·Senserity

The ICO's confiscation orders against employees who sold personal data: what it reveals about supplier data governance risk

data protectionICO enforcementsupplier riskUK GDPRcompliance

Two enforcement actions landed in quick succession from the Information Commissioner's Office (ICO) in the spring of 2026, and the numbers are striking. The ICO secured confiscation orders totalling almost £475,000 against individuals who profited from the unlawful sale of personal data, signalling a tougher approach to data misuse for financial gain. The targets were not organisations — they were individual employees. But as procurement and compliance teams, the cases deserve your attention all the same, because they expose a form of data governance failure that sits squarely inside your supplier risk picture.

What actually happened

The ICO secured a £355,880.10 confiscation order against former Manchester motor insurance worker Rizwan Manjra, who had previously pleaded guilty to an offence under the Computer Misuse Act 1990 of causing a computer to perform a function with intent to secure unauthorised access to personal information. The order was granted at a Proceeds of Crime Act (POCA) hearing at Manchester Crown Court on 15 May 2026. The order must be paid within three months. Should Manjra fail to pay, he faces a default prison sentence of three years and six months and remains liable for the full amount.

Weeks later came a second case. The ICO secured £118,852.32 in confiscation orders against two former RAC employees, Debbie Okparavero and Maliha Islam. The Proceeds of Crime Act hearings followed an October 2024 hearing at which both were sentenced to six-month prison sentences suspended for 18 months, and each ordered to complete 150 hours of unpaid work. Both had previously pleaded guilty to a conspiracy to commit offences under section 1 of the Computer Misuse Act 1990 and the Data Protection Act 2018, for unlawfully copying and selling almost 30,000 lines of personal information.

The mechanism that exposed the RAC case is worth noting. The RAC's unlawful conduct was discovered after it installed new security monitoring software, which showed Okparavero had accessed and copied personal information relating to people involved in road traffic accidents. A subsequent search of her mobile phone showed the information had been shared in a WhatsApp chat with Islam, with messages indicating that a third party was paying for the data. The breach was discovered from the inside, not reported by an external party.

The enforcement shift you need to understand

The ICO is not simply levying fines. It has begun seeking confiscation orders under the Proceeds of Crime Act to strip offenders of their gains. For many defendants, the prospect of losing money, cars, or homes is more daunting than a short custodial term. The regulator's position is unambiguous: it pursued confiscation under POCA to ensure that people who profit from the unlawful use of personal information do not retain the benefits from their criminal activity, with the order reflecting the financial advantage gained through the illegal access and onward sale of personal information.

While the action was aimed at employees rather than their employers, the cases raise important questions for organisations about governance, oversight, and responding to data incidents. That last point matters particularly for procurement teams. When you engage a supplier who has access to personal data — your customers' records, your employees' details, sensitive transactional data — you are relying on that supplier's internal controls to prevent exactly this kind of conduct.

Why this is a supplier risk issue, not just an employment one

Under Article 28 of the UK General Data Protection Regulation (UK GDPR), the obligation on you as a data controller is specific. Article 28(1) requires a controller to use only a processor that can provide "sufficient guarantees" — particularly in terms of its expert knowledge, resources and reliability — to implement appropriate technical and organisational measures to ensure the processing complies with the UK GDPR and protects the rights of individuals. A Data Processing Agreement is mandatory, but it is not enough on its own. Controllers should ensure a processor's compliance on an ongoing basis, in order to satisfy the accountability principle and demonstrate due diligence. Article 28(3)(h) explicitly requires the processor to allow for and contribute to audits and inspections, carried out either by the controller or a third party appointed by the controller.

The RAC cases illustrate what "sufficient guarantees" actually means in practice. Someone in a customer-service role was able to access and copy accident-related records, move them onto a phone, and share them in a WhatsApp chat linked to payment. By the time the case reached court, the failure had already travelled through access control, monitoring, incident response, and staff conduct. If that company were one of your suppliers, your organisation would have had a legitimate interest in knowing whether those controls existed and whether they were working. A contract clause stating that staff are trained in data protection is not the same as evidence that access is monitored, that bulk downloads are flagged, or that staff are subject to meaningful oversight.

A controller is primarily responsible for its own compliance and ensuring the compliance of its processors. This means that, regardless of the terms of the contract with a processor, the controller may be subject to corrective measures and sanctions set out in the UK GDPR, including orders to bring processing into compliance, claims for compensation from a data subject and administrative fines. The supplier's employee committing the offence does not transfer the liability away from you.

What good supplier data governance vetting looks like

When you assess a supplier who will handle personal data on your behalf, the right questions go beyond asking whether they have a privacy policy or a signed Data Processing Agreement. You want evidence of the controls beneath those documents.

The ICO's own guidance is clear on what "sufficient guarantees" looks like in practice. Considerations include the extent to which the processor complies with industry standards, whether they have sufficient technical expertise to assist with obligations under Articles 32 to 36 of the UK GDPR, and whether they can provide relevant documentation such as their privacy policy, record management policy and information security policy. Certifications such as ISO 27001 give you some assurance, but they are snapshots. Access control policies matter more than certificates when the risk is an insider quietly exporting records to a mobile phone.

Specific things to probe include: how role-based access is managed and reviewed, whether bulk data exports or unusual access patterns are logged and monitored, what staff training looks like and how often it is refreshed, and how a supplier would detect and report a breach of this nature to you. The RAC case is instructive precisely because the breach was caught by new monitoring software, not by pre-existing controls. Many suppliers will not have even that.

For compliance teams using Senserity to assess supplier risk, data protection governance sits within the broader picture of how well a company is run. Corporate filing discipline, director conduct, and the presence or absence of regulatory findings are all signals that bear on whether a supplier is likely to take its internal governance obligations seriously. A company with persistent filing failures or adverse findings against its officers is more likely to have governance gaps across the board, including in how it manages access to personal data.

The takeaway

The ICO's use of the Proceeds of Crime Act 2002 (POCA) in these cases marks a meaningful escalation. Criminal prosecution, suspended prison sentences, and now confiscation orders stripping individuals of the proceeds of data theft: the regulatory environment for personal data misuse has changed materially. The question for you is not whether your suppliers have signed the right paperwork. It is whether their internal controls would actually catch the conduct these cases describe, and whether you would find out quickly enough to limit your own exposure if they did not.