Key takeaways
- Despite a data breach affecting approximately 5.12 million Australians, the OAIC declined to open a formal investigation into Qantas, finding no evidence the airline failed to take reasonable steps to comply with the Privacy Act 1988 (Cth). A breach alone does not equal non-compliance.
- The outcome turned on Qantas’ ability to demonstrate strong privacy governance, including regular supplier security assessments, mandatory cybersecurity training, role-based access controls and a documented privacy framework - measures the OAIC expects all organisations to have in place.
- Organisations that use overseas service providers should ensure they have contractual privacy and security obligations, audit rights, ISO 27001 (or equivalent) compliance requirements, and ongoing oversight in place. These measures were important in demonstrating that Qantas had taken reasonable steps under APP 8 to ensure appropriate handling of personal information by the overseas recipient.
- Effective incident response was a decisive factor. Qantas’ rapid containment, engagement of specialist advisers, timely customer notification and post-incident uplift of controls all weighed in its favour.
- The report is a practical roadmap for regulatory expectations: organisations should review their privacy governance frameworks, third-party arrangements, security controls, incident response plans and breach notification processes now, before an incident occurs.
The Office of the Australian Information Commissioner (OAIC) has recently published its report into the 2025 Qantas data breach. Despite the incident affecting approximately 5.12 million Australians, the Privacy Commissioner declined to commence a Commissioner-initiated investigation, concluding that the available evidence did not indicate Qantas had failed to take reasonable steps to comply with its obligations under the Privacy Act 1988 (Cth).
The report offers valuable guidance for organisations seeking to demonstrate compliance with the Australian Privacy Principles (APPs) in the face of increasingly sophisticated cyber threats, particularly social engineering attacks.
The Breach
The breach occurred following a successful “vishing” (voice phishing) attack targeting an employee of an overseas contact centre operated by a third-party provider engaged by Qantas. The threat actor impersonated IT support personnel and persuaded the employee to perform actions that ultimately enabled unauthorised access to customer information held within a customer relationship management (CRM) platform.
Following detection of unusual activity, Qantas acted promptly to contain the incident, revoke access, commence forensic investigations and activate its incident response processes. Qantas publicly disclosed the breach on 2 July 2025 and subsequently notified affected customers regarding the specific information impacted.
Why did the OAIC decide not to investigate further?
The OAIC's preliminary inquiries considered whether Qantas may have contravened APP 1 (governance), APP 8 (cross-border disclosure) and APP 11 (security of personal information). The Commissioner ultimately determined that the evidence did not indicate a likely breach of these obligations.
Importantly, the report reinforces that the occurrence of a data breach does not automatically mean an organisation has failed to take reasonable steps to protect personal information.
- 1. Strong privacy governance and oversight
- The OAIC was influenced by evidence that Qantas had implemented and maintained a comprehensive privacy and cybersecurity governance framework, including:
-
- • regular supplier security assessments and audits of the overseas contact centre provider;
• pre-engagement security assessments;
• mandatory and recurring cybersecurity awareness training;
• mandatory privacy training for personnel handling personal information;
• monitoring and reporting of training compliance; and
• established procedures for dealing with privacy-related inquiries and complaints.
- The Commissioner considered these measures to be reasonable steps to support compliance with APP 1.2, which requires organisations to implement practices, procedures and systems to ensure compliance with the Australian Privacy Principles and to deal with privacy-related inquiries and complaints.
- 2. Robust third party management
- The report provides a useful reminder that privacy obligations extend beyond an organisation's own systems and employees.
- The OAIC noted that Qantas had:
- • contractual arrangements requiring its overseas service provider to comply with the Privacy Act, GDPR and relevant security standards;
• audit rights over the provider;
• requirements for the provider to maintain ISO 27001 compliance (or equivalent); and
• ongoing oversight of the provider's privacy and security practices.
- These measures were considered significant in demonstrating that Qantas had taken reasonable steps under APP 8 to ensure overseas recipients handled personal information appropriately.
- 3. Security controls proportionate to risk
- In assessing compliance with APP 11, the OAIC examined both technical and organisational security measures.
- The Commissioner placed particular weight on:
- • role-based access controls limiting access to information required for employees' duties;
• documented training requirements;
• established cybersecurity risk management processes;
• incident management and reporting frameworks; and
• the prompt identification, escalation and containment of the incident.
- Notably, the OAIC accepted that the attack exploited a legitimate user action enabled by a software configuration rather than a systemic failure in Qantas' security framework. The report also observed that the attack may not have been prevented by standard social engineering training or stronger role-based access controls.
- 4. Effective incident response
- The Commissioner's comments strongly reinforce the importance of preparedness.
- The OAIC specifically highlighted Qantas':
- • timely activation of its incident response processes;
• engagement of specialist legal and forensic advisers;
• rapid containment and remediation efforts;
• customer notification strategy; and
• post-incident enhancement of training and controls.
- The Commissioner noted that these actions reduced the impact of the breach and demonstrated a commitment to ongoing risk reduction.
Key lessons for organisations
The Qantas report demonstrates the types of evidence the OAIC expects organisations to be able to produce when responding to regulatory scrutiny following a cyber incident.
Organisations should ensure they can demonstrate:
- A documented privacy governance framework;
- Regular privacy and cybersecurity training;
- Effective vendor and third-party risk management processes;
- Contractual requirements for service providers to comply with the Privacy Act and relevant security standards;
- Security controls aligned with recognised frameworks such as ISO/IEC 27001, the Australian Government Information Security Manual (ISM) and the ASD Essential Eight Maturity Model;
- Data retention and destruction practices;
- Tested incident response and crisis management procedures; and
- Clear notification and customer support processes following a data breach.
How Russell Kennedy can assist
The OAIC's report highlights that regulatory outcomes can turn on whether an organisation can demonstrate that it had appropriate governance, security and response measures in place before an incident occurred.
Our Corporate & Commercial team can assist organisations to:
-
prepare and review Data Breach Response Plans;
- review third-party supplier agreements and cross-border data arrangements;
- develop privacy governance frameworks and policies;
- advise on Notifiable Data Breaches (NDB) Scheme obligations;
- manage communications with regulators, customers and stakeholders following a data breach; and
- provide legal advice during cyber incidents and OAIC investigations.
As the Qantas report demonstrates, while no organisation can eliminate cyber risk entirely, organisations that can evidence compliant governance, reasonable security measures and a well-executed incident response will be significantly better positioned when regulatory scrutiny follows.
If you would like to discuss how this may affect your business, please contact a member of our Corporate & Commercial team.
If you’d like to stay up to date with Russell Kennedy Alerts and Events, you can subscribe to our mailing list here.