Australia's Privacy Regulator Ends Its Inquiry Into the 2025 Qantas Data Breach Without a Full Investigation

Australia's Privacy Regulator Ends Its Inquiry Into the 2025 Qantas Data Breach Without a Full Investigation
Australia's Office of the Australian Information Commissioner (OAIC) published a report on 16 July 2026 finding the evidence did not show Qantas failed to take reasonable steps to comply with the Privacy Act 1988 over the 2025 cyber incident that exposed millions of customer records, and the Privacy Commissioner declined to open a formal investigation.
Information last verified on 29 July 2026. This reflects the OAIC's published report as at that date.
Jurisdiction scope: This article addresses Australian federal privacy law under the Privacy Act 1988 and the decision of the OAIC. It does not address privacy laws in other countries. For background, see our guide to Australia's data privacy laws.
What Happened
On 16 July 2026, the OAIC published its "Report into preliminary inquiries of Qantas". The report sets out how the regulator examined the 2025 Qantas cyber incident and why it decided not to take the matter further.
The incident became public in 2025 after an attacker accessed a third-party platform used by a Qantas contact centre. According to the OAIC's report, approximately 5.67 million customer records were compromised, including records of overseas customers. The data related to Qantas's frequent-flyer and customer-service systems rather than payment-card or password stores.
Between 11 July 2025 and 1 June 2026, the OAIC conducted preliminary inquiries under section 42(2) of the Privacy Act 1988. The purpose of those inquiries was to assess Qantas's compliance with the Notifiable Data Breaches scheme and to decide whether to commence a Commissioner-initiated investigation under section 40(2) of the Act. The inquiries focused on the likelihood that Qantas had contravened three of the Australian Privacy Principles: APP 1, which requires open and transparent management of personal information; APP 8, which governs cross-border disclosure; and APP 11, which requires reasonable steps to secure personal information.
The OAIC concluded that the information it obtained did not suggest Qantas had failed to take reasonable steps to comply with the APPs. The report stated the steps Qantas took were adequate in the circumstances, including the measures it had in place to manage and monitor its third-party service providers and to deal with inquiries and complaints from affected individuals. On that basis, Privacy Commissioner Carly Kind decided not to open a formal investigation.

What the Law Actually Says
The Privacy Act 1988 gives the Australian Information Commissioner a graduated set of tools. Under section 42, the Commissioner can make preliminary inquiries to work out whether a fuller response is warranted. Under section 40(2), the Commissioner may commence an own-motion, or Commissioner-initiated, investigation even without a complaint. A preliminary inquiry sits before that step: it is how the regulator decides whether the higher-intensity investigation power should be used at all.
The substantive obligations come from the Australian Privacy Principles in Schedule 1 of the Act. APP 11 requires an entity to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access or disclosure. APP 8 addresses what happens when personal information is sent overseas or handled by offshore providers, which was relevant here because the breach involved a third-party contact-centre platform. APP 1 requires an entity to manage personal information in an open and transparent way. For a fuller explanation, see our guide to the 13 Australian Privacy Principles.
Separately, the Notifiable Data Breaches scheme requires an organisation to notify the OAIC and affected individuals about an eligible data breach that is likely to result in serious harm. The OAIC's inquiries considered Qantas's compliance with that scheme; our explainer on Australia's Notifiable Data Breaches scheme sets out how it works. The Act has also been changing: recent amendments added new enforcement options and a statutory tort, covered in our overview of Australia's Privacy Act reforms.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
A regulator publicly declining to investigate a breach that affected millions of people is a notable and, at first glance, counter-intuitive outcome. It is worth reading precisely. The OAIC did not say the breach was harmless or that Qantas was faultless in every respect. It said the evidence gathered in preliminary inquiries did not indicate that Qantas failed to take reasonable steps to comply with the APPs. Australian privacy law generally asks whether an organisation took reasonable steps, not whether a breach occurred at all. A sophisticated attack can succeed against reasonable security.
The report also underlines how much weight sits on third-party risk management. The breach ran through a contact-centre provider, and the OAIC pointed to Qantas's oversight of its providers as part of why it saw adequate compliance. For organisations that outsource customer contact, that is the operative signal: the reasonableness of vendor controls, not just internal systems, is what the regulator examined.
Finally, this is a preliminary-inquiry result, not a judgment. It closes one regulatory avenue. It does not resolve any civil claim an affected individual might separately pursue, and it does not prevent the OAIC from acting on new information.
How This Affects You
This section describes general principles, not advice about any specific situation. Under Australian law, the fact that a data breach occurred does not automatically mean the organisation broke the law. The Privacy Act generally asks whether the organisation took reasonable steps to protect the information and to comply with the APPs and the Notifiable Data Breaches scheme.
If you were affected by a breach, a regulator's decision not to investigate the organisation does not remove your ability to raise your own privacy complaint about how your information was handled. Individuals can complain to the OAIC about their own circumstances, and our guide to making a privacy complaint in Australia explains that process. For advice about a specific situation, consult a lawyer qualified in Australia.
This is general legal information, not legal advice. It summarises the OAIC's Report into preliminary inquiries of Qantas, published 16 July 2026, as verified on 29 July 2026. It covers Australian federal privacy law and does not address your individual situation or create a lawyer-client relationship. Laws change; consult a lawyer qualified in Australia about your specific circumstances.
Last updated: 2026-07-29. This is a developing story; details verified as of 2026-07-29.
Frequently Asked Questions
What did the OAIC decide about the Qantas data breach?
In a report published on 16 July 2026, the OAIC found the evidence did not show Qantas failed to take reasonable steps to comply with the Privacy Act 1988, and Privacy Commissioner Carly Kind declined to open a formal Commissioner-initiated investigation.
How many people were affected by the Qantas breach?
According to the OAIC's report, roughly 5.67 million customer records were compromised, including records of overseas customers. The breach involved a third-party contact-centre platform used by Qantas.
Does this mean Qantas did nothing wrong?
Not exactly. The OAIC found the steps Qantas took were adequate in the circumstances. Australian privacy law generally asks whether an organisation took reasonable steps to protect information, not whether a breach happened. A finding of no likely contravention is not the same as a finding that nothing went wrong.
What are APPs 1, 8 and 11?
They are Australian Privacy Principles under the Privacy Act. APP 1 requires open and transparent management of personal information, APP 8 governs cross-border disclosure to overseas recipients, and APP 11 requires reasonable steps to secure personal information.
What is a preliminary inquiry under section 42?
Section 42 of the Privacy Act lets the Commissioner make preliminary inquiries to decide whether to take further action, such as commencing a Commissioner-initiated investigation under section 40(2). It is an early step that comes before a full investigation.
Can affected customers still complain?
Yes. The OAIC's decision not to investigate Qantas does not remove an individual's separate right to complain to the OAIC about how their own personal information was handled.
Updates
verification.history.draft
Independently fact-checked against the cited primary sources
Sources and References
- OAIC, Report into preliminary inquiries of Qantas (published 16 July 2026)(oaic.gov.au).gov
- OAIC, statement on the Qantas cyber incident(oaic.gov.au).gov
- OAIC, About the Notifiable Data Breaches scheme under the Privacy Act 1988(oaic.gov.au).gov
- OAIC, the Australian Privacy Principles (APPs), including APP 1, APP 8 and APP 11(oaic.gov.au).gov