The Times Australia
Google AI
The Times World News

.

regulatory changes announced, but legislative reform still needed

  • Written by Brendan Walker-Munro, Senior Research Fellow, The University of Queensland
regulatory changes announced, but legislative reform still needed

In response to Australia’s biggest ever data breach, the federal government will temporarily suspend regulations[1] that stop telcos sharing customer information with third parties.

It’s a necessary step to deal with the threat of identify theft faced by 10 million current and former Optus customers. It will allow Optus to work with banks and government agencies to detect and prevent the fraudulent use of their data.

But it’s still only a remedial measure, intended to be in place for 12 months. More substantive reform is needed to tighten Australia’s loose approach to data privacy and protection.

Read more: A class action against Optus could easily be Australia's biggest: here's what is involved[2]

Changing regulations, not legislation

The changes – announced[3] by Treasurer Jim Chalmers and Federal Communications Minister Michelle Rowland – involve amending the Telecommunications Regulation 2021[4].

This a piece of “subordinate” or “delegated law[5]” to the Telecommunications Act 1997[6]. Amending the act itself would require a vote of parliament. Regulations can be amended at the government’s discretion.

Man pointing while speaking
Treasurer Jim Chalmers has announced new measures to allow banks to help detect fraud against Optus customers. Lukas Coch/AAP Image

Under the Telecommunications Act it is a criminal offence for telcos to share information about “the affairs or personal particulars of another person”.

The only exceptions are sharing information with the National Relay Service[7] (which enables those with hearing or speech disabilities to communicate by phone), to “authorised research entities” such as universities, public health agencies or electoral commissions, or to police and intelligence agencies with a warrant[8].

That means Optus can’t tell banks or even government agencies set up to prevent identity fraud, such as the little-known Australian Financial Crime Exchange[9], who the affected customers are.

Important safeguards

The government says the changes will only allow the sharing of “approved government identifier information[10]” – driver’s licences, Medicare and passport numbers.

This information can only be shared with government agencies or financial institutions regulated by[11] the Australian Prudential Regulatory Authority. This means Optus (or any other telco) won’t be able to share information with the Australian branches of foreign banks.

Man and woman speaking at podium
The government’s new measures are intended to last 12 months, but longer-term reform is needed. Lukas Coch/AAP Image

Financial institutions will also have to meet strict requirements about secure methods for transferring and storing personal information shared with them, and make undertakings to the Australian Competition and Consumer Commission (which can be enforced in court[12]).

The information can be shared only “for the sole purposes of preventing or responding to cybersecurity incidents, fraud, scam activity or identify theft”. Any entity receiving information must destroy it after using it for this purpose.

These are incredibly important safeguards given the current lack of limits on how long companies can keep identity data.

Read more: Optus says it needed to keep identity data for six years. But did it really?[13]

What is needed now

Although temporary, these changes could be a game changer. For the next 12 months, at least, Optus (and possibly other telcos) will be able to proactively share customer information with banks to prevent cybersecurity, fraud, scams and identity theft.

It could potentially enable a crackdown on scams that affect both banks and telcos – such as fraudulent texts and phone calls[14].

But this does not nullify the need for a larger legislative reform agenda.

Australia’s data privacy laws and regulations should put limits on how much data companies can collect, or for how long they can keep that information. Without limits, companies will continue to collect and store much more personal information than they need[15].

Read more: What do TikTok, Bunnings, eBay and Netflix have in common? They’re all hyper-collectors[16]

This will require amending the federal Privacy Act – subject to a government review[17] now nearing three years in length. There should be limits on what data companies can retain, and how long, as well as bigger penalties for non-compliance.

We all need to take data privacy more seriously.

References

  1. ^ temporarily suspend regulations (ministers.treasury.gov.au)
  2. ^ A class action against Optus could easily be Australia's biggest: here's what is involved (theconversation.com)
  3. ^ announced (ministers.treasury.gov.au)
  4. ^ Telecommunications Regulation 2021 (www.legislation.gov.au)
  5. ^ delegated law (peo.gov.au)
  6. ^ Telecommunications Act 1997 (www.legislation.gov.au)
  7. ^ National Relay Service (www.infrastructure.gov.au)
  8. ^ with a warrant (www.homeaffairs.gov.au)
  9. ^ Australian Financial Crime Exchange (www.afr.com)
  10. ^ approved government identifier information (ministers.treasury.gov.au)
  11. ^ regulated by (www.apra.gov.au)
  12. ^ which can be enforced in court (www.accc.gov.au)
  13. ^ Optus says it needed to keep identity data for six years. But did it really? (theconversation.com)
  14. ^ fraudulent texts and phone calls (www.ato.gov.au)
  15. ^ than they need (theconversation.com)
  16. ^ What do TikTok, Bunnings, eBay and Netflix have in common? They’re all hyper-collectors (theconversation.com)
  17. ^ government review (www.ag.gov.au)

Read more https://theconversation.com/optus-data-breach-regulatory-changes-announced-but-legislative-reform-still-needed-192009

Times Magazine

Freak Weather Spikes ‘Allergic Disease’ and Eczema As Temperatures Dip

“Allergic disease” and eczema cases are spiking due to the current freak weather as the Bureau o...

IPECS Phone System in 2026: The Future of Smart Business Communication

By 2026, business communication is no longer just about making and receiving calls. It’s about speed...

With Nvidia’s second-best AI chips headed for China, the US shifts priorities from security to trade

This week, US President Donald Trump approved previously banned exports[1] of Nvidia’s powerful ...

Navman MiVue™ True 4K PRO Surround honest review

If you drive a car, you should have a dashcam. Need convincing? All I ask that you do is search fo...

Australia’s supercomputers are falling behind – and it’s hurting our ability to adapt to climate change

As Earth continues to warm, Australia faces some important decisions. For example, where shou...

Australia’s electric vehicle surge — EVs and hybrids hit record levels

Australians are increasingly embracing electric and hybrid cars, with 2025 shaping up as the str...

The Times Features

Freak Weather Spikes ‘Allergic Disease’ and Eczema As Temperatures Dip

“Allergic disease” and eczema cases are spiking due to the current freak weather as the Bureau o...

The Man Behind Sydney’s New Year’s Eve Midnight Moment: Jono Ma

When the clock strikes midnight on New Year’s Eve, Sydney will ring in 2026 powered by a high-volt...

Australians Can Choose Their Supermarket — But Have Little Independence With Electricity

Australians can choose where they shop for groceries. If one supermarket lifts prices, reduces q...

Sweeten Next Year’s Australia Day with Pure Maple Syrup

Are you on the lookout for some delicious recipes to indulge in with your family and friends this ...

Operation Christmas New Year

Operation Christmas New Year has begun with NSW Police stepping up visibility and cracking down ...

FOLLOW.ART Launches the Nexus Card as the Ultimate Creative-World Holiday Gift

For the holiday season, FOLLOW.ART introduces a new kind of gift for art lovers, cultural supporte...

Bailey Smith & Tammy Hembrow Reunite for Tinder Summer Peak Season

The duo reunite as friends to embrace 2026’s biggest dating trend  After a year of headlines, v...

There is no scientific evidence that consciousness or “souls” exist in other dimensions or universes

1. What science can currently say (and what it can’t) Consciousness in science Modern neurosci...

Brand Mentions are the new online content marketing sensation

In the dynamic world of digital marketing, the currency is attention, and the ultimate signal of t...