Business Daily Media

Men's Weekly

.

Optus says it needed to keep identity data for six years. But did it really?

  • Written by Brendan Walker-Munro, Senior Research Fellow, The University of Queensland
The Australian government's MyGov website was hacked in 2020.

Among the many questions raised by the Optus data leak – cybersecurity experts are confident it wasn’t a hack, but that may have to be decided by a court – is why the company was storing so much personal information for so long.

Optus had a legitimate need[1] to collect that data – to verify customers were real people and potentially to recover any debts later. This is known as a “know your customer[2]” (or “KYC”) requirement.

But the reason about 4 million former customers[3] along with 5.8 million current customers are now worrying about their driver’s licences, passport numbers and Medicare numbers ending up in the hands of criminals[4] is due to Optus hanging on to it for six years.

Optus has said[5] it is legally required to do so.

It is required by the Telecommunications Consumer Protections Code[6], the industry code of practice overseen by the Australian Communications and Media Authority, to provide customers (or former customers) billing information for “up to six years prior to the date the information is requested”.

But your name, address and account reference number should be all it needs for this, not your passport, driver’s licence or Medicare details. If it needs to confirm your identity it could simply ask for documents again.

The only clear legal requirement for it to keep “information for identification purposes” comes from the Telecommunications (Interception and Access) Act 1979[7], which requires that identification information and metadata be kept for two years (to assist law enforcement and intelligence agencies).

Read more: What does the Optus data breach mean for you and how can you protect yourself? A step-by-step guide[8]

Is there any limit?

The big problem with Australia’s data retention laws is that there’s really no limit on how long a company can keep personal data.

The federal Privacy Act[9] says only that information must be destroyed “where the entity no longer needs the information for any purpose for which the information may be used or disclosed by the entity”.

That’s a loose requirement. A company could theoretically argue it “needs” to keep customer information for anything – such as defending against a civil claim in court, as part of its corporate records, or for marketing. This is especially the case when we have consented to those uses when we sign up for the services, another practice the Privacy Act allows.

This is a serious weakness with our privacy laws. Consumer data is big business. Companies are collecting – and keeping – much more personal information than they need without a truly legitimate commercial or legal purpose.

I call this trend “hyper-collection”. It’s turning companies into goldfields for hackers. Once personal information is stolen there is often little authorities can do[10].

Read more: What do TikTok, Bunnings, eBay and Netflix have in common? They’re all hyper-collectors[11]

It’s time to get serious about data privacy

Australia needs to get more serious about unnecessary data collection and retention. As technology gets more interwoven into our daily lives, protecting personal data presents massive challenges.

The need for vigilance should have been made clear to the federal government in 2020, when its own myGov website was hacked[12].

The usernames and passwords of thousands of accounts were made available for sale on the dark web. Anyone buying those details would have had access to Medicare, Centrelink, National Disability Insurance Scheme and tax office records.

The Australian government's MyGov website was hacked in 2020.
The Australian government’s MyGov website was hacked in 2020. Shutterstock

Privacy laws are too weak both in obligations and penalties. The fines for “serious interference with privacy” are $444,000 for individuals and $2.2 million for companies – hardly enough for a corporation the size of Optus to sit up and take notice. Nor do they offer comfort to those affected.

Legislative action is needed to clarify what information companies can collect, how they can collect it, and what they can do with it.

Read more: The 'Optus hacker' claims they've deleted the data. Here's what experts want you to know[13]

Opportunities for action

There are two obvious opportunities for the federal government to act.

The first is in its response to recommendations arising from the Attorney-General’s Department’s long-running review of the Privacy Act[14] (which has yet to deliver its final report). Ironically Optus made a submission to the review that actually suggested weakening privacy protections[15].

The second is what it does with the National Data Security Action Plan[16] being developed by the Department of Home Affairs.

The intention of this plan appears to be to treat data as a national asset. If so, it should strengthen policy and legislation around security, ensure Australians know their rights and responsibilities, and ensure consistent responses to cybercrime.

We need to scrutinise every company – not just Optus, and not just after the fact – and ask questions about their data collection. Why do they need to know things? What information are they keeping, how long for and why?

Without action, the next breach at this kind is a matter of when, not if.

We asked Optus to clarify the reasons it needs to keep identification data for six years but received no response.

Authors: Brendan Walker-Munro, Senior Research Fellow, The University of Queensland

Read more https://theconversation.com/optus-says-it-needed-to-keep-identity-data-for-six-years-but-did-it-really-191498

From Check-in to Touchdown: How AI and smarter systems are transforming the travel industry

Richard Valente, VP of Customer Experience Strategy at TP in Australia, explores how IT-BPM outsourcing is revolutionising the travel sector throu...

Online Christmas shoppers fund climate and biodiversity projects via HealthPost's Click Sphere for Good initiative

Online shoppers with HealthPost’s Flora & Fauna have made 11,000 contributions towards climate and biodiversity projects when ordering parcel ...

US landmark settlement protects SMEs, highlighting flaws in the RBA's proposed blanket card surcharging ban for Australia

Aussie SMEs warn RBA not to ignore global trends, with the current sledgehammer approach threatening business viability and increasing inflation ...

Thryv Australia named Employer of Choice for third consecutive year at Australian Business Awards

Thryv® (NASDAQ: THRY), Australia’s provider of the leading small business marketing and sales software platform, has been awarded the Employer of ...

RogersDigital.com Announces the Launch of TheBulletin.au, a Destination for Business, Policy and Financial Insight

RogersDigital.com has announced the launch of TheBulletin.au, a new national digital publication designed to deliver sharp, data-driven reporting ...

Controlling business spend is helping finance leaders to forecast with confidence

Forecasting has always been central to financial planning; however, traditional methods based on historical trends are no longer enough. Economic ...

hacklink hack forum hacklink film izle hacklink สล็อตเว็บตรงbets10คลิปหลุดไทยÜsküdar Evden Eve Nakliyatsetrabettimebettimebettimebetbahisoistanbul escort telegramcasibomcasibompantheraproject.netdeneme bonusubetsmoveholiganbetmarsbahiscasibomstreameast한국야동casibom girişสล็อตjojobet girişholiganbet girişpornopadişahbetBetigmacasibomBetigmaBetlora girişgiftcardmall/mygiftgaziantep escorteb7png pokiesbest online casino australiabest online pokies australiareal money pokies online australiabcgame96 casinocrown155 hk casinohb88kh casinoGalabetartemisbetmarsbahisgalabetholiganbet girişjojobetgooglebets10bets10betasusjojobetolimposcasinobetbabajojobet 1115jojobet 1115olabahis girişjojobetzbahis girişblooketasyabahis girişpinbahis girişmegapari girişdumanbet girişjojobetStreameastmostbetpusulabetdaftar situs judi slot gacor hb88 indonesiajojobet 1114mostbetmostbetmostbetgalabettlcasinobahis siteleri 2025matbet girişcasinowon girişkavbetjojobetgiftcardmall/mygift check balance visajojobetjojobetซื้อหวยออนไลน์grandpashabetcasibomcasibom girişsadfasdfsdfasdasdasdasdkonya escortgalabetjojobetbetasus girişpin up azSlot Heart Casinomamibet logincasinomedklarna.sebetworld96 online casino cambodiajojobet 1115www.giftcardmall.com/mygiftwww.giftcardmall.com/mygiftCasibomtm menards loginartemisbetroyalbetsekabet girişe wallet casino australiabetasusplay aristocrat pokies onlinesekabetbets10maltcasino girişcanlı maç izledinamobetSahabetcasibomcasibomlunabetzbahis güncel adresfixbetzbahisbets10casibomcasibom girişdeneme bonusu veren sitelerPinup AZhazbetcasibombetpas girişmostbetjojobet girişsitus slot gacorgalabetGalabetmigliori casino non aamsasyabahis girişgoogle hit botuCasibomdizipalmarsbahisgrandpashabetkulisbetmarsbahisgrandpashabetpusulabetGanobetmostbetshrooms online canadacasibom girişeSIM Evropaapp di scommesse 2026jojobetgalabetjojobetartemisbetbetasusjojobetkonya escortmatbetCasino WinnitaholiganbetMarsbahisizmir escort telegramMeritkingpusulabetcasibomjojobet girişjojobetbetcio girişgiftcardmall/mygiftbetlikeqqmamibetbahiscasinoholiganbet girişcasibom girişbets10matbetzbahiszbahisGalabetcasinolevantsekabet girişmarsbahisjojobet girişkonya escortbetcio girişextrabetholiganbetprimebahisJojobethttps://vozolturkiyedistributoru.com/bets10casibomstarzbetbetpasbets10bets10jojobetbetnanocasibomwbahislimanbetcasibombets10bets10bets10vdcasinojojobetMatbetholiganbetjojobetmatbetonwin girişmilanobetelexbetsekabet