Optus Data Breach - Notice of Services Australia Data Matching Program

Administered by Department of Social Services

Legislation au C2022G00963 In force Gazette

Legislation content

 

OPTUS DATA BREACH - NOTICE OF SERVICES AUSTRALIA

DATA MATCHING PROGRAM

This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by SingTel Optus Pty Limited (Optus) about customers affected by the September 2022 data breach (Optus Data Breach).

Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Optus Data Breach, the following data, to the extent available to Optus, has been provided by Optus to the Agency:

  • card number, expiry date and name appearing on Medicare or Centrelink card
  • customer’s date of birth
  • customer’s home address
  • customer’s telephone number.

The Agency will compare the data provided by Optus to Medicare and Centrelink customer records held by the Agency. This will assist the agency to identify affected customers and apply proactive security measures to affected customer records.

A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:

 https://www.servicesaustralia.gov.au/centrelink-data-matching-activities?context=1

The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available from:

 

https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.