The Computer Misuse Act and GDPR

The Computer Misuse Act 1990 is one of the first, and most important, examples of cybersecurity legislation in the UK.

It was introduced in response to the growing threat of cybercrime and was designed to address unauthorised access to computer systems and data. At its core, the legislation seeks to protect individuals, businesses, and governments from digital exploitation and malicious activity.

The Act not only applies to hackers breaking into systems for financial gain or mischief but also covers a broader spectrum of offences. It governs how individuals and organisations interact with data and systems.

The Act therefore has an important role in information governance and data protection.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

 

Key Offences Under the Computer Misuse Act

 

1. Unauthorised Access to Computer Material

 

This is the most fundamental offense under the Act. It prohibits accessing computer systems, software, or data without authorisation. Whether someone guesses a password or exploits a system vulnerability, unauthorised access is illegal.

Crucially the unauthorised access need not be to a particular programme, application, or data. This means simply knowingly accessing a computer system without authorisation is an offence.

That means a person is in breach of the law if they improperly access a computer system with personal data on it, even if they do not access that data itself.

 

2. Unauthorised Access with Intent to Commit Further Offenses

 

Accessing a system unlawfully becomes a graver offense when the intent is to commit additional crimes, such as fraud or theft. This provision addresses scenarios where unauthorised entry is merely the first step in a broader criminal scheme.

Again, when it comes to the GDPR., this means any breach of the Data Protection Act committed in this way is also a breach of the Computer Misuse Act.

 

3. Unauthorised Acts with Intent to Impair Operations

 

This includes actions like deploying malware, ransomware, or viruses to disrupt the functionality of systems. Even if such acts do not result in immediate harm, the intent alone constitutes a breach.

 

4. Making, Supplying, or Obtaining Tools for Offenses

 

The Act also criminalises the creation, distribution, or possession of tools—such as hacking software—intended to facilitate computer misuse. This provision targets individuals who enable others to commit cybercrimes.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Penalties for Breaching the Computer Misuse Act

 

The penalties for violating the Computer Misuse Act vary in severity, depending on the nature and impact of the offence.

 

1. Fines

 

Lesser offenses, such as minor unauthorised access, are more likely to result in financial penalties. These fines serve as a deterrent for individuals and organisations who may otherwise underestimate the consequences of seemingly trivial infractions.

 

2. Imprisonment

 

More serious breaches, especially those involving malicious intent or significant harm, can lead to custodial sentences. Convictions for offenses like deploying ransomware or large-scale data breaches can result in prison terms of up to ten years.

 

3. Reputational Damage and Legal Liabilities

 

Beyond legal penalties, organisations found complicit in breaches often suffer reputational harm. Trust is a cornerstone of business operations, and any association with cybercrime can lead to loss of clientele, revenue, and partnerships.

 

The Relationship Between the Computer Misuse Act and GDPR

 

1. Shared Goals of Data Protection and Security

 

The General Data Protection Regulation (GDPR) emphasises safeguarding and protecting personal data. While the Computer Misuse Act addresses general unauthorised access and misuse, GDPR extends this protection to ensuring lawful and transparent data processing. Both frameworks aim to mitigate risks to individuals’ digital privacy.

 

2. Liability for Breaches

 

Organisations that fail to secure their systems in accordance with GDPR requirements may inadvertently enable violations of the Computer Misuse Act. For example, if poor cybersecurity measures lead to unauthorised access, the organisation could face GDPR fines alongside criminal investigations under the Computer Misuse Act.

 

Case Study

In 2020 an employee of Morrisons stole payroll data he had access to for audit purposes and published it. Morrisons’ employees sued the company claiming it was liable for the illegal actions of the employee who stole and published the data.

Although Morrisons was ultimately found not to be liable, it had to go all the way to the Supreme Court to get that judgement, which took time, money and generated a lot of publicity.

3. Proactive Measures for Compliance

 

Adopting robust cybersecurity practices is essential for compliance with both the Computer Misuse Act and GDPR. This includes regular risk assessments, encryption of sensitive data, and the implementation of multi-factor authentication to prevent unauthorised access.

You also need to have systems in place to identify wrongdoing including unauthorised access as soon as possible, to try and mitigate the risk of harm. This includes encouraging people to speak up if they think something inappropriate it happening.

 

Good Information Governance and the Computer Misuse Act

 

1. Establishing Clear Policies and Procedures

 

Good information governance ensures that data is managed responsibly. Organisations should implement policies that regulate who can access specific systems and data, with strict oversight mechanisms to detect and prevent unauthorised activities.

Those policies should set out that access to systems is monitored, and the consequences of non-compliance.

 

2. Training and Awareness

 

A key component of information governance (and GDPR compliance) is educating employees about their responsibilities. Awareness programs should highlight the risks and legal implications of breaching the Computer Misuse Act, reinforcing the importance of cybersecurity in day-to-day operations.

 

3. Regular Audits and Incident Response Plans

 

Auditing system access logs and conducting penetration tests can help identify vulnerabilities before they are exploited. Incident response plans ensure swift action in the event of a breach, minimising damage and demonstrating accountability.

 

4. Integration of Governance Frameworks

 

Good information governance involves aligning various legal and regulatory requirements, such as the Computer Misuse Act, GDPR, and sector-specific standards. This integrated approach promotes compliance and mitigates risks across all facets of data management.

 

An illustration of an information governance framework

 

Conclusion

 

The Computer Misuse Act, GDPR, and principles of good information governance collectively form a comprehensive framework for protecting digital assets and personal data. Adherence to these regulations is not just a legal necessity but a moral obligation. Organisations must proactively adopt measures to secure systems, educate stakeholders, and foster a culture of accountability. In doing so, they can navigate the challenges of the digital age while safeguarding the trust of their clients and partners.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial