Type
Industry

Gold Stars and Red Flags: Lessons on Information Security from Recent OAIC Matters

On 16 July 2026, the Australian Privacy Commissioner published a concerning Qantas Airways Limited’s (Qantas) 2025 data breach (Report).[1]  The Report outlined the Office of the Australian Information Commissioner’s (OAIC) preliminary inquiries into the incident which the personal information of millions of customers, and involved information including dates of birth, telephone numbers, residential addresses, email addresses and frequent flyer number.

As highlighted in the Report, the data breach incident occurred when a threat actor impersonated Qantas IT support and directed an employee of an overseas third-party service provider contracted by Qantas to connect their customer relationship management account to the threat actor’s data extraction tool.  This allowed the threat actor to gain access to Qantas customer .

The Report did not make concluded findings about Qantas’ practices or processes.  The OAIC’s inquiry was preliminary and did not proceed to a Commissioner initiated investigation (a more extensive .  However, the Report indicates how the OAIC may assess the reasonableness of an entity’s controls, oversight, and incident response, particularly when considering the Australian Privacy Principles (APPs), most notably APP 11.

The Report identifies practical factors that may support the reasonableness of an entity’s cyber, outsourcing and breach response arrangements in a particular factual context.

What material did the OAIC consider?

As part of the Report, the OAIC examined the circumstances, indicated a likelihood that Qantas had contravened certain APPs.  The relevant APPs and the OAIC’s observations are summarised below:

APP

Relevant Obligation

Material considered by the OAIC

OAIC observations

APP 1 – Open and transparent management of personal information

APP 1.2 requires an APP entity to take reasonable steps to implement practices, procedures and systems that will ensure the entity complies with the APPs and any binding registered APP code and enable the entity to deal with inquiries or complaints from individuals about the entity’s compliance with the APPs and any binding registered APP code · Undertook cyclical audits of the third-party service provider.

· Qantas ensured staff of the third- party service provider had taken mandatory cyber awareness training programs.

· Staff with access to personal information completed further regular mandatory training.

· Qantas’ contract with the third-party service provider required compliance with the APPs when handling personal information.

· After the cyber-attack Qantas notified all individuals impacted by the incident and opened a dedicated support line 24 hours, 7 days a week.

The information before the OAIC did not suggest that Qantas had failed to take reasonable steps to ensure compliance with the APPs.

APP 8 – Cross-border disclosure of personal information

Before disclosing personal information about an individual to an overseas recipient, the entity must take reasonable steps in the circumstances to ensure that the recipient does not breach the APPs (other than APP 1). Qantas service agreement required the provider to maintain ISO 27001 compliance, comply with the Privacy Act, the General Data Protection Regulation (GDPR), and provide Qantas with audit rights. The information did not indicate a likelihood that Qantas had failed to take reasonable steps to ensure its overseas provider complied with the relevant APPs.

APP 11 – Security of Personal Information

APP 11.1 requires organisations to take reasonable steps (including technical and organisational measures) in the circumstances to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. APP 11 also addresses destruction or de-identification when information is no longer required. · The third-party service provider had maintained training requirements that were checked during Qantas audits.

· Qantas used role-based access controls to restrict the third-party service provider employees to only accessing information necessary to perform their role.

· Qantas implemented an incident management and reporting framework and took appropriate steps to remediate the incident when detected.

· Qantas followed standard information retention practices and had procedures in place to regularly delete unnecessary customer information, including upon request from customers.

On the material available during the preliminary inquiries, the information did not indicate a likelihood that Qantas had failed to take reasonable steps under APP 11.

How does Qantas compare with Clinical Labs and AMEX?

It is also important to consider the Report in light of the Federal Court case of Australian Information Commissioner v Australian Clinical Labs (Clinical Labs),[2] and the OAIC’s determination in the matter of ‘BAM’ and American Express Australia Ltd (AMEX).[3]

The different outcomes in these matters illustrate the context-specific nature of APP 11.  The Report arose from preliminary inquiries following a cyber incident and did not contain concluded findings that Qantas had breached APP 11.  By contrast, Clinical Labs resulted in Federal Court penalties following established contraventions, while the AMEX matter resulted in an OAIC privacy determination that found APP 11 had been breached.  The differences in outcome largely reflect differences in the evidence available to the regulator and the nature of the security controls in question.

Clinical Labs

Following investigation, the OAIC commenced action against Clinical Labs.[4]  In October 2025, the Federal Court ordered Clinical Labs to pay $5.8 million in civil penalties, following the data breach by its Medlab Pathology business in February 2022 which compromised the personal information of over 223,000 individuals.[5]  The Court identified a range of systemic security and governance deficiencies within the acquired Medlab Pathology business.  This included material weaknesses in the Medlab IT environment, failures to adequately assess those weaknesses following the acquisition, inadequate testing of incident response arrangements, and unclear cyber incident response roles and responsibilities.

Unlike the Report into Qantas, the Clinical Labs matter involved findings that longstanding and identifiable deficiencies existed before the incident occurred and that those deficiencies formed part of a broader failure to implement reasonable security measures.  The case demonstrates that APP 11 is not limited to technical controls.  It extends to governance, integration of acquired businesses, risk assessment, monitoring and incident response preparedness.  Where deficiencies are systemic, persistent and inadequately managed, regulators are more likely to view them as evidence that reasonable steps were not taken.

Amex

The AMEX determination concerned a different kind of information security risk.  Rather than an external cyber intrusion, it involved unauthorised internal access by an employee to a customer’s personal information.  The OAIC’s determination found AMEX to have breached APP 11 because it had not taken reasonable steps to protect personal information from unauthorised access by its own staff.[6]

The OAIC identified weaknesses in AMEX’s management of internal access risk.  The OAIC observed that account-level access logging was not uniformly enabled across the relevant systems, which limited AMEX’s ability to monitor employee access to customer information.  AMEX also could not practically restrict employee access to certain customer data across four of five relevant systems.

The determination also considered the absence of a sufficiently clear policy dealing with employee access to the accounts of friends and family, and gaps in monitoring arrangements that limited AMEX’s ability to detect inappropriate access promptly.

Unlike the Report into Qantas, the AMEX determination highlights that APP 11 extends beyond protection against external threat actors.  An entity must also implement effective controls to manage insider risk, including access restrictions, logging, monitoring and clear policies governing employee access to personal information.  The OAIC’s remedial orders requiring AMEX to compensate the complainant, issue a formal apology and implement stronger access restrictions and audit logging systems reflect the central importance of those measures.

How do we reconcile Qantas, Clinical Labs and AMEX?

Taken together, the three matters suggest how the OAIC or Court may assess whether “reasonable steps in the circumstances” were taken, having regard to the particular risks the entities are likely to face.

  • Qantas involved the OAIC’s Report into an external cyber incident where the OAIC identified areas for improvement but did not make findings that APP 11 had been contravened;
  • Clinical Labs was a Federal Court case where the relevant facts involved systemic cyber security, governance and incident response failures that pre-dated the breach and ultimately resulted in court-imposed penalties; and
  • AMEX focused on an entity’s internal risk and inadequate monitoring and access controls, resulting in an OAIC determination and remedial orders.

The common theme emerging from these matters is that APP 11 does not appear to prescribe a fixed set of controls, nor do these examples provide a single benchmark for compliance.  Rather, they suggest that entities are expected to take reasonable steps to address the security risks that are foreseeable in their particular operating environment. What constitutes reasonable steps will depend on the specific circumstances, including the nature of the information held, the threats faced, the controls implemented, and the entity’s ability to detect, respond to and mitigate security incidents.

Our top takeaways

Depending on the entity’s operating environment, relevant practical steps may include:

  • Taking reasonable steps to ensure third-party service providers comply with the APPs.
  • Maintaining a documented cyber security and privacy framework designed to comply with the APPs.
  • Using role-based access controls, limiting employees’ access to only the customer information necessary to perform their duties.
  • Maintaining strong information retention and destruction procedures.
  • Implementing effective monitoring and detection capabilities, so that when unusual activity and unauthorised access attempts are identified these can be escalated promptly.

TIP 1: APP 11 requires entities to take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.  The OAIC increasingly expects entities to implement both technical measures and organisational measures (e.g. policies, training, accountability and risk management).[7]

TIP 2: Ensure privacy and information security are regularly considered at board and management level, with documented risk assessments, policies and training.  We consider this is particularly important for AFS and credit licensees given ASIC’s focus on cyber resilience and risk management systems.[8]

Have any further questions?

Contact Us Our Expert Team Our Training

Author: Tali Borowick (Lawyer) 

[1] Report into preliminary inquiries of Qantas | OAIC

[2] Australian Information Commissioner v Australian Clinical Labs Limited (No2) [2025] FCA 1224 (ACL).

[3] Australian Privacy Commissioner orders American Express Australia Limited to compensate complainant following interference in privacy | OAIC

[4] OAIC commences Federal Court proceedings against Australian Clinical Labs Limited | OAIC

[5] Australian Clinical Labs ordered to pay penalties in relation to Medlab Pathology data breach in first for Privacy Act | OAIC

[6] Australian Privacy Commissioner orders American Express Australia Limited to compensate complainant following interference in privacy | OAIC

[7] Chapter 11: APP 11 Security of personal information | OAIC

[8] 26-092MR ASIC calls for urgent cyber uplift as AI accelerates cyber threats | ASIC