Beware the Risk Within: What the AMEX privacy case means for employers
As mentioned in our June T-REX, the Office of the Australian Information Commissioner (OAIC) has delivered an important reminder that some of the most significant threats to privacy come from inside an organisation’s own walls, and they will be held liable for their failures to prevent them.
The OAIC found that American Express Australia Ltd (AMEX) had interfered with a customer’s privacy after a “rogue” employee improperly accessed, used and disclosed the customer’s personal information. While the misconduct was engaged in by an individual employee in breach of their own employment obligations, the OAIC found AMEX had failed to take reasonable steps to prevent unauthorised access to customer personal information, resulting in a breach of Australian Privacy Principle (APP) 11.1.
The decision is significant because it demonstrates that privacy obligations are not limited to protecting against external cyber threats. Organisations must also actively manage the risk that employees may misuse the personal information they can access through their roles. For employers across all sectors, particularly those handling large volumes of sensitive customer information, the determination provides valuable lessons on governance, access controls and privacy risk management.
Background
The complaint arose from a personal relationship between a customer and an AMEX employee. Following the breakdown of that relationship, the AMEX employee accessed, used and disclosed the customer’s credit card transaction information for purposes unrelated to their employment duties. The OAIC found that some of the conduct occurred both during the relationship and after it ended.
The question before the OAIC was not whether the employee had acted improperly (which was largely uncontested). Instead, the key issue was whether AMEX had taken such steps as were reasonable in the circumstances to protect the personal information it held from unauthorised access, as required by APP 11.1.
The OAIC concluded that it had not.
In reaching that conclusion, the OAIC emphasised that:
- Insider security risk is a genuine and foreseeable privacy risk. Employees may seek access to personal information for improper purposes, including financial fraud, domestic and family violence, or political, military or corporate espionage.
- This risk is heightened in sectors that store significant volumes of personal information, including the financial services sector.
Why the decision matters
Many organisations devote substantial resources to protecting themselves from cyber criminals, ransomware attacks and other external threats, and making their employees’ obligations around privacy abundantly clear in policies and employment contracts. However, this OAIC determination highlights that an organisation’s privacy obligations extend well beyond external security incidents, or well-written documents.
The OAIC’s reasoning reflects an increasingly mature regulatory approach to privacy compliance. The focus is not simply on whether a privacy breach occurred, but whether the organisation had implemented appropriate governance, monitoring and technical controls to minimise foreseeable risks.
This distinction is important.
An organisation cannot avoid responsibility merely because the unauthorised conduct was carried out by a “rogue” employee acting contrary to company policy. If the risk was foreseeable and reasonable mitigation measures were available, regulators will expect those measures to have been implemented.
The decision also reinforces a broader regulatory trend towards organisational accountability. Across privacy, cyber security, financial services and anti-money laundering regulation, Australian regulators are increasingly focused on governance frameworks, risk management processes and the effectiveness of controls rather than simply the existence of written policies.
In practical terms, organisations are expected to identify foreseeable risks, assess the adequacy of their controls and continually review whether those controls remain appropriate.
What privacy obligations does the decision highlight?
The determination provides useful insight into how the OAIC assesses compliance with APP 11.1.
Under APP 11.1, organisations must take reasonable steps to protect personal information from misuse, interference, loss and from unauthorised access, modification or disclosure.
What constitutes “reasonable steps” will depend on the circumstances, including the nature and volume of information held, the potential harm that could result from misuse and the resources available to the organisation.
Importantly, the OAIC did not suggest that organisations must eliminate all privacy risk or guarantee that misconduct can never occur. Rather, the determination focused on whether the implementation of additional controls that were reasonably available could have reduced the likelihood of unauthorised access by employees.
The OAIC identified several measures that it considered AMEX could reasonably have implemented, including:
- uniform account-level access logging across relevant systems;
- restrictions on access to particular customer records;
- “just in time” access arrangements; and
- controls preventing employees from accessing the accounts of friends or family members.
These findings provide a useful roadmap for organisations assessing their own exposure to insider security risks.
Practical lessons for employers
- Treat insider security risk as a genuine risk
Many risk assessments focus heavily on external security risks while giving comparatively little attention to internal security risks.
The OAIC’s determination makes clear that insider security risks should be expressly identified, assessed and managed. Organisations should consider scenarios involving employee curiosity, personal relationships, financial motivations and deliberate misconduct when conducting privacy risk assessments.
- Restrict access on a genuine need-to-know basis
Large organisations often accumulate broad access permissions over time. Employees may retain system access long after operational requirements have changed.
A key lesson from the determination is that access to personal information should be limited to those who need it to perform their role. Role-based access controls and periodic access reviews can help reduce the risk of inappropriate access.
- Enhance monitoring and audit capabilities
Monitoring controls are only effective if organisations can identify who accessed information, when they accessed it and what actions they took.
The OAIC specifically identified account-level access logging as an area where additional controls could have been implemented. Robust audit trails not only assist in detecting suspicious behaviour but can also support investigations and regulatory responses when incidents occur.
- Consider additional protections for high-risk customers
The determination highlights the benefit of being able to restrict access to specific customer information where heightened risks exist.
Depending on the nature of the business, organisations may wish to consider enhanced protections for vulnerable customers, high-profile individuals or customers facing safety risks. This may involve additional approval processes, restricted access groups or enhanced monitoring arrangements.
- Policies alone are not enough
Most organisations have privacy policies, codes of conduct and employee confidentiality obligations. These remain important, but the AMEX determination demonstrates that written policies are unlikely to be sufficient if they are not supported by effective operational and technical controls.
Regulators increasingly expect organisations to be able to demonstrate not only what their policies say, but how risks are managed in practice.
Consequences of non-compliance
The consequences for AMEX extended beyond a finding of regulatory non-compliance.
The OAIC ordered AMEX to compensate the complainant for economic loss and non-economic loss, reimburse expenses incurred in making the complaint, provide a written apology and implement additional technical controls and logging capabilities across relevant systems.
These outcomes illustrate that privacy failures can result in financial, operational and reputational consequences. They may also require organisations to undertake costly remediation exercises after the fact.
Looking ahead
The AMEX determination is likely to be viewed as an important reference point for future OAIC assessments of insider security controls.
More broadly, it reflects increasing regulatory expectations that organisations take a proactive and risk-based approach to privacy compliance. As privacy enforcement activity continues to increase and organisations collect larger volumes of personal information, regulators are likely to place greater scrutiny on how access to that information is controlled, monitored and governed.
For employers, the message is straightforward. Privacy compliance is no longer just about preventing external attacks. It also requires organisations to understand how their own employees can access personal information and whether sufficient controls exist to prevent that access from being misused.
Key takeaways
The OAIC’s determination serves as a reminder that insider security risks are not theoretical risks. They are foreseeable risks that organisations must actively manage.
Employers should use the AMEX determination as an opportunity to review their privacy risk assessments, access controls, monitoring capabilities and governance frameworks. Organisations that can demonstrate a thoughtful, risk-based approach to managing employee access to personal information will be better placed to meet regulatory expectations and reduce the likelihood of costly privacy incidents.
| Contact Us | Our Expert Team | Our Training |
Author: Anthony Jensen (Special Counsel)
