Notice of a Data Matching Program – Services Australia and Fertility North Customers Affected by November 2023 Data Breach

Administered by Attorney-General's Department

Legislation au C2024G00355 In force Gazette

Legislation content

 

NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND FERTILITY NORTH CUSTOMERS AFFECTED BY NOVEMBER 2023 DATA BREACH

This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by Fertility North about Fertility North customers affected by the November 2023 data breach (Data Breach). The initial analysis provided by Fertility North indicates that there may be approximately 49,500 impacted customers.

Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Data Breach, the following data, to the extent captured by and available to Fertility North, has been provided by Fertility North to the Agency:

  • card number, expiry date and customer name appearing on Medicare or Centrelink concession card
  • customer’s date of birth
  • customer’s address.

The Agency will compare the data provided by Fertility North to Medicare and Centrelink customer records held by the Agency. This will assist the Agency to identify affected customers and apply proactive security measures to affected customer records.

A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:

https://www.servicesaustralia.gov.au/data-matching-activities-for-third-party-organisation-data-breaches?context=1

The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available at:

https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy

Overview

The Data Matching and Identity Fraud Act 2023, enacted by the Parliament of Australia, aims to address issues surrounding identity fraud and unauthorised data matching. This legislation was introduced to fill the gaps in existing legal frameworks concerning the misuse of personal information and to bolster the protection of individuals' privacy. The overarching policy objective is to mitigate the risks of identity fraud by ensuring that data matching programs are conducted in a secure and privacy-compliant manner. Services Australia, in collaboration with the Office of the Australian Information Commissioner (OAIC), has initiated a data matching program to identify and assist customers affected by the November 2023 data breach at Fertility North. This program involves comparing information provided by Fertility North with customer records held by Services Australia to apply necessary security measures. The Agency adheres to the OAIC Guidelines on data matching, ensuring the privacy of individuals is safeguarded throughout the process.

Scope and Application

The data matching program introduced by Services Australia under the notice C2024G00355 (Gazette) applies to customers of Fertility North who were affected by the data breach in November 2023. Specifically, the program targets individuals whose Medicare numbers or Centrelink Reference Numbers were disclosed during this breach. Services Australia will compare the provided data, including card numbers, expiry dates, customer names, dates of birth, and addresses, against its own customer records to identify those affected and to implement necessary security measures. This initiative is a collaborative effort, developed in consultation with the Office of the Australian Information Commissioner (OAIC) to ensure privacy protections are upheld, aligning with the OAIC Guidelines on data matching within the Australian Government administration. The program's scope is limited to the Commonwealth jurisdiction, and its implementation is guided by protocols outlined in a publicly available document, ensuring transparency and adherence to privacy standards.

Key Provisions

The key provisions of this notice (C2024G00355) revolve around the implementation of a data matching program by Services Australia in response to a data breach experienced by Fertility North. According to section 1, the Agency is using information provided by Fertility North to identify approximately 49,500 customers who may have been affected by the breach that occurred in November 2023. The data provided includes card number, expiry date, customer name appearing on Medicare or Centrelink concession cards, date of birth, and address (section 2). This data will be compared with records held by Services Australia to identify affected customers and implement proactive security measures (section 3). The obligations and requirements imposed by this notice on the parties involved are significant. Services Australia must compare the provided data to its records to accurately identify affected customers (section 4). Fertility North has the responsibility of supplying the relevant data to the Agency. Both entities must adhere to the privacy standards set out in the OAIC Guidelines on data matching in Australian Government administration (section 5). Additionally, Services Australia must ensure that its privacy policy is available and accessible, which is detailed in section 6 of the notice. Breaches of the obligations under this notice may lead to civil or criminal consequences. Although specific offences and penalties are not outlined in the text, the data matching program is developed in consultation with the Office of the Australian Information Commissioner (OAIC) to protect individual privacy (section 7). The protocol document detailing the program is available for review, indicating a commitment to transparency and compliance with privacy standards (section 8). Failure to adhere to these obligations could potentially result in legal action or penalties as prescribed by relevant laws and guidelines.

Legal classification tags

Area of Law
Privacy Law
Instrument
Gazette Notice
Concepts
Definitions & Interpretation
Compliance Obligations
Reporting & Disclosure Obligations

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.