A new ICO case is a useful reminder that personal-data risk is not limited to phishing, lost devices or external attackers. On 21 July 2026, the ICO announcement reported that a former Herefordshire Council employee received a suspended prison sentence after unlawfully accessing sensitive records. For employers, the practical lesson is to make sure staff access is limited, reviewable and acted on when something looks wrong.
What the ICO investigation found
The ICO says the employee worked in Herefordshire Council’s Children and Young People directorate. Concerns about unauthorised access to a referral case led the council to investigate other records. Over four days, the investigation found that he had accessed approximately 490 records and downloaded 94 documents. The information included medical records, social-worker reports and child and family assessments relating to people known to him.
On 27 May 2026, he pleaded guilty to an offence under section 1 of the Computer Misuse Act 1990. The ICO reported that Worcester Magistrates’ Court imposed two months’ imprisonment, suspended for 12 months, 120 hours of unpaid work, £2,000 costs and a victim surcharge. The ICO’s account concerns the individual’s misuse of access; it does not say that Herefordshire Council was fined or prosecuted.
Why role-based access is not enough
Role-based access is an important starting point: people should be able to reach only the systems and information needed for their job. But a role can still be wider than a particular case requires. In this incident, the concern arose because the records did not have a legitimate work purpose for the employee. Controls therefore need to answer two questions: “Can this role access this system?” and “Why is this person accessing this record now?”
This is especially important where staff handle children’s, health or safeguarding information. The ICO’s data-security guidance stresses the need for appropriate organisational and technical measures. A clear process, usable systems and regular supervision give managers a better chance of detecting misuse early than a policy sitting on its own.
Five controls to reduce employee data misuse
1. Review access by role and by case
Document which teams need each system, remove access promptly when jobs change, and make higher-risk case files available only where there is a defined work need. Periodic access reviews should have an accountable manager, an evidence trail and a deadline for removing unnecessary permissions.
2. Use audit logs that can be investigated
Log record views, searches, downloads and exports with the user, time and record reference. Decide in advance which patterns trigger review, such as repeated access to records outside a caseload, unusual volumes, downloads shortly before departure or searches for people known to an employee. An alert is useful only if someone owns the triage and can preserve the evidence.
3. Give managers a clear escalation route
Managers need to know where to send a concern and what information to retain. That should include a route to information governance, HR, security and legal advisers where appropriate. Avoid informal fact-finding that changes records or tips off a suspect before the organisation has agreed how to preserve evidence and protect affected people.
4. Train for real access decisions
Training should make the rule operational: access personal data only for a legitimate work purpose, not out of curiosity, personal connection or convenience. Scenarios based on the systems people actually use are more memorable than generic reminders. This complements the broader expectations explained in our guide to employee data under GDPR.
5. Test the controls, not only the policy
Ask whether a supervisor could identify an inappropriate record view, how quickly the team could restrict access, and whether the audit trail would support a fair investigation. Tabletop exercises can expose gaps in handoffs between IT, HR and information governance before a real incident creates pressure.
What to do after suspected unauthorised access
First, contain the risk without destroying evidence: restrict access where justified, preserve relevant logs and identify which records may be involved. Then use a documented investigation process to establish the facts, including the employee’s role, the apparent purpose of access, the categories of data and whether anything was downloaded or disclosed.
Assess whether the incident is a personal data breach and whether it needs to be reported to the ICO. The regulator’s personal data breach guidance explains that organisations must report a notifiable breach without undue delay and, where feasible, within 72 hours of becoming aware of it. Involve the people responsible for that assessment early; do not assume that an internal misuse incident is automatically reportable, or automatically not reportable.
A practical checklist for employers
- Confirm that each sensitive system has an owner and a current access matrix.
- Set a recurring review for privileged, leaver and role-change access.
- Retain logs for record views and downloads long enough to investigate concerns.
- Define alert patterns and assign a named triage owner.
- Give staff and managers a short, practical route for reporting suspected misuse.
- Test the investigation and breach-assessment process with a realistic scenario.
Frequently asked questions
Can an employee be prosecuted for accessing personal data without a work reason?
The Herefordshire case shows that unauthorised access can lead to criminal consequences on its own facts. Whether an offence has been committed depends on the evidence and applicable law. Employers should obtain appropriate advice rather than treating one case as a rule for every incident.
What audit controls help identify unauthorised staff access?
Useful logs capture who accessed which record, when, what they did and whether they downloaded or exported data. Pair that evidence with a defined review process and escalation owner.
What should an employer do when it suspects employee data misuse?
Contain the risk, preserve evidence, investigate fairly and assess whether the event is a personal data breach. The appropriate response will depend on the facts, systems and information involved.
