Notice of Data Matching Program - Services Australia

Administered by Department of Social Services

Legislation au C2020G00284 In force Gazette

Legislation content

 

NOTICE OF A DATA MATCHING PROGRAM

Services Australia

Services Australia intends to enhance data matching practices between Centrelink and Medicare programs. Services Australia will match identities and details held in Centrelink records with those held in Medicare records. 

The objectives of the data-matching program are to:

  • make sure Centrelink payments are only made to people who are entitled to those payments
  • provide rigour around the authenticity of customer identities
  • protect personal information from identity theft
  • detect and investigate fraud
  • provide net savings by detecting overpayments and recovering debt
  • help the whole-of-government approach to identify serious and complex fraud so the integrity of payments and taxpayer expectations are met
  • increase public awareness and raise voluntary compliance.

 

The following information in relation to customers who appear on both the Centrelink and Medicare databases will be data matched:

 

  • standardised first name
  • nickname/alias
  • standardised surname
  • gender
  • date of birth
  • address
  • email address
  • telephone number, and
  • Medicare Benefits Schedule Usage (date of last service).

 

Services Australia expects to match approximately 9.8 million unique records held in its Centrelink database.  Based on fraud criteria, Services Australia anticipates it will examine approximately 5,000-9,000 records per year.

A protocol document describing this program has been developed with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:

https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/centrelink-data-matching-activities

 

Services Australia adheres to the Australian Information Commissioner’s Guidelines on Data Matching in Australian Government Administration which includes standards for data matching to protect the privacy of individuals. The Services Australia privacy policy is available from:

https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy

Overview

The Notice of a Data Matching Program issued by Services Australia in 2020 aims to improve the accuracy and security of Centrelink payments by cross-referencing records with those held in Medicare databases. This initiative was introduced to address the gaps in ensuring that payments are made only to entitled individuals, safeguarding identities, and preventing fraud while recovering overpayments. The Australian Government, through Services Australia, intends to employ rigorous data matching to meet these objectives, including detecting and investigating fraudulent activities, achieving net savings, and upholding the integrity of government payments. This program is aligned with the Australian Information Commissioner’s Guidelines on Data Matching and the overarching privacy policy of Services Australia, which aims to protect personal information from identity theft and ensure compliance with privacy standards.

Scope and Application

The Data Matching Program, as announced by Services Australia, encompasses the matching of identities and details between Centrelink and Medicare records to achieve specific objectives including the verification of entitlement for Centrelink payments, protection of personal information, fraud detection, and increased public awareness and compliance. This program applies to the approximately 9.8 million unique records held in the Centrelink database, with an anticipated examination of 5,000 to 9,000 records annually based on fraud criteria. The geographic and jurisdictional reach of this Act is national, as it pertains to the Australian Government's administration of Centrelink and Medicare, which are federal programs. The Act does not specify exclusions or exemptions, but it is subject to the Australian Information Commissioner’s Guidelines on Data Matching in Australian Government Administration, which includes privacy standards. This program does not extend or restrict its application through subordinate instruments beyond what is stipulated in the protocol document developed with the Office of the Australian Information Commissioner (OAIC) and the privacy policy of Services Australia.

Key Provisions

Services Australia, as outlined in C2020G00284 (Gazette), has introduced a data-matching program (sections 1-2) to enhance the accuracy and integrity of payments made through Centrelink and Medicare by cross-referencing identity and payment details. The primary objective of this program is to ensure that Centrelink payments are only disbursed to eligible recipients, thereby preventing fraudulent activities and identity theft. This is achieved by matching several key identifiers between the Centrelink and Medicare databases, such as standardised first names, surnames, date of birth, addresses, email addresses, telephone numbers, and Medicare Benefits Schedule usage (section 3). The Act imposes several obligations on Services Australia and the individuals involved. Services Australia is mandated to adhere to the Australian Information Commissioner's Guidelines on Data Matching in Australian Government Administration, which includes stringent privacy standards designed to protect individual data (section 4). Additionally, the data matching process itself is governed by a protocol document developed in conjunction with the Office of the Australian Information Commissioner (OAIC) (section 5). This document, along with the privacy policy, is made publicly available to ensure transparency and accountability in the data matching activities (section 6). Breaching the provisions of this Act can lead to serious consequences. The Act does not explicitly detail the specific offences, penalties, or consequences for non-compliance within the text provided, but it is understood that failure to comply with data protection standards and privacy guidelines could result in both civil and criminal penalties. The potential for such penalties is derived from the broader legislative framework governing data privacy and protection in Australia, which includes fines and imprisonment for severe breaches. Therefore, adherence to the guidelines and protocols is crucial to avoid any legal repercussions.

Legal classification tags

Area of Law
Privacy Law
Instrument
Gazette Notice
Concepts
Definitions & Interpretation
Enforcement Powers
Regulatory Standards
Catchwords
Data Matching Program

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.