Skip to main content
Data Deletion Turned Criminal: What ChangedRecords & Recordkeeping
4 min readFor Security Awareness Teams

Data Deletion Turned Criminal: What Changed

A UK magistrate court recently convicted Anne Donaghy, a former council chief executive, on two criminal counts for deleting a single email. She was fined £750 on each count after the court found she instructed her assistant to delete correspondence to prevent its disclosure under a freedom of information request. Donaghy maintains her innocence and plans to appeal.

This case is significant because a similar criminal provision exists in the Data Protection Act 2018, which applies to subject access requests in private companies. Section 173 makes it a criminal offense to delete, alter, or conceal information with the intent to prevent disclosure after someone exercises their right of access. This isn't just a civil penalty; it's a recordable criminal offense that can apply to individual employees, not just the organization.

Understanding the Law

Section 173 of the Data Protection Act 2018 outlines a criminal offense when three conditions are met:

  1. An individual exercises a data subject access right.
  2. They are entitled to receive the information.
  3. Someone employed by or acting under the direction of the controller alters, defaces, blocks, erases, destroys, or conceals that information with the intention of preventing disclosure.

This provision covers UK GDPR Article 15 access rights. Unlike the Freedom of Information Act offense, which primarily affects public authorities, Section 173 applies to private-sector organizations and their staff. The criminal element doesn't require an elaborate cover-up. An employee can commit the offense through routine actions, like deleting an email, if the intent to prevent disclosure exists.

Four Findings That Change Your Risk Profile

Senior managers are your highest exposure point. Employment disputes often lead to subject access requests, and the emails most likely to become contentious are in managers' inboxes. The Donaghy case involved a chief executive. Your equivalent risk lies with directors, HR business partners, and anyone handling sensitive personnel matters. These individuals often have the least data protection training and the most sensitive correspondence.

Routine deletion becomes criminal when timing and intent converge. Organizations should delete information according to legitimate retention schedules. The Data Protection Act provides two statutory defenses: the deletion would have occurred anyway, or the person reasonably believed the requester wasn't entitled to the information. A documented retention schedule is your evidence that deletion was a legitimate business process, not intentional concealment.

Personal devices and private accounts don't create legal distance. The Information Commissioner's Office confirms that personal information stored by staff on private devices can fall within the scope of a subject access request if they're holding it on the controller's behalf. The same principle applies to private email accounts used for work. Treating such information as outside the organization's control could itself constitute concealment.

The offense can overlap with personal data breach obligations. Under UK GDPR, a personal data breach includes unlawful destruction, loss, or alteration of personal data. An employee who deletes information without authorization could trigger two separate compliance questions: whether the deletion was a security incident requiring breach assessment, and whether it was carried out with intent to prevent disclosure under Section 173.

What This Means for Security Awareness Teams

Your current training probably covers what a subject access request is, who handles it, and how long you have to respond. It likely doesn't address what employees can do with underlying information once the request arrives.

This gap matters because the criminal provision applies to individual employees. An HR manager who deletes an uncomfortable email chain after learning it falls within an employee's subject access request faces something more serious than an internal disciplinary issue, they face potential criminal conviction.

The risk extends beyond malicious actors. Consider a manager who receives notification that a former employee submitted a subject access request. The manager reviews their sent items, sees an email thread they wish they'd worded differently, and deletes it thinking, "this will just cause problems." That single action, if done with intent to prevent disclosure, satisfies the elements of the criminal offense.

Action Items by Priority

Immediate: Build a preservation instruction into your SAR workflow. When your team receives a subject access request, the acknowledgment to the requester should be accompanied by an internal notification to relevant custodians. The instruction should be explicit: do not delete, edit, or move potentially responsive information without approval from the data protection or legal team. Suspend automated deletion settings for identified custodians during the response period.

Within 30 days: Map where potentially contentious information actually lives. Your corporate email system is obvious. Also consider Microsoft Teams, Slack, shared drives, archived mailboxes, and collaboration platforms. Identify which systems have automated deletion rules and how to suspend them for specific custodians when preservation becomes necessary.

Within 90 days: Revise training for managers and HR teams. These groups handle the most sensitive correspondence and often have the least data protection training. The training doesn't need to make them experts in Section 173. It needs to make them understand a simple instruction: once you know information may fall within an access request, do not delete or alter it because you'd prefer it wasn't disclosed. Escalate instead.

Ongoing: Document your retention schedule and follow it. The statutory defense requires showing that deletion would have occurred anyway. That defense only works if you can demonstrate a legitimate, documented retention policy that you actually follow. Good data governance requires deleting information you no longer need, while preservation obligations require keeping information once certain triggers occur. The solution is defensible retention, not indefinite storage.

For next review cycle: Extend preservation protocols beyond SARs. The same principles apply to litigation holds, regulatory investigations, and internal investigations. Your organization likely has preservation procedures for litigation. Ensure those procedures also cover data subject access requests and treat them with equivalent seriousness.

You Might Also Like