Skip to content

Dealing With Employee Data Theft In The UK

Summary

  • When an employee takes personal data without permission, usually on leaving, both the employer and the employee can face data protection consequences.
  • As data controller, the employer must keep personal data secure and may need to report the incident to the Information Commissioner’s Office within 72 hours.
  • The employee can be prosecuted under section 170 of the Data Protection Act 2018, and may also face dismissal and a breach of contract claim.
  • This guide explains the data protection risks of employee data theft for employers in the United Kingdom.
  • LegalVision’s business lawyers specialise in advising clients on UK data protection and employee data theft.

Tips for Businesses

Restrict access to personal data to staff who need it. Keep audit trails and lawful monitoring in place. Set clear policies and contract terms banning removal of personal data. Train staff regularly. If you suspect theft, preserve evidence, cut access and take legal advice before contacting anyone.

Summarise with:
ChatGPT logo ChatGPT Perplexity logo Perplexity

On this page

Employee data theft happens when a member of staff takes personal data, such as customer lists or contact details, without the employer’s authorisation, often when leaving for a new role. Under the UK GDPR and the Data Protection Act 2018, the employer, as data controller, must protect that data and may need to report the incident to the Information Commissioner’s Office within 72 hours where it poses a risk to people’s rights. The employee can face criminal liability under section 170 of the Data Protection Act 2018 for knowingly obtaining or retaining personal data without consent. Employers can also be liable where the misuse is closely connected to the employee’s role. While data theft is a very broad concept, this article explores key data protection law issues arising when employees take personal data without authorisation when leaving their employer. 

Risk Arising From Employees Taking Personal Data

Employees can often access a broad range of sensitive, confidential, and personal information in their everyday roles. But if an employee takes data, such as customer lists, when they leave, the business could face significant legal and commercial risks.

However, staff who steal or misuse any type of company information or data, including confidential and non-personal business data, can trigger broader and serious legal and financial consequences beyond the scope of this article. Employers should seek tailored legal advice on those.

Insider threats are increasingly prevalent in the digital age, as many staff work remotely and have easy access to copy and download information. The risk is higher because much data is now electronic, which makes it far easier to copy or transfer large volumes quickly.

Employees may take personal data for various reasons. Some may mistakenly believe that taking customer contact details will help them in a new role, without realising the legal risks and consequences. Others can act out of spite if they feel unfairly treated and seek to cause deliberate harm by taking information on their departure.

A case involving Morrisons in 2020 shows this: an employee who felt mistreated during a disciplinary process leaked the data of around 100,000 staff.

The Supreme Court confirmed that Morrisons was not vicariously liable, because the employee acted far outside the course of his employment. But the court also made clear that employers can be liable where an employee misuses personal data as part of their job duties, depending on whether the conduct is closely connected to their role.

So employers need to understand that any misuse of employee data can carry serious consequences.

Potential Data Protection Consequences Resulting From Data Theft

RiskWhat it means
Data breachUnauthorised access to, copying or sharing personal data may amount to a data breach.
Employer liabilityEmployers must protect personal data and may need to notify the ICO and affected individuals. Serious breaches generally must be reported within 72 hours.
Regulatory actionThe ICO may investigate and take enforcement action if an employer failed to protect personal data.
Employee liabilityEmployees may face criminal liability under section 170 of the Data Protection Act 2018 for knowingly or recklessly taking, sharing or retaining personal data without consent.
Workplace consequencesEmployees may also face disciplinary action, dismissal or a breach of contract claim for breaking workplace policies or taking data when they leave.
Continue reading this article below the form
Need legal advice?
Call 0808 196 8584 for urgent assistance.
Otherwise, complete this form, and we will contact you within one business day.

Preventing Data Theft Risks

Data theft brings complications, uncertainty and stress, so prevention is better than cure. Employers can take several practical steps to reduce the risk.

Key examples include the following:

  • Put technical and organisational measures in place that match the sensitivity of the personal data you process. For example, restrict access to personal data to key staff on a need-to-know basis.
  • Audit trails and detection tools can help you spot suspicious activity and potential breaches. Any staff monitoring must be lawful and proportionate, and comes with its own legal rules.
  • Introduce and actively enforce policies that protect personal information. For example, set clear rules that employees must not remove or use personal information without permission.
  • Regular training is an essential safeguard. Employees need to understand the legal risks of misusing personal data and what your internal policies requires.

Key Statistics

  1. Staff sending data to personal devices caused 20% of insider breaches: In the ICO’s analysis of insider attacks in the education sector, a fifth of incidents came from staff sending data to personal devices.
  2. 92 section 170 cases investigated since 2018: The ICO’s criminal investigations team had looked into 92 cases involving section 170 offences as of June 2023. Verify directly with the ICO before publishing.
  3. 2,970 data security incidents reported in Q1 2024: Organisations reported 2,970 data security incidents to the ICO in the first quarter of 2024, up 21% year on year. Verify directly with the ICO before publishing.

Sources

  • Information Commissioner’s Office, 2025
  • Information Commissioner’s Office (reported via Local Government Lawyer), 2023
  • Information Commissioner’s Office, 2024

Even with protective measures in place, you may still find that a staff member has committed data theft. If you suspect data theft, act quickly to work out which data has been affected and take the right steps. Depending on the circumstances, this may mean reporting the matter as a data breach and notifying your insurers, the regulator and, if necessary, affected individuals.

You may also need to take action against the employee to prevent further damage, depending on whether they still work for you or have left. Beyond data protection, data theft can create a range of other legal duties and risks. Legal advice helps you understand the full scope of the risks and take the right action to limit further damage.

Front page of publication
Personal Data Breach Notification Factsheet

This factsheet outlines the steps for notifying the ICO and affected individuals about personal data breaches.

Download Now

First Steps When You Suspect Data Theft

Act in the first 48 hoursWhen you suspect an employee has taken personal data, the first 48 hours matter most. Move quickly and keep a written record of what you find, because you may need it for the ICO, your insurer or a later claim.
Identify and preserve the evidenceIdentify what data the employee accessed, copied or sent, and where it went. Check email logs, downloads to personal devices, USB activity and cloud file transfers. Preserve this evidence before anyone deletes it.
Cut accessCut the employee’s access to your systems straight away, including remote logins and shared drives. If they have already left, contact them in writing and ask them to return or delete the data and confirm they have done so.
Report and take adviceAssess whether the incident is likely to risk people’s rights and freedoms. If it is, you must report it to the Information Commissioner’s Office within 72 hours of becoming aware. Tell your insurer early, as many cyber and management policies require prompt notice. Take legal advice before you contact the employee or the individuals affected, because what you say now can affect both your ICO position and any civil claim.

Key Takeaways

With remote working now widespread, employees taking personal data without permission is increasingly common. Employee data theft can create significant legal, regulatory, and commercial risks for employers. Clear data access controls, policies, training and monitoring can help you reduce the risk. But if you suspect data theft, act urgently and seek legal advice on how to manage the incident.

LegalVision provides ongoing legal support for businesses through our fixed-fee legal membership. Our experienced data, privacy and IT lawyers help businesses manage contracts, employment law, disputes, intellectual property, and more, with unlimited access to specialist lawyers for a fixed monthly fee. To learn more about LegalVision’s legal membership, call 0808 196 8584 or visit our membership page.

Frequently Asked Questions

How can employers reduce the risk of data theft?

Employers may seek to reduce risk by restricting employee access to data, enforcing clear policies around data use, and providing comprehensive training so staff understand the risks around data theft to help prevent such behaviour from arising.

Is employee data theft a personal data breach?

If an employee takes data without authorisation, this would constitute a personal data breach under the UK GDPR. It may require reporting to the ICO within 72 hours if the breach is likely to result in a risk to individuals’ rights and freedoms.

Do we have to report employee data theft to the ICO?

Not every incident. You must report a personal data breach to the Information Commissioner’s Office within 72 hours only where it is likely to risk individuals’ rights and freedoms. Assess the severity, record your decision, and notify affected individuals if the risk is high.

Can an employee be prosecuted for taking personal data?

Yes. Under section 170 of the Data Protection Act 2018, knowingly or recklessly obtaining, disclosing or retaining personal data without the controller’s consent is a criminal offence, punishable by a fine. The employee may also face dismissal and a breach of contract claim.

Register for our free webinars

Consumer Rights and Returns: Ensuring Your Business is Compliant

Online
Learn what your business’ returns policy must include and how to handle related customer disputes. Register for our free webinar.
Register Now

Recruiting New Franchisees to Your Network: How to Avoid Costly Mistakes

Online
Learn how to select the right franchisees to reduce your risks and ensure your network grows. Register today to learn more.
Register Now

Is Your Marketing Exposing You? A Defamation and Advertising Risk Check For 2026

Online
Check your marketing for defamation and advertising risk before it costs you. Register for our free webinar.
Register Now

When AI Is Misused: How One Business Responded Without Runaway Legal Fees

Online
How one business recovered its IP without incurring high legal costs after relying on an AI-drafted contract. Register for our free webinar.
Register Now
See more webinars >

Maddison Zahra

Associate | View profile

Maddison is an Associate at LegalVision, working in the Commercial and Regulatory team. She has particular expertise in commercial contracts, data and privacy and regulatory compliance advice for small businesses and startups. She also has previous experience in Government and Property Law, where she worked with a variety of clients, from small to medium businesses to large corporate and Government clients.

Qualifications:  Bachelor of Laws, Bachelor of International Studies (International Business Major), University of New South Wales.

Read all articles by Maddison

About LegalVision

LegalVision is an innovative commercial law firm that provides businesses with affordable, unlimited and ongoing legal assistance through our membership. We operate in Australia, the United Kingdom and New Zealand.

Learn more

LegalVision is an award-winning business law firm

  • Award

    2025 Future of Legal Services Innovation Finalist - Legal Innovation Awards

  • Award

    2024 Law Company of the Year Finalist - The Lawyer Awards

  • Award

    2024 Law Firm of the Year Finalist - Modern Law Private Client Awards

  • Award

    2023 Economic Innovator of the Year Finalist - The Spectator

  • Award

    2023 Law Company of the Year Finalist - The Lawyer Awards