally Accessing Personal Information

Published: 21 July 2026 Topic: Access Controls / Staff Misuse Source: ICO Enforcement

The ICO has reported that an employee received a suspended sentence after unlawfully accessing hundreds of personal records.

The case is a reminder that staff access to personal information should be limited, monitored and clearly governed, especially where sensitive information is involved.

Reading time 2 minutes

What changed

The ICO has reported that a council employee received a suspended sentence after unlawfully accessing hundreds of personal records.

The case involved a Herefordshire Council employee who accessed approximately 490 records and downloaded 94 documents over a four-day period. The records included sensitive information relating to children and adults, including medical records, social worker reports and child and family assessments.

Why is staff access a data protection issue?

Staff access becomes a data protection issue when employees can view, download or use personal information without a legitimate work-related reason. Organisations must make sure access is limited, monitored and used only for authorised purposes.

Why this matters

This case is a reminder that data protection risk does not only come from hackers, lost laptops or external cyber attacks. It can also come from people inside an organisation who already have system access but use it for the wrong purpose.

Internal misuse can be especially serious where records contain sensitive or confidential information. Organisations should be able to show that access permissions are appropriate, staff understand their responsibilities, and unusual access can be detected and investigated. For wider updates across privacy, security and data protection, see our Regulatory Updates page.

What organisations should do

Organisations should review whether staff access to personal information is properly controlled, monitored and documented.

  • Check whether staff only have access to the systems and records they need for their role.
  • Remove or reduce access when people change roles, teams or responsibilities.
  • Use audit logs to monitor unusual access, downloads or searches.
  • Train staff on when they can and cannot access personal information.
  • Make clear that accessing records out of curiosity, personal interest or for non-work reasons is not allowed.
  • Review higher-risk areas involving special category data, children’s information or safeguarding records.
  • Have a clear process for investigating suspected internal misuse quickly.

Practical takeaway

Access to personal information should never be open-ended. Organisations should make sure staff can only access what they need, that access is monitored, and that misuse can be spotted and acted on quickly.

Grounded in

ICO enforcement reporting on a Herefordshire Council employee who unlawfully accessed approximately 490 records and downloaded 94 documents, including sensitive information relating to children and adults.

Sources

Future Implementation Support Waitlist