Data Privacy at SMBtech

Australian Privacy Commissioner Orders American Express To Compensate Complainant Over Insider Access Breach

Surprisingly Useful AI Article Enhancements

The Office of the Australian Information Commissioner (OAIC) has published its summary report into a privacy determination against American Express Australia Limited, finding the financial services company breached the Privacy Act by failing to protect a complainant’s personal information from unauthorised internal access.

Australian Privacy Commissioner, Carly Kind, found that American Express Australia (AMEX) interfered with the complainant’s privacy under the Privacy Act 1988 (Cth) by failing to take reasonable steps to protect their personal information from unauthorised access, in breach of Australian Privacy Principle (APP) 11.1.

The Commissioner ordered that AMEX must not repeat or continue the conduct.

The case, involving a complainant referred to as “BAM” in the proceedings, centres on the issue of insider security risk – the threat posed by employees accessing personal information held by their employer for improper purposes. The OAIC’s investigation found that AMEX failed to adequately mitigate those risks.

What the determination requires

Under the determination, American Express Australia is required to pay the complainant specified amounts for economic loss and non-economic loss caused by the privacy interference, along with reimbursement of expenses incurred in making the complaint. The specific amounts were not disclosed in the summary report.

AMEX must also issue a written apology to the complainant, signed by a representative of sufficient seniority, acknowledging its interference with the complainant’s privacy.

On the technical side, the company has been ordered to implement access controls across the relevant systems to restrict employees’ access to specific customer information. The OAIC noted this should include protections for the personal information of vulnerable or high-profile customers.

AMEX is also required to implement account-level access logging and action logging across the relevant systems that remain in operation, creating timestamped log entries whenever an employee accesses or takes action on a customer’s records.

Insider threat in the financial sector

The OAIC described insider security risk as a frequently overlooked threat to organisations and to the individuals whose personal information those organisations hold.

The regulator noted that the risk of employees seeking access to personal information for improper purposes – including financial fraud, domestic and family violence or corporate and political espionage – is heightened in sectors that store large volumes of personal data.

The financial services sector, which by its nature holds detailed personal and financial records on customers, is one such area.

The determination underscores the role that ICT access controls play in ensuring personal information is protected from unauthorised access, particularly from employees within the same organisation.

The OAIC stated that entities holding personal information, including those in the financial sector, must ensure sufficient controls are in place to protect that data from the risk of unauthorised employee access.

Why a summary report was published

The OAIC chose to publish a summary report rather than the full determination in this matter, citing Section 33C of the Privacy Act, which empowers the Privacy Commissioner to release information where doing so is in the public interest.

Both AMEX and the complainant provided the OAIC with sensitive information during the investigation, and each party made separate confidentiality claims.

The OAIC determined that disclosing this information in full could cause harm to individuals, present a risk to AMEX’s cyber security and undermine the regulator’s investigation processes.

The approach and reasoning were communicated to both parties in correspondence.

Background

The OAIC issued a statement regarding the American Express investigation in October 2025. The findings conclude what the regulator described as an extended investigation and decision-making process.

The OAIC’s report of investigation into AMEX is available for download on the OAIC website.

Last Updated on June 15, 2026 by Nick Ross

Surprisingly Useful AI Article Enhancements

Sign-up to the SMBtech Daily Newsletter

We will not spam you. You can easily unsubscribe any time. Read our privacy policy.