NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND QIMR BERGEHOFER CUSTOMERS AFFECTED BY THE DATATIME 2022 DATA BREACH
This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by the QIMR Berghofer Medical Research Institute (QIMR) about QIMR customers affected by the 2022 data breach affecting PNORS Technology Group including Datatime, a third party providing services to QIMR (Datatime Data Breach).
Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Datatime Data Breach, the following data, to the extent captured by the Datatime Data Breach and available to QIMR, has been provided by QIMR to the Agency:
- card number and name appearing on Medicare or Centrelink concession card
- customer’s date of birth
- customer’s address.
The Agency will compare the data provided by QIMR to Medicare and Centrelink customer records held by the Agency. This will assist the agency to identify affected customers and apply proactive security measures to affected customer records.
A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:
https://www.servicesaustralia.gov.au/centrelink-data-matching-activities?context=1
The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available from:
https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy
Overview
The Notice of a Data Matching Program issued by Services Australia and the QIMR Berghofer Medical Research Institute addresses the issue arising from the 2022 Datatime data breach, which compromised sensitive information of customers of QIMR. Enacted under the relevant provisions of Australian law, this notice aims to ensure that affected customers are identified and necessary protective measures are implemented to safeguard their information. The Agency intends to use the data provided by QIMR, including card numbers, names, dates of birth, and addresses, to match against its records to proactively enhance the security of affected customers' information. This initiative adheres to the guidelines set forth by the Office of the Australian Information Commissioner to maintain the privacy and security of personal data. The program has been developed in consultation with the OAIC, reflecting a commitment to robust data protection standards and ensuring compliance with privacy laws.
The enactment of this data matching program by Services Australia, as authorised by the appropriate legislative body, aims to address the critical need to mitigate the impact of the Datatime data breach on affected individuals. By collaborating with QIMR and following the OAIC's guidelines, the Agency seeks to protect the privacy and security of its customers' data, ensuring that appropriate measures are taken to prevent further breaches and enhance data security protocols. The Agency's privacy policy, available on its official website, outlines its commitment to safeguarding personal information and maintaining the trust of its customers.
Scope and Application
The data matching program, as described in the notice, applies to customers of the QIMR Berghofer Medical Research Institute (QIMR) who have been affected by the Datatime 2022 data breach. Specifically, it targets individuals whose Medicare number or Centrelink Reference Number (CRN) was disclosed in this data breach. Services Australia, the agency responsible for administering Medicare and Centrelink, will use the information provided by QIMR, which includes the card number and name on Medicare or Centrelink concession cards, the customer's date of birth, and address, to compare against their records. This comparison is aimed at identifying affected customers and implementing proactive security measures for their records. The program operates under the guidelines set by the Office of the Australian Information Commissioner (OAIC) and adheres to the OAIC's standards for data matching, which are designed to protect the privacy of individuals. The geographic reach of this program is within Australia, as both Services Australia and QIMR operate within the Commonwealth jurisdiction. The notice does not specify any exclusions, exemptions, or thresholds for the application of this data matching program.
Key Provisions
The main operative sections of this legislation concern the commencement of a data matching program between Services Australia and the QIMR Berghofer Medical Research Institute (QIMR) in response to the 2022 Datatime data breach. According to section 1, the Agency will receive specific information from QIMR about its customers who were affected by the breach. This includes the card number and name on Medicare or Centrelink concession cards, the customer's date of birth, and their address, provided these details were disclosed during the breach. The Agency will then compare this information against its own records to identify affected customers and implement necessary security measures (section 2). The protocol for this data matching program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC) and is available for review (section 3).
The legislation imposes several obligations on both Services Australia and QIMR. Services Australia must adhere to the OAIC Guidelines on data matching in Australian Government administration, ensuring that the process is conducted in a way that protects the privacy of individuals (section 4). QIMR, on the other hand, is required to provide the specified personal information to Services Australia to facilitate the identification of affected customers (section 1). Both entities are expected to follow the standards outlined in the protocol document, which includes measures to safeguard the privacy and security of the shared data (section 3).
There are no explicit offences, penalties, or civil/criminal consequences mentioned in the legislation for breaches of the data matching program. However, the Agency adheres to the OAIC Guidelines, which provide a framework for handling personal information responsibly. Non-compliance with these guidelines could result in administrative, civil, or criminal penalties under other applicable laws, such as the Privacy Act 1988. The maximum penalties for breaches of privacy laws can include substantial fines for individuals and corporations, depending on the severity and intent of the breach. The OAIC has the authority to investigate complaints and take appropriate action against entities that fail to comply with privacy standards.