Info Gov

Data theft shutterstock 183269990

Recently, the Information Commissioner’s Office published the outcome of a criminal prosecution.

The title?

Just two names: Christopher Munro and William Chipoma.

No explanation. No softening. No anonymity.

And that, in itself, is a powerful lesson in how data protection law really works.

Data protection isn’t about secrecy

There’s a persistent myth that data protection is about hiding information.

It isn’t.

It’s about using personal data lawfully, fairly and appropriately.

In this case, the ICO has deliberately published the names of two individuals convicted of unlawfully accessing and selling personal data. That information is now:

- Public
- Searchable
- Permanently associated with them

That’s not a failure of data protection.
That’s data protection law working exactly as intended.

From exploiting data… to becoming the data

The facts of the case are stark.

Both individuals deliberately sought employment in organisations handling personal data. Not to do the job, but to gain access.

They then:

- Accessed thousands of records without authority
- Sold personal data for financial gain
- Moved roles when access was restricted

This wasn’t a mistake. It wasn’t poor training.
It was intentional misuse of personal data for profit.

And now, their own personal data is being used to hold them accountable.

The risk most organisations underestimate

When businesses think about data protection risk, they usually think about:

- Hackers
- Cyber attacks
- External threats

But this case highlights a different reality:

The biggest risk to your data may already have legitimate access to it.

This is insider threat.

No sophisticated hacking required.

Just:

- Access to systems
- Weak controls
- Lack of monitoring

What this means for your organisation

This isn’t just an interesting case. It’s a warning.

If your organisation handles personal data (and every organisation does), you should be asking:

- Who has access to your data and why?
- Are access levels genuinely limited to what’s necessary?
- Would you know if someone was extracting large volumes of data?
- Do you review access regularly, or just set it and forget it?

And perhaps most importantly:

- Are you assuming trust, instead of actively managing risk?

The bigger picture

The ICO publishing two names in a headline is not heavy-handed.

It’s deliberate.

It demonstrates that data protection law is not about shielding people from consequences. It’s about ensuring personal data is used appropriately, whether that’s protecting individuals, or holding them to account.

Final thought

Everyone worries about hackers.

Far fewer organisations consider the risk of someone walking through the front door, gaining access legitimately, and misusing data from the inside.

But as this case shows, that risk is very real and the consequences are too.

Jemma Handley is the founder of JH Data Protection Ltd, a specialist data protection consultancy led by a legally‑qualified advisor providing support on UK GDPR, EU GDPR and privacy law, including DPIAs, risk assessments, policy development, training and external DPO services.

Also in this section

May 26, 2026

Key Data Protection Issues for Automated Recruitment in the Public Sector

The need to recruit faster in a competitive market, the need to minimise costs in the recruitment process, and the need to secure the best candidate quickly, makes the use of AI an appealing option for any employer including public bodies. But there are pitfalls for the unwary write David Leach and Charlotte Smith.
May 08, 2026

Schools warned over AI blackmail threat as guidance urges rethink on pupil images

Schools across the UK are being urged to review or remove identifiable photographs of pupils from their websites and social media accounts, following warnings that criminals are using artificial intelligence tools to manipulate those images into child sexual abuse material (CSAM) and then threaten to release it unless a ransom is paid.
Apr 28, 2026

AI in Education: Why Data Protection Must Come First

Artificial Intelligence promises a lot. It can undoubtedly do amazing things. But secretly (or maybe not so secretly), it also makes us slightly nervous. Adam Halsey looks at what this means for schools, and why data protection needs to sit at the centre of any decision to use AI.
Apr 22, 2026

Preparing for the new complaints regime

From 19 June 2026, all organisations acting as data controllers are required to have in place an effective process to enable individuals to raise complaints about how their personal data is handled. Ashleigh Dibb looks at what this will mean in practice.
Mar 27, 2026

Tribunal strikes out s.166 DPA 2018 application over medical records dispute

The First‑tier Tribunal has rejected a complaint against the Information Commissioner (ICO), deeming that an application under section 166 Data Protection Act 2018 against an ICO finding was seeking a ruling on the substantive merits of a complaint when s166 should only be applied to procedural defects in an ICO investigation.

InfoGov Masthead Newsletter 800