X
  • About
  • Advertise
  • Contact
  • Events
Subscribe to our Newsletter
  • News
    • Markets
    • Regulation
    • Super
    • M&A
    • Tech
    • Appointments
  • Podcast
  • Webcasts
  • Video
  • Analysis
  • Promoted Content
No Results
View All Results
  • News
    • Markets
    • Regulation
    • Super
    • M&A
    • Tech
    • Appointments
  • Podcast
  • Webcasts
  • Video
  • Analysis
  • Promoted Content
No Results
View All Results
No Results
View All Results
Home News Regulation

CBA’s enforceable undertaking accepted by commissioner

The Australian Information Commissioner has accepted an enforceable undertaking offered by CBA after a data breach in 2016 and 2018. 

by Eliot Hastie
June 28, 2019
in News, Regulation
Reading Time: 2 mins read
Share on FacebookShare on Twitter

The undertaking follows Commonwealth Bank’s ongoing work to address two separate incidents, one relating to the disposal of data tapes containing customer statements and the other relating to inadequate internal access controls to consumer data. 

The incidents were reported at the time to the Office of the Australian Information Commissioner (OAIC) in 2016 and 2018, and the bank has been working to address them since. 

X

OAIC commissioner Angelene Falk said the inquiries into CBA considered an APRA report, which found the bank was reactive in dealing with risk matters. 

“Our inquiries identified deficiencies in CBA’s management of personal information, specifically its internal access controls and approach to retention and destruction.

“As a result of this work, CBA has committed through a court-enforceable undertaking to substantially improve their privacy practices.”

The incident with the tapes was particularly embarrassing for the bank as they admitted to losing track of magnetic tapes, which contained the details of 20 million customers. 

CBA announced at the time of the incidents that customers’ personal information had not been comprised and has said in an ASX release that this continues to be the case. 

In its undertaking, CBA has committed to review and implement further enhancements in relation to its internal privacy policies and procedures, internal user access controls on systems that hold personal information and privacy risk management, and monitor processes as they apply to service providers. 

CBA now has 90 days to develop and submit to the OAIC a work plan and a timetable in which it will meet its obligations that are enforceable in court. 

Chief risk officer at CBA Nigel Williams said the bank offered the enforceable undertaking as a demonstration of its commitment to appropriately managing the privacy of customers. 

“We continue to take action to address issues, earn trust and be a better bank for our customers. This includes proactively engaging with our regulators to ensure we continue to build better systems, processes and controls to manage the personal information of our customers,” he said. 

The undertaking will be overseen by an independent external reviewer who will consult and report to the OAIC on the bank’s compliance. 

Ms Falk said it was a warning to all organisations regulated under the Privacy Act that they needed to proactively manage their data holdings. 

“This matter should send a sharp reminder to all organisations that data holdings must have a clearly defined retention period and should be securely destroyed or de-identified when no longer needed. Failing to do so can increase the risk that personal information will be compromised.”

Related Posts

Barwon data shows exit uplifts halved since 2023

by Olivia Grace-Curran
November 20, 2025

Barwon’s analysis of more than 300 global listed private equity exits since 2013 revealed that average uplifts have dropped from...

AI reshapes outlook as inflation dangers linger

by Adrian Suljanovic
November 20, 2025

T. Rowe Price has released its 2026 global investment outlook, stating that artificial intelligence had moved “beyond hype” and begun...

‘Diversification isn’t optional, it’s essential’: JPMAM’s case for alts

by Georgie Preston
November 20, 2025

In its 2026 Long-Term Capital Market Assumptions (LTCMAs) released this week, JPMAM’s forecast annual return for an AUD 60/40 stock-bond...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

VIEW ALL
Promoted Content

Global dividends hit a Q3 record, led by financials.

Global dividends surged to a record US$518.7 billion in Q3 2025, up 6.2% year-on-year, with financials leading the way. The...

by Capital Group
November 18, 2025
Promoted Content

Why smaller can be smarter in private credit

Over the past 15 years, middle market direct lending has grown into one of the most dynamic areas of alternative...

by Tim Warrick, Managing Director of Principal Alternative Credit, Principal Asset Management
November 14, 2025
Promoted Content

Members Want Super Funds to Step Up Security

For most Australians, superannuation is their largest financial asset outside the family home. So, when it comes to digital security,...

by MUFG Pension & Market Services
October 3, 2025
Promoted Content

Boring Can Be Brilliant: Why Steady Investing Builds Lasting Wealth

In financial markets, drama makes headlines. Share prices surge, tumble, and rebound — creating the stories that capture attention. But...

by Zagga
October 2, 2025

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

Latest Podcast

Podcast

Relative Return Insider: Economic shifts, political crossroads, and the digital future

by InvestorDaily team
November 13, 2025
After more than two decades, InvestorDaily continues to be an institution that connects and influences Australia’s financial services sector. This influential and integrated media brand connects with leading financial services professionals within superannuation, funds management, financial planning and intermediary distribution through a range of channels, including digital, social, research, broadcast, webcast and events.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About Us

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • Markets
  • Appointments
  • Regulation
  • Super
  • Mergers & Acquisitions
  • Tech
  • Promoted Content
  • Analysis

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
  • Markets
  • Regulation
  • Super
  • M&A
  • Tech
  • Appointments
  • Podcast
  • Webcasts
  • Promoted Content
  • Events
  • About
  • Advertise
  • Contact Us

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited