Data theft & intellectual property
Suspected removal of client lists, pricing, confidential documents, trade secrets or other proprietary information.

Independent digital misconduct investigations
Dekela provides independent HR investigations into suspected data theft, IT misuse, cyber-policy breaches, inappropriate content and workplace social-media misconduct for UK employers.
Where digital evidence meets fair HR process
Server logs, device records and access reports can be important evidence, but employers still need to establish context, attribution, policy awareness and the employee’s explanation before deciding what happened.
Dekela works alongside your IT team or managed service provider. We translate relevant technical records into a structured workplace investigation while maintaining the distinction between independent fact-finding and the employer’s later disciplinary decision.
Why employers outsource
Urgency matters during a cyber incident, but immediate protective action and the later HR investigation must each be proportionate and carefully documented.
| The internal HR risk | The Dekela outsourced approach |
|---|---|
| Rushing to judgementA decision is made from an alert or log before attribution, context and the employee’s response have been tested. | Procedural fairnessWe examine evidence from both sides and conduct a structured interview before reporting findings. |
| Intrusive evidence collectionManagers access messages or device content without first considering privacy, necessity or proportionality. | Lawful, scoped handlingWe define what evidence is relevant and work with appropriate technical and data-protection specialists where needed. |
| A gap between IT and HRTechnical teams understand system records while decision-makers need a clear account of the employment allegations. | A usable factual reportWe relate the available digital evidence to the agreed allegation, policy and employee response without making the disciplinary decision. |
What we investigate
Each case is scoped around the alleged conduct, relevant policies, available technical evidence and any immediate regulatory considerations.
Suspected removal of client lists, pricing, confidential documents, trade secrets or other proprietary information.
Reckless or deliberate unauthorised disclosure, transfer or loss of personal information.
Viewing, downloading, storing or distributing explicit, offensive or prohibited material using workplace systems or devices.
Online conduct that may breach confidentiality, target colleagues or materially affect the organisation.
Unauthorised software, password sharing, deliberate circumvention of controls or other breaches of cyber-security policy.
Does the digital conduct form part of bullying or harassment? Explore our bullying and harassment investigation service.
SME case study
A regional employer identified unusual download activity after a senior employee resigned to join a competitor. Records suggested that confidential CRM information may have been transferred to removable storage.
Dekela helped scope the HR investigation and worked alongside the employer’s IT provider so relevant logs could be preserved. The evidence was then put to the employee in a formal investigatory meeting, giving them a fair opportunity to respond.
The investigation produced a clear factual record of the digital activity, policy position and employee response. This enabled the employer to move into its disciplinary and legal decision-making processes on an informed basis.
Details have been generalised to protect confidentiality.A rapid but fair process
Speed can help preserve evidence and reduce ongoing risk, but the process must remain thorough, objective and proportionate.
We agree terms of reference, identify evidence-preservation needs and help the employer consider proportionate interim safeguards.
We work with your IT provider or an appropriate specialist to obtain relevant logs, communications and device records lawfully.
We test attribution, intent, policy awareness and context, giving the employee a proper opportunity to answer the evidence.
We provide objective findings on the balance of probabilities against each allegation within the agreed scope.
Current official guidance: Acas investigations at work · ICO monitoring workers guidance · ICO personal data breach guidance
Common questions
For advice about a live situation, speak to our team in confidence.
Accessing communications is not automatically lawful simply because the device belongs to the employer. Any monitoring or review must have a lawful basis, a clear purpose, and be necessary, proportionate and transparent. The organisation should consider its policies, privacy information, data minimisation obligations and whether a data protection impact assessment is required before accessing content.
Not every security incident is reportable. The organisation must assess the likely risk to people’s rights and freedoms. A notifiable personal data breach must be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. All personal data breaches should be documented, whether or not they are reported.
Potentially, where the conduct has a sufficiently clear connection to the employment relationship or a demonstrable effect on the organisation, colleagues, clients, confidentiality or reputation. The employer should investigate thoroughly, apply its policies consistently and consider the employee’s explanation before deciding what action is fair and reasonable.
Confidential initial conversation
Share a high-level outline in confidence. We’ll discuss the alleged conduct, immediate evidence risks and an appropriate fixed-fee investigation scope.