Employee browsing: the overlooked privacy risk facing New Zealand workplaces

When we think about privacy breaches our minds often turn to major cyber incidents, data leaks or lost devices. However, many privacy breaches occur in much simpler ways, including when employees access personal information they are not authorised to view.

The Office of the Privacy Commissioner has recently highlighted “employee browsing” as an area of rising concern. Employee browsing occurs when an employee accesses, uses or discloses personal information without a legitimate work purpose. For example, an employee may be able to access sensitive personal information as part of their role particularly if they work in a health, financial services, legal, government or customer-facing organisation. This may involve looking up a customer/patient’s information out of curiosity, accessing a colleague’s personal records without authorisation, or accessing CCTV footage without a legitimate reason.

While these incidents may not always attract public attention, the consequences can be significant for the individuals involved and the organisations responsible for protecting their information. These breaches are not only employee misconduct issues, for example a breach of workplace policies or code of conduct, but they are also privacy breaches under the Privacy Act 2020 (Act).

Employer responsibilities: prevention is key

Organisations have obligations under the Act to take reasonable steps to protect personal information from misuse, loss or unauthorised access. This means employers should consider whether their systems and processes adequately prevent and detect inappropriate access. This includes (but is not limited to):

  • having workplace policies in place that clearly explain what constitutes employee browsing and the potential consequences of inappropriate access (including disciplinary action);
  • providing training so employees understand their privacy obligations and the consequences of inappropriate access;
  • implementing appropriate access controls so employees can only access information necessary for their role;
  • regularly reviewing user permissions, particularly when employees change roles or leave the organisation; and
  • maintaining audit logs to monitor access to personal information and identify unusual activity.

Ultimately, organisations should create a workplace culture where employees understand that personal information is entrusted to them and must be handled appropriately.

Employee responsibilities: access is not permission

The key takeaway is that access and use of personal information must always be connected to a lawful and authorised purpose. A quick look at a file “out of curiosity” may seem harmless, particularly in a small community where a familiar name appears in a workplace database. However, curiosity is not a legitimate business purpose. Unauthorised access may breach workplace obligations and the Act.

A recent Employment Relations Authority decision involved an anaesthetist who was dismissed for accessing patient files without a legitimate work reason. Interim reinstatement was declined for this employee as, although she had a case for unjustified dismissal, her conduct had contributed to the situation and therefore interim reinstatement was not appropriate. For more information on the recent amendments regarding contributory conduct and how it affects employment remedies, see our article here.

Employees should only access personal information when they need it to perform their role. Where privacy breaches or inappropriate access is suspected this should be immediately reported.

Conclusion

By taking employee browsing seriously, organisations can reduce privacy risks, protect the people whose information they hold, and strengthen trust in their workplace.

If you would like to implement or strengthen your existing Privacy Policies, are interested in bespoke privacy training for your organisation, or would like to receive advice regarding a privacy breach, please do not hesitate to get in touch with us.

Meet the team that makes
things simple.

Elisabeth Giles
Jane Tingey
Sarah Wadworth

Let's Talk

"*" indicates required fields

Lane Neave is not able to provide legal opinion or advice without specific instructions from you and the completion of all formal engagement processes.