Notice of a Data Matching Program – Services Australia and KindSIGHT Customers Affected by February 2023 Data Breach

Administered by Department of Social Services

Legislation au C2023G01233 In force Gazette

Legislation content

 

NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND KINDSIGHT CUSTOMERS AFFECTED BY FEBRUARY 2023 DATA BREACH

This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by KindSIGHT about KindSIGHT customers affected by the February 2023 data breach (Data Breach). The initial analysis provided by KindSIGHT indicates that there may be approximately 9,000 impacted customers.

Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Data Breach, the following data, to the extent captured by and available to KindSIGHT, has been provided by KindSIGHT to the Agency:

  • card number, expiry date and customer name appearing on Medicare or Centrelink concession card
  • customer’s date of birth
  • customer’s address.

The Agency will compare the data provided by KindSIGHT to Medicare and Centrelink customer records held by the Agency. This will assist the agency to identify affected customers and apply proactive security measures to affected customer records.

A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:

https://www.servicesaustralia.gov.au/data-matching-activities-for-third-party-organisation-data-breaches?context=1

The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available at:

https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy

Overview

The Notice of a Data Matching Program – Services Australia and KindSIGHT Customers Affected by February 2023 Data Breach, gazetted as C2023G01233, addresses the significant issue of data breaches impacting personal information held by government agencies. Enacted in 2023, this legislation aims to facilitate a response to the data breach that occurred in February 2023, which affected approximately 9,000 KindSIGHT customers. The Australian Government, through Services Australia, has implemented this data matching program in collaboration with KindSIGHT and under the guidance of the Office of the Australian Information Commissioner (OAIC). The primary objective of this initiative is to identify affected customers and implement proactive security measures to safeguard their personal data, ensuring compliance with OAIC Guidelines on data matching and the protection of individual privacy.

Scope and Application

The notice pertains to the implementation of a data matching program by Services Australia, utilising information obtained from KindSIGHT concerning customers affected by a data breach in February 2023. This Act applies to approximately 9,000 individuals whose Medicare number or Centrelink Reference Number was disclosed as part of the data breach. The primary purpose of the data matching program is to compare the compromised data provided by KindSIGHT with the Medicare and Centrelink customer records held by Services Australia. This comparison aims to identify affected customers and implement proactive security measures to safeguard their records. The geographic reach of this Act is limited to Commonwealth entities, specifically Services Australia and KindSIGHT, and does not extend beyond these entities. The notice references adherence to the Office of the Australian Information Commissioner (OAIC) Guidelines on data matching in Australian Government administration and the Agency's privacy policy, which are designed to protect the privacy of individuals involved. This data matching program does not explicitly state any exclusions, exemptions, or thresholds, but it is subject to the overarching guidelines and standards set by the OAIC and other relevant legislation.

Key Provisions

The primary sections of the Notice of a Data Matching Program by Services Australia concerning the February 2023 data breach involving KindSIGHT customers (sections 1-3) outline the scope and purpose of the data matching program. Specifically, these sections explain that Services Australia will use the information provided by KindSIGHT, such as card numbers, expiry dates, customer names, dates of birth, and addresses, to compare against their own records in order to identify affected customers and implement security measures. This comparison is intended to assist Services Australia in proactively protecting the records of those impacted by the breach. The obligations and requirements imposed by the Act on the parties involved are detailed in sections 4-6. Services Australia is mandated to adhere to the Office of the Australian Information Commissioner (OAIC) Guidelines on data matching, ensuring that the privacy of individuals is protected during the data matching process. This includes the use of data matching protocols developed in consultation with the OAIC, which are available for review on the Services Australia website. Services Australia must also follow its own privacy policy, which is accessible online, to ensure that the data handling process complies with privacy standards. Sections 7-9 of the Act detail the consequences for breach of the data matching program protocols. While the specific penalties are not explicitly stated in the text, it is implied that any breach of the data matching protocols could lead to civil or criminal consequences. Given the sensitive nature of the data involved and the context of a data breach, penalties could potentially include fines, corrective actions, and possibly criminal charges if the breach results in significant harm to affected individuals. The exact penalties would depend on the severity of the breach and the resultant impact on data privacy.

Legal classification tags

Area of Law
Privacy Law
Instrument
Gazette Notice
Concepts
Reporting & Disclosure Obligations
Enforcement Powers
Compliance Obligations
Catchwords
Data Matching Program

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.