The cost of overlooking insider security risks: Lessons from the OAIC's privacy case against AMEX

Sam Fiddian, Brenton Steenkamp, Sharon Segal and Christa Queern
16 Jul 2026
4.5 minutes

Recent enforcement action by the OAIC has brought insider security risks into sharp focus, underscoring the need for robust controls to safeguard personal information from unauthorised access by employees.

Insider security risks: a frequently overlooked threat

Cyber security and privacy controls are usually thought of as ways to protect from external attacks on systems and data. Sometime however the threat comes from inside the house.

Insider security risk the threat that an individual with authorised access to an entity's systems and data will misuse that access in ways that compromise privacy or security. It can occur in various contexts, including fraud, domestic or family violence and espionage. According to the Office of the Australian Information Commissioner (OAIC), insider security risk remains a significant, yet frequently overlooked, threat to entities and the individuals whose information the entity is entrusted with. This risk is heightened in sectors that store large volumes of personal information – such as the financial services sector.

On 15 June 2026, the OAIC published a summary report on its investigation into American Express Australia Limited (AMEX) and the Privacy Commissioner's determination that AMEX failed to meet its obligation under Australian Privacy Principle (APP) 11.1 to take reasonable steps to protect the personal information it held from unauthorised access.

The OAIC stated that it published the summary report because of the educative value of the Privacy Commissioner's findings against AMEX for the broader community of entities regulated by the Privacy Act 1988 (Cth).

The Privacy Commissioner's findings are a of the importance of not only keeping threats out, but of taking adequate measures to manage those within.

The dangers within

A privacy complaint was made against AMEX alleging unauthorised access to a customer's personal information held on AMEX's systems by an employee of AMEX with whom the complainant had formerly had a personal relationship. As part of their role with AMEX, the employee had access to a number of ICT systems containing personal information of the complainant. The unauthorised access came to light when, in conversation, the employee referred to information that could only have been learned by viewing the complainant's customer account. By this point, it is likely the conduct had gone undetected for over three years.

The OAIC initiated an investigation of the complaint, which involved inquiring into the technical and organisational measures that AMEX had in place to prevent any unauthorised access to personal information, including steps to prevent unauthorised access by AMEX's staff.

AMEX pointed to its various measures, including:

  • a system for managing role-based access to systems and applications;

  • risk management policies and technology standards relating to cyber security and privacy;

  • staff training including training on how information access and entitlements should properly be used;

  • reviews of employee information access entitlements;

  • cyber security reviews, assessments and business unit audits;

  • a code of conduct governing employee access to customer information;

  • an end point protection standard, which required detection, prevention, removal and recovery controls to protect information against malicious activity; and

  • a monitoring program, which deployed analytical risk indicators to detect out-of-pattern or excessive access by frontline staff to customer accounts (however, crucially, did not extend to the employee's team during the period in question).

The importance of holistic measures and account-level controls

APP 11.1 requires entities to take such steps as are reasonable in the circumstances to protect the personal information they hold from misuse, interference and loss, as well as unauthorised access, modification or disclosure.

Many of the measures AMEX had in place were straight out of the data security playbook. However, the "reasonable steps" test requires consideration of whether the measures taken to protect personal information were commensurate to the risks presented in the relevant circumstances. The obligation will differ depending on the complexity of the entity’s business and the internal procedures it has in place. It is not capable of being discharged simply by delegating it to another entity and requires a holistic analysis, considering the full framework of the entity’s systems, policies and procedures.

While acknowledging that the measures AMEX had in place went some way toward the reasonable steps required by APP 11.1, the Privacy Commissioner concluded that AMEX failed to implement appropriate, uniformly applied technical and organisational measures to address insider security risks posed by its staff. In particular, the failure to extend the monitoring program to the employee's team was considered a significant gap in coverage given AMEX was on notice of the need for uniform monitoring coverage having experienced a previous insider threat incident.

For organisations of the size, complexity and means of AMEX, the Privacy Commissioner was of the view that additional measures could reasonably have been taken including:

  • uniform account-level access logging across the ICT systems to which the employee had access;

  • restricting access to certain customer records;

  • implementing "just in time" access; and

  • prohibiting employee access to the customer accounts of their friends and family.

The Privacy Commissioner issued declarations requiring that AMEX apologise, pay compensation to the complainant for economic loss and non-economic loss, and implement technical controls, account-level access logging, and action logging across the relevant systems to appropriately restrict and record employee access to customer records.

Handle with care

While not squarely within the scope of the OAIC's investigation, concerns arose during the investigation that AMEX's handling of the complaint did not meet the requisite standard. It became apparent that the employee had retained the ability to access the complainant's customer account following the complaint being made and that AMEX provided the complainant with incorrect information in its response to the complaint.

The summary report stresses the need for entities to take such steps as are reasonable in the circumstances to implement practices, procedures and systems that will enable them to deal with inquiries or complaints from individuals about their compliance with the APPs. Yet again, the Privacy Commissioner has stressed that it is not just about the incident, but the response as well.

Questions about confidentiality remain

While the OAIC published a summary report, it withheld publication of the Privacy Commissioner's full determination, citing potential harm to individuals, AMEX's cyber security and the OAIC's investigation processes.

The move prompted considerable media commentary, and peaked the interest of politicians, with some commentators characterising the decision as an attempt to “gag” the complainant. Without wishing to insert ourselves into this particular debate, there are good sound reasons why the Privacy Commissioner can, and does, opt to keep certain details confidential.

To reach her determination, the Privacy Commissioner would have needed to carefully examine information concerning AMEX’s internal systems and security posture. Such information is necessarily confidential, and would be highly valuable to external threat actors. In the circumstances, a detailed and substantive summary report clearly outlining the Commissioner’s findings, reasoning, and declarations made against AMEX seems to strike the right balance between transparency and legitimate confidentiality and security concerns.

However, on 2 July 2026, the Australian Senate passed a motion compelling the OAIC to release the full report on its investigations into AMEX, subject only to the redaction of the personal information of the complainant and any third parties. The motion reflects the increasing scrutiny on privacy practices and regulatory compliance by organisations that hold vast amounts of personal information. But it risks causing organisations to rethink the provision of information (outside of compulsory processes) which is crucial in providing regulators such as the OAIC with sufficient visibility of emerging trends and issues.

Key takeaways

  • The obligation under APP 11 to take reasonable steps to protect personal information from unauthorised access applies equally to external risks (eg cyber attacks) and insider security risks.

  • Entities must implement technical and organisational measures to prevent unauthorised internal access, particularly unauthorised access by employees. This requires more than organisational policies or staff training – it also requires the implementation of technical controls such as access and action logging and an ability to restrict access to specific customer information.

  • The response to a complaint matters. Entities should ensure they have robust systems in place to address inquiries and complaints about their compliance with the APPs, and be prepared to take interim measures to avoid any further compliance issues while the complaint is investigated.

Disclaimer
Clayton Utz communications are intended to provide commentary and general information. They should not be relied upon as legal advice. Formal legal advice should be sought in particular transactions or on matters of interest arising from this communication. Persons listed may not be admitted in all States and Territories.