
What organisations can learn from the Privacy Commissioner’s decision to conclude preliminary inquiries without further action.
The Privacy Commissioner has completed preliminary inquiries into the 2025 Qantas data incident, which affected approximately 5.12 million Australians following a social-engineering attack on an overseas third-party contact centre provider. After almost a year of inquiries, the Commissioner concluded that the evidence did not reveal omissions or failings that made a contravention of the Privacy Act 1988 (Cth) sufficiently likely to justify a full investigation or further action at this stage.
The finding does not suggest that the scale or impact of the breach was unimportant. It demonstrates that regulatory defensibility depends on evidence of the reasonable steps taken before an incident and the quality of the response when it occurs.
What supported Qantas’s position?
The OAIC examined Qantas’s compliance with APPs 1, 8 and 11, including its governance arrangements, security controls and oversight of the overseas service provider. Relevant factors included:
- privacy and cyber security due diligence before appointing the provider;
- contractual privacy, confidentiality and security obligations;
- role-based access controls, workforce screening and training;
- monitoring, alerting and audit arrangements;
- incident-response processes and escalation pathways;
- prompt investigation of unusual login activity, revocation of affected access and containment of the platform;
- engagement of specialist legal and forensic advisers;
- public disclosure and subsequent communication with affected customers about the categories of information involved; and
- extensive cooperation with the OAIC, supported by information and documents.
Practical lessons for organisations
The report reinforces several practical steps organisations should take now:
- Document why security and privacy controls are reasonable and proportionate to the information, systems and threat environment.
- Treat third-party contact centres, cloud platforms and service providers as part of the organisation’s control environment, with due diligence, enforceable obligations, monitoring and assurance.
- Ensure alerts are escalated to people with authority to investigate, contain access and activate incident-response arrangements.
- Retain reliable logs and decision records so the organisation can reconstruct what occurred and demonstrate its response.
- Prepare communications that are accurate, staged where necessary and responsive to what affected individuals need to know.
- Review controls after the incident and preserve evidence of remediation, testing and continuing monitoring.
The key takeaway is that regulatory defensibility is built before an incident. Policies alone are insufficient; organisations need evidence that controls operated, risks were overseen and the response was prompt, informed and proportionate.
Read more: Privacy Commissioner’s media statement | Report into preliminary inquiries of Qantas