Personally I believe they are in breach of APP 13 if they keep this information about me when I am no longer a customer. The reason they told me they needed this information was to identify me, as required by law. As no longer a customer I believe they no longer need this information about me!
Australian Privacy Principle 11 — security of personal information
11.1 If an APP entity holds personal information, the entity must take such steps as are reasonable in the circumstances to protect the information:
- from misuse, interference and loss; and
- from unauthorised access, modification or disclosure.
11.2 If:
- an APP entity holds personal information about an individual; and
- the entity no longer needs the information for any purpose for which the information may be used or disclosed by the entity under this Schedule; and
- the information is not contained in a Commonwealth record; and
- the entity is not required by or under an Australian law, or a court/tribunal order, to retain the information;
the entity must take such steps as are reasonable in the circumstances to destroy the information or to ensure that the information is de-identified.