"I Didn't Think" Isn't a Defence to a Workplace Data Breach

Most workplace data breaches don't begin with hackers. They begin with people.

When employers think about data breaches, they often picture cyberattacks, stolen laptops or confidential emails being sent to the wrong recipient. In reality, many breaches happen during ordinary workplace interactions—a casual conversation, unnecessary curiosity or a momentary lapse in judgement.

One explanation appears time and again:

"I didn't think."

While that may explain how a breach happened, it does nothing to undo the damage it may cause to the individual whose information has been exposed.

A conversation that should never have happened

Imagine someone applies for a new job.

They haven't told their current employer or colleagues because they want their application to remain confidential. Before the recruitment process has progressed very far, they discover that someone outside the recruiting organisation already knows they've applied.

The information didn't come from the applicant.

It came from an employee who casually mentioned the application during what they considered to be a private conversation with someone they knew.

The employee may not have shared a CV, interview notes or contact details. They may simply have revealed that an application had been made.

That is still personal information.

Job applicants are entitled to expect that information provided during recruitment will only be accessed and used for legitimate recruitment purposes. Data protection obligations apply to applicants just as much as they do to existing employees.

For the individual concerned, what seemed like an innocent remark could damage relationships with their current employer, cause embarrassment and undermine confidence in the recruiting organisation.

Being able to access information doesn't mean you're entitled to view it

Now consider a different scenario.

An employee has access to an HR system or shared drive containing personnel records. Out of curiosity, they open a colleague's file even though they have no work-related reason to do so.

Perhaps they want to compare salaries.

Perhaps they're interested in someone's appraisal, sickness record or performance review.

Or perhaps they assume that because the system allows access, they're entitled to look.

They're not.

Access to personal information should always be based on a genuine need to know.

Simply having the technical ability to open a record does not give someone authority to access it.

A personal data breach can include unauthorised access to personal information, even where nothing has been downloaded, shared or emailed outside the organisation. Sometimes, simply viewing confidential information without a legitimate reason is the breach itself.

While employers rightly invest in protecting themselves against cyber threats, they should not overlook one of the biggest risks of all—the misuse of information by people who already work within the organisation.

When does a mistake become misconduct?

Not every data breach will justify disciplinary action, and not every mistake amounts to gross misconduct.

Each situation must be considered on its own facts.

There is an important difference between someone who accidentally sends an email to the wrong recipient, reports it immediately and helps contain the incident, and someone who deliberately accesses confidential records or knowingly shares personal information with others.

When deciding how serious the conduct is, employers should consider:

  • What information was accessed or disclosed;
  • Why the employee accessed or shared it;
  • Whether their actions were deliberate;
  • Who received or viewed the information;
  • The impact on the individual concerned;
  • Whether the employee understood the organisation's policies;
  • Whether they reported the incident promptly;
  • Whether they demonstrated genuine insight and remorse;
  • Whether there have been previous concerns; and
  • Whether trust and confidence can realistically be restored.

Repeated incidents can significantly alter the employer's assessment.

An employee who "wasn't thinking" after a genuine one-off mistake presents a very different picture from someone who repeatedly ignores confidentiality obligations.

Could a data breach amount to gross misconduct?

Potentially, yes.

Many disciplinary procedures identify serious breaches of confidentiality, misuse of personal data and unauthorised access to records as examples of conduct that could amount to gross misconduct.

However, the outcome should never be automatic.

Employers should still carry out a fair investigation, explain the allegations clearly, invite the employee to a disciplinary hearing and give them a reasonable opportunity to respond before reaching a decision.

Whether dismissal is appropriate will depend on factors such as:

  • The employee's role;
  • The sensitivity of the information;
  • Whether the breach was deliberate;
  • Any harm caused; and
  • The employee's response once the breach came to light.

Managing the breach and the disciplinary process

Where an employee is suspected of misusing personal information, employers usually have two separate responsibilities.

The first is managing the disciplinary process.

The second is responding appropriately to the data breach itself.

That means taking prompt steps to contain the incident, identifying what information was involved, preserving evidence where necessary and assessing the potential risk to the individual affected.

Not every breach must be reported to the Information Commissioner's Office (ICO). However, some incidents must be reported without undue delay and, where feasible, within 72 hours of the organisation becoming aware of them. Where there is a high risk to the affected individual, they may also need to be informed.

Importantly, employers should not delay considering their data protection obligations simply because a disciplinary investigation is ongoing.

Training should reflect real-life roles

Annual data protection training is valuable, but it isn't always enough.

The confidentiality risks facing a line manager are very different from those faced by a recruiter, payroll administrator, HR professional or general employee.

Managers need guidance on handling sickness information, grievances, appraisals and disciplinary matters.

Recruiters need to understand that applicant details, interview discussions and recruitment decisions are confidential.

HR and administrative staff need clear boundaries around which records they may access and why.

Every employee should understand that information learned through work must never be shared with friends, family members or colleagues who have no legitimate reason to know it.

Training is most effective when it reflects the situations people genuinely encounter in their day-to-day roles.

Employers should also review access permissions regularly so employees only have access to the information they genuinely need. Good data protection should never rely solely on people resisting temptation.

"I didn't think" isn't enough

Employees are trusted with a significant amount of personal information.

They may know who has applied for a vacancy, why someone is absent, how much a colleague earns, what happened during an appraisal or whether an employee has raised a complaint.

That information doesn't belong to them and it is not theirs to share.

A careless conversation or an unnecessary look at a confidential record may take only a few seconds. The consequences for the individual, the organisation and its reputation can last much longer.

Creating a culture of confidentiality means ensuring employees understand not only that the rules exist, but how those rules apply in the reality of their everyday work.

Helping employers get confidentiality right

At Rely Ltd – HR & Training Specialists, we provide practical, role-specific training that helps employees understand what confidentiality means in their day-to-day work—not just in theory.

Whether you need training for managers, recruiters, HR teams, administrators or your wider workforce, we use realistic workplace scenarios that help employees recognise risks before they become data breaches.

We also support employers with data breach investigations, disciplinary procedures, policy reviews and strengthening internal controls around access to personal information.

If you'd like to strengthen your organisation's approach to confidentiality and data protection, we'd be delighted to discuss how we can help.


This article provides general information only and should not be relied upon as legal advice. Decisions relating to personal data breaches, including whether notification to the Information Commissioner's Office is required, should always be based on the specific circumstances and a documented assessment of the risks arising from the incident.