Skip to content

Information Theft By Employees In The UK: Legal Actions Employers Can Take

Summary

  • Employers can respond to suspected data theft through disciplinary action, civil claims for breach of confidence, urgent injunctions or criminal reporting, often combining several routes.
  • Data theft can justify summary dismissal for gross misconduct, provided the employer runs a fair and proportionate investigation first.
  • Where the stolen material includes personal data, the UK GDPR and the Data Protection Act 2018 require notifying the Information Commissioner’s Office within 72 hours, and the Computer Misuse Act 1990 may apply to unauthorised computer access.
  • This guide explains the legal options available to UK business owners when a business suspects an employee of taking confidential information or data, including the disciplinary, civil, criminal and data protection routes and the legislation behind each.
  • LegalVision’s employment lawyers advise UK businesses on running a fair misconduct investigation, pursuing civil claims for breach of confidence, and meeting ICO reporting deadlines after a suspected data theft.

Tips for Businesses
Investigate suspected data theft fairly, gather evidence, and give the employee a chance to respond before deciding on dismissal. Assess whether the stolen material includes personal data, since a breach must reach the Information Commissioner’s Office within 72 hours. Preserve evidence and consider an injunction only where misuse is ongoing and urgent. Speak to an employment lawyer at LegalVision about running a compliant investigation into suspected data theft.

Summarise with:
ChatGPT logo ChatGPT Perplexity logo Perplexity

On this page

UK employers have several legal routes against an employee suspected of taking confidential business information, and the right one depends on urgency and evidence. Disciplinary action can lead to summary dismissal where the theft amounts to gross misconduct. Civil claims for breach of confidence, urgent injunctions and criminal reporting under the Computer Misuse Act 1990 sit alongside disciplinary steps, and often run together rather than as alternatives. This article explains the disciplinary, civil, injunctive, criminal and data protection options available to a UK employer whose employee has taken confidential information, and the specific legislation behind the reporting and criminal offence routes.

Understanding The Staff Theft Problem 

Employees may misuse and remove business information without authority in simple yet damaging ways. 

For example, they might download client information onto personal devices, forward internal documents or try to copy sensitive information. These actions can cause lasting harm.

Remote and hybrid work can further increase the risk of misuse, especially where staff can access a wide range of information remotely without oversight. 

Employees who plan to join a competitor or start their own business may pose a higher risk.

The impact can be damaging and extend beyond commercial loss. If the stolen material includes personal data, the business may have specific reporting obligations under UK data protection law. Prompt action is therefore vital, as delays can increase the risk of financial loss and, in some cases, legal penalties. 

If you suspect an employee has taken data or information from your business, you may have several options. The best course of action will depend on the nature and severity of the conduct. 

Considering Employment and Disciplinary Measures

Your business may investigate suspected misconduct if you believe theft has occurred. You must conduct the investigation fairly and in accordance with your internal procedures. You are responsible for making sure the process is reasonable and proportionate.

In this case, you should carefully gather evidence and review it objectively. You will need to give the employee an opportunity to respond before making any decision. A rushed or one-sided process may weaken your position later if you are challenged. 

If there is evidence supporting the allegation, the theft of your business information may amount to gross misconduct.

In serious cases, this may justify dismissal of the employee without notice.

In some situations, you may suspend the employee while you investigate.

If you are unsure about how to handle employment processes, you should seek legal advice from an employment solicitor. 

Injunctions and Urgent Court Action

If you believe the employee or former employee is continuing to use or disclose confidential information, your business may need to pursue urgent legal protection.

You may, in some circumstances, be able to apply to the court for an injunction. An injunction is designed to stop further misuse and require the return or deletion of relevant material. The court may also order steps to preserve evidence, including requiring devices to be handed over for independent inspection.

Speed is important in these situations. If a competitor uses your information, commercial damage can escalate quickly.  However, this is an extremely challenging, costly and serious route and should be considered only in the most urgent cases. In most cases, it will not be practical. 

Civil Claims for Breach of Confidence or Contract

Your business may be able to pursue civil proceedings against a party that breaches confidentiality obligations. 

Clear contractual terms on confidentiality can strengthen your position and reduce disputes over which information qualifies as confidential.

Through civil claims, you may be able to seek financial compensation for losses caused by misuse and request that the court order the return or destruction of confidential material. In some cases, you may also seek an account of profits made through unlawful use.

Civil action may be pursued alongside disciplinary steps. The appropriate combination of actions will depend on the facts.

Criminal Reporting

In certain circumstances, your employee’s conduct may constitute a criminal offence. This may apply where there has been dishonesty or unauthorised access to computer systems.

Your business may consider reporting the matter to the relevant law enforcement bodies. However, you should consider the wider commercial and strategic implications before taking this step.

Data Protection and Regulatory Considerations

If the unauthorised use of information includes personal data, your business must thoroughly evaluate its regulatory obligations.

For instance, the unauthorised disclosure of personal data may constitute a personal data breach.

You should document your assessment of whether a data breach has occurred and consider the risk to individuals. If the legal threshold is met, you must notify the regulator within the statutory timeframe. Failure to manage reporting obligations properly may increase regulatory exposure.

Carefully assess your data protection and any other regulatory obligations once you learn of an employee’s theft. 

Continue reading this article below the form
Need legal advice?
Call 0808 196 8584 for urgent assistance.
Otherwise, complete this form, and we will contact you on the same business day.

Your business should seek legal advice to understand your options in specific data theft scenarios. Data theft cases could involve multiple areas of law and potential avenues of action, including employment law, confidentiality, data protection, and potentially criminal law.

It is important to understand the full implications of the incident before choosing a course of action. This means assessing the likely financial loss, the strength of the available evidence, the reputational impact and any regulatory exposure.

The level of urgency will influence your strategy. Ongoing misuse of information may require immediate injunctive relief. However, a minor or contained issue may allow you to concentrate on internal processes with the relevant employee. 

Taking Active Steps to Stop Future Misconduct

After dealing with a theft incident, your business should review lessons learned and its internal safeguards. 

For example:

  • check that you have clear employment contracts that define confidential information and set out obligations during and after employment;
  • make sure access to any sensitive data or material is restricted to only what is necessary for employees’ roles;
  • monitoring and internal audit processes should also be reviewed, provided you comply with the relevant legal requirements; or
  • regular or repeated training can help reinforce expectations and help staff understand their responsibilities.

No system will remove this risk entirely. However, continuing to focus on robust rules and policies, controlled access to information, and consistent enforcement may help you reduce the likelihood and impact of future employee theft.

“Businesses often treat data theft as one problem with one solution, when in reality the disciplinary process, the civil claim and the data protection notification usually need to run at the same time, not one after another. The biggest mistake I see is waiting for the internal investigation to finish before even checking whether a regulatory reporting clock has started.”

Paula Kumar
Paula Kumar Practice Leader, LegalVision
Front page of publication
Guide to UK Employment Disputes

Learn how to manage employment disputes and protect your business from legal action.

Download Now

Key Takeaways

Employee data theft can expose your business to serious commercial and legal risk. If you suspect such misconduct, your business should act promptly but fairly. There are a range of actions you may be able to take depending on the circumstances. You should seek legal advice to assess your options and the most appropriate route. 

LegalVision provides ongoing legal support for businesses through our fixed-fee legal membership. Our experienced employment lawyers help businesses manage contracts, employment law, disputes, intellectual property, and more, with unlimited access to specialist lawyers for a fixed monthly fee. To learn more about LegalVision’s legal membership, call 0808 196 8584 or visit our membership page.

Frequently Asked Questions

What can a UK employer do if an employee steals confidential information?

A business can investigate through its disciplinary procedure, pursue civil claims for breach of confidence, apply for an urgent injunction in serious cases, or report suspected criminal conduct. Several of these steps often run together rather than as separate alternatives.

How quickly must a business report a data breach to the ICO?

A business must notify the Information Commissioner’s Office within 72 hours of becoming aware of a personal data breach under UK GDPR and the Data Protection Act 2018. Missing this deadline is itself a breach, regardless of the underlying theft.

Can an employer dismiss an employee for stealing company data?

Yes, where the evidence supports it. Data theft can amount to gross misconduct, which may justify dismissal without notice, provided the employer follows a fair and proportionate investigation process first.

Is unauthorised access to a company’s computer systems a criminal offence?

Yes. The Computer Misuse Act 1990 makes it an offence for an employee to deliberately access computer material without permission, and the Data Protection Act 2018 separately criminalises obtaining or sharing personal data without authorisation.

Register for our free webinars

Ask a Contract Lawyer Live: The Legal Traps Putting Your Business at Risk

Online
Learn how to spot contract risks before they cost your business. Register for our free webinar.
Register Now

Director Duties for In-House Counsel: Governance Risks Boards Overlook

Online
Director duties and board governance risks for in-house counsel. Register for our free webinar.
Register Now

Construction Disputes: Protecting Payment and Managing Contract Risk

Online
Protect your construction business from risk during a dispute. Register for our free webinar.
Register Now

Managing Sponsored Workers: Your Ongoing Employer Duties

Online
Learn your ongoing sponsor licence duties and how to stay compliant. Register for our free webinar.
Register Now
See more webinars >
Avatar photo

Sej Lamba

Sej is an Expert Legal Contributor at LegalVision. She is an experienced legal content writer who enjoys writing legal guides, blogs, and know-how tools for businesses. She studied History at University College London and then developed a passion for law, which inspired her to become a qualified lawyer.

Qualifications: Legal Practice Course, Kaplan Law School; Graduate Diploma in Law, Kaplan Law School; BA, History, University College.

Read all articles by Sej

About LegalVision

LegalVision is an innovative commercial law firm that provides businesses with affordable, unlimited and ongoing legal assistance through our membership. We operate in Australia, the United Kingdom and New Zealand.

Learn more

LegalVision is an award-winning business law firm

  • Award

    2025 Future of Legal Services Innovation Finalist - Legal Innovation Awards

  • Award

    2024 Law Company of the Year Finalist - The Lawyer Awards

  • Award

    2024 Law Firm of the Year Finalist - Modern Law Private Client Awards

  • Award

    2023 Economic Innovator of the Year Finalist - The Spectator

  • Award

    2023 Law Company of the Year Finalist - The Lawyer Awards