Employee Privacy Breach
An employee privacy breach tends to be treated more casually than a customer one. A payslip emailed to the wrong person, a spreadsheet of salaries shared internally, a medical certificate left on a printer, or an HR file accessible to people who should not see it.
The instinct is to handle it quietly because the people affected are colleagues. That instinct is where the delay comes from, and delay is the problem.
Where an organisation is covered by privacy law and suspects an eligible data breach, there is an obligation to assess it and, where serious harm is likely, to notify affected individuals and the regulator within a defined period. The clock starts on becoming aware.
The practical control is to make internal breaches reportable through the same route as any other, and to say so explicitly, because staff assume otherwise.
The Office of the Australian Information Commissioner publishes breach guidance. This is general information rather than legal advice, and obligations vary by state and territory.
See Sentrient’s privacy training course and records management software.
Employee Privacy Breach | Employer Fined $60,000 | What Can We Learn?
Case Study: A Thursday Morning Nobody Planned For Picture this: it is Thursday morning. The compliance manager at a mid-size Australian organisation arrives at the office, coffee in hand, ready for an ordinary day. By 10 am, three employees are sitting in front of them, visibly upset. What followed was a serious employee privacy breach: […]
