Got home this morning and had an email from a casual employer about some new SOPs they are initiating.
2 mins later, I get an email that says "Recall: *reference to original email*…" in the title and an automated system that seems to be trying to use some sort of remote delete function (body of email contains garbage, automated response nonsense).
10 mins later I get another message "URGENT: DELETE… *reference to first email*".
Curious, I went back to have a look at the first email thinking that it was just an SOP bulletin, just not for my department (get them all the time) and I found two attachments. Upon opening the files (MS Office type) it was revealed why the massive panic emails following. They contain a lot of personal data… on A LOT of people. Basically everyone I work with and everyone doing the same job as me… for the entire state. There are some 3000+ entries on this list.
The data includes;
Name: (first and last)
Address:
Ph: (Both home and mobile)
Start date:
Internal staff ID:
Area: (where they work)
Supervisor:
Zone:
Current employment status: (includes inactive/sacked/quit/retired as well as active employees)
I called work to find out what their policy was to deal with such a huge data leak and if they reported it and was informed that no, no reporting required as everyone was asked to delete the email and a "recall" was sent out to users who have this function turned on and that the information was technically not reportable because it didn't contain payment or any ID information.
So, what do I do form here? I'm kind of ambivalent about it (been through Optus and Medibank recently, so I am already on hyper vigilent mode) until I spoke to work who brushed it off as "dealt with". A poll because you love a nice poll ;)
You could make a complaint to OAIC - https://www.oaic.gov.au/