a day ago
- CBA staff used ChatGPT to find a phone number for a customer requesting Secretlab's contact, but disclosed the personal phone number of a director of Secret Lab (a different company), which is also a CBA customer.
- This action potentially violated the Privacy Act 1988 (APP 6, 8, 11), the Banking Code of Practice, AUSTRAC requirements, Australian Consumer Law (Section 18), ASIC Act (Section 12D), and CBA's own privacy and security policies.
- The incident reveals systemic issues: lack of verification protocols, no authority checks, missing security controls, staff training failures, and use of personal devices/accounts for unauthorized AI queries.
- CBA's reliance on unverified external AI sources and cross-border data transmission without safeguards contradicts stated commitments to privacy and security.
- The disclosure was not only improper but also unhelpful, as the phone number given was for the wrong company, illustrating the unreliability of LLMs.