on this page
What we’re doing
When we match data, we compare information we get from an outside source with our own.
We do this to find out if any of our customers have had their personal information exposed in the breach.
If they have, the security of their customer information may be compromised, and they may be at risk of identity fraud.
When we identify customers who may be at risk, we take steps to protect their Centrelink and Medicare records from further harm.
How we do this
We data match the records of our customers with the data held by the organisation who experienced a breach.
We only look at the data that was confirmed as being compromised or exposed in the breach. We don’t match our customer information with all of the data the organisation holds.
Legally, we’re authorised to match data. We tell you about our activities in our Privacy Policy. All personal information we deal with aligns with the:
- Privacy Act 1988
- relevant secrecy provisions in program legislation.
We work with the Office of the Australian Information Commissioner (OAIC), the Australian Government Solicitor and our own legal team to ensure our systems and practices for matching data are appropriate.
Data matching activities are governed by a protocol. Protocols are established in line with the Guidelines on Data Matching in Australian Government Administration set by the OAIC.
Current data matching protocols
Program protocols outline the purpose, operation and governance of our data matching activities.
For customers affected by the June 2026 Partnered Health data breach, download the:
For customers affected by the March 2026 RX Management data breach, download the:
- Program Protocol - Data matching between Services Australia and RX Management
- Program Protocol - Data matching between Services Australia and RX Management.
How to view or update your personal information
You can view or update your personal details online through myGov using your:
How to protect your personal information
There are steps you can take to protect your personal information after a data breach.