ICO investigation leads to sentence for unlawful council-record access: what employers should do

Scott Dooley
5 min read · Jul 28, 2026

A new ICO case is a useful reminder that personal-data risk is not limited to phishing, lost devices or external attackers. On 21 July 2026, the ICO announcement reported that a former Herefordshire Council employee received a suspended prison sentence after unlawfully accessing sensitive records. For employers, the practical lesson is to make sure staff access is limited, reviewable and acted on when something looks wrong.

What the ICO investigation found

The ICO says the employee worked in Herefordshire Council’s Children and Young People directorate. Concerns about unauthorised access to a referral case led the council to investigate other records. Over four days, the investigation found that he had accessed approximately 490 records and downloaded 94 documents. The information included medical records, social-worker reports and child and family assessments relating to people known to him.

On 27 May 2026, he pleaded guilty to an offence under section 1 of the Computer Misuse Act 1990. The ICO reported that Worcester Magistrates’ Court imposed two months’ imprisonment, suspended for 12 months, 120 hours of unpaid work, £2,000 costs and a victim surcharge. The ICO’s account concerns the individual’s misuse of access; it does not say that Herefordshire Council was fined or prosecuted.

Why role-based access is not enough

Role-based access is an important starting point: people should be able to reach only the systems and information needed for their job. But a role can still be wider than a particular case requires. In this incident, the concern arose because the records did not have a legitimate work purpose for the employee. Controls therefore need to answer two questions: “Can this role access this system?” and “Why is this person accessing this record now?”

This is especially important where staff handle children’s, health or safeguarding information. The ICO’s data-security guidance stresses the need for appropriate organisational and technical measures. A clear process, usable systems and regular supervision give managers a better chance of detecting misuse early than a policy sitting on its own.

Five controls to reduce employee data misuse

1. Review access by role and by case

Document which teams need each system, remove access promptly when jobs change, and make higher-risk case files available only where there is a defined work need. Periodic access reviews should have an accountable manager, an evidence trail and a deadline for removing unnecessary permissions.

2. Use audit logs that can be investigated

Log record views, searches, downloads and exports with the user, time and record reference. Decide in advance which patterns trigger review, such as repeated access to records outside a caseload, unusual volumes, downloads shortly before departure or searches for people known to an employee. An alert is useful only if someone owns the triage and can preserve the evidence.

3. Give managers a clear escalation route

Managers need to know where to send a concern and what information to retain. That should include a route to information governance, HR, security and legal advisers where appropriate. Avoid informal fact-finding that changes records or tips off a suspect before the organisation has agreed how to preserve evidence and protect affected people.

4. Train for real access decisions

Training should make the rule operational: access personal data only for a legitimate work purpose, not out of curiosity, personal connection or convenience. Scenarios based on the systems people actually use are more memorable than generic reminders. This complements the broader expectations explained in our guide to employee data under GDPR.

5. Test the controls, not only the policy

Ask whether a supervisor could identify an inappropriate record view, how quickly the team could restrict access, and whether the audit trail would support a fair investigation. Tabletop exercises can expose gaps in handoffs between IT, HR and information governance before a real incident creates pressure.

What to do after suspected unauthorised access

First, contain the risk without destroying evidence: restrict access where justified, preserve relevant logs and identify which records may be involved. Then use a documented investigation process to establish the facts, including the employee’s role, the apparent purpose of access, the categories of data and whether anything was downloaded or disclosed.

Assess whether the incident is a personal data breach and whether it needs to be reported to the ICO. The regulator’s personal data breach guidance explains that organisations must report a notifiable breach without undue delay and, where feasible, within 72 hours of becoming aware of it. Involve the people responsible for that assessment early; do not assume that an internal misuse incident is automatically reportable, or automatically not reportable.

A practical checklist for employers

  • Confirm that each sensitive system has an owner and a current access matrix.
  • Set a recurring review for privileged, leaver and role-change access.
  • Retain logs for record views and downloads long enough to investigate concerns.
  • Define alert patterns and assign a named triage owner.
  • Give staff and managers a short, practical route for reporting suspected misuse.
  • Test the investigation and breach-assessment process with a realistic scenario.

Frequently asked questions

Can an employee be prosecuted for accessing personal data without a work reason?

The Herefordshire case shows that unauthorised access can lead to criminal consequences on its own facts. Whether an offence has been committed depends on the evidence and applicable law. Employers should obtain appropriate advice rather than treating one case as a rule for every incident.

What audit controls help identify unauthorised staff access?

Useful logs capture who accessed which record, when, what they did and whether they downloaded or exported data. Pair that evidence with a defined review process and escalation owner.

What should an employer do when it suspects employee data misuse?

Contain the risk, preserve evidence, investigate fairly and assess whether the event is a personal data breach. The appropriate response will depend on the facts, systems and information involved.

Sources

Author

  • Scott Dooley is a seasoned entrepreneur and data protection expert with over 15 years of experience in the tech industry. As the founder of Measured Collective and Kahunam, Scott has dedicated his career to helping businesses navigate the complex landscape of data privacy and GDPR compliance.

    With a background in marketing and web development, Scott brings a unique perspective to data protection issues, understanding both the technical and business implications of privacy regulations. His expertise spans from cookie compliance to implementing privacy-by-design principles in software development.

    Scott is passionate about demystifying GDPR and making data protection accessible to businesses of all sizes. Through his blog, he shares practical insights, best practices, and the latest developments in data privacy law, helping readers stay informed and compliant in an ever-changing regulatory environment.

    View all posts