Suspected employee data theft should be treated as an incident to investigate, not an accusation to prove. The first priorities are to contain immediate risk, preserve volatile evidence, protect business systems and establish what information was actually accessed, copied, transferred or disclosed. A rushed confrontation can destroy evidence, alert other people involved and make a later employment, civil or criminal case harder to prove.

At Trojan Investigations, we support UK organisations with insider-risk, employee misconduct and corporate investigations. We combine lawful intelligence gathering, chronology building, evidence review and—where it is justified—targeted surveillance. Technical forensic acquisition should be handled by appropriately competent digital-forensics professionals when device-level evidence is required.

Originally published: 3rd August 2026  |  Updated: 7th September 2026

What counts as employee data theft?

The phrase can cover very different conduct: copying confidential customer lists before joining a competitor, sending source code to a personal account, exporting a CRM database, removing design files, sharing trade secrets, taking personal data without authority or retaining files after employment ends. Whether the conduct is a contractual breach, breach of confidence, trade-secret misuse, data-protection incident or criminal offence depends on the facts.

Why Insider Data Incidents Are Difficult to Investigate

An employee often has legitimate access to the very information later alleged to have been taken. The investigation therefore has to distinguish access from misuse. Downloading a file may be completely normal in one role and highly unusual in another. A copied file also does not prove where it went or why it was copied.

NPSA insider-risk guidance treats the employee lifecycle, including departure, as a significant security consideration. Exit procedures matter because employees serving notice or leaving abruptly may still hold access to systems, repositories, devices and knowledge assets.

72 hoursWhere a personal-data breach is notifiable, the ICO says it must be reported without undue delay and, where feasible, within 72 hours of the organisation becoming aware of it.
Shortest timeICO guidance says exceptional covert monitoring should be tightly targeted and limited to the shortest time necessary for the investigation.
Exit riskNPSA identifies staff departure as a significant point for controls designed to protect confidentiality, integrity and availability of critical assets.

Common Data-Theft Scenarios

Different incidents require different evidence
ScenarioLikely evidence questionsPotential legal issues
Customer list copied before resignationWas the list exported, to where, when and by whom?Contract, confidentiality, trade secrets, personal data
Source code sent externallyWas code transferred, retained or used elsewhere?Copyright, confidentiality, computer access, contract
CRM database downloadedWas access normal for the role and was there onward transfer?Personal-data breach, confidentiality, employment duties
Documents uploaded to personal cloud storageWhich documents, account, time and purpose?Policy, confidentiality, trade secrets, data protection
Former employee still accessing systemsWere credentials active and was access authorised?Computer Misuse Act risk, security failure, contract

Do Not Assume Every Download Is Theft

Automated alerts can be valuable but can also mislead. A legitimate project, backup, remote-working task or authorised migration may generate unusual activity. Investigators should therefore establish role permissions, normal baselines, project context and whether the person had a business reason to handle the information.

Preserve first; interpret second

If you suspect misconduct, avoid immediately changing timestamps, opening original files on suspect devices, deleting accounts or allowing routine retention systems to overwrite logs before the evidence plan is agreed. Containment may be urgent, but preservation should be coordinated with IT, HR, legal advisers and digital-forensics specialists where necessary.

Build a Chronology Around the Suspected Event

The most useful early question is usually not “Did they steal data?” but “What happened before, during and after the suspected transfer?” A chronology can combine access logs, device events, email records, resignation dates, meetings, cloud activity, physical access and witness information.

1. Define the suspected assets

Identify exactly what information matters—customer records, source code, formulas, designs, pricing, research, contracts or other confidential material.

2. Stabilise evidence

Preserve relevant logs, devices, account records and documents using methods suitable for the likely employment, civil or criminal route.

3. Establish authorised access

Understand what the employee was permitted and expected to access, rather than treating every interaction as suspicious.

4. Test transfer routes

Look for evidence of email forwarding, removable media, cloud uploads, repositories, printing or other relevant channels without making assumptions from a single alert.

5. Corroborate purpose and destination

Where possible, link the digital event to communications, meetings, later use or other evidence showing why the transfer matters.

Trade Secrets Need to Be Treated as Secrets

Not every confidential document qualifies as a statutory trade secret. Current UK government guidance explains that a trade secret must be secret, have commercial value because it is secret and have been subject to reasonable steps to keep it secret. Protection can arise through the Trade Secrets (Enforcement, etc.) Regulations 2018 and the common law of breach of confidence.

That makes pre-incident governance evidentially important. Access restrictions, NDAs, confidentiality clauses, classification, logging, training and controlled repositories can help show that the organisation genuinely treated information as protected rather than calling it a trade secret only after a dispute begins.

The Computer Misuse Act Can Be Relevant, but the Facts Matter

Section 1 of the Computer Misuse Act 1990 addresses unauthorised access to computer material. Former employees who use credentials after authority has ended, credential sharing or access to systems outside authorised permissions may raise criminal-law issues. But an employee who had legitimate system access presents a more fact-sensitive question; employers should not assume that every misuse of information automatically satisfies a computer-misuse offence.

Where criminal conduct is suspected, legal advice and police involvement may be appropriate. Internal fact finding should avoid actions that could prejudice a criminal investigation.

Personal Data Creates a Separate Incident-Response Track

If stolen information contains identifiable customer, employee or other personal data, the organisation also needs to assess whether a personal-data breach has occurred. The ICO says all personal-data breaches should be recorded and certain breaches must be notified without undue delay and, where feasible, within 72 hours of awareness when the risk threshold is met. High-risk breaches may also require affected people to be informed without undue delay.

Can Employers Monitor Staff to Find Data Theft?

Data-protection law does not ban employee monitoring, but the ICO says it must be lawful and fair, based on a defined purpose and limited to what is necessary. Excessive monitoring can intrude into private life and undermine trust. Monitoring that is likely to create high risk may require a DPIA.

Covert monitoring is a much higher bar. The ICO says it is unlikely to be justified in most normal circumstances, but it may be possible for exceptional suspected criminal activity or gross misconduct if there are strong grounds and informing the worker would prejudice prevention or detection. It should be senior-authorised, targeted and time-limited.

Where a proportionate investigative purpose exists, our business investigations can support the wider fact pattern, while our surveillance services may help answer defined public-location or association questions that cannot be resolved from records alone.

What About Interviews?

Digital evidence is rarely the whole story. Employees may have legitimate explanations for activity that looks unusual. Interviewing should therefore take place after enough objective evidence has been preserved to ask focused questions, but before assumptions harden into conclusions.

In an employment investigation, the process should also align with the organisation's policies and Acas principles of fairness. The investigator should examine evidence for and against the allegation and allow relevant explanations to be tested.

Departing Employees Need Structured Controls

NPSA recommends formal exit and legacy controls because departure can create risks to critical assets. Good offboarding is not an accusation; it is normal security hygiene.

Useful exit controls can include:

  • reviewing and removing access at the appropriate time;
  • recovering company devices, tokens and physical credentials;
  • preserving relevant business data before device reuse;
  • reminding staff of continuing confidentiality duties;
  • reviewing unusual access during the notice period where justified;
  • transferring ownership of business accounts and repositories; and
  • recording exceptions where continuing access is legitimately required.

Investigation Findings Should Separate What Is Proven

A strong report distinguishes: access to data; copying or export; destination; possession; disclosure; subsequent use; and the employee's explanation. Those are separate evidential propositions. Proving that a file was downloaded is not the same as proving it was supplied to a competitor.

The report should also describe technical limitations. Logs may be incomplete, devices may be unavailable, shared credentials can complicate attribution and cloud systems can display timestamps in different time zones. Overclaiming weakens otherwise useful evidence.

When Legal Proceedings Are Possible

Trade-secret, breach-of-confidence, contractual or other civil action can move quickly, particularly if an organisation is considering urgent injunctive relief. Evidence preservation and a clear factual chronology can therefore matter immediately. Our legal and litigation support can work to an instructed scope alongside solicitors, but legal strategy and remedies remain matters for the client's lawyers and the court.

The strongest data-theft cases are usually built before the incident

Clear access controls, information classification, sensible logging, staff training, robust offboarding and well-drafted confidentiality obligations make suspicious events easier to investigate and legitimate behaviour easier to distinguish from misuse.

Suspect confidential business information has been removed?

Preserve the evidence and define the immediate risk before confronting the person involved. We can help scope the factual investigation and identify where surveillance, corporate intelligence or legal-support work is proportionate. Book a confidential consultation.

Shared Accounts and Third-Party Access Can Complicate Attribution

Not every suspicious event can be attributed to one person simply because their username appears in a log. Shared credentials, service accounts, delegated access, remote support tools and poorly controlled contractor accounts can all create attribution problems. An investigator should therefore ask who actually controlled the account at the relevant time, whether multi-factor authentication was in use, whether the device was uniquely assigned and whether any other person could have performed the action.

This is especially important when suppliers, consultants or outsourced IT providers have privileged access. A company that focuses only on employees may miss a third-party route into the same information. Contract records, access lists, support tickets and privileged-account logs can be as important as the employee's own activity.

Create an Incident Record From the First Decision

Major investigations often become difficult because important decisions were made verbally and reconstructed later. A contemporaneous incident record can document when the concern was raised, who knew, what containment was authorised, what evidence was preserved, when access changed and why particular investigative steps were chosen.

An incident record should capture:

  • the time and source of the initial alert;
  • what systems and data may be affected;
  • who authorised containment or monitoring;
  • what logs, devices or files were preserved;
  • when HR, legal, security and data-protection teams were informed;
  • whether the ICO risk assessment was triggered;
  • what information remains unknown; and
  • when the scope or risk assessment changes.

Do Not Let the Investigation Become the Security Fix

Finding out who did what is only one workstream. If the suspected route is still open, the organisation may need to reset credentials, restrict sharing, revoke tokens, change access permissions, recover devices or block exfiltration channels. Those containment steps should be proportionate and documented so they do not unnecessarily destroy evidence.

After the immediate incident, organisations should review why the activity was possible. That may expose over-broad permissions, unmanaged personal cloud use, weak offboarding, poor classification, inadequate logging or a culture in which staff routinely move data between personal and business systems. Fixing those conditions reduces the risk of a second incident and makes future anomalies easier to interpret.

Evidence Quality Matters More Than the Number of Alerts

Security products can generate hundreds of alerts around one event. A useful investigation reduces that volume into a small number of propositions supported by the strongest records. For example: the employee authenticated to the system; a specific archive was created; the archive was copied to a removable device; the same device identifier appears on the workstation; and a later communication refers to the files. Each proposition should be supported independently where possible.

That approach is stronger than presenting a dashboard screenshot and describing it as proof of theft. It also makes the case easier for HR, solicitors, insurers or law enforcement to review because the evidence chain is understandable without specialist guesswork.

Sources and References

  • National Protective Security Authority — Ongoing Personnel Security and Exit Procedures guidance on insider risk.
  • Information Commissioner's Office — Data protection and monitoring workers; guidance on fairness, transparency, lawful basis, DPIAs and covert monitoring.
  • Information Commissioner's Office — Personal data breaches: a guide; current 72-hour notification framework.
  • Computer Misuse Act 1990 — section 1 unauthorised access offence.
  • Trade Secrets (Enforcement, etc.) Regulations 2018.
  • GOV.UK / Knowledge Asset Management guidance — trade secret requirements and reasonable protection steps, updated 2026.
  • Intellectual Property Office — IP Basics and trade-secret guidance.
  • Acas — Investigations at work, updated 24 June 2026.

Frequently Asked Questions About Investigating Data Theft by Employees

Answers about insider risk, employee data theft, digital evidence, monitoring, trade secrets, Computer Misuse Act issues, personal-data breaches and lawful investigation steps.


It is a broad description for unauthorised copying, removal, sharing, retention or misuse of business information by an employee, contractor or former worker. The legal consequences depend on what data was involved, the person's authority, contracts, confidentiality, data protection and what was done with the information.

Not necessarily. A premature confrontation can lead to evidence being deleted, accounts being altered or other people being alerted. Immediate containment may be necessary, but it should be coordinated with evidence preservation, HR, IT and legal advice.

No. It is an indicator that needs context. The investigator should establish the employee's role, normal access patterns, active projects, destination and whether there is evidence of retention, disclosure or misuse.

Potentially, but monitoring must have a lawful basis and be necessary, fair and proportionate. Employers should consider policies, privacy information, data minimisation and whether less intrusive evidence can answer the same question.

Only in exceptional circumstances is covert monitoring likely to be justified. ICO guidance expects strong grounds, senior approval, a DPIA, tight targeting, a short period and controls preventing unrelated information being used.

If the incident is a personal-data breach that is notifiable, the organisation must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Not every data-theft allegation reaches the notification threshold, but every personal-data breach should be assessed and recorded.

The ICO recognises that complex breaches may not be fully understood within 72 hours. Organisations should report what they know when notification is required and provide further information without undue delay as the investigation develops.

It can be relevant where access is unauthorised, for example certain access after authority has ended or access beyond permissions. However, cases involving employees who had legitimate access can be legally complex, so organisations should avoid assuming every misuse automatically amounts to a Computer Misuse Act offence.

Current UK guidance describes a trade secret as information that is secret, has commercial value because it is secret and has been subject to reasonable steps to keep it secret. Contractual confidentiality and common-law breach of confidence can also be important.

Potentially, depending on its content, secrecy, commercial value and the steps taken to protect it. A customer list that is widely accessible or assembled from public information may raise different issues from a restricted proprietary database.

Relevant access logs, cloud audit logs, email records, removable-media events, devices, security footage, resignation communications and the allegedly taken files are common priorities. The exact approach should be set by people competent to preserve the evidence without unnecessarily altering it.

Sometimes immediate access restriction is necessary to contain risk, but it should be balanced with operational needs and evidence preservation. The decision is best coordinated between security, IT, HR and legal advisers.

It can sometimes corroborate a narrow issue such as meetings, movements or transfer activity in public places, but surveillance does not replace digital evidence and must be necessary, proportionate and lawful.

It should separate access, copying, destination, possession, disclosure and use, and explain the evidence for each. A good report also records technical limitations and the employee's explanation rather than collapsing the whole case into a single allegation.

Yes. We can support lawful corporate fact finding, intelligence gathering, interviews or surveillance where appropriate and coordinate our findings with the organisation and its legal or digital-forensics advisers.