L

Lord Clement-Jones (LD)

Speaking in the House of Lords on 7 January 2026

Debate

Crime and Policing Bill

Contribution

My Lords, my Amendment 359 would create a new offence of digital identity theft. I am very pleased that the noble Lord, Lord Holmes of Richmond, has signed and supports it. The amendment is deliberately tightly framed. It targets the foundational act that underpins so much modern fraud and serious criminality: the deliberate harvesting of someone else’s personal and sensitive information with the intent to impersonate them and conduct transactions, activities or communications in their name without their knowledge or consent. It is about criminalising the act of stealing and weaponising a digital identity before the fraud or other downstream offending takes place. As things stand—and I hope the Minister will confirm this and, indeed, that the promised fraud strategy will recognise—the act of identity theft is not recognised in our law as a criminal offence in its own right. The Fraud Act 2006, the Computer Misuse Act 1990, the Data Protection Act 2018 and subsequent data protection Acts all play an important role, but they are concerned primarily with what happens after the identity has been stolen—after the account has been opened, the loan has been taken out or the money has been moved. They address the fraud, the unauthorised access or the misuse of data. What they do not do is grapple squarely with the initial acquisition of personal and sensitive information with the purpose of impersonation. Indeed, as the House of Lords Fraud Act 2006 and Digital Fraud Committee, chaired by the noble Baroness, Lady Morgan, heard in evidence, identity theft is still formally regarded in much official material as a social rather than a legal concept. That might have been tolerable in a predominantly analogue world, but it is simply not credible in the age of data breaches, credential stuffing, deepfakes and synthetic identities. Treating identity theft as a mere background condition rather than as a legal wrong in itself leaves people’s most intimate identifiers—biometric data, passwords, national insurance numbers and digital credentials—fundamentally underprotected. The effect in practice is that law enforcement may feel it has limited tools to intervene at an early stage, even where there is clear evidence that large quantities of personal data have been harvested and traded with a view to impersonation. Instead, the system waits for the fraud, money laundering or other downstream crime to crystallise. By then, the victim’s credit record may be shredded, their bank accounts compromised and their reputation damaged. Yet the initial act of stealing their identity remains conceptually elusive. The scale and nature of digital identity theft make this gap increasingly untenable. We now know that organised criminals and fraudsters operate, in effect, industrial-scale harvesting operations, feeding on the constant stream of data breaches and leaks from both public and private sector systems. Those databases of stolen credentials are then traded, refined and recombined, very often on the dark web, to facilitate mass impersonation and fraud. This activity is not just an adjunct to fraud. It is, as the Fraud Act 2006 and Digital Fraud Committee rightly described it, a “predicate action”—a necessary precursor to a great deal of online financial crime and, in some cases, to other serious and organised criminality, including terrorism financing. The threat is being turbocharged by new technologies. Large language models enable highly convincing phishing and social engineering communications at scale and with very low cost. Deepfake audio and video systems allow criminals to mimic a person’s voice or image in ways that can be all but indistinguishable from the real thing. When those tools are combined with rich stolen identity data, criminals can construct synthetic identities or impersonate genuine individuals to open bank accounts, obtain credit cards, register mobile phones and pass remote know your customer checks with alarming ease. In that ecosystem, the act of stealing and collating identity data is itself a sophisticated, harmful criminal enterprise, not simply background noise. The Bill is rightly concerned with modernising a range of policing and crime powers for the digital age. It updates police powers in relation to electronic devices and remotely stored data and seeks to equip the criminal justice system to deal with contemporary threats, yet it does not deal with this most basic of digital harms: the theft of a person’s identity. That is why this amendment would define a clear, free-standing offence of digital identity theft. The test that the amendment proposes is straight- forward and proportionate. A person would commit the offence if “the person intends to use this personal or sensitive information to impersonate that individual, or to enable another person to impersonate that individual, with the purpose of carrying out any transaction, activity, or communication in their name without their consent or lawful authority”.

More from Lord Clement-Jones (LD)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.

Partner sites