Handling and security Current

Controlling who can access sensitive client records

A practical, risk-based approach to access control.

Not everyone in a firm needs to see every client's sensitive compliance records. This guide sets out a practical approach to deciding and reviewing who does. It is general information, not legal or IT security advice.

Action plan

1 Take reasonable steps to prevent unauthorised access The OAIC's own security principle is explicit that unauthorised access includes access by your own staff, not just outside attackers.

Under Australian Privacy Principle 11, an entity that holds personal information must take reasonable steps to protect it from misuse, interference, and loss, as well as unauthorised access, modification, or disclosure. The OAIC's guidance is explicit that unauthorised access includes access by an entity's own employees or contractors, not only external attackers -- so internal access control is itself a security measure, not a separate concern.

  • Treat internal access by staff who don't need it as a form of unauthorised access, not a lesser concern
  • Base the steps taken on the sensitivity of the records and the consequences of a breach
  • Apply the relevant Essential Eight controls (such as multi-factor authentication and restricted administrative privileges) to systems holding sensitive records

Done when: Reasonable steps against unauthorised access, including by internal staff, are in place for sensitive client records

OAIC: APP 11 security of personal information
2 Assign access by role, not by individual request Role-based access is easier to review and audit than a list of one-off individual grants.

Deciding access by role, rather than granting it ad hoc as individuals ask, makes it far easier to see at a glance who should have access to what, and to review that consistently over time.

  • Define which roles in your firm need access to which categories of sensitive record
  • Grant access according to role, not one-off individual requests
  • Document the reasoning behind each role's access level

Done when: Access to sensitive client records is assigned by defined role rather than ad hoc grants

See storing client identity evidence securely
3 Review access periodically and when roles change Access that made sense when it was granted can become stale as people change roles or leave.

Access reviews shouldn't only happen when something goes wrong. Periodically reviewing who has access, and reviewing immediately when someone changes role or leaves the firm, keeps access current rather than accumulating unused grants over time.

  • Review access on a periodic schedule, not only in response to an incident
  • Review and remove access immediately when someone changes role or leaves
  • Keep a record of each review and what changed as a result

Done when: Access to sensitive client records is reviewed periodically and on role change