Hacker News new | ask | show | jobs
by mytailorisrich 1933 days ago
Employees should have access to customers' data on a need to know basis. Most employees do not need access so should not have access.

Then, there should be an audit trail of all accesses and this should be known to employees. First that dissuades employees from acting improperly, second that allows the company to verify that they indeed do not act improperly and to track down culprits if something happens.