The Computer Misuse Act 1990 is one of the first, and most important, examples of cybersecurity legislation in the UK.
It was introduced in response to the growing threat of cybercrime and was designed to address unauthorised access to computer systems and data. At its core, the legislation seeks to protect individuals, businesses, and governments from digital exploitation and malicious activity.
The Act not only applies to hackers breaking into systems for financial gain or mischief but also covers a broader spectrum of offences. It governs how individuals and organisations interact with data and systems.
The Act therefore has an important role in information governance and data protection.
Key Offences Under the Computer Misuse Act
1. Unauthorised Access to Computer Material
This is the most fundamental offense under the Act. It prohibits accessing computer systems, software, or data without authorisation. Whether someone guesses a password or exploits a system vulnerability, unauthorised access is illegal.
Crucially the unauthorised access need not be to a particular programme, application, or data. This means simply knowingly accessing a computer system without authorisation is an offence.
That means a person is in breach of the law if they improperly access a computer system with personal data on it, even if they do not access that data itself.
2. Unauthorised Access with Intent to Commit Further Offenses
Accessing a system unlawfully becomes a graver offense when the intent is to commit additional crimes, such as fraud or theft. This provision addresses scenarios where unauthorised entry is merely the first step in a broader criminal scheme.
Again, when it comes to the GDPR., this means any breach of the Data Protection Act committed in this way is also a breach of the Computer Misuse Act.
3. Unauthorised Acts with Intent to Impair Operations
This includes actions like deploying malware, ransomware, or viruses to disrupt the functionality of systems. Even if such acts do not result in immediate harm, the intent alone constitutes a breach.
4. Making, Supplying, or Obtaining Tools for Offenses
The Act also criminalises the creation, distribution, or possession of tools—such as hacking software—intended to facilitate computer misuse. This provision targets individuals who enable others to commit cybercrimes.
Sign Up Here:
The penalties for violating the Computer Misuse Act vary in severity, depending on the nature and impact of the offence. Lesser offenses, such as minor unauthorised access, are more likely to result in financial penalties. These fines serve as a deterrent for individuals and organisations who may otherwise underestimate the consequences of seemingly trivial infractions. More serious breaches, especially those involving malicious intent or significant harm, can lead to custodial sentences. Convictions for offenses like deploying ransomware or large-scale data breaches can result in prison terms of up to ten years. Beyond legal penalties, organisations found complicit in breaches often suffer reputational harm. Trust is a cornerstone of business operations, and any association with cybercrime can lead to loss of clientele, revenue, and partnerships. The General Data Protection Regulation (GDPR) emphasises safeguarding and protecting personal data. While the Computer Misuse Act addresses general unauthorised access and misuse, GDPR extends this protection to ensuring lawful and transparent data processing. Both frameworks aim to mitigate risks to individuals’ digital privacy. Organisations that fail to secure their systems in accordance with GDPR requirements may inadvertently enable violations of the Computer Misuse Act. For example, if poor cybersecurity measures lead to unauthorised access, the organisation could face GDPR fines alongside criminal investigations under the Computer Misuse Act. In 2020 an employee of Morrisons stole payroll data he had access to for audit purposes and published it. Morrisons’ employees sued the company claiming it was liable for the illegal actions of the employee who stole and published the data. Although Morrisons was ultimately found not to be liable, it had to go all the way to the Supreme Court to get that judgement, which took time, money and generated a lot of publicity. Adopting robust cybersecurity practices is essential for compliance with both the Computer Misuse Act and GDPR. This includes regular risk assessments, encryption of sensitive data, and the implementation of multi-factor authentication to prevent unauthorised access. You also need to have systems in place to identify wrongdoing including unauthorised access as soon as possible, to try and mitigate the risk of harm. This includes encouraging people to speak up if they think something inappropriate it happening. Good information governance ensures that data is managed responsibly. Organisations should implement policies that regulate who can access specific systems and data, with strict oversight mechanisms to detect and prevent unauthorised activities. Those policies should set out that access to systems is monitored, and the consequences of non-compliance. A key component of information governance (and GDPR compliance) is educating employees about their responsibilities. Awareness programs should highlight the risks and legal implications of breaching the Computer Misuse Act, reinforcing the importance of cybersecurity in day-to-day operations. Auditing system access logs and conducting penetration tests can help identify vulnerabilities before they are exploited. Incident response plans ensure swift action in the event of a breach, minimising damage and demonstrating accountability. Good information governance involves aligning various legal and regulatory requirements, such as the Computer Misuse Act, GDPR, and sector-specific standards. This integrated approach promotes compliance and mitigates risks across all facets of data management.Penalties for Breaching the Computer Misuse Act
1. Fines
2. Imprisonment
3. Reputational Damage and Legal Liabilities
The Relationship Between the Computer Misuse Act and GDPR
1. Shared Goals of Data Protection and Security
2. Liability for Breaches
Case Study
3. Proactive Measures for Compliance
Good Information Governance and the Computer Misuse Act
1. Establishing Clear Policies and Procedures
2. Training and Awareness
3. Regular Audits and Incident Response Plans
4. Integration of Governance Frameworks

Conclusion
The Computer Misuse Act, GDPR, and principles of good information governance collectively form a comprehensive framework for protecting digital assets and personal data. Adherence to these regulations is not just a legal necessity but a moral obligation. Organisations must proactively adopt measures to secure systems, educate stakeholders, and foster a culture of accountability. In doing so, they can navigate the challenges of the digital age while safeguarding the trust of their clients and partners.
Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.
Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: