Council Employee Given Suspended Sentence for Illegal Personal Data Access 

Rogue employees accessing personal data for their own gain, or just morbid curiosity, is a real issue for organisations, especially in the public sector, who hold vast databases of information about service users. 

In May, the medical director of Nottingham University Hospitals issued a public apology after staff inappropriately accessed the medical records of victims of the Nottingham attacks. Eleven employees were dismissed following initial investigations into the data breaches. In the same month, Aintree Hospital in Liverpool admitted that nearly fifty employees had pried into the medical records of victims of the Southport knife attack. 

Section 170 of the Data Protection Act 2018 makes it a criminal offence for a person to knowingly or recklessly obtain or disclose personal data without the consent of the controller. Over the years there have been a number of prosecutions under section 170 usually resulting in a fine. Most recently a teenage mechanic was fined £706 after he shared a football referee address and phone number online following a controversial penalty decision.  

Section 170 prosecutions would have a much greater deterrent effect if the sanctions included a custodial sentence. Successive Information Commissioners have argued for this but to no avail. This has led to some cases of unauthorised data access being prosecuted under section 1 of the Computer Misuse Act 1990 which carries tougher sentences including a maximum of 2 years imprisonment on indictment.  

In July the ICO announced that it had used Section 1 to successfully prosecute a council worker who accessed hundreds of personal records without lawful authority. Geoffrey Smith was a new employee at Herefordshire Council working in the Children and Young People directorate. His conduct was discovered after concerns were raised within the council about potential unauthorised access to a referral case, prompting an investigation into other records he had accessed. That investigation revealed that, over a four-day period, Smith unlawfully accessed approximately 490 records and downloaded 94 documents. The records related to his family members and families known to him and included children and adults. The records accessed involved highly sensitive material such as medical records, social worker reports and child and family assessments.  

On 27th May 2026, Smith pleaded guilty to an offence under Section 1 of the Computer Misuse Act 1990. He was sentenced to two months imprisonment suspended for 12 months, 120 hours unpaid work, £2000 costs plus a victim surcharge of £154.  

If a disgruntled or rogue employee commits a data protection offence, the employer may also be liable for the consequences. More on this in episode 13 of the Guardians of Data podcast where we discuss: 

  • what happens when employees are involved in personal data breaches; 
  • the legal and practical issues arising when employees misuse personal data; 
  • how employers should approach workplace investigations involving personal data; and 
  • how to respond effectively to employee Data Subject Access Requests. 

Our guest is Andrew Latham, a partner in the Public Law team at Capsticks, who specialises in data protection and privacy law.  

Click here to listen to Andrew.

New Podcast: Managing Workplace Data Protection Risks 

The biggest data protection challenges facing organisations do not stem solely from cyber-attacks or AI deployment; they also arise from employees. Sometimes it’s an innocent mistake; an email sent to the wrong person, confidential information shared inadvertently or a document uploaded to the wrong system. In other cases, the issues are more serious; employees accessing information they have no business looking at, taking confidential data when they leave, or deliberately misusing personal information. 

When those situations arise, employers need to investigate what has happened, decide whether a breach needs to be reported to the ICO and manage employment law issues such as disciplinary action; all the while protect the rights of the individuals whose data is involved, including employees.  

And then there’s the inevitable employee Data Subject Access Request, or DSAR to deal with. Often made alongside a grievance or before Employment Tribunal proceedings, DSARs can present significant legal and practical challenges for employers trying to balance transparency with confidentiality and legal privilege. 

In Episode 13 of the Guardians of Data podcast we explore: 

  • what happens when employees are involved in personal data breaches; 
  • the legal and practical issues arising when employees misuse personal data; 
  • how employers should approach workplace investigations involving personal data; and 
  • how to respond effectively to employee Data Subject Access Requests. 

Our guest is Andrew Latham, a partner in the Public Law team at Capsticks, who specialises in data protection and privacy law.  

Listen on your preferred platform via our podcast page, or download the episode directly.

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’tdesigned for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Caroline Wong talking about responsible the impact of AI on Cybersecurity, Jen Persson, a privacy campaigner, explaining the privacy implications of the Government’s new plans for children’s data, and Ilyas Nagdee analysing the impact of predictive policing in human rights.