Jul 22, 2026
Policy

Herefordshire Council worker sentenced over unlawful records access

Geoffrey Smith admitted accessing council systems without authorisation, viewing about 490 records and downloading 94 documents, the ICO said.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Herefordshire Council worker sentenced over unlawful records access
Photo: The Register

A Herefordshire Council employee has been given a suspended prison sentence after admitting he unlawfully used internal systems to access sensitive records on people he knew. Geoffrey Smith, 31, was sentenced at Worcester Magistrates’ Court on July 17 to two months in prison, suspended for 12 months, and ordered to pay £2,154 in costs and surcharge.

The case is a straightforward insider-access failure with unusually sensitive data at stake. According to the Information Commissioner’s Office, Smith was a new employee in the council’s Children and Young People directorate when he accessed roughly 490 records over four days and downloaded 94 documents.

The ICO said the records related to family members and other families known to Smith. The information included records on both adults and children, with the watchdog identifying medical records, social worker reports, and child and family assessments among the material accessed.

Computer Misuse Act conviction

Smith, from Ledbury, pleaded guilty to an offence under Section 1 of the Computer Misuse Act 1990, covering unauthorised access to computer-held data. The court also ordered him to complete 120 hours of unpaid work, in addition to £2,000 in costs and a £154 victim surcharge.

The ICO said Smith had no proper reason to view the information and used his council access to look at personal data belonging to people connected to him. Andy Curry, the regulator’s head of investigations, said the conduct was serious because of the nature of the records held by a directorate responsible for children and young people.

Curry said people should be able to expect that personal data is protected and used only for the reasons for which access was granted. The ICO did not say whether Smith shared any of the downloaded documents, whether the council detected the access internally, or whether any separate employment action was taken.

Insider risk for public-sector systems

For public-sector technology leaders, the facts disclosed by the ICO point to the limits of access permission alone as a control. Smith’s role gave him a route into systems holding sensitive material, but the offence concerned access without a legitimate work purpose, according to the regulator.

The ICO did not disclose technical details such as audit logging, alerting thresholds, user access reviews, or whether controls changed after the incident. Those omissions matter because the activity described by the watchdog took place across a four-day period and involved hundreds of records.

The regulator’s public statement comes after its former information commissioner resigned, having admitted that his conduct fell below the standards expected of public officials. In this case, the ICO’s enforcement action ended with a guilty plea under the Computer Misuse Act and a suspended custodial sentence rather than immediate imprisonment.

This story draws on original reporting from The Register.

More from Policy

All Policy →