KPMG Australia named John Sams as its new chief executive on Tuesday 21 July 2026, elevating the firm's chief financial and operating officer to the top job as the accounting giant fights to contain a scandal over the handling of confidential client information. Sams inherits a firm accused of using material clients had shared in confidence to help win new contracts — and a June action plan promising governance and integrity reforms that regulators and a parliamentary committee are now watching closely.
For the thousands of Australian businesses that hand sensitive data to accountants, consultants and IT providers every week, the episode is a blunt warning. The controls that protect your commercial secrets are only as strong as the contracts you sign and the technical safeguards you insist on. Here is what the KPMG affair reveals about data risk — and the practical steps an information-security specialist would tell you to take before you share another spreadsheet.
Why the scandal matters beyond KPMG
Professional service firms sit on a mountain of their clients' most valuable information: pricing models, tender strategies, merger plans, payroll records and customer lists. The allegations against KPMG Australia — that confidential material was reused to gain a competitive edge — strike at the core assumption of any advisory relationship: that what you disclose stays sealed to your engagement.
Sams said on his appointment that he would work to restore confidence among clients and staff, deliver the June action plan and engage constructively with the parliamentary committee and regulators. That is the right message. But it also confirms the underlying problem was real enough to force leadership change at one of the country's largest firms.
The lesson for business owners is uncomfortable. A brand name and a professional reputation are not a data-security strategy. If a Big Four firm can face these questions, a small consultancy or freelance contractor can too. The onus is on you to define, in writing and in your systems, exactly how your information may be used.
What the law already requires
Australian organisations that handle personal information are bound by the Australian Privacy Principles (APPs), the 13 standards at the heart of the Privacy Act 1988. As the Office of the Australian Information Commissioner explains, the APPs govern the collection, use and disclosure of personal information and are deliberately "technology neutral" so they apply as tools change (oaic.gov.au).
APP 6 is the one that bites hardest here: personal information collected for one purpose generally cannot be used or disclosed for another without consent. Reusing client data to chase unrelated contracts is precisely the kind of secondary use the framework restricts. But the APPs cover personal information — names, records tied to individuals — not every commercial secret. Your tender strategy or pricing model may fall outside the Privacy Act entirely, which is why contracts and technical controls do the heavy lifting for pure business data.
The confidentiality gap most contracts leave open
An IT governance specialist reviewing your supplier agreements will look first for a confidentiality clause that is specific, not decorative. Vague promises to "keep information confidential" are hard to enforce. Strong clauses name the categories of data covered, prohibit any use outside the engagement, forbid reuse for the firm's own benefit or for other clients, and set out what happens to your data when the work ends.
Just as important is what the contract says about sub-contractors, offshore processing and retention. Many firms move data to third-party platforms or overseas teams. If your agreement is silent on that, you have lost visibility over where your secrets live. Insist on a clause that requires your written approval before your data is shared onward, and a deletion-and-certification obligation once the project closes.
Technical controls you can insist on
Contracts set the rules; technology enforces them. A security consultant would recommend a short, non-negotiable checklist before onboarding any external firm:
- Least-privilege access. Share only the specific files an engagement needs, through a controlled portal rather than open email attachments. Named individuals, not whole teams, should have access.
- Encryption and audit logs. Data should be encrypted in transit and at rest, and every access event should be logged so you can see who opened what, and when.
- Time-boxed access. Grant access for the life of the project and revoke it automatically on completion, rather than leaving permissions live indefinitely.
- Data segregation. Ask how the firm keeps your information walled off from other clients' data and from its own business-development teams — the exact boundary the KPMG allegations concern.
- Breach notification terms. Require prompt written notice of any suspected misuse or breach, with a defined timeframe.
None of these measures is exotic. They are standard practice for well-run providers — and a firm that resists them is telling you something useful.
What to do now
If you engage professional advisers, treat the KPMG story as a prompt to audit your own exposure. Pull your three most important supplier contracts and check whether the confidentiality clauses actually restrict use, not just disclosure. Map what sensitive data each provider currently holds, and revoke access that projects no longer need. Where personal information is involved, confirm your provider's obligations align with the APPs.
An information-technology or data-governance consultant can run this review in days and translate the gaps into contract amendments and access changes your suppliers must accept. Connecting with a qualified IT or legal expert through ExpertZoom is a fast way to pressure-test whether your confidential data is genuinely protected — before, not after, a supplier's judgement is called into question.
The change of leadership at KPMG Australia will play out over months. Your data risk is present today, and it is one of the few things in this saga you can actually control.
This article is general information, not legal advice. For obligations specific to your business, consult a qualified professional.

Liam O'Connell