30 July 2026
Access is not Permission
By Clare Chatfield, Information Governance Manager
Introduction
Recent data protection incidents are a timely reminder that not every data breach begins with a cyberattack. Sometimes the risk comes from inside the organisation, where staff have legitimate access to systems but use that access for reasons unrelated to their role.
This post looks at why “access” should never be confused with “permission”, and why organisations need to take insider misuse seriously. Using recent UK examples, it explores how curiosity, poor access controls and weak monitoring can turn everyday system access into a serious data protection risk.
The Insider Data Breach Risk Sitting Inside Your Organisation
Data breaches do not always start with a hacker. Sometimes they start with a staff member thinking, “I’ll just have a quick look” – even when they have no genuine work-related reason to do so. In many organisations, the problem is not that staff are trying to break the rules but rather that the rules are not visible enough at the point where curiosity kicks in.
Recent cases show a worrying pattern[1]. Staff with legitimate system access are using that access for the wrong reasons: curiosity, personal interest, gossip or potential financial gain.
From private medical suites to busy hospital wards, sensitive records are being opened not because someone needs to view them to do their job, but because they want to know more.
Access is not permission. If a system lets you open a file, that does not automatically mean you are authorised to look at it.
For organisations, that distinction matters. If staff can browse records they do not need to see, curiosity is not just poor judgement; it is a breach risk in plain sight.
Here are two recent UK examples that show why insider access needs to be taken seriously.
Case Study 1: When Access Becomes Opportunity
In June 2026, the ICO concluded a criminal investigation that put insider misuse firmly in the spotlight. The case involved a former staff member at The London Clinic, the private hospital where Catherine, the Princess of Wales, had undergone abdominal surgery[2].
The employee attempted to access and obtain private medical information. The allegation was serious: the ICO said the conduct involved an offer to disclose sensitive information for financial gain.
The ICO did not just issue another reminder about policies and procedures; it issued a formal criminal caution to the individual involved.
That is the point organisations cannot afford to miss. Insider misuse is not only a corporate governance issue. In the wrong circumstances, it can become a criminal data protection matter for the individual too.
Case Study 2: When Curiosity Becomes a Breach
Financial gain is one risk. Curiosity is another, particularly when a high-profile incident attracts public attention.
When a serious local incident becomes national news, staff may be tempted to look at records they have no reason to view. The ICO has warned that this is exactly the kind of moment where confidential information becomes vulnerable.
In June 2026, Cambridge University Hospitals referred itself to the ICO after around 40 members of staff accessed the medical records of a three-year-old boy who had been injured in a crocodile enclosure at Johnsons of Old Hurst near Huntingdon and taken to Addenbrooke’s Hospital[3]. The trust said it was investigating whether everyone who viewed the child’s information had a legitimate clinical or operational reason to do so and warned that inappropriate access could lead to robust disciplinary action, including dismissal.
The problem is not always one rogue actor. Sometimes it is a chain reaction: one person looks, then another, then another. Before long, “just checking” has become a reportable breach.
That is why organisations need more than a confidentiality policy sitting on an intranet. They need controls, monitoring and a culture that makes the line unmistakably clear.
Curiosity might feel harmless in the moment, but in data protection terms, it is anything but.
Why This Matters
These stories may come from healthcare, but the lesson reaches far beyond hospitals. HR files, payroll systems, customer records, safeguarding notes, case files and complaints data all carry the same risk.
If people can access information without a clear business need, the breach risk is already inside the organisation. It is not theoretical. It is sitting behind everyday logins, routine permissions and familiar systems.
Access is Not Authorisation
Having the ability to view a record is not the same as having a legitimate need to do so.
In July 2026 NHS England published new guidance[4] for all NHS organisations on preventing and monitoring unauthorised access, as well as their responsibilities in investigating and reporting it.
Under the Data Protection Act 2018, knowingly or recklessly obtaining or disclosing personal data without authorisation can be a criminal offence. Recent reforms to the UK data protection landscape also reinforce the importance of being able to explain and evidence how personal data is accessed, controlled and monitored.
In other words, “I was only looking” is not a defence.
That responsibility does not sit with individual staff alone. Organisations, as data controllers, need to design systems and processes that reduce the opportunity for curious humans to get into trouble in the first place. Good data protection by design means building in friction where it matters: limiting access, prompting users to confirm a legitimate reason for viewing sensitive records, monitoring unusual activity and making it clear that access is granted for work purposes only. If a system makes inappropriate browsing easy, invisible or culturally tolerated, the organisation has not done enough to manage the risk.
So, what should organisations do before curiosity turns into a breach report, an internal investigation or a headline they would rather not see?
Practical Steps for Organisations
The answer is not more generic reminders. Organisations need to test whether day-to-day access controls, monitoring and staff expectations are working in practice, so inappropriate access is harder to justify, easier to detect and impossible to excuse:
- Tighten role-based access controls: give staff access to the records they need for their role, not a free pass to browse everything the system contains;
- Design systems to prevent avoidable misuse: build permissions, prompts and monitoring around real human behaviour, recognising that curiosity is predictable and that the controller is responsible for reducing the risk before it becomes a breach;
- Use real-time audit alerts: flag unusual patterns, such as multiple staff suddenly opening the same record after a high-profile incident;
- Make accountability visible: staff should understand that unauthorised browsing may lead to disciplinary action, professional consequences and referral to the ICO;
- Train for real-life pressure points: use scenario-based training to show staff what to do when a case becomes newsworthy, sensitive or personally interesting; and
- Review access regularly: check whether permissions still reflect current roles, responsibilities and business need, especially after staff move teams or change duties.
Conclusion
The message from these incidents is clear: the insider threat is not always malicious, but it is always serious.
Protecting personal data is not just about keeping external attackers out. It is also about making sure trusted users only access information when they genuinely need it.
That means clear permissions, active monitoring and a culture where “need to know” is treated as a rule, not a slogan.
One unauthorised click can trigger serious consequences for the individual, the organisation and the people whose privacy has been breached.
The real test is not whether someone can open a record. It is whether they should be able to.
If your organisation holds sensitive personal data, now is a good time to test whether access permissions, audit logging, staff training and breach response processes are strong enough to prevent, detect and respond to inappropriate internal access. A short, focused review can identify where curiosity, convenience or poor system design may be creating avoidable risk -before it becomes a breach report, an internal investigation or a headline.
Looking to learn more about how you can identify privacy risks early and implement effective safeguards? Our intermediate half day CPD UK accredited course, Privacy by Design, next runs on 27 October, 9:30am-1pm. You can also prepare to manage data security risks and respond effectively to breaches in our other upcoming intermediate half day CPD UK accredited course, Information Security & Data Breach Management, where through practical insights, this course helps you develop effective breach response strategies, understand security principles, and build organisational awareness of data protection risks. The course next runs on 15 October, 9:30am-1pm. To learn more or book your place, click the links above or get in touch by emailing info@naomikorn.com.
[1] York and Scarborough hospital staff wrongfully accessed records – BBC News
[2] Ex-health worker tried sell Catherine, Princess of Wales’ medical notes – BBC News
[3] Crocodile attack: Hospital probe after boy’s records accessed – BBC News
[4] NHS England » NHS warns ‘snooping’ staff face sack or prison for inappropriate access of patient data