OPTUS DATA BREACH - NOTICE OF SERVICES AUSTRALIA
DATA MATCHING PROGRAM
This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by SingTel Optus Pty Limited (Optus) about customers affected by the September 2022 data breach (Optus Data Breach).
Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Optus Data Breach, the following data, to the extent available to Optus, has been provided by Optus to the Agency:
- card number, expiry date and name appearing on Medicare or Centrelink card
- customer’s date of birth
- customer’s home address
- customer’s telephone number.
The Agency will compare the data provided by Optus to Medicare and Centrelink customer records held by the Agency. This will assist the agency to identify affected customers and apply proactive security measures to affected customer records.
A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:
https://www.servicesaustralia.gov.au/centrelink-data-matching-activities?context=1
The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available from:
https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy