Optus Data Breach - Notice of Services Australia Data Matching Program

Administered by Department of Social Services

Legislation au C2022G00963 In force Gazette

Legislation content

 

OPTUS DATA BREACH - NOTICE OF SERVICES AUSTRALIA

DATA MATCHING PROGRAM

This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by SingTel Optus Pty Limited (Optus) about customers affected by the September 2022 data breach (Optus Data Breach).

Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Optus Data Breach, the following data, to the extent available to Optus, has been provided by Optus to the Agency:

  • card number, expiry date and name appearing on Medicare or Centrelink card
  • customer’s date of birth
  • customer’s home address
  • customer’s telephone number.

The Agency will compare the data provided by Optus to Medicare and Centrelink customer records held by the Agency. This will assist the agency to identify affected customers and apply proactive security measures to affected customer records.

A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:

 https://www.servicesaustralia.gov.au/centrelink-data-matching-activities?context=1

The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available from:

 

https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy

Overview

The Optus Data Breach - Notice of Services Australia Data Matching Program, introduced under the C2022G00963 Act, was enacted in response to the significant data breach experienced by SingTel Optus Pty Limited in September 2022. This legislation was introduced by the Australian Government to address the vulnerability of personal data in the wake of the breach, which exposed sensitive information of numerous individuals. The primary objective of this Act, as overseen by the relevant federal legislature, is to ensure that Services Australia can effectively identify affected customers and implement proactive security measures to safeguard their data. The Act mandates the use of data matching to compare the compromised information provided by Optus with customer records held by Services Australia, thus enabling the protection of affected individuals' privacy and mitigating potential misuse of their personal data. Services Australia is committed to adhering to the Office of the Australian Information Commissioner (OAIC) Guidelines on data matching to safeguard individual privacy. This commitment is further reinforced by the Agency's privacy policy, which outlines the measures taken to protect personal information. The data matching program has been developed in consultation with the OAIC, ensuring compliance with privacy standards and reinforcing the government's dedication to data security and individual rights.

Scope and Application

The Optus Data Breach - Notice of Services Australia Data Matching Program applies to individuals who have had their Medicare number or Centrelink Reference Number (CRN) disclosed as part of the September 2022 data breach at SingTel Optus Pty Limited (Optus). Services Australia (the Agency) will use the data provided by Optus, including card number, expiry date and name appearing on Medicare or Centrelink card, customer’s date of birth, home address, and telephone number, to compare with Medicare and Centrelink customer records. This process is aimed at identifying affected customers and implementing proactive security measures to safeguard their records. The geographic and jurisdictional reach of this program is within the Commonwealth of Australia, specifically under the purview of Services Australia. The program operates in accordance with the OAIC Guidelines on data matching, ensuring the protection of individuals' privacy, and adheres to the Agency's privacy policy. It should be noted that the scope of the data matching program is limited to the specific information disclosed during the Optus Data Breach and does not extend to other types of personal information unless explicitly covered under subordinate instruments or subsequent amendments to the program.

Key Provisions

The Optus Data Breach - Notice of Services Australia Data Matching Program outlines the process initiated by Services Australia (the Agency) to handle data affected by the September 2022 breach at SingTel Optus Pty Limited (Optus). The primary sections of this legislation, specifically Sections 1 and 2, mandate the transfer of specific personal data from Optus to the Agency. This data includes the card number, expiry date and name on the Medicare or Centrelink card, date of birth, home address, and telephone number of customers whose Medicare number or Centrelink Reference Number (CRN) was compromised in the breach. The Agency intends to compare this information with its own records to identify affected customers and implement security measures to safeguard their records. Services Australia is required under Section 3 to adhere to the Office of the Australian Information Commissioner (OAIC) Guidelines on data matching. This ensures that the data matching process respects individual privacy and complies with legal standards. The Agency's privacy policy, available at [https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy](https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy), further details how personal information is managed and protected. The Agency's commitment to privacy is underscored by the development of a protocol document in consultation with the OAIC, which outlines the data matching program and is accessible at [https://www.servicesaustralia.gov.au/centrelink-data-matching-activities?context=1](https://www.servicesaustralia.gov.au/centrelink-data-matching-activities?context=1). The obligations imposed by this Act on the parties involved are significant. Optus, as the source of the compromised data, must provide the specified information to Services Australia. The Agency, on the other hand, has the responsibility to compare this information with its records, identify affected customers, and apply necessary security measures to protect these customers' data. Both parties must ensure that all data handling complies with the OAIC Guidelines and the Agency's privacy policy. The Agency must also maintain transparency by making the protocol document publicly available, ensuring stakeholders are informed about the data matching process. Any breach of the provisions outlined in this Act could result in civil or criminal consequences. Although the specific penalties are not detailed in the text, such breaches could potentially lead to legal action against Optus for failing to protect customer data and against Services Australia for any mishandling of the provided data. The penalties for non-compliance could range from fines to more severe legal repercussions, depending on the nature and severity of the breach. The OAIC also has the authority to take action against parties that fail to comply with data protection standards, which could include issuing fines or other penalties as stipulated by relevant legislation.

Legal classification tags

Instrument
Gazette Notice
Catchwords
Data Matching
Privacy

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.