Optus Faces The Mother-of-All Data Breach Class Actions

KG
K&L Gates

Contributor

At K&L Gates, we foster an inclusive and collaborative environment across our fully integrated global platform that enables us to diligently combine the knowledge and expertise of our lawyers and policy professionals to create teams that provide exceptional client solutions. With offices spanning across five continents, we represent leading global corporations in every major industry, capital markets participants, and ambitious middle-market and emerging growth companies. Our lawyers also serve public sector entities, educational institutions, philanthropic organizations, and individuals. We are leaders in legal issues related to industries critical to the economies of both the developed and developing worlds—including technology, manufacturing, financial services, health care, energy, and more.
Without regular hygiene, personal information holdings can grow out to mother lode proportions, and the last thing Australia needs is a data breach gold rush.
Australia Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

The data breach that affected 9.8 million Australians and resulted in the personal information of 10,000 Optus customers being exposed on the dark web in September last year will be litigated in a class action lawsuit filed last Friday (21 April) in the Federal Court of Australia.

The allegations made against Optus include that the telecommunications company breached its contract with and duty of care towards Optus customers, that Optus breached the Australian Consumer Law and that Optus breached the Australian Privacy Principles under the Privacy Act 1988 ("Privacy Act").

The class is broad, including "[a]ll former and current Optus customers whose information was compromised in the September 2022 data breach", which means that the potential liability in dispute is quite substantial.

While businesses might demonstrate reasonable steps were taken to protect data, many like Optus will struggle to explain why they had retained so much data. It would seem that it is a rare thing for organisations to have a proper process in place to regularly review and action data that is no longer required.

Without regular hygiene, personal information holdings can grow out to mother lode proportions, and the last thing Australia needs is a data breach gold rush.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More