A local government employee in England has been convicted of unlawfully accessing sensitive personal data after snooping on records of people he knew. Geoffrey Smith, 31, worked in Herefordshire Council's Children and Young People directorate when he accessed approximately 490 records and downloaded 94 documents over a four-day period. The Information Commissioner's Office (ICO) confirmed the records included highly sensitive material such as medical records, social worker reports, and child and family assessments.
Smith pleaded guilty to an offense under Section 1 of the Computer Misuse Act 1990, which prohibits unauthorized access to computer systems. Worcester Magistrates' Court sentenced him on July 17 to two months' imprisonment, suspended for 12 months. The court also ordered him to complete 120 hours of unpaid work and pay £2,000 in costs plus a £154 victim surcharge.
The case highlights the risks posed by insider threats in organizations handling sensitive personal information. Smith had legitimate access to council systems as part of his role but used that access to view records of family members and other individuals known to him without any work-related justification. The systematic nature of the access over multiple days demonstrated deliberate misuse rather than accidental viewing.
The breach affects vulnerable populations whose information was stored in the Children and Young People directorate systems. These records typically contain some of the most sensitive personal data held by local authorities, including details about child welfare cases, family circumstances, and medical conditions. The unauthorized access violated the privacy rights of multiple adults and children whose information was viewed or downloaded.
Organizations handling sensitive personal data should implement robust access controls and monitoring systems to detect unusual patterns of record access. Regular audits of who accesses what information can help identify potential insider threats before they escalate. The ICO emphasized that individuals have a right to expect their personal information remains secure and is only accessed for legitimate purposes by authorized personnel.
Source: https://www.theregister.com/security/2026/07/22/council-worker-spared-prison-after-four-day-data-snooping-spree/5276054


