Council Employee Given Suspended Sentence for Illegal Personal Data Access 

Rogue employees accessing personal data for their own gain, or just morbid curiosity, is a real issue for organisations, especially in the public sector, who hold vast databases of information about service users. 

In May, the medical director of Nottingham University Hospitals issued a public apology after staff inappropriately accessed the medical records of victims of the Nottingham attacks. Eleven employees were dismissed following initial investigations into the data breaches. In the same month, Aintree Hospital in Liverpool admitted that nearly fifty employees had pried into the medical records of victims of the Southport knife attack. 

Section 170 of the Data Protection Act 2018 makes it a criminal offence for a person to knowingly or recklessly obtain or disclose personal data without the consent of the controller. Over the years there have been a number of prosecutions under section 170 usually resulting in a fine. Most recently a teenage mechanic was fined £706 after he shared a football referee address and phone number online following a controversial penalty decision.  

Section 170 prosecutions would have a much greater deterrent effect if the sanctions included a custodial sentence. Successive Information Commissioners have argued for this but to no avail. This has led to some cases of unauthorised data access being prosecuted under section 1 of the Computer Misuse Act 1990 which carries tougher sentences including a maximum of 2 years imprisonment on indictment.  

In July the ICO announced that it had used Section 1 to successfully prosecute a council worker who accessed hundreds of personal records without lawful authority. Geoffrey Smith was a new employee at Herefordshire Council working in the Children and Young People directorate. His conduct was discovered after concerns were raised within the council about potential unauthorised access to a referral case, prompting an investigation into other records he had accessed. That investigation revealed that, over a four-day period, Smith unlawfully accessed approximately 490 records and downloaded 94 documents. The records related to his family members and families known to him and included children and adults. The records accessed involved highly sensitive material such as medical records, social worker reports and child and family assessments.  

On 27th May 2026, Smith pleaded guilty to an offence under Section 1 of the Computer Misuse Act 1990. He was sentenced to two months imprisonment suspended for 12 months, 120 hours unpaid work, £2000 costs plus a victim surcharge of £154.  

If a disgruntled or rogue employee commits a data protection offence, the employer may also be liable for the consequences. More on this in episode 13 of the Guardians of Data podcast where we discuss: 

  • what happens when employees are involved in personal data breaches; 
  • the legal and practical issues arising when employees misuse personal data; 
  • how employers should approach workplace investigations involving personal data; and 
  • how to respond effectively to employee Data Subject Access Requests. 

Our guest is Andrew Latham, a partner in the Public Law team at Capsticks, who specialises in data protection and privacy law.  

Click here to listen to Andrew.

Author: actnowtraining

Act Now Training is Europe's leading provider of information governance training, serving government agencies, multinational corporations, financial institutions, and corporate law firms. Our associates have decades of information governance experience. We pride ourselves on delivering high quality training that is practical and makes the complex simple. Our extensive programme ranges from short webinars and one day workshops through to higher level practitioner certificate courses delivered online or in the classroom.

Leave a Reply

Discover more from Your Front Page For Information Governance News

Subscribe now to keep reading and get access to the full archive.

Continue reading