We were working with a client recently to support data protection and a contract we were asked to review read that if the other party received personal data they should from our client they would keep it and use it.
We flagged this up as inappropriate partly because it could be a criminal offence under the Data Protection Act to do so.
Why?
The Criminal Offence of Knowingly or Recklessly Obtaining Personal Data
Most discussions about data protection focus on regulatory fines issued to organisations. However, the Data Protection Act 2018 (DPA 2018) also creates criminal offences for individuals. One of this is for those who knowingly or recklessly obtain, disclose, or retain personal data without lawful authority.
This offence, found in Section 170 DPA 2018, applies to individuals — not just organisations — and can lead to prosecution, fines, and significant reputational consequences.
What Does Section 170 Say?
Under Section 170 DPA 2018, a person commits an offence if they knowingly or recklessly:
- obtain or disclose personal data without the consent of the data controller, or
- procure the disclosure of personal data to another person without the controller’s consent, or
- retain personal data without the controller’s consent (where it was previously obtained unlawfully).
The offence focuses on absence of lawful authority and the mental element — knowingly or recklessly.
Key Elements of the Offence
To understand the scope of this offence, it helps to break it down.
- Personal Data Must Be Involved
The data must relate to an identified or identifiable living individual.
This could include:
- health records
- HR files
- customer databases
- financial information
- CCTV footage
- system login details
The offence does not apply to anonymised information, or to data about deceased people as these are outside the scope of the UK GDPR.
- No Lawful Authority
The person must lack authority to obtain, disclose, or retain the data.
This is critical. Many employees legitimately access personal data as part of their job. The offence arises when someone exceeds their authority or acts outside their role.
For example:
- accessing a system out of curiosity
- looking up a neighbour’s medical records
- passing on information to a third party without permission
- Knowingly or Recklessly
The offence requires intention or recklessness.
- Knowingly means the person understood they had no authority.
- Recklessly means they were aware of the risk that they lacked authority but proceeded anyway.
Simple accidents or genuine misunderstandings are unlikely to meet this threshold.

Sign Up Here:
Although often associated with malicious insiders, the offence can arise in a range of contexts. An NHS employee accessed the medical records of relatives and acquaintances without a clinical reason. Even though the employee did not disclose the data further, the act of unauthorised access itself constituted unlawful obtaining. Courts have consistently treated such “curiosity access” as a criminal matter because it undermines trust in sensitive systems. Key lesson: Accessing data without a legitimate work reason can amount to a criminal offence, even if no harm follows. In several historic prosecutions (under predecessor legislation and continued under the DPA 2018), individuals have obtained customer lists from employers and sold them to marketing companies. In one well-known example, an employee in the financial sector extracted personal data and disclosed it to third parties for payment. Here, the elements were clear: These cases often result in fines and criminal records. “Blagging” refers to impersonating someone to obtain personal data — for example, calling a utility company while pretending to be the account holder. Private investigators and journalists have historically been prosecuted for this conduct. The act of procuring disclosure — even if you never directly handle the data — can fall within Section 170. There have been multiple prosecutions involving police officers or public officials accessing databases for personal reasons. Examples include: The courts have treated misuse of privileged access particularly seriously. If an employee copies personal data before leaving and retains it without permission — for example, taking a customer list to a new employer — they may commit an offence. Retention itself can be unlawful if the original obtaining lacked authority. Section 170 offences are criminal matters prosecuted in the Magistrates’ Court or Crown Court. The penalties include: Imprisonment is not possible for this specific offence, but fines can be significant and of course people convicted of the offence will have a criminal record. Yes. The Act provides certain statutory defences, including where: Journalistic investigations can, in limited circumstances, rely on public interest defences — but the threshold is high. It is important to distinguish: The ICO can investigate both, but prosecution involves criminal procedure. This distinction matters because individuals sometimes assume “data protection is just a compliance issue.” In reality, serious misuse can lead to criminal records. Although the offence applies to individuals, organisations must create environments that reduce risk. Key safeguards include: Strong governance reduces both regulatory and criminal exposure. Remember, even if the organisation itself is a victim of the offence not having appropriate procedures (including training) in place could leave the organisation exposed to regulatory action. You can find more linked content here:
Section 170 of the Data Protection Act 2018 is a reminder that personal data is not just an administrative asset — it is protected by criminal law. Knowingly or recklessly accessing data without authority is not merely a policy breach. It can be a crime. For professionals with privileged access to sensitive systems or data — healthcare, policing, finance, HR, and IT — the message is clear: authority matters. Curiosity is not a defence.Common Scenarios That Can Trigger Prosecution
Case Study 1: NHS Employee Accessing Records Out of Curiosity
Case Study 2: Selling Customer Data
Case Study 3: “Blagging” Information
Case Study 4: Police or Public Sector Misuse of Systems
Case Study 5: Retaining Data After Leaving Employment
What Are the Penalties?
Are There Any Defences?
How This Offence Differs From Regulatory Breaches
What Organisations Should Do
Further Reading
Conclusion
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: