

The Office of the Australian Information Commissioner (OAIC) has commenced proceedings against Optus in the Federal Court of Australia. A headline grabbing aspect of these proceedings is that the penalty could range into the trillions – since it could range into the trillions. Each person whose data was breached is alleged to be a separate contravention under the law, meaning the maximum penalty of $2.22 million could be applied to each of the 9.5 million affected individuals.
In this post, we outline the basis of the OAIC’s claim against Optus, explain the separate claim by ACMA briefly, and detail what this means for Australian organisations.
In September 2022, Optus experienced a significant cyberattack, leading to the access and theft of personal information belonging to millions of its current and former customers. The personal information exposed in the breach included names, dates of birth, addresses, and contact details like phone numbers and email addresses. The breach also compromised government-related identifiers, such as passport and driver’s license numbers, along with Medicare card details and various forms of armed forces and police identification.
Following the breach, the OAIC launched an investigation into Optus’s privacy practices. The investigation was not merely about the breach itself but focused on whether Optus had met its obligations under Australian privacy law. The OAIC sought to determine if the telecommunications giant had taken reasonable steps to protect the personal information in its care from misuse, unauthorised access, or disclosure.
It alleges that Optus did not take reasonable steps to secure the personal information it held. The Commissioner’s case considers Optus’s size, resources, the high volume and sensitive nature of the data it held, and the potential for harm to individuals should that data be compromised. That’s why it has commenced legal proceedings against Optus.
“The commencement of these proceedings confirms that the OAIC will take the action necessary to uphold the rights of the Australian community,” said Australian Information Commissioner Elizabeth Tydd.
“Organisations hold personal information within legal requirements and based upon trust. The Australian community should have confidence that organisations will act accordingly, and if they don’t the OAIC as regulator will act to secure those rights.”
The ACMA (Australian Communications and Media Authority) has taken Optus to Federal Court over the September 2022 data breach. The ACMA alleges Optus failed to protect its customers’ personal information from unauthorized access as required under the Telecommunications (Interception and Access) Act 1979. This is a separate legal action from the one brought by the OAIC.
When we initially heard about the OAIC’s civil penalty proceedings against Optus for the 2022 breach, the key takeaways we drew were:
With the benefit of additional time to digest what’s been published so far, we also noted these additional takeaways for Australian organisations:
We’ve previously written about the Optus data breach across multiple posts:
Subscribe to our bi-monthly newsletter to stay up to date on privacy enforcement actions, and what they mean for Australian organisations. You can unsubscribe at any time.
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.