Optus, one of the major mobile carriers in Australia, has been slapped with a hefty penalty by the ACMA for breaching the rules of the IPND.
The IPND is a secure database that contains the phone numbers, names, addresses and location information of all phone users in Australia. It is used by emergency services to locate and contact people in need of help, as well as by government agencies to send alerts and warnings during emergencies.
The IPND industry code requires all carriers to upload their customers’ information to the IPND within one business day of activating or changing their service.
According to the ACMA, Optus did not upload the information of nearly 200,000 customers who bought plans under the Coles Mobile and Catch Connect brands between January 2021 and September 2023. These customers were not registered in the IPND and could not be reached by emergency services or receive emergency alerts.
The ACMA said it discovered the breach when it conducted a compliance audit and found that Optus’ customer service provider, Prvidr, had failed to upload the data to the IPND.
The ACMA imposed a fine of more than $1.5 million on Optus for violating the IPND industry code. It also issued a formal direction to Optus to comply with the code and to conduct an independent review of its IPND compliance processes when using a third-party data provider.
The ACMA’s member Samantha Yorke said in a statement that the breach was serious and unacceptable, as it put the safety of Australians at risk.
She also said that carriers cannot outsource their obligations to third parties and must have effective oversight and assurance mechanisms in place.Optus accepted the fine and the direction from the ACMA. It also offered a court-enforceable undertaking to improve its IPND compliance and to cooperate with the ACMA’s ongoing monitoring.
Optus apologised to its customers and said it had taken steps to prevent such breaches from happening again. It also said it had contacted the affected customers and offered them compensation.


