
When a regulator investigates the loss of millions of customer records and then decides to walk away, the reasons it gives are worth reading closely. On 16 July 2026 the Office of the Australian Information Commissioner did exactly that with Qantas, and in the process it published the clearest picture yet of what “reasonable steps” to protect personal information actually looks like.
The OAIC released its report of preliminary inquiries into the 2025 Qantas data breach and closed them without opening a commissioner-initiated investigation and without taking any regulatory action. The June 2025 incident exposed around 5.7 million customer records (the OAIC put the number of affected Australians at roughly 5 million) after a voice-phishing attack, or vishing, on an overseas contact-centre provider Qantas had contracted. An attacker posing as Qantas IT support talked a contact-centre agent into granting access. No penalty, no enforceable undertaking, no full investigation.
Australian Privacy Commissioner Carly Kind was blunt about why. “I do not consider that the evidence supports the likelihood that a breach of privacy law occurred,” she said. “As a result, it would not be appropriate for the OAIC, a proportionate and risk-based regulator, to commence a full investigation or take further action at this stage.”
“Reasonable steps” is the phrase that matters
Under Australian Privacy Principle 11, an organisation must take reasonable steps to protect the personal information it holds. The word doing the work is “reasonable”. It does not mean perfect, and it does not mean breach-proof. The OAIC’s decision turns on a distinction every auditor lives with: being breached is not the same as failing to take reasonable steps. Qantas was breached, and the regulator still found no likely contravention, because the evidence showed the airline had done the work beforehand and could prove it.
That is the part worth sitting with if you run a smaller business. The regulator did not ask “were you breached?” It asked “can you show what you had in place, and was it reasonable for an organisation like you?” The OAIC pointed to specific, documented measures Qantas had taken before the incident: it had audited its overseas third-party contact-centre provider, it ran cyber and data-protection training for the agents handling customer data, it had processes to destroy and de-identify personal information once it was no longer needed, and it used role-based access controls to limit who could reach what. None of that stopped the breach. All of it is why Qantas kept its regulatory record clean.
The breach came through a supplier, and that is where most businesses are exposed
Look at where the attack landed. Not Qantas’s own systems, but an overseas contact centre it had outsourced to. The OAIC did not just look at Qantas’s internal controls. It also examined whether Qantas had taken reasonable steps to ensure that third-party provider handled the data properly, which is squarely the territory of Australian Privacy Principle 8 on cross-border disclosure. The airline passed that test because it could show it had assessed and audited the supplier.
Most small and mid-sized businesses could not. They use offshore support, cloud tools, bookkeepers, marketing agencies and IT providers, and if you asked them to produce evidence that they had assessed how each of those suppliers protects data, the honest answer would be a shrug. Your data does not stop being your responsibility when it sits on someone else’s system. The Qantas outcome is a preview of the standard you will be held to when your own “we trusted our provider” moment arrives.
This is exactly what an ISO 27001 system is built to produce
Read the list of things that saved Qantas again: a documented view of what data it held and where, assessed and audited suppliers, trained staff, controlled access, and an incident response it could evidence. That is not a coincidental collection of good habits. It is the standard content of an ISO 27001 information security management system.
ISO 27001 asks you to identify your information assets and the risks to them, then treat those risks with controls you can point to. Its Annex A includes controls for supplier relationships (assessing and monitoring the third parties who touch your data), for information security awareness and training, for access control, and for managing security incidents when they happen. In other words, the framework produces exactly the evidence trail the OAIC went looking for at Qantas. A certified business can answer “show me your reasonable steps” with a register, an audit record and a training log, in minutes rather than weeks. An uncertified one is relying on memory, and memory does not survive contact with a regulator.
You do not have to be certified to comply with the Privacy Act. But the system that gets you certified is the same system that lets you prove you took reasonable steps, and that is a far better reason to build one than a logo for a tender.
The Commissioner’s warning: the bar is about to rise
Kind did not treat the Qantas outcome as a reason to relax. She used it to look forward. “Agentic and advanced AI will only increase the cyber-security risks that businesses face,” she said, “and it is critical that all organisations continuously review and enhance their security to protect against this growing threat.”
Two things follow from that. First, “reasonable steps” is a moving target. What counted as reasonable last year will not necessarily count next year, which is why ISO 27001 is built around continual improvement rather than a one-off tick. Second, as AI works its way into your operations, governing it becomes part of protecting data, which is where ISO 42001 AI management starts to sit alongside your security work rather than apart from it.
What to do before it is your turn
- Map where your data actually lives. List the suppliers, tools and offshore services that hold or handle personal information. You cannot protect what you have not written down.
- Get evidence on your suppliers. For each one that touches customer data, can you show you assessed how they protect it? If not, that is your Qantas-style exposure, and it is the first gap to close.
- Check your training and access records. The Qantas attack worked on a person, not a firewall. Documented awareness training and role-based access are the controls the OAIC actually credited.
- Start with an honest gap analysis. An independent gap analysis against ISO 27001 tells you where your “reasonable steps” story is strong and where it falls apart, before a breach forces the question.
Frequently asked questions
Does getting breached mean I failed to take reasonable steps?
No, and the Qantas outcome makes that clear. The OAIC found no likely breach of privacy law despite millions of records being exposed, because Qantas could show it had reasonable controls in place beforehand. Under APP 11 you are judged on the steps you took, not on whether an attacker got through anyway.
What counts as “reasonable steps” under APP 11?
It depends on your size, the sensitivity of the data and the risks you face, but the OAIC’s assessment of Qantas is a strong guide: assessing and auditing the suppliers who handle your data, training the people who touch it, controlling access, disposing of data you no longer need, and having an incident response you can evidence. The common thread is that each step is documented and can be shown.
How does ISO 27001 help me prove reasonable steps?
ISO 27001 gives you the exact machinery the OAIC looked for: a register of your information assets and risks, documented supplier controls, awareness training records, access controls and incident management, all kept current through a required audit cycle. It turns “we take security seriously” into something you can put in front of a regulator.
Speak with an experienced ISO auditor
If the Qantas findings have you wondering whether you could evidence your own reasonable steps, we can help you find out. Whether that is an independent gap analysis, a full ISO 27001 certification project, practical cyber and information security advisory, or ISO mentoring if your team wants to build it themselves, you deal directly with an experienced ISO auditor. Email hello@streamline.business or call us.
- Brisbane 07 3667 8280
- Sydney 02 8315 7780
- Melbourne 03 9034 3990
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











