Modern Australian
Times Advertising

Optus says it needed to keep identity data for six years. But did it really?

  • Written by Brendan Walker-Munro, Senior Research Fellow, The University of Queensland
The Australian government's MyGov website was hacked in 2020.

Among the many questions raised by the Optus data leak – cybersecurity experts are confident it wasn’t a hack, but that may have to be decided by a court – is why the company was storing so much personal information for so long.

Optus had a legitimate need to collect that data – to verify customers were real people and potentially to recover any debts later. This is known as a “know your customer” (or “KYC”) requirement.

But the reason about 4 million former customers along with 5.8 million current customers are now worrying about their driver’s licences, passport numbers and Medicare numbers ending up in the hands of criminals is due to Optus hanging on to it for six years.

Optus has said it is legally required to do so.

It is required by the Telecommunications Consumer Protections Code, the industry code of practice overseen by the Australian Communications and Media Authority, to provide customers (or former customers) billing information for “up to six years prior to the date the information is requested”.

But your name, address and account reference number should be all it needs for this, not your passport, driver’s licence or Medicare details. If it needs to confirm your identity it could simply ask for documents again.

The only clear legal requirement for it to keep “information for identification purposes” comes from the Telecommunications (Interception and Access) Act 1979, which requires that identification information and metadata be kept for two years (to assist law enforcement and intelligence agencies).

Read more: What does the Optus data breach mean for you and how can you protect yourself? A step-by-step guide

Is there any limit?

The big problem with Australia’s data retention laws is that there’s really no limit on how long a company can keep personal data.

The federal Privacy Act says only that information must be destroyed “where the entity no longer needs the information for any purpose for which the information may be used or disclosed by the entity”.

That’s a loose requirement. A company could theoretically argue it “needs” to keep customer information for anything – such as defending against a civil claim in court, as part of its corporate records, or for marketing. This is especially the case when we have consented to those uses when we sign up for the services, another practice the Privacy Act allows.

This is a serious weakness with our privacy laws. Consumer data is big business. Companies are collecting – and keeping – much more personal information than they need without a truly legitimate commercial or legal purpose.

I call this trend “hyper-collection”. It’s turning companies into goldfields for hackers. Once personal information is stolen there is often little authorities can do.

Read more: What do TikTok, Bunnings, eBay and Netflix have in common? They’re all hyper-collectors

It’s time to get serious about data privacy

Australia needs to get more serious about unnecessary data collection and retention. As technology gets more interwoven into our daily lives, protecting personal data presents massive challenges.

The need for vigilance should have been made clear to the federal government in 2020, when its own myGov website was hacked.

The usernames and passwords of thousands of accounts were made available for sale on the dark web. Anyone buying those details would have had access to Medicare, Centrelink, National Disability Insurance Scheme and tax office records.

The Australian government's MyGov website was hacked in 2020.
The Australian government’s MyGov website was hacked in 2020. Shutterstock

Privacy laws are too weak both in obligations and penalties. The fines for “serious interference with privacy” are $444,000 for individuals and $2.2 million for companies – hardly enough for a corporation the size of Optus to sit up and take notice. Nor do they offer comfort to those affected.

Legislative action is needed to clarify what information companies can collect, how they can collect it, and what they can do with it.

Read more: The 'Optus hacker' claims they've deleted the data. Here's what experts want you to know

Opportunities for action

There are two obvious opportunities for the federal government to act.

The first is in its response to recommendations arising from the Attorney-General’s Department’s long-running review of the Privacy Act (which has yet to deliver its final report). Ironically Optus made a submission to the review that actually suggested weakening privacy protections.

The second is what it does with the National Data Security Action Plan being developed by the Department of Home Affairs.

The intention of this plan appears to be to treat data as a national asset. If so, it should strengthen policy and legislation around security, ensure Australians know their rights and responsibilities, and ensure consistent responses to cybercrime.

We need to scrutinise every company – not just Optus, and not just after the fact – and ask questions about their data collection. Why do they need to know things? What information are they keeping, how long for and why?

Without action, the next breach of this kind is a matter of when, not if.

We asked Optus to clarify the reasons it needs to keep identification data for six years but received no response.

Read more: I've given out my Medicare number. How worried should I be about the latest Optus data breach?

Authors: Brendan Walker-Munro, Senior Research Fellow, The University of Queensland

Read more https://theconversation.com/optus-says-it-needed-to-keep-identity-data-for-six-years-but-did-it-really-191498

What People Mean by “Alternative Doctor” And Why Expectations Around Care Are Changing

When people search for an “alternative doctor,” they’re usually looking for something specific, even if they haven’t fully defined it yet. I...

Why Does My Power Keep Tripping? Common Causes Explained by Electricians Sydney

The electrical system is the lifeblood of your home, powering everything from your phones to cooking utensils and more. But from time to time, your po...

Interstate Car Transporter Urges Buyers to Book Early

As the conflict in the Middle East continues to put increasing pressure on local fuel supply, Australian transport companies are experiencing increasi...

Digital Minimalism for Business Owners: Fewer Tools, Better Systems

Be honest. How many apps are open right now? One for scheduling, another for invoices, a third for customer notes, plus a spreadsheet someone email...

The Importance Of Proactive NDIS Renewal Preparation For Sustaining Your Provider Business

Your NDIS renewal notice is not a signal to start preparing. By the time it arrives, preparation should already be well underway. For new providers, s...

Why Fire Extinguisher Testing in Sydney Is Becoming a Records Game, Not Only a Maintenance Job

A fire extinguisher used to feel like one of the simpler parts of building safety. It hung on the wall, wore a service tag, and sat there quietly unle...

The Switchboard Upgrade Question Every Melbourne Renovator Should Ask Before the Walls Close Up

Renovations have a funny way of making people think on surfaces first. Splashback, stone, joinery, tapware, paint. Fair enough too. That is the exciti...

Winter Sanitation Gaps in Parramatta Kitchens: A Hidden Pest Risk

Winter brings a host of changes to our homes, from the chill in the air to the cozy warmth indoors. However, this season also introduces sanitation ch...

When to Seek Advice from Employment Lawyers in Melbourne

Australian employment law is detailed and, at times, complex, with rights and obligations that aren't always obvious to employees or employers witho...

7 Benefits of Professional Gutter Cleaning for Australian Homeowners

Gutters aren't exactly glamorous. They sit up there on the edge of your roof, doing their job quietly - until they stop working. Clogged, overflowing ...

Pipe Floats Strengthening Pipeline Performance In Demanding Environments

Pipelines often travel through environments that are anything but predictable, water currents shift, terrain changes, and materials keep moving unde...

Why Ceiling Fans Are Essential For Comfort, Efficiency, And Modern Living

Creating a comfortable indoor environment is not just about temperature; it is about how air moves, how a room feels, and how efficiently energy is ...

Why Duct Cleaning In Melbourne Is A Smart Investment For Healthier Living Spaces

Behind your walls, ceilings, and vents lies a network quietly working every day to keep your home comfortable. Yet over time, this system can become...

Disability Service Providers Supporting Inclusive And Independent Living

Finding the right support system can feel like assembling a puzzle where every piece must fit just right. For individuals and families navigating di...

A Beginner's Guide to Owning a Caravan in Australia

Owning a caravan opens up a style of travel that's hard to match for freedom and flexibility. However, for those just starting out, the process of c...

Preparing Your Air Conditioner for Summer: What Most Homeowners Overlook

As temperatures rise, many homeowners switch on their air conditioning for the first time in months — only to find it’s not performing the way i...

What Actually Adds Value to Properties in Newcastle

Newcastle has seen steady growth over the past few years, with more buyers looking beyond Sydney for lifestyle, space, and long-term value. As dema...

What is Design and Build in Construction?

Imagine you’re about to start a new construction project, maybe it’s a custom home or a commercial building. You’ve got the idea, the land, an...