top of page

What should you do if an employee takes company data?

  • 22 hours ago
  • 5 min read


An employee leaving your business may have access to customer lists, contact details, pricing information, employee records and other commercially sensitive information. If they copy or retain that information without permission, particularly to use it in a new role or competing business, you may need to act quickly.


Where the information includes personal data, the incident may also amount to a personal data breach under the UK GDPR and Data Protection Act 2018, potentially triggering obligations towards the Information Commissioner’s Office (ICO) and the individuals concerned.


The issue is therefore not simply getting your information back. You need to establish what has been taken, where it has gone, whether it has been used or disclosed, and what legal and practical steps are required to protect your business.


An employee has taken data without your permission

Employees routinely have access to significant amounts of business information. Depending on their role, this could include customer and supplier contacts, employee information, commercial terms, pricing information or other confidential material.

The risk is particularly acute when an employee is preparing to leave. Electronic information can be copied or transferred quickly, for example, by emailing files to a personal account, downloading information to a personal device or USB drive, or transferring documents to personal cloud storage.

If the information contains personal data and has been accessed, copied, retained or disclosed without authority, you may also be dealing with a personal data breach.

However, not every case of employee data theft is necessarily a personal data breach. Purely commercial information which does not relate to an identifiable individual may fall outside data protection legislation while remaining protected by the employee's contractual and confidentiality obligations.

The first problem for an employer is therefore to establish exactly what information has been taken and what has happened to it.


What happens if you do not deal with it quickly?

Delay can make the situation considerably more difficult.

An employee who has retained customer information could use it to approach your clients after joining a competitor or establishing a competing business. Confidential commercial information could be disclosed to third parties. Personal data could be used or shared without the knowledge of the individuals concerned.

There may also be regulatory consequences.

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, the employer may be required to notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where there is a high risk to affected individuals, they may also need to be informed.

Even where the breach does not need to be reported, the employer should document the incident and its assessment of whether notification was required.

This means that waiting to see what the employee does with the information may not be an appropriate response.


Could the employer be liable?

Potentially.

As data controller, an employer is responsible for putting appropriate technical and organisational measures in place to protect the personal data it processes.

Following an incident, questions may therefore arise about whether access to the information was appropriately controlled, whether adequate security arrangements were in place, and whether employees had received appropriate policies and training.

There is also a separate question of whether an employer can be responsible for an employee's wrongful conduct.

The Supreme Court considered this issue in the Morrisons litigation [Wm Morrison Supermarkets plc v Various Claimants [2020] UKSC 12], which arose after a disgruntled employee deliberately disclosed payroll data relating to approximately 100,000 employees. Morrisons was not held vicariously liable because the employee was pursuing a personal vendetta rather than acting in the ordinary course of his employment.

The decision does not, however, mean that employers can never be liable for an employee's misuse of data. Liability will depend on the circumstances, including the relationship between the employee's conduct and the work they were employed to perform. The source article identifies the Morrisons case as an important example of this distinction.


What are the consequences for the employee?

An employee who takes personal data without authority may themselves face significant consequences.

Under section 170 of the Data Protection Act 2018, knowingly or recklessly obtaining or disclosing personal data without the consent of the data controller, procuring its disclosure, or retaining personal data obtained without the controller's consent can constitute a criminal offence, subject to the statutory defences.

The employee's actions may also breach their employment contract, confidentiality obligations and company policies.

For a current employee, this may result in disciplinary action and potentially dismissal, depending on the circumstances. If the employee has already left, the employer may instead need to consider what steps are available to prevent the information being retained, disclosed or used.


What should you do when you discover that data has been taken?

The priority is to contain the problem and establish the facts before valuable evidence disappears or the information is disseminated further.

An employer faced with a suspected data theft should consider the following:

  1. Preserve the evidence. Identify relevant emails, downloads, access logs, USB activity, cloud transfers and other records which may show what information was accessed or removed.

  2. Secure your systems. Review and, where appropriate, remove the employee's access to email accounts, shared drives, databases and remote systems.

  3. Identify the information involved. Establish whether the employee has taken personal data, confidential commercial information or both.

  4. Find out what happened to it. There is an important difference between an employee having copied a document to a personal device and having sent your customer database to a competitor or used it to contact clients.

  5. Assess your data protection obligations. If personal data is involved, determine whether the incident needs to be notified to the ICO and/or the affected individuals.

  6. Consider action against the employee. Depending on the circumstances, this may include requiring the return or permanent deletion of information, obtaining appropriate undertakings, taking disciplinary action or considering legal proceedings.

  7. Check your insurance arrangements. Relevant cyber or other insurance policies may contain notification requirements.


Employers should be particularly careful about immediately confronting the employee where doing so could result in evidence being deleted or make it more difficult to establish what has happened.


Reduce the risk before an employee leaves

It is much easier to protect information before it has been taken.

Employers should consider whether employees have access only to the information they genuinely require for their roles and whether appropriate controls exist to identify unusual downloads or transfers.

Employment contracts and internal policies should also clearly address confidentiality, the use and copying of company information, use of personal devices and accounts, and employees' obligations to return and delete company information when their employment ends.

The employee's departure is particularly important. A proper offboarding process can include reviewing access rights, recovering company equipment and information, disabling access at the appropriate time and reminding the departing employee of continuing confidentiality and other post-termination obligations.

Any employee monitoring used to identify or prevent inappropriate use of information must itself be lawful, transparent and proportionate.


How can BLS help?

An employee taking company information can create several problems at once. What initially appears to be an employment issue may also involve data protection, confidentiality, restrictive covenants and the protection of commercially sensitive information.


We can help employers assess the legal implications of an incident and determine what action is required, including:

-assessing whether an incident constitutes a personal data breach and whether notification to the ICO or affected individuals is required;

-advising on the employer's rights against a current or former employee;

-preparing correspondence seeking the return or deletion of information and appropriate undertakings;

-advising on disciplinary action where the individual remains employed;

-reviewing confidentiality provisions, restrictive covenants and employment documentation; and

-advising on preventative measures to reduce the risk of similar incidents occurring in the future.


Action: speak to us before the problem escalates

If you believe that a current or former employee has taken customer information, personal data or confidential business information, early action can be important both to protect the information and to establish your legal position.

Contact BLS to discuss what has happened and the steps available to protect your business.

Comments


Featured Posts
Recent Posts
Archive
Search By Tags

Lega

Legal

Berard & Lovell Solicitors is a trading name of Berard & Lovell Limited. Registered in England & Wales, Company No 09003314. Authorised and regulated by the Solicitors Regulation Authority, Registration No 630918.

3 Heath Lodge, 4 St. Albans Rd, London NW5 1RD.

Copyright © 2016-2025 by Berard & Lovell Ltd.

            

Co5oWooWIAExYLS.jpg
  • LinkedIn - Grey Circle
  • Twitter Clean
  • Facebook
bottom of page