Typically when we're discussing the lessons to be learned about a cyber or privacy incident, we’re working backwards from a negative ruling.

In this episode, we discuss the OAIC’s favourable ruling about Qantas’ mid-2025 cyber-related data breach that affected millions of customers. While the OAIC’s investigation largely clears Qantas of wrongdoing, the report highlights plenty of lessons for organisations seeking to understand what the regulator expects when it comes to taking “reasonable steps” to protect personal information.

 

Links

Full report into preliminary inquiries of Qantas (OAIC) https://www.oaic.gov.au/privacy/privacy-assessments-and-decisions/privacy-decisions/Investigation-i…
OAIC media statement https://www.oaic.gov.au/news/media-centre/privacy-commissioner-completes-preliminary-inquiries-into…
Media article at time of incident (ABC News) https://www.abc.net.au/news/2025-07-02/qantas-cyber-attack-significant-data-stolen/105484720
Article about summary of OAIC findings (Mi3) https://www.mi-3.com.au/17-07-2026/qantas-cleared-privacy-law-breach-2025-data-incident
OAIC’s Australian Clinical Labs ruling (OAIC) https://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-rela…

 

Credits

Editing and post-production by Martin Franklin (East Coast Studio) www.eastcoaststudio.com.au

Listen on Spotify