How do we stop staff looking at records they do not need?
Short answer: Role access, flags and weekly log review
Snooping on VIP, celebrity, colleague or neighbour records is a common problem. Give access by role, mark sensitive records, ask for a reason before opening them, allow break-glass access in emergencies, and review those logs every week.
What the law says
Rule 6 requires access control and monitoring.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Section 8(6) · Rule 7: On becoming aware of a personal data breach, tell each affected person and the Data Protection Board without delay. Send the Board a detailed report within 72 hours, or a longer period if the Board allows on request.
Steps
Flag VIP, staff and sensitive records.
Ask for a reason to open them.
Allow break-glass with review.
Review logs weekly.
Act on misuse consistently.
Evidence to keep
Flag settings
Review records
Action records
Common mistakes
Everyone can see everything
Break-glass never reviewed
No action on misuse
From each seat
CISO / Security head: Build the weekly review.
HR head: Misuse needs a consistent HR response.
Operations head: Front desk and billing also browse records.
Medical director: Back the rule with clinicians.
What a good answer from management sounds like
“Flagged records need a reason, break-glass is reviewed weekly, and misuse is acted on.” Effort and time: Medium.