Types of Cybersecurity Risks and Threats to Personal Data
11. Data access abuse
Data access abuse refers to any situation in which a person uses their authority to access information in a manner that is inconsistent with the organisation’s policies, laws, or ethical standards. This includes:
-
unauthorised data viewing - when an employee accesses sensitive information (e.g., customer personal information, medical records, financial statements) without a legitimate business reason;
-
sharing data with third parties – when information is taken outside the organisation without permission, such as by sending data to competitors or acquaintances;
-
using data for personal gain – such as identity theft, personal gain, manipulating information, or exploiting confidential information for other purposes;
-
abuse of administrative privileges – when IT staff or other users with higher levels of access bypass security controls or modify data without supervision.
Such incidents can cause serious harm to an organisation, including loss of customer trust, legal consequences, financial losses, and reputational damage. This is why it is crucial to have clear access management policies, regular audits, and employee education on the proper and responsible use of access rights.
Example:
A faculty employee using students' personal data for private purposes, without permission – this is a misuse of access.
Related to GDPR (more on GDPR in Lesson 7) – misuse of data can also be legally punishable under the General Data Protection Regulation (GDPR).
More information on personal data protection: Croatian Personal Data Protection Agency.
Background Colour
Font Face
Font Size
Text Colour
Font Kerning
Image Visibility
Letter Spacing
Line Height
Link Highlight