Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

ICO Utilises the Computer Misuse Act to Impose Tougher Penalties for Unauthorised Access to Data

By Francesca Fellowes on February 22, 2021
Email this postTweet this postLike this postShare this post on LinkedIn

In this case, on the 8th January 2021, a former employee (“D”) of the RAC, (a well-known breakdown and recovery service in the UK and Europe) pleaded guilty to charges of conspiracy to secure unauthorised access to computer data and to selling unlawfully obtained personal data. The ICO investigation had found that D had been compiling lists of road traffic accident data without the permission of her employer. The data was accessible by virtue of D’s position as an RAC Performance Manager and included partial names, phone numbers and registration numbers. D was then unlawfully transferring the data to the director of an accident claims management firm, trading as LIS Claims (“S”), who then used this information to make nuisance calls to the relevant individuals.

Both S and D were found guilty of offences under the Act and were sentenced to eight months’ imprisonment, suspended for two years. They were also ordered to carry out 100 hours’ unpaid work and contribute £1,000 to costs. In addition, the court made a Confiscation Order under the Proceeds of Crimes Act 2002, requiring D and S to pay £25,000 and £15,000 respectively.

The ICO pursued prosecutions under the Act due to the severity of the data breaches. Typically, it would prosecute such offences under the DPA 2018, in reliance upon Section 170, which makes it an offence for a person to knowingly or recklessly:

  1. obtain or disclose personal data without the consent of the controller;
  2. procure the disclosure of personal data to another person without the consent of the controller; or
  3. after obtaining personal data, to retain it without the consent of the person who was the controller in relation to the personal data when it was obtained.

The maximum penalty for such an offence is a fine. However, the Computer Misuse Act makes provision for more severe sentences, including imprisonment. Under Section 1, it is an offence to cause a computer to perform a function with the intention to secure unauthorised access to any program or data held on that computer, carrying a maximum custodial (prison) sentence of up to two years.

This case, alongside comments from Mike Shaw (who heads up the Criminal Investigations team at the ICO), suggests that the ICO will make full use of the various legislative frameworks available to it in order to seek to match the level of punishment to the severity of the data breach. Mr Shaw stated,

offenders must know that we will use all the tools at our disposal to protect people’s information and prevent it from being used to make nuisance calls.

Furthermore, the ICO will make “full use of the Proceeds of Crime Act” to prevent criminals benefitting financially from their crimes.

We closely monitor trends in the ICO’s enforcement actions and prosecutions. The tougher stance taken by the ICO in this case should serve as a warning to individuals who seek to gain unauthorised access to personal data held electronically, that they may face not only penalties under the DPA 2018, but also prosecution and therefore tougher penalties under the Act.

This case also reinforces the message to businesses and organisations who are controllers of the personal data that they must prepare for and safeguard against the risks posed by rogue employees who gain unauthorised access to personal data electronically and/or sell it on. Security measures which aim to protect personal data from unauthorised or unlawful processing, such as those designed to identify unusual activity and data exports need to be sufficiently robust and effective to guard against both internal and external threats. The risks may be exacerbated by the increased number of employees working remotely and without regular supervision (including due to the COVID-19 pandemic). Employee vetting, training, regular communications and ongoing compliance checks are essential to reduce the risks.

Please do not hesitate to reach out to your usual Squire Patton Boggs contact, or any member of our Data Privacy and Cybersecurity team, for further information or assistance on this, or other related topics.

Photo of Francesca Fellowes Francesca Fellowes

Francesca Fellowes’ practice covers both commercial and intellectual property work. She has substantial experience in all aspects of non-contentious commercial work and specialises in both contentious and non-contentious intellectual property work. She also has a specialist knowledge of data protection law and in…

Francesca Fellowes’ practice covers both commercial and intellectual property work. She has substantial experience in all aspects of non-contentious commercial work and specialises in both contentious and non-contentious intellectual property work. She also has a specialist knowledge of data protection law and in particular, advising on the compliance aspects of and project-managing multi-jurisdictional projects for global clients.

Read more about Francesca FellowesEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Privacy World
  • Organization:
    Squire Patton Boggs
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo