The Office of the Australian Information Commissioner and the New Zealand Office of the Privacy Commissioner have launched a joint investigation into the way the Latitude Group handles the personal information of its customers.

This marks the first joint privacy investigation by Australia and New Zealand, and “reflects the impact of the data breach on individuals in both countries”, according to the two bodies

The investigation will reduce the regulatory impact on Latitude, but doesn’t preclude the OAIC and OPC reaching separate regulatory outcomes, or making separate decisions.

Latitude confirmed in late March the theft of 7.9 million driver’s license numbers; 53,000 passport numbers; as well as 6.1 million separate customer records which include personal information. The customer records are separate customers from the driver’s license numbers.

Harvey Norman, David Jones, JB Hi-Fi, and the Apple Store have their financial services offerings tied up with Latitude.

Coles confirmed that historic users of its former credit cards may have had their personal data stolen as part of the breach.

The OAIC investigation will focus on whether Latitude “took reasonable steps to protect the personal information they held from misuse, interference, loss, unauthorised access, modification or disclosure”, and whether it took reasonable steps to destroy or de-identify personal information that was no longer required.

Latitude customers from as far back as 2005 could be impacted. Victims include legacy customers of the company, known as GE prior to 2015, as well as some customers who merely enquired about its services.

If Latitude has breached one or more of the Australian Privacy Principles, then the Commissioner has the power to seek civil penalties through the Federal Court of up to $50 million for each contravention.