Optus Hack
Anyone that does not know about the recent Optus hack is probably not an Aussie. Optus, one of Australia's largest telcos, and a subsidiary of Singtel, was recently hacked, and critical information about its customers has been compromised.
Initially I was not concerned, but alas, I discovered, when advised by eMail, that my information was also compromised. You see, I had an Optus account going back at least 5 years ago. I have not used it since.
There seems to be a lot of uncertainty about maintaining data of past customers. It is suggested that Telcos are required by law to maintain data of past customers for a period of time. My reading of this is that it is to help in the event that communications fraud is committed.
However, how long the data is kept seems to be some unknown and not agreed to number. I have seen suggestions that it is somewhere between two (2) and seven (7) years. There is also some question surrounding what information should be kept, and what should be (effectively) deleted after a customer ceases to be just that. Information such as Driver Licence, Medibank, Passport etc should be deleted after a customer ceases to be a customer.
At the moment I wait to see what occurs. Many millions of pieces of information were stolen in the hack, so hopefully they ignore my details.
Clearly some work needs to be done to define what data is collected, what data is kept (& for how long) and how it is stored. Time to get a unified approach to customer records & privacy.












