Legal 500 Leading Firm 2026   /  The Time Best Law Firms 2026  /  40+ Years of Expert Legal Practice in London

020 4572 1313

  • Phone
× Send

Data Misuse and The Proceeds of Crime Act: How the ICO are enforcing Confiscation Orders.

Personal data has become a valuable commodity which criminals are now unlawfully obtaining and selling as form of financially motivated crime. These offences can arise where individuals with legitimate access to personal information misuse that access, or where data is obtained through unauthorised access to computer systems, with the intention of selling or exploiting it for financial gain.

Under the Data Protection Act 2018, it is a criminal offence to knowingly or recklessly obtain, disclose or retain personal data without the consent of the data controller, subject to limited exceptions. Where offenders gain access to systems without authority in order to obtain information, offences under the Computer Misuse Act 1990 may also apply.

Individuals may use this data to create false identities, obtain credit information or carry out targeted attacks. In more serious cases, stolen corporate or personal information may also be used as leverage for extortion.

Data stolen from insurers, claims management companies, garages and financial institutions may be sold to third parties who use this data for identity theft, insurance fraud, phishing campaigns and wider crime. In many cases, offenders do not use the information themselves but sell large quantities of personal data for profit.

For this reason, the ICO have increasingly sought to prosecute individuals involved, and subsequently pursue confiscation proceedings against them, recovering any financial benefit obtained.

Who are the ICO?

The Information Commissioner’s Office (ICO) is the United Kingdom’s independent authority that protects personal privacy, upholds data protection laws, and ensures public access to official information. In addition, the ICO are able to prosecution offences under the Data Protection Act and, where appropriate, the Computer Misuse Act 1990 (CMA).

For many years, the ICO primarily issued monetary penalties against organisations who failed to protect personal data. Increasingly, however, the ICO is extending its powers into POCA proceedings.

ICO use of Confiscation Proceedings:

Unlike compensation or fines, confiscation orders are designed to deprive offenders of the financial benefit obtained through criminal conduct.

The ICO’s use of POCA is not a new development and the regulator has on occasion sought confiscation payments.

In December 2024, a former motor insurance employee pleaded guilty under the Computer Misuse Act 1990, and was ordered to pay £355,880.10. In the preceding years

two former RAC employees also pleaded guilty to offences under both the Data Protection and Computer Misuse Act and were ordered to pay £85,727.32 and £33,125 respectively.

The most significant recent development is the conviction of Christopher Munro and William Chipoma, who appeared before Manchester Crown Court in February 2026. These proceedings form part of the ICO’s largest ever nuisance call investigation.

Both men pleaded guilty to offences under the Computer Misuse Act 1990 and the Data Protection Act 1998 after unlawfully accessing and selling personal data obtained from more than 400 garages, insurance companies and claims management businesses. Mr Munro and Chipoma have received suspended custodial sentences together with unpaid work requirements but this is unlikely to be the end of the matter, with the ICO implying that they are looking to recoup the financial benefits obtained by the offenders by utilising the Proceeds of Crime Act 2002.

The significance of this demonstrates the ICO’s message that those who profit from unlawfully exploiting personal information should expect not only prosecution, but also financial recovery proceedings designed to remove any economic incentive for offending.

How Are Confiscation Orders Calculated?

Confiscation proceedings under POCA do not serve as re-punishment, but identify and recover financial benefits derived through illicit conduct. The proceedings will consider two separate figures; the benefit, and available amount. The benefit figure is often calculated over a 6-year period, with any unidentifiable income and expenditure forming part of the calculation alongside the identifiable benefit from criminal conduct. The available amount however, is formed by assets the individual currently holds in their name, no matter whether these assets have been legitimately obtained or not.

As such, those subject to ICO prosecutions may find themselves responsible not only for the sums obtained through illegally sold or misused data, but also any unidentifiable income over a 6-year period. Moreover, assets held both jointly and solely may be subject to recovery.

Potential Challenges to ICO Confiscation Proceedings:

Where POCA proceedings are instigated, the individual has the opportunity to challenge the Prosecution’s figures. Issues of proportionality may arise, and arguments can be formed should the defence be able to clearly trace and separate legitimate income.

The defence may also scrutinise the evidential basis relied upon, in connecting particular payments or assets to the criminal conduct.

Given the increasingly sophisticated financial investigations undertaken by the ICO, confiscation proceedings are becoming a substantial area of criminal defence, with long and complex proceedings being instigated after the sentencing has concluded.

Implications for Organisations:

Although the recent confiscation orders have been directed against individuals rather than employers, organisations should not view these cases as purely individual misconduct.

Corporate criminal liability laws in the UK underwent a major expansion under the Crime and Policing Act 2026, which took effect on 29 June 2026. The laws means that organisations can be held criminally liable for offences committed by senior managers acting within their apparent authority.

Depending on the circumstances, organisations may still face investigation into their own security controls, governance and compliance with data protection obligations risking criminal prosecutions themselves. As such, rigid procedures on data usage are required.

Conclusions:

Taken together, these cases illustrate the ICO’s increasing use of POCA proceedings.

Should substantial confiscation orders follow from the Munro/Chipoma proceedings, they will further reinforce the ICO’s willingness to combine data protection enforcement with the financial recovery mechanisms available under POCA.

For organisations, the cases underline the importance of robust internal controls and early engagement with the ICO. For individuals tempted to misuse personal data, they demonstrate that the financial consequences of unlawfully exploiting this information now extend well beyond conviction and sentence, with confiscation becoming an increasingly powerful tool.

Fionnuala O’Reilly

Contact us via our website enquiries link or by telephone 020 7387 2032.

Book a
confidential
consultation

For discreet legal advice, contact Lewis Nedas Law today.