OAIC determination puts insider privacy risk back in the spotlight

The Office of the Australian Information Commissioner (OAIC) doesn’t issue determinations against household names very often. When it does, the findings are worth reading carefully — not for the specifics of one company’s failure, but for what they reveal about the controls most organisations quietly lack. The OAIC’s June 2026 determination in the matter of BAM and American Express Australia is one of those findings.

The 30-second take

The OAIC found American Express Australia breached Australian Privacy Principle 11.1 by failing to take reasonable steps to protect a customer’s personal information from unauthorised internal access — not a cyber attack, but an employee accessing information they should not have seen. AMEX has been ordered to pay compensation, issue a written apology, and implement access controls across affected systems.

With the Medibank civil penalty case still before the Federal Court, OAIC enforcement on APP 11 is active, escalating, and no longer limited to cyber perimeter failures.

The inside threat is now in scope.

What the OAIC found against American Express

In a determination published in June 2026, Australian Privacy Commissioner Carly Kind found that American Express Australia Limited interfered with the complainant’s privacy by failing to take reasonable steps to protect their personal information from unauthorised access by an employee. This is a breach of APP 11.1 — the obligation requiring APP entities to protect the personal information they hold from misuse, interference, loss, and unauthorised access, modification or disclosure.

The determination is significant because the failure was not a cyber attack from outside.

It was an internal access problem — an employee reaching information they had no legitimate reason to see.

AMEX has been required to pay the complainant compensation for both economic and non-economic loss, reimburse complaint expenses, issue a written apology, and — critically — implement access controls across the relevant systems to restrict employees’ access to specific customer information.

That last remedy is instructive: “implement access controls” ordered after a breach means those controls were not in place, or were not effective, before it occurred.

For any organisation holding significant volumes of customer personal information, that is worth sitting with.

The broader pattern: Medibank and the civil penalty precedent

The AMEX determination does not stand alone. In June 2024, the Information Commissioner commenced civil penalty proceedings in the Federal Court against Medibank Private Limited, alleging that Medibank seriously interfered with the privacy of approximately 9.7 million Australians by failing to take reasonable steps to protect their personal information — a breach of APP 11. The Medibank case involves external attackers using stolen contractor credentials, but the underlying failure is the same: insufficient controls over who can access what, and insufficient monitoring to detect when access goes wrong.

The Medibank proceedings expose the organisation to potential penalties of up to $2.22 million per contravention under section 13G of the Privacy Act. For large-scale systemic failures, those figures compound quickly. The OAIC’s Notifiable Data Breaches reports have consistently recorded that approximately 5% of all notifiable breaches involve a rogue employee or insider threat — a figure that understates actual insider-access incidents, since many never become notifiable data breaches.

Taken together, the AMEX determination and the Medibank proceedings show a regulator that is actively enforcing APP 11 across both external and internal threat vectors, using both determination and civil penalty powers, and ordering remedies that go beyond apologies to structural changes in how organisations control access to personal information.

What APP 11.1 actually requires — and where most organisations fall short

APP 11.1 requires an entity to take reasonable steps to protect the personal information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure.

The OAIC’s guidelines make clear that “reasonable steps” include IT system controls, internal access controls, and audit trails — not just perimeter cyber defences.

In practice, most organisations have strong controls at the boundary: firewalls, MFA on external-facing systems, endpoint detection. The controls that are more often weak are the internal ones: role-based access management that reflects actual job functions rather than historical permissions, monitoring and alerting on anomalous internal access patterns, regular access reviews that remove stale permissions, and audit trails that can reconstruct what an employee accessed and when.

The controls that are more often weak are the internal ones

APRA-regulated entities face a compounding obligation: under CPS 234, information security incidents — including unauthorised access to customer information — must be reported to APRA within 72 hours. A breach that triggers an OAIC complaint can simultaneously trigger a CPS 234 notification obligation. The entities that manage this best are the ones that treat access control as an operational risk question with a named owner, not a technology question managed quietly by IT.

Privacy and Information Security as Operational Risk

This case illustrates a recurring theme: privacy risk managed as a compliance checkbox produces a different control environment than privacy risk managed as operational risk.

The question is not “do we have a privacy policy?” but “can we demonstrate that our controls prevent and detect unauthorised access — by employees, contractors, and third parties — and can we evidence that capability to a regulator if asked?”

For organisations operating in financial services, health, or any sector holding sensitive personal information at scale, the AMEX determination and Medibank proceedings together make the enforcement landscape clear: APP 11 is actively supervised, both internal and external threats are in scope, and remediation ordered after a breach is more costly — financially, operationally, and reputationally — than controls put in place before one occurs.

Questions your organisation should be asking now

  • Can we map which employees and contractors have access to which categories of customer personal information — and does that access reflect their actual job function today, not when they joined?
  • Do we have monitoring and alerting in place that would detect anomalous internal access to personal information — and has that capability been tested?
  • When did we last conduct a formal access review across systems holding sensitive personal information, and what did we do with the results?
  • If the OAIC asked us to demonstrate our APP 11.1 controls today, what evidence could we produce — and where would the gaps be?
  • Do our incident response and CPS 234 notification processes account for insider-access events, not just external cyber incidents?
  • Who owns insider-access risk in our organisation — and is it treated as an operational risk with a named accountable owner, or managed informally by IT?

Where to go from here

The OAIC’s determination against American Express is a clear signal that APP 11 enforcement has moved beyond cyber perimeter failures. Internal access controls — who can see what, whether that access is logged, and whether anomalous access is detected and acted on — are now a direct enforcement focus.

For most organisations, the honest answer to “could this determination have been made about us?” deserves a careful look.

Explore more about risk and governance readiness tools at the Innovation of Risk.

More from the Reading Room

APRA’s Corporate Plan Reinforces the Focus on AI Governance

The wrong response to increasing AI risk is to stop people using AI. That does not remove the risk. It often pushes AI use underground,...

Regulators continuous focus on delivering effective risk management

APRA’s licence conditions followed Deloitte findings of longstanding and pervasive non-financial risk weaknesses at Bendigo and Adelaide Bank. Bendigo Bank has announced a three-year, $70 million rectification program, while APRA retains a $50 million operational-risk capital add-on and requires independent assurance and board attestation.

The Hidden Cost of Poor Transparency in Insurance

ASIC's 2026 Report 838 shows that 31% of consumers who contacted their insurer obtained a lower renewal premium without changing cover. AFCA's complaint data adds a practical signal for boards testing car-insurance pricing and renewal transparency.

Beyond the Label: Importance of Accountability

An eight-month forensic investigation by Four Corners revealed widespread mislabelling and adulteration in food products sold in Australia, including tomato paste sourced from China’s Xinjiang region and seafood falsely promoted as Australian. In response, the ACCC launched an inquiry into misleading conduct, spotlighting the urgent need for stronger accountability and supply chain transparency to protect consumers.