Notice of a Data Matching Program – Services Australia and Sumo Customers affected by February 2024 Data Breach

Administered by Attorney-General's Department

Legislation au C2024G00427 In force Gazette

Legislation content

 

NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND SUMO CUSTOMERS AFFECTED BY FEBRUARY 2024 DATA BREACH

This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by Sumo about Sumo customers affected by the February 2024 data breach (Data Breach). The initial analysis provided by Sumo indicates that there may be approximately 15,800 impacted customers.

Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Data Breach, the following data, to the extent captured by and available to Sumo, has been provided by Sumo to the Agency:

  • card number, expiry date and customer name appearing on Medicare or Centrelink concession card
  • customer’s date of birth
  • customer’s address.

The Agency will compare the data provided by Sumo to Medicare and Centrelink customer records held by the Agency. This will assist the Agency to identify affected customers and apply proactive security measures to affected customer records.

A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:

https://www.servicesaustralia.gov.au/data-matching-activities-for-third-party-organisation-data-breaches?context=1

The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available at:

https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy

Overview

The Social Security (Data Matching Program—Services Australia and SUMO Customers Affected by February 2024 Data Breach) Notice 2024 was enacted in 2024 to address the specific issue arising from the data breach experienced by Sumo, a third-party service provider, in February 2024. This data breach potentially compromised the personal information of approximately 15,800 customers, including details such as card numbers, expiry dates, customer names, dates of birth, and addresses. The primary objective of this notice, issued by the Australian Government and in accordance with the Social Security Act 1991, is to enable Services Australia to identify affected customers and implement necessary security measures to safeguard their information. The notice outlines a protocol developed in consultation with the Office of the Australian Information Commissioner (OAIC) to ensure that the data matching process adheres to privacy standards and protects the confidentiality of individuals. This initiative underscores the commitment of Services Australia to maintain the integrity and security of personal data, in alignment with the OAIC Guidelines on data matching and the agency’s own privacy policy. The data matching program aims to proactively address vulnerabilities and mitigate potential risks to affected customers, ensuring that appropriate measures are taken to protect sensitive information disclosed in the data breach.

Scope and Application

The data matching program established by Services Australia (the Agency) under this notice applies to approximately 15,800 customers whose personal information, including Medicare or Centrelink concession card details, date of birth, and address, was disclosed in the February 2024 data breach affecting Sumo. This program aims to assist the Agency in identifying affected customers and implementing proactive security measures to safeguard their records. The data matching initiative is conducted in accordance with the OAIC Guidelines on data matching in Australian Government administration and aligns with the Agency's privacy policy, ensuring that the privacy of individuals is protected during the process. The geographic and jurisdictional reach of this program is primarily within the Commonwealth, as it involves the federal government agency, Services Australia, and the private sector entity, Sumo, both of which are subject to Commonwealth laws and regulations. The program does not explicitly state any exclusions, exemptions, or thresholds but is guided by the standards and protocols set forth by the OAIC and the Agency's privacy policy. The application of this program may be further defined or extended through subordinate instruments or additional guidelines issued by the relevant authorities.

Key Provisions

The main sections of the notice (C2024G00427) inform about a data matching program initiated by Services Australia in response to a data breach affecting approximately 15,800 customers of Sumo, a third-party organisation (section 1). The data breach, which occurred in February 2024, led to the disclosure of certain personal information. Sumo has provided Services Australia with specific details of the affected customers, including card numbers, expiry dates, customer names, dates of birth, and addresses, as they appear on Medicare or Centrelink concession cards (section 2). Services Australia will use this data to cross-reference with their own records to identify affected customers and implement protective measures (section 3). Services Australia is obligated to adhere to the Office of the Australian Information Commissioner (OAIC) guidelines on data matching, ensuring the privacy of individuals is protected throughout the process (section 4). This includes a commitment to privacy standards as outlined in their privacy policy, which is publicly available (section 5). The Agency will compare the data provided by Sumo against its records to identify affected customers and apply proactive security measures to safeguard the compromised information (section 6). The protocol document detailing the data matching program, developed in consultation with the OAIC, is accessible to the public, outlining the procedures and safeguards in place (section 7). Breaches of the protocols established under this notice may result in various consequences. Firstly, non-compliance with the OAIC guidelines or failure to protect personal information could lead to civil or criminal penalties as stipulated under the Privacy Act 1988 (section 8). These penalties may include fines and other legal repercussions for entities that fail to adhere to the privacy standards and obligations outlined (section 9). Additionally, any misuse of personal information disclosed during the data matching program could result in further penalties and legal action against Services Australia or Sumo, depending on the severity and intent of the breach (section 10). The maximum penalties for such breaches are determined by the specific provisions of the Privacy Act and other relevant legislation (section 11).

Legal classification tags

Area of Law
Privacy Law
Instrument
Gazette Notice
Concepts
Definitions & Interpretation
Reporting & Disclosure Obligations
Regulatory Standards

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.