The purpose of this guidance is to support transparency in how personal information is collected, used and disclosed in accordance with the Privacy Code of Practice for Service NSW Fraud Management (Privacy Code of Practice). The Code of Practice commenced on 27 February 2026 to support Service NSW’s fraud control functions.
Service NSW’s fraud control functions and objectives
The Minister for Customer Service and Digital Government has conferred additional functions on Service NSW for the prevention, detection and investigation of fraud relating to the use of MyServiceNSW accounts and transactions, and the grant, rebate and voucher (GRV) programs we administer. This includes using data analytics to identify accounts that may be used for fraudulent or unauthorised purposes.
Service NSW's fraud control functions are critical to protecting public funds, detecting and preventing fraud relating to the use of a MyServiceNSW Account, and ensuring GRV payments are delivered efficiently and in line with program requirements.
These activities aim to safeguard customer identities and personal information, prevent payments to fraudsters, maintain public confidence and government reputation, fulfil obligations to partner agencies, and support compliant, risk-based grants administration aligned with the Government Sector Finance Act 2018 (NSW) and the M2024-03 Grants Administration Guide.
Collection, use and disclosure of personal information
Service NSW collects, uses and discloses personal information and health information in accordance with the Privacy and Personal Information Protection Act 1998 (NSW) (PPIP Act), the Health Records and Information Privacy Act 2002 (HRIP Act) and the Privacy Code of Practice. This includes information provided by MyServiceNSW account holders for GRV programs and other services.
How the Privacy Code of Practice operates
The Privacy Code of Practice modifies certain Information Protection Principles in the PPIP Act to support fraud control by Service NSW.
In this context, Service NSW may collect personal information from third parties and publicly available sources to verify applicant details, generate new insights through data matching and analytics and otherwise use personal information originally collected for other purposes.
Service NSW also uses information collected when a customer performs a MyServiceNSW Account transaction to detect whether an account has been or is likely to be used for fraudulent or unauthorised purposes. This includes using information collected across GRV programs to detect and prevent non-compliance or suspected criminal activity.
Service NSW discloses information to third parties if we have a reasonable belief it would assist in identifying, detecting, preventing, or responding to, suspected fraud, identity theft, or other similar conduct. The types of organisations this may include is provided in Schedule 1 of the Privacy Code of Practice.
The Privacy Code of Practice operates alongside existing privacy obligations, and Service NSW will continue to ensure personal information is securely managed, kept accurate and up to date, and is accessible for individuals to access and correct.
In some cases, where personal information is collected from third parties for fraud investigations, it may not be reasonable to notify individuals at the time and this guidance is published to support transparency.
Use of data analytics tools
Service NSW uses data analytic tools to identify and investigate fraudulent or unauthorised MyServiceNSW Account activity, detect high-risk customers and to support fraud control functions.
More information
Please see our privacy statement and Privacy Management Plan for more information about how Service NSW handles your personal information. This includes how you can access and seek correction of the information, how privacy enquiries or complaints can be made, how information is securely stored and how to contact us. Service NSW is located at 2-24 Rawson Place, Sydney NSW 2000.