Skip to content
Telecom

Two regulators open investigations into Optus over data breach

By Rajiv MenonAustralia
1 min read
optus
optus
In this article (5)

Two Australian regulators said on Tuesday they have opened investigations into Optus, the country’s No. 2 telecoms provider, after a breach of its systems resulted in the theft of personal data from up to 10 million accounts.

The probes only add to headaches for Optus, which disclosed the breach on Sept. 22 and has since come under heavy fire from the government and the public for not preventing the massive cyberattack.

The Office of the Australian Information Commissioner (OAIC) said it was investigating whether the Singapore Telecommunications Ltd-owned company took reasonable steps to protect customer data and comply with privacy laws.

The Australian Communications and Media Authority (ACMA) said it was investigating whether Optus met its industry obligations as a telecommunications provider in terms of the keeping and disposing of personal data.

Amid the widening fallout, the federal government has flagged it will overhaul data security laws to force firms that have had a cyberattack to notify banks about customers who may be compromised. Several law firms are also considering filing class action lawsuits.

The OAIC said in a statement if it finds that “interference with the privacy of one or more individuals has occurred”, it may force Optus to take steps to ensure the breach cannot be repeated.

The agency added that it finds there was a breach of Australian privacy law, it can seek civil penalties of up to A$2.2 million ($1.4 million) per contravention.

ACMA Chair Nerida O’Loughlin said in a statement that failure by telecommunications providers to safeguard customer information “has significant consequences for all involved”.

Australian Competition and Consumer Commission Chair Gina Cass-Gottlieb told a parliamentary hearing the regulator was receiving 600 calls a day from people concerned about the Optus breach, although few had been scammed as a result.

Optus said in a statement that it had received formal notices of investigation from both regulators and that it would fully engage with them.

Questions & Answers

Q.

What specifically are the two regulators investigating Optus for?

A.

The OAIC is investigating if Optus took reasonable steps to protect data and comply with privacy laws. ACMA is looking into whether Optus met industry obligations regarding keeping and disposing of personal data.

Q.

What are the potential consequences for Optus if the OAIC finds a breach of privacy law?

A.

If a breach is found, the OAIC may force Optus to take steps to prevent a repeat. It can also seek civil penalties of up to A$2.2 million per contravention.

Q.

How will the federal government respond to this data breach?

A.

The federal government plans to overhaul data security laws. This will force firms experiencing cyberattacks to notify banks about potentially compromised customers.

Q.

What impact has the breach had on customers, according to the ACCC?

A.

The ACCC is receiving 600 calls daily from concerned individuals. However, the chair noted that few customers have actually been scammed as a result of the breach.

Reader pulse

What is the biggest takeaway for your business?

16,050 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Tuesday, Thursday and a Saturday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Tuesday, Thursday and the Saturday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready