Summary
- The IPND is Australia's central ledger for public telephone numbers and associated customer data used by authorized public-safety and law-enforcement services.
- ACMA recorded 197,985 underlying occasions between 13 January 2021 and 22 September 2023. The Act and the IPND Code each classified those same occasions, so the two legal rows must not be added together.
- Prvidr operated the relevant data-provider process for Optus's Challenger brands and acknowledged a systems-and-processes error. Optus accepted that the carrier still bore ultimate responsibility.
- Reliable outsourcing requires owner-visible evidence: accepted records, exception queues, complete reconciliation, supplier governance and independent testing—not merely a contract or a “file sent” status.
What the IPND is—and what it is not
To most people, a mobile number is simply a way to receive calls and messages. Behind it sits a record describing the service: the public number, the customer name and address, the provider, whether the service is connected, and whether the number is listed or unlisted.
Australia stores this public-number customer data in the Integrated Public Number Database, or IPND. ACMA's investigation report says authorized users rely on it for emergency calls, emergency alerts, national-security and law-enforcement work. It can also support permitted research and publication of number directories.
The IPND is not the mobile network. It does not carry a call, attach a handset to a radio cell or send an emergency alert by itself. It is a ledger used by operational services. That difference avoids two opposite mistakes. A database row cannot make a broken network work, but a working phone service does not make an absent or inaccurate database row safe.
Imagine that a mobile service is activated on Monday. The carrier's billing and network systems recognize it immediately. If the outsourced feed never creates the corresponding IPND record, the running service and the public ledger describe different realities. The accountable question is not only whether someone attempted an upload. It is whether the required record arrived, passed validation and remained reconciled.
Reading the 197,985 findings correctly
ACMA's formal investigation report recorded 197,985 contraventions of subsection 101(1) of the Telecommunications Act and 197,985 contraventions of clause 4.2.1 of the IPND Code. These are two legal classifications of the same underlying occasions. They do not produce a total of 395,970 unique customers or failures.
The court-enforceable undertaking places the broad period from 13 January 2021 to 22 September 2023. ACMA's public release described close to 200,000 mobile customers supplied under the Coles Mobile and Catch Connect brands as having been placed at risk. For audit purposes, those two descriptions should remain labelled: “close to 200,000 customers” is the regulator's public summary, while 197,985 is the precise count in the formal findings.
A separate infringement notice focused on 91 active carriage services under the same two brands on dates between 9 January and 16 February 2023. Those 91 services are a specified subset used for the notice, not an extra group to add to 197,985.
This separation matters because regulatory documents often count different things: customers, services, transaction occasions and legal provisions. A large number may be accurate and still become misleading if its unit or overlap is lost.
The supplier operated the feed; the carrier owned the outcome
Optus had engaged Prvidr Pty Ltd as the Data Provider for the Challenger-brand IPND updates. In practical terms, the supplier handled work needed to turn service information into records for the central database. The undertaking says Prvidr acknowledged that integrity problems arose from an error in its systems and processes.
That explains where the operational fault sat. It does not move the accountability boundary. The same undertaking records Optus's acceptance that it ultimately bore responsibility for compliance with the IPND obligations. ACMA expressed the point plainly in its public release: a carrier cannot outsource its obligations merely because a third party performs part of the process.
This is not an argument against outsourcing. Specialist providers can run reliable, well-controlled services. The lesson is that a supplier contract is not operational evidence. A service-level agreement may say what should happen. The carrier still needs evidence of what did happen for every relevant class of record.
The distinction is familiar across network-resource systems. A registry records allocation, identity or status; it is not the running infrastructure. An operator may delegate the mechanics of updating that registry, but it must still reconcile the delegated output with the live service it controls.
Why “sent” is not enough
An outsourced interface can fail in several places. A source event may never enter the supplier queue. A file may be built with the wrong fields. A transfer may fail. The receiving system may reject a row. A correction may remain open. A full population may slowly drift even when daily files appear normal.
For that reason, a trustworthy control has at least four forms of evidence:
- a live service event that identifies what changed and when;
- a durable record of what the supplier submitted;
- a receiving result showing acceptance or a visible exception; and
- a periodic comparison of the complete carrier inventory with the central ledger.
If management sees only the second item, a green “submitted” dashboard can hide a missing record. If it sees only monthly percentages, a small but persistent class of services can remain outside the feed for years. The control must follow individual exceptions and also test the whole population.
What the remediation reveals
The enforceable undertaking describes remediation in operational terms. Prvidr corrected the relevant system or process failure, reconciled Challenger-brand customer data against the IPND, updated records where necessary, and reviewed its practices to strengthen error checking and regular audits.
Optus also changed the way it governed the arrangement. The documented measures included weekly operational meetings, monthly steering meetings, monthly compliance reporting, a revised outsourcing framework and six-monthly IPND reconciliations reported to relevant executives.
Those measures form a useful control stack. Weekly meetings can expose current exceptions. Monthly governance can identify trends and ownership gaps. Six-monthly full reconciliation tests whether the daily process missed a whole category. Executive reporting makes unresolved differences visible above the teams that operate the feed.
The undertaking went further by requiring an ACMA-approved independent reviewer. The reviewer was to assess the supplier's remediation and the joint processes, procedures, training, monitoring and governance controls. An action plan would then address accepted recommendations. Independence matters because the same teams that designed or operated a control may not see its blind spots.
What the regulatory outcome does—and does not—prove
ACMA says Optus paid an AUD 1,501,500 infringement penalty. The regulator also accepted a court-enforceable undertaking and directed Optus to comply with the IPND Code.
The infringement notice itself explains an important legal boundary: payment is not an admission of liability and does not itself equal a court finding. The article therefore reports the payment and ACMA's findings without calling the notice a court judgment.
There is an equally important harm boundary. ACMA said it was not aware of anyone being directly harmed by the non-compliance in this case. Missing public-number data can create potential risk because authorized emergency and law-enforcement users depend on the ledger. That potential consequence justifies strong controls, but it is not evidence that 197,985 emergency calls failed or that a particular person missed an alert.
A practical owner-side control
A carrier using an external Data Provider can make accountability observable with a simple chain:
- Record every activation, disconnection, address change and listing-status change in a source ledger.
- Assign each event a durable identifier that survives the supplier handoff.
- Require proof that the supplier built and sent the correct IPND transaction.
- Capture the receiving system's acceptance or rejection for that same identifier.
- Put every exception into an owned queue with an age, deadline and repair evidence.
- Compare the complete live-service inventory with the IPND on a fixed schedule.
- Test the process after software changes and during staff or supplier outages.
- Report unresolved population differences and missed controls to accountable executives.
The most useful metric is not “files sent.” It is the share of required live-service changes that can be traced to an accepted registry state, plus the age of every unexplained mismatch.
The durable lesson
Outsourcing changes who performs a task. It does not change who must answer for the result. In this case, the supplier's systems and processes were part of the failure, but the carrier remained responsible for the public-number records associated with its services.
The IPND is a ledger, not the mobile network. Its authority comes from accurately recording operational reality for authorized users, not from replacing that reality. A dependable arrangement therefore connects three views: the carrier's live services, the supplier's transactions and the central registry's accepted state.
Contracts, meetings and policies can support that connection. Proof comes from receipts, exceptions, reconciliation and independent review. When all four are visible, an outsourced feed can be governed. When they are not, accountability has been delegated on paper but left unperformed in practice.
Sources
- ACMA media release — Optus penalised $1.5M for public safety failures
- ACMA publication page — investigation report, infringement notice, enforceable undertaking and direction
- ACMA investigation report — Optus Mobile Pty Ltd
- ACMA infringement notice — Optus Mobile Pty Ltd
- ACMA enforceable undertaking — Optus Mobile Pty Ltd
- ACMA direction to comply with the IPND Code — Optus Mobile Pty Ltd
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
