The Quest Incident and the Third-Party Problem

Quest Apartment Hotels confirmed unauthorised access to a database system in August 2026. The breach exposed customer names, email addresses, contact details, and a small number of dates of birth. Quest traced the incident to a vulnerability involving a third-party service provider. That detail matters. It means the failure originated outside Quest’s own IT environment, yet Quest still carries the notification burden under the Privacy Act 1988 (Cth).

This is the uncomfortable reality for Australian businesses. You can outsource data processing. You cannot outsource accountability. When a supplier’s system fails and your customer data leaks, the Office of the Australian Information Commissioner looks to you. The data minimisation principle applies here. If you held less data, or held it for less time, the exposure would shrink.

Quest’s response was exemplary in many ways. They contained the incident, engaged external advisers, notified the OAIC and the Australian Cyber Security Centre, and contacted affected customers. But the fact they needed to notify at all raises the question many SME owners ask: when does a breach cross the line from “we handled it internally” to “we must tell the regulator”?

What the Notifiable Data Breach Scheme Actually Requires

The Notifiable Data Breach (NDB) scheme under Part IIIC of the Privacy Act sets a specific threshold. An eligible data breach occurs when three conditions are met.

  1. There is unauthorised access to, unauthorised disclosure of, or loss of personal information held by an entity.
  2. A reasonable person would conclude that the access, disclosure, or loss is likely to result in serious harm to any of the individuals to whom the information relates.
  3. The entity has not been able to take remedial action that reduces the likelihood of serious harm below that threshold.

The word “likely” is critical here. It does not mean certain. It does not mean possible in a remote sense. It means more probable than not, or a real and substantial risk. That is a judgement call. And it is a judgement call with legal consequences if you get it wrong.

For a cybersecurity lawyer in Melbourne advising SMEs, the assessment usually turns on the nature of the data and the context of the breach. Names and email addresses alone might not clear the bar. Names, email addresses, and dates of birth together create a higher risk of identity fraud or targeted phishing. Add financial details or government identifiers, and the assessment shifts quickly.

Why “Serious Harm” Is a Business Decision, Not Just a Legal One

The Privacy Act does not define “serious harm” with precision. The OAIC’s guidance points to factors including the sensitivity of the information, whether the information is protected by security measures like encryption, the nature of the harm, and who obtained the information.

For a business owner, this is where legal advice for data breach response becomes practical. You need to weigh the likelihood of harm against the cost and reputational impact of notification. Over-notifying creates unnecessary alarm and can damage customer trust. Under-notifying exposes you to penalties, regulatory action, and potential class actions.

The OAIC can seek civil penalties for serious or repeated interferences with privacy. The maximum penalty for serious interferences by bodies corporate is the greater of $50 million, three times the value of the benefit obtained, or 30% of adjusted turnover during the breach turnover period. Those numbers are a significant concern for executives.

But the decision to notify is not simply about avoiding penalties. It is about managing liability across multiple fronts. Your cyber insurance policy may require notification as a condition of cover. Your contracts with third-party providers may allocate responsibility for breach costs. Your customers may have contractual rights under your terms of service. Each of these intersects with the NDB threshold.

Third-Party Risk and Contractual Allocation

Quest’s breach involved a third-party service provider. That provider has not been publicly identified, but the incident highlights a common gap in SME risk management. Many businesses assume their supplier’s cyber problem is the supplier’s legal problem. That assumption fails under the Privacy Act.

Under Australian Privacy Principle 11, an APP entity must take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. This obligation extends to information held by third-party processors. You must conduct due diligence on suppliers. You must include privacy and security obligations in your contracts. You must monitor compliance.

When a supplier breach occurs, the contractual position matters. Does the supplier indemnify you for notification costs? Do they cover the cost of credit monitoring for affected individuals? Do they have insurance that responds? These are commercial questions that shape your response strategy.

The FTC’s data breach response guide typically recommends engaging legal counsel early in any incident response. That advice applies equally in Australia. Legal advice protects privilege over your investigation. It also helps you structure the factual record in a way that supports your NDB assessment.

Practical Steps for SMEs Before a Breach Happens

Waiting until a breach occurs to think about notification thresholds is a mistake. The time to prepare is now. Several practical steps can reduce your exposure.

  • Map your data flows. Know what personal information you hold, where it sits, and who has access to it. This includes data held by third parties.
  • Review your supplier contracts. Ensure they include privacy obligations, security standards, breach notification requirements, and indemnities.
  • Test your incident response plan. A plan that works on paper but fails under pressure is not a plan. Run a tabletop exercise with your leadership team.
  • Establish a relationship with a lawyer who understands privacy law before you need one. Incident response moves fast. You do not want to be searching for advisers at 9pm on a Friday.

Data minimisation deserves particular attention. The less personal information you hold, the less you expose when something goes wrong. Review your retention practices. Delete what you do not need. Limit collection to what is necessary for your functions. These steps reduce the likelihood that a breach will clear the serious harm threshold.

When the Regulator Comes Knocking

If you notify the OAIC, expect follow-up. The Commissioner may ask for details of your investigation, your containment measures, and your remediation plans. They may ask why you did not notify earlier. They may ask about your third-party contracts and your security posture before the incident.

This is where documentation matters. Record your NDB assessment at the time you make it. Note the factors you considered, the advice you received, and the reasons for your decision. If you decide not to notify, document that decision with the same rigour. A contemporaneous record shows the OAIC you took the assessment seriously, even if they disagree with your conclusion.

The Quest incident also shows the value of clear customer communication. Quest told customers that if they did not receive a notification, their information was unlikely to be affected. That is a simple, direct message that manages anxiety and reduces inbound enquiries. It also demonstrates a considered approach to the notification scope.

Legal Advice for Data Breach Response Is Not Optional

The notifiable data breach threshold in Australia is not a technical test. It is a legal judgement about the likelihood of serious harm. That judgement has consequences for regulatory exposure, contractual liability, insurance coverage, and customer trust.

For SME owners, the lesson from Quest is clear. Third-party vulnerabilities are your vulnerabilities. The NDB threshold is your threshold. And the decision to notify is your decision. Getting it right requires legal advice that understands both the Privacy Act and the commercial realities of running a business.

If you are reviewing your data breach readiness, or if you have received a notification from a supplier about a potential exposure, we can help you assess your obligations and plan your response. Our team advises businesses across Melbourne on privacy compliance, incident response, and regulatory engagement.

Avatar photo
About Blaine HattieBlaine Hattie is a Principal in Commercial Transactions at Sutton Laurence King Lawyers. He advises businesses on transactions and finance with a special interest in technology, cybersecurity, digital media, defamation, and artificial intelligence.

Book an appointment with one of our Lawyers to discuss your specific needs.

Book a Consultation

A Note on the Information We Share

Reading this information does not create a lawyer-client relationship between you and SLK Lawyers. This only occurs with a formal written agreement. Content is current at publication and applies to Victorian law unless stated otherwise. It is general information only and not a substitute for specific legal advice. Strict time limits apply to legal claims. You should seek immediate legal advice on your specific situation to ensure your rights are protected.