Summary
- When an employee takes personal data without permission, usually on leaving, both the employer and the employee can face data protection consequences.
- As data controller, the employer must keep personal data secure and may need to report the incident to the Information Commissioner’s Office within 72 hours.
- The employee can be prosecuted under section 170 of the Data Protection Act 2018, and may also face dismissal and a breach of contract claim.
- This guide explains the data protection risks of employee data theft for employers in the United Kingdom.
- LegalVision’s business lawyers specialise in advising clients on UK data protection and employee data theft.
Tips for Businesses
Restrict access to personal data to staff who need it. Keep audit trails and lawful monitoring in place. Set clear policies and contract terms banning removal of personal data. Train staff regularly. If you suspect theft, preserve evidence, cut access and take legal advice before contacting anyone.
Employee data theft happens when a member of staff takes personal data, such as customer lists or contact details, without the employer’s authorisation, often when leaving for a new role. Under the UK GDPR and the Data Protection Act 2018, the employer, as data controller, must protect that data and may need to report the incident to the Information Commissioner’s Office within 72 hours where it poses a risk to people’s rights. The employee can face criminal liability under section 170 of the Data Protection Act 2018 for knowingly obtaining or retaining personal data without consent. Employers can also be liable where the misuse is closely connected to the employee’s role. While data theft is a very broad concept, this article explores key data protection law issues arising when employees take personal data without authorisation when leaving their employer.
Risk Arising From Employees Taking Personal Data
Employees can often access a broad range of sensitive, confidential, and personal information in their everyday roles. But if an employee takes data, such as customer lists, when they leave, the business could face significant legal and commercial risks.
Insider threats are increasingly prevalent in the digital age, as many staff work remotely and have easy access to copy and download information. The risk is higher because much data is now electronic, which makes it far easier to copy or transfer large volumes quickly.
Employees may take personal data for various reasons. Some may mistakenly believe that taking customer contact details will help them in a new role, without realising the legal risks and consequences. Others can act out of spite if they feel unfairly treated and seek to cause deliberate harm by taking information on their departure.
Potential Data Protection Consequences Resulting From Data Theft
| Risk | What it means |
|---|---|
| Data breach | Unauthorised access to, copying or sharing personal data may amount to a data breach. |
| Employer liability | Employers must protect personal data and may need to notify the ICO and affected individuals. Serious breaches generally must be reported within 72 hours. |
| Regulatory action | The ICO may investigate and take enforcement action if an employer failed to protect personal data. |
| Employee liability | Employees may face criminal liability under section 170 of the Data Protection Act 2018 for knowingly or recklessly taking, sharing or retaining personal data without consent. |
| Workplace consequences | Employees may also face disciplinary action, dismissal or a breach of contract claim for breaking workplace policies or taking data when they leave. |
Call 0808 196 8584 for urgent assistance.
Otherwise, complete this form, and we will contact you within one business day.
Preventing Data Theft Risks
Data theft brings complications, uncertainty and stress, so prevention is better than cure. Employers can take several practical steps to reduce the risk.
Key examples include the following:
- Put technical and organisational measures in place that match the sensitivity of the personal data you process. For example, restrict access to personal data to key staff on a need-to-know basis.
- Audit trails and detection tools can help you spot suspicious activity and potential breaches. Any staff monitoring must be lawful and proportionate, and comes with its own legal rules.
- Introduce and actively enforce policies that protect personal information. For example, set clear rules that employees must not remove or use personal information without permission.
- Regular training is an essential safeguard. Employees need to understand the legal risks of misusing personal data and what your internal policies requires.
Legal Advice Regarding Data Theft Scenarios
Even with protective measures in place, you may still find that a staff member has committed data theft. If you suspect data theft, act quickly to work out which data has been affected and take the right steps. Depending on the circumstances, this may mean reporting the matter as a data breach and notifying your insurers, the regulator and, if necessary, affected individuals.
You may also need to take action against the employee to prevent further damage, depending on whether they still work for you or have left. Beyond data protection, data theft can create a range of other legal duties and risks. Legal advice helps you understand the full scope of the risks and take the right action to limit further damage.
This factsheet outlines the steps for notifying the ICO and affected individuals about personal data breaches.
First Steps When You Suspect Data Theft
| Act in the first 48 hours | When you suspect an employee has taken personal data, the first 48 hours matter most. Move quickly and keep a written record of what you find, because you may need it for the ICO, your insurer or a later claim. |
| Identify and preserve the evidence | Identify what data the employee accessed, copied or sent, and where it went. Check email logs, downloads to personal devices, USB activity and cloud file transfers. Preserve this evidence before anyone deletes it. |
| Cut access | Cut the employee’s access to your systems straight away, including remote logins and shared drives. If they have already left, contact them in writing and ask them to return or delete the data and confirm they have done so. |
| Report and take advice | Assess whether the incident is likely to risk people’s rights and freedoms. If it is, you must report it to the Information Commissioner’s Office within 72 hours of becoming aware. Tell your insurer early, as many cyber and management policies require prompt notice. Take legal advice before you contact the employee or the individuals affected, because what you say now can affect both your ICO position and any civil claim. |
Key Takeaways
With remote working now widespread, employees taking personal data without permission is increasingly common. Employee data theft can create significant legal, regulatory, and commercial risks for employers. Clear data access controls, policies, training and monitoring can help you reduce the risk. But if you suspect data theft, act urgently and seek legal advice on how to manage the incident.
LegalVision provides ongoing legal support for businesses through our fixed-fee legal membership. Our experienced data, privacy and IT lawyers help businesses manage contracts, employment law, disputes, intellectual property, and more, with unlimited access to specialist lawyers for a fixed monthly fee. To learn more about LegalVision’s legal membership, call 0808 196 8584 or visit our membership page.
Frequently Asked Questions
How can employers reduce the risk of data theft?
Employers may seek to reduce risk by restricting employee access to data, enforcing clear policies around data use, and providing comprehensive training so staff understand the risks around data theft to help prevent such behaviour from arising.
Is employee data theft a personal data breach?
If an employee takes data without authorisation, this would constitute a personal data breach under the UK GDPR. It may require reporting to the ICO within 72 hours if the breach is likely to result in a risk to individuals’ rights and freedoms.
Do we have to report employee data theft to the ICO?
Not every incident. You must report a personal data breach to the Information Commissioner’s Office within 72 hours only where it is likely to risk individuals’ rights and freedoms. Assess the severity, record your decision, and notify affected individuals if the risk is high.
Can an employee be prosecuted for taking personal data?
Yes. Under section 170 of the Data Protection Act 2018, knowingly or recklessly obtaining, disclosing or retaining personal data without the controller’s consent is a criminal offence, punishable by a fine. The employee may also face dismissal and a breach of contract claim.
We appreciate your feedback! Request your free consultation now.