Data Breaches 2022 onward (including Optus)

Maybe so. But this is in direct contradiction with what the government currently demands. The government currently demands that the telco retain sufficient data to demonstrate compliance with this particular part of the law for the entire time that the service is active - and then some data must be retained for 2 years after the service is deactivated - and then the government encourages telcos to retain the latter data longer.

I already proposed a technical solution to this but I really don’t think the government has any inclination to take ownership of this problem.

Would that apply to governments as well? :wink:

Logically the same government identification requirements should apply regardless of whether pre-paid or post-paid. Logically, if one were easier to rort than the other, wouldn’t criminals simply gravitate towards the easier one?

The commercial requirements may in fact be more severe with a post-paid service since they are extending you credit. In addition, the provision of credit may then trigger additional government requirements.