Types of Cybersecurity Risks and Threats to Personal Data

11. Data access abuse

Data access abuse refers to any situation in which a person uses their authority to access information in a manner that is inconsistent with the organisation’s policies, laws, or ethical standards. This includes:

  • unauthorised data viewing - when an employee accesses sensitive information (e.g., customer personal information, medical records, financial statements) without a legitimate business reason;

  • sharing data with third parties – when information is taken outside the organisation without permission, such as by sending data to competitors or acquaintances;

  • using data for personal gain – such as identity theft, personal gain, manipulating information, or exploiting confidential information for other purposes;

  • abuse of administrative privileges – when IT staff or other users with higher levels of access bypass security controls or modify data without supervision.

Such incidents can cause serious harm to an organisation, including loss of customer trust, legal consequences, financial losses, and reputational damage. This is why it is crucial to have clear access management policies, regular audits, and employee education on the proper and responsible use of access rights.

Example:

A faculty employee using students' personal data for private purposes, without permission – this is a misuse of access.

Related to GDPR (more on GDPR in Lesson 7) – misuse of data can also be legally punishable under the General Data Protection Regulation (GDPR).

More information on personal data protection: Croatian Personal Data Protection Agency.

Accessibility

Background Colour Background Colour

Font Face Font Face

Font Size Font Size

1

Text Colour Text Colour

Font Kerning Font Kerning

Image Visibility Image Visibility

Letter Spacing Letter Spacing

0

Line Height Line Height

1.2

Link Highlight Link Highlight