Knowingly or Recklessly Obtaining Personal Data

We were working with a client recently to support data protection and a contract we were asked to review read that if the other party received personal data they should from our client they would keep it and use it.

We flagged this up as inappropriate partly because it could be a criminal offence under the Data Protection Act to do so.

Why?

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

The Criminal Offence of Knowingly or Recklessly Obtaining Personal Data

Most discussions about data protection focus on regulatory fines issued to organisations. However, the Data Protection Act 2018 (DPA 2018) also creates criminal offences for individuals. One of this is for those who knowingly or recklessly obtain, disclose, or retain personal data without lawful authority.

This offence, found in Section 170 DPA 2018, applies to individuals — not just organisations — and can lead to prosecution, fines, and significant reputational consequences.

What Does Section 170 Say?

Under Section 170 DPA 2018, a person commits an offence if they knowingly or recklessly:

  • obtain or disclose personal data without the consent of the data controller, or
  • procure the disclosure of personal data to another person without the controller’s consent, or
  • retain personal data without the controller’s consent (where it was previously obtained unlawfully).

The offence focuses on absence of lawful authority and the mental element — knowingly or recklessly.

Key Elements of the Offence

To understand the scope of this offence, it helps to break it down.

  1. Personal Data Must Be Involved

The data must relate to an identified or identifiable living individual.
This could include:

  • health records
  • HR files
  • customer databases
  • financial information
  • CCTV footage
  • system login details

The offence does not apply to anonymised information, or to data about deceased people as these are outside the scope of the UK GDPR.

  1. No Lawful Authority

The person must lack authority to obtain, disclose, or retain the data.

This is critical. Many employees legitimately access personal data as part of their job. The offence arises when someone exceeds their authority or acts outside their role.

For example:

  • accessing a system out of curiosity
  • looking up a neighbour’s medical records
  • passing on information to a third party without permission
  1. Knowingly or Recklessly

The offence requires intention or recklessness.

  • Knowingly means the person understood they had no authority.
  • Recklessly means they were aware of the risk that they lacked authority but proceeded anyway.

Simple accidents or genuine misunderstandings are unlikely to meet this threshold.

 

Periodic Table of the GDPR

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Common Scenarios That Can Trigger Prosecution

Although often associated with malicious insiders, the offence can arise in a range of contexts.

Case Study 1: NHS Employee Accessing Records Out of Curiosity

An NHS employee accessed the medical records of relatives and acquaintances without a clinical reason.

Even though the employee did not disclose the data further, the act of unauthorised access itself constituted unlawful obtaining. Courts have consistently treated such “curiosity access” as a criminal matter because it undermines trust in sensitive systems.

Key lesson: Accessing data without a legitimate work reason can amount to a criminal offence, even if no harm follows.

Case Study 2: Selling Customer Data

In several historic prosecutions (under predecessor legislation and continued under the DPA 2018), individuals have obtained customer lists from employers and sold them to marketing companies.

In one well-known example, an employee in the financial sector extracted personal data and disclosed it to third parties for payment.

Here, the elements were clear:

  • personal data was obtained,
  • there was no lawful authority,
  • the action was intentional.

These cases often result in fines and criminal records.

Case Study 3: “Blagging” Information

“Blagging” refers to impersonating someone to obtain personal data — for example, calling a utility company while pretending to be the account holder.

Private investigators and journalists have historically been prosecuted for this conduct.

The act of procuring disclosure — even if you never directly handle the data — can fall within Section 170.

Case Study 4: Police or Public Sector Misuse of Systems

There have been multiple prosecutions involving police officers or public officials accessing databases for personal reasons.

Examples include:

  • checking vehicle registration systems for personal disputes,
  • accessing records relating to acquaintances,
  • using official systems to look up individuals out of curiosity.

The courts have treated misuse of privileged access particularly seriously.

Case Study 5: Retaining Data After Leaving Employment

If an employee copies personal data before leaving and retains it without permission — for example, taking a customer list to a new employer — they may commit an offence.

Retention itself can be unlawful if the original obtaining lacked authority.

What Are the Penalties?

Section 170 offences are criminal matters prosecuted in the Magistrates’ Court or Crown Court.

The penalties include:

  • a fine
  • a criminal conviction,
  • reputational and career damage,
  • potential dismissal from employment.

Imprisonment is not possible for this specific offence, but fines can be significant and of course people convicted of the offence will have a criminal record.

Are There Any Defences?

Yes. The Act provides certain statutory defences, including where:

  • the obtaining or disclosure was necessary for preventing or detecting crime,
  • it was required by law or court order,
  • it was justified in the public interest,
  • the person reasonably believed they had lawful authority.

Journalistic investigations can, in limited circumstances, rely on public interest defences — but the threshold is high.

How This Offence Differs From Regulatory Breaches

It is important to distinguish:

  • Organisational GDPR breaches → typically result in ICO enforcement, civil penalties, reprimands, or corrective orders.
  • Section 170 offences → are criminal prosecutions.

The ICO can investigate both, but prosecution involves criminal procedure.

This distinction matters because individuals sometimes assume “data protection is just a compliance issue.” In reality, serious misuse can lead to criminal records.

What Organisations Should Do

Although the offence applies to individuals, organisations must create environments that reduce risk.

Key safeguards include:

  • strict role-based access controls
  • audit logging and monitoring of system access
  • clear acceptable use policies
  • staff training on lawful authority
  • disciplinary procedures for misuse
  • prompt reporting of suspicious access patterns

Strong governance reduces both regulatory and criminal exposure. Remember, even if the organisation itself is a victim of the offence not having appropriate procedures (including training) in place could leave the organisation exposed to regulatory action.

Further Reading

You can find more linked content here:

Conclusion

Section 170 of the Data Protection Act 2018 is a reminder that personal data is not just an administrative asset — it is protected by criminal law.

Knowingly or recklessly accessing data without authority is not merely a policy breach. It can be a crime.

For professionals with privileged access to sensitive systems or data — healthcare, policing, finance, HR, and IT — the message is clear: authority matters. Curiosity is not a defence.