Impersonation is not investigation: why GDPR compliance matters when you instruct someone to gather information
- 5 days ago
- 4 min read

The story from Leeds Magistrates' Court this week has been widely shared, mostly for its absurdity. Conor Johnstone, a Cheshire-based solicitor who marketed himself as "the Legal Missile," was sentenced on Monday to a 12-month community order and 260 hours of unpaid work after being convicted of impersonating a police officer. He had rung a Nando's restaurant in Warrington posing as "PC Matt Gregory" of Cheshire Police's Domestic Violence Unit, and requested CCTV footage of persons within the establishment. The Solicitors Regulation Authority has also opened its own investigation.
It is, on the face of it, a story about a man behaving badly and being caught. But underneath the headline is a serious point that anyone who ever instructs someone else to gather information about a person — solicitors, insurers, HR teams, corporate compliance, private individuals — should take note of.
Someone, somewhere, was willing to break the law to get personal data. And they very nearly got it.
The Nando's staff acted appropriately and were not negligent. They received a phone call from a person who sounded plausible, gave a plausible name, referenced a plausible police unit, and produced an email address that looked legitimate. The only reason Johnstone got caught was that he had bought the fake email domain using his own personal details, and Cheshire Police followed the paper trail straight back to him.
If Johnstone had been better at deception — a better-forged email, a cleaner domain purchase, a slightly more careful pretext — the CCTV would have been handed over. Personal data, obtained by deception, with no lawful basis, with no data subject rights considered, and no controller in a position to answer for it.
Why this is a GDPR issue as much as a criminal one
Impersonating a police officer is an offence in its own right under section 90(1) of the Police Act 1996. But the wider issue — obtaining personal data by pretending to be someone you are not — is also a matter for the Data Protection Act 2018 - it is a criminal offence to knowingly or recklessly obtain, disclose or procure personal data without consent, and the ICO prosecutes these cases.
Pretexting — using a false identity or false pretext to extract information from a data holder — it is one of the oldest tricks. It is also, in almost every scenario, unlawful. And critically for anyone commissioning investigative work: the person who instructs the pretexting can be as legally exposed as the person who carries it out.
ABI's UK GDPR Code of Conduct
The Association of British Investigators' UK GDPR Code of Conduct is currently the only ICO-approved code of conduct for the private investigation sector. It means the code has been formally scrutinised by the Information Commissioner's Office and confirmed as reflecting a lawful, workable, sector-specific interpretation of the UK GDPR. It is not a marketing document. It is a regulatory instrument.
Members who sign up to the code are professionally bound to conduct their work in line with it. That includes:
Establishing a lawful basis for every processing activity before it happens
Rejecting instructions that would require unlawful data acquisition — including pretexting, impersonation, or the use of unlawful databases
Maintaining data minimisation, proportionality and purpose limitation
Recording and evidencing lawful basis, so it can be produced if challenged
Ensuring data subject rights are respected even in adversarial contexts
Providing clients with clear scope and method documentation
Members are audited before admission, & subject to a code-of-ethics complaints procedure. They are required to carry professional indemnity insurance, and required to hold GDPR training. Membership is not a badge you buy; it is a credential you earn and can lose.
What this means for those who instruct investigators
If you are a solicitor, an insurer, an HR director, or anyone else who has cause to engage someone to trace a person, verify an identity, gather evidence, or conduct surveillance, then you should be aware that the methods your investigator uses become your problem the moment you instruct them.
If the trace was obtained through pretexting, the data cannot lawfully be relied upon in proceedings. If the information came from an unlawful database, you could face regulatory action of your own. If the investigator impersonated a professional — a police officer, a solicitor, a bank employee, a public authority — the reputational damage attaches to the party who instructed them, not just the person on the phone.
The Johnstone case is a warning to instructing parties as much as it is to the investigation industry. He is a solicitor, but the person he was trying to obtain data about was his ex-partner, and he acted in his personal capacity. But had this same call been made by an investigator on behalf of a client — same pretext, same illegal method — the client's exposure would have been very real.
A short due-diligence checklist when you instruct an investigator
Are they an ABI member? (Check the directory — theabi.org.uk)
Are they intending to sign up to the UK GDPR Code of Conduct?
Do they carry professional indemnity insurance?
Will they provide a written scope of instruction that identifies the lawful basis for each processing activity?
Do they refuse work that requires pretexting or impersonation? A good investigator will say so, unprompted.
If challenged in litigation, could their method be defended in front of a judge and the ICO?
If the answers are yes, you are working with a professional. If the answers are vague, evasive, or dismissive — "don't worry about all that, we'll get it done" — walk away.
The point of the profession
The whole reason the private investigation industry exists as a legitimate service is that there are lawful ways to find people, verify facts, trace debts, gather evidence and support legal proceedings — and there is expertise in doing those things well, ethically, and in a manner that will withstand scrutiny.
Impersonation is not one of them. Deception is not one of them. Nando's CCTV obtained under false pretences is not one of them.
The industry's reputation, and the reputation of every professional in it, depends on drawing that line clearly and holding it.
If you instruct investigation work — whatever the sector — please instruct people who work above that line, not below it.




