New Zealand's Privacy Commissioner Warns of a Hidden Threat Inside Your Own Organisation

A quarter of all reported privacy breaches in New Zealand now involve staff snooping on people's personal records. Organised crime is making the problem worse.

ThreatVectr Newsdesk· 3 min read
AI analyzing network data
Share

Key points

  • New Zealand Privacy Commissioner Michael Webster told RNZ News that 25 percent of reported privacy breaches now involve employees looking at personal records they have no right to see.
  • Webster believes the true number is higher, because many organisations have no systems to detect unauthorised browsing in the first place.
  • Criminals are increasingly bribing, blackmailing, and pressuring bank, insurance, and health sector employees to hand over data from internal databases.
  • Organisations in New Zealand are legally required to report a serious privacy breach to the Privacy Commissioner's office within 72 hours of discovering it.
  • Staff at every level should know that accessing a colleague's or customer's record out of curiosity, or under pressure from outside, can be a criminal act.

When people think about data breaches, they picture an outside hacker. The Privacy Commissioner wants them to think again.

Michael Webster says a quarter of all privacy breaches reported to his office now come from inside organisations, where employees browse personal records they have no business looking at. He told RNZ News he believes the real figure is considerably higher, because many workplaces simply lack the tools to catch it.

The examples range from uncomfortable to criminal. A delivery worker used a customer's address, given innocently at a department store checkout, to contact her and ask if she was single. A health professional sent unsolicited personal messages to a young female patient after she attended a clinic. Webster's description was blunt: "creepy, serious, harassment."

But there is a sharper edge to the problem. Webster says organised crime is now actively targeting employees who hold access to valuable databases, meaning the digital filing systems where banks, insurers, and health providers store customers' personal and financial details. Staff are being bribed, coerced, or threatened into pulling records and passing them on.

Why should ordinary customers care?

If your bank, doctor, or insurer holds your data, and one of their employees is pressured into accessing it, your home address, financial position, or medical history could end up in criminal hands. You would almost certainly never know it happened.

Webster pointed to a recent case within New Zealand Police, where an officer accessed the force's database for dishonest purposes. Police subsequently issued new internal guidance to staff on what counts as unauthorised access.

His advice to organisations is practical: run proper induction and training so staff understand the rules from day one, build technical controls that prevent or flag unauthorised access, and keep audit logs, which are automatic records of who looked at what and when, so a breach can be traced after the fact.

Under New Zealand's Privacy Act 2020, a serious breach must be reported to the Commissioner's office within 72 hours of discovery. The affected individuals must also be told.

If you are a customer of any organisation that holds sensitive data about you, it is worth knowing you have the right to ask what information they hold and how they protect it. If you receive unexpected contact from someone who should only know your details through a business transaction, report it.

© 2026 Threat Vectr