Australia's Privacy Regulator Ends Its Inquiry Into the 2025 Qantas Data Breach Without a Full Investigation

Independently fact-checkedBy Recording Law Editorial Team6 min read

Independently fact-checked against primary sources (last audited July 29, 2026). · 4 primary sources cited on this page. How we verify our legal content

Australia's Privacy Regulator Ends Its Inquiry Into the 2025 Qantas Data Breach Without a Full Investigation

Frequently Asked Questions

What did the OAIC decide about the Qantas data breach?

In a report published on 16 July 2026, the OAIC found the evidence did not show Qantas failed to take reasonable steps to comply with the Privacy Act 1988, and Privacy Commissioner Carly Kind declined to open a formal Commissioner-initiated investigation.

How many people were affected by the Qantas breach?

According to the OAIC's report, roughly 5.67 million customer records were compromised, including records of overseas customers. The breach involved a third-party contact-centre platform used by Qantas.

Does this mean Qantas did nothing wrong?

Not exactly. The OAIC found the steps Qantas took were adequate in the circumstances. Australian privacy law generally asks whether an organisation took reasonable steps to protect information, not whether a breach happened. A finding of no likely contravention is not the same as a finding that nothing went wrong.

What are APPs 1, 8 and 11?

They are Australian Privacy Principles under the Privacy Act. APP 1 requires open and transparent management of personal information, APP 8 governs cross-border disclosure to overseas recipients, and APP 11 requires reasonable steps to secure personal information.

What is a preliminary inquiry under section 42?

Section 42 of the Privacy Act lets the Commissioner make preliminary inquiries to decide whether to take further action, such as commencing a Commissioner-initiated investigation under section 40(2). It is an early step that comes before a full investigation.

Can affected customers still complain?

Yes. The OAIC's decision not to investigate Qantas does not remove an individual's separate right to complain to the OAIC about how their own personal information was handled.

Updates

Independently fact-checked against the cited primary sources

Sources and References

  1. OAIC, Report into preliminary inquiries of Qantas (published 16 July 2026)(oaic.gov.au).gov
  2. OAIC, statement on the Qantas cyber incident(oaic.gov.au).gov
  3. OAIC, About the Notifiable Data Breaches scheme under the Privacy Act 1988(oaic.gov.au).gov
  4. OAIC, the Australian Privacy Principles (APPs), including APP 1, APP 8 and APP 11(oaic.gov.au).gov
Share: