Site navigation

Man Jailed in First ICO Computer Misuse Act Prosecution

Ross Kelly

,

ICO Computer Misuse Act

A motor industry employee has been sentenced to six months in prison in the first prosecution to be brought by the Information Commissioner’s Office (ICO).

A car repair worker has been sentenced to prison for stealing customers’ personal data from his former place of work. Mustafa Kasim stole personal information, including names, phone numbers and vehicle details of people involved in road accidents.  

Kasim was sentenced to six months in prison following a guilty plea at London’s Wood Green Crown Court.  

ICO Investigations

The watchdog believes Kasim accessed thousands of customer records by using his colleagues’ login details to access a software system that estimates vehicle repair costs.  

He continued to do this despite leaving the firm, Nationwide Accident Repair Services, to join another car repair organisation which used the same software system; known as Audatex.  

Mike Shaw, Group Manager of the ICO Criminal Investigations Team, commented: “The potential reputational damage to affected companies whose data is stolen in this way can be immeasurable.

“Both Nationwide Accident Repair Services and Audatex have put appropriate technical and organisational measures in place to ensure that this cannot happen again.” 

Landmark Ruling 

This case marks a significant moment for the Information Commissioner’s Office as it is the first time someone has been sentenced following an investigation by the watchdog. The data regulator had been investigating Kasim’s former workplace amid claims of nuisance calls by the firm’s clients.  

While the ICO has traditionally prosecuted offences such as these under the Data Protection Act, on this occasion the regulator pursued charges under the Computer Misuse Act. An individual cannot be sentenced to prison for breaching the Data Protection Act.  

Shaw said that in the future, this ruling could dissuade people who “think it’s worth their while to obtain and disclose personal data without permission.” 

He added: “Although this was a data protection issue, in this case, we were able to prosecute beyond data protection laws resulting in a tougher penalty to reflect the nature of the criminal behaviour.” 

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data