What happened, in plain terms
On 19 August 2026, Quest Apartment Hotels confirmed a customer data breach. According to reporting, Quest identified unauthorised access on 17 August and traced it to a vulnerability at a third-party service provider — a company Quest had engaged, holding a database of Quest's customer records.
The records reported as potentially affected number more than 1.5 million, all dating from before June 2025. The information involved was largely names, email addresses and other contact details, with a small number of records also containing dates of birth. There has been no public indication that payment card details or passwords were exposed. Quest said the incident was contained and remediation completed, and notified both the Office of the Australian Information Commissioner (OAIC) — Australia's privacy regulator — and the Australian Cyber Security Centre. It declined to name the provider.
Here's the part that matters to you, and it has nothing to do with hotels. Quest did not have a hole in its own website. Someone else did. And Quest is still the business writing to a million-plus customers, still the business that notified the regulator, and still the name in the headline.
The rule that surprises people
Australia's Privacy Commissioner, Carly Kind, put it about as plainly as a regulator ever does, in the OAIC's own commentary on the most recent published breach statistics:
That single sentence is the whole guide. When you hand customer information to a supplier — a booking system, a CRM, an email platform, a form tool, an offshore bookkeeper — you have not handed over the obligation that comes with it. Under the Australian Privacy Principles, a business covered by the Privacy Act must take reasonable steps to protect the personal information it holds, and information sitting in a supplier's system on your behalf can still count as information you hold.
Two specific things follow, and both are worth knowing by name:
If your supplier is breached, you may have to notify — not them. Under the Notifiable Data Breaches scheme, where a breach affects more than one organisation, more than one can carry obligations. The OAIC's stated position is that, generally, the entity with the most direct relationship with the affected individuals should be the one that notifies them. That's usually you — the business whose name the customer recognises — not the software company they've never heard of.
If your supplier is overseas, you may be accountable for what they do. Australian Privacy Principle 8 requires a business, before disclosing personal information to an overseas recipient, to take reasonable steps to ensure that recipient doesn't breach the APPs. Section 16C of the Privacy Act goes further: an act by that overseas recipient that would breach the APPs is taken to have been done by you. There are exceptions, and whether they apply to your arrangement is genuinely a legal question worth putting to a professional — but the default position is accountability, not distance. Plenty of the tools on a typical Australian small-business website store data in the United States, Ireland or Singapore.
Why this lands harder on small businesses
Not because the rules are harsher. Because the count is higher than you think, and nobody's tracking it.
A large company has a procurement team, a vendor register and a contract for each supplier. A four-person business has a website that was set up over a few weekends, and somewhere in it are a dozen third parties that quietly collect and store customer information. Most owners can name three of them.
The OAIC's most recent published figures — covering January to June 2025, released 4 November 2025 — recorded 532 breach notifications in six months. Malicious or criminal attacks were the largest source at 59%, but human error accounted for 37%, up from 29% in the previous period. The regulator devoted a case study in that same release to a third-party provider running an unauthorised script on a government website, which made private documents public and searchable. Not a master hacker. A supplier doing something nobody had asked them to do.
Earlier, when the OAIC first highlighted supply-chain risk in its breach reporting, it noted that most multi-party breaches it saw resulted from a breach of a cloud or software provider — and pointed businesses at the same fix: address the risk in your contracts, and know in advance who does what if something goes wrong.
Does any of this actually apply to my business?
Honest answer: it depends, and it's worth checking rather than assuming either way.
Most Australian businesses with an annual turnover of $3 million or less are currently exempt from the Privacy Act under the small business exemption. But that exemption has holes that catch a lot of ordinary operators, including private-sector health service providers that hold health information — which covers GPs, dentists, physios, psychologists and allied health, regardless of size — and businesses that buy or sell personal information. Separately, from 1 July 2026 new anti-money-laundering rules brought a range of professional services into Privacy Act obligations regardless of turnover; we've covered that in a separate guide.
Removal of the small business exemption altogether has been proposed as part of a second tranche of Privacy Act reform. As at the date of this guide, no bill has passed and no commencement date has been set. It is not law, and anyone telling you the exemption is gone is ahead of the facts. It is, however, a reasonable thing to prepare for rather than be surprised by.
And there's a simpler point underneath the legal one. Whether or not the Act binds you, if a supplier leaks your customers' details, your customers will hold you responsible. That part doesn't have a turnover threshold.
The 30-minute job: list who holds your data
This is the single most useful thing to do this week, and it needs no technical skill. Open a blank page and write down every tool that touches customer information. Most owners find between eight and fifteen. Work through these categories:
| Where to look | What you're likely to find |
|---|---|
| Your website's forms | Contact, quote and booking forms. Where do submissions go — an inbox, a plugin's database, a form service like a hosted form builder? Somebody stores them, often forever. |
| Your booking or appointment system | Names, phone numbers, appointment history, and for health providers, potentially health information — the most sensitive category there is. |
| Your email marketing platform | Your whole customer list, plus behavioural data on who opened what. Usually stored overseas. |
| Your CRM or sales tracker | Including the spreadsheet in a cloud drive that's doing the job of a CRM. It counts. |
| Chat widgets and reviews | Live-chat transcripts and review platforms both capture customer identity and free-text messages people assume are private. |
| Analytics and advertising tags | Tracking pixels send visitor data to platforms you don't control. If yours aren't disclosed in your privacy policy, that's a separate and well-tested problem — we've written about it here. |
| Payments and invoicing | Your payment provider and accounting software hold customer names, contact details and transaction history. |
| People with logins | Your web developer, marketing agency, virtual assistant and bookkeeper. A person with an admin login is a third party too — including the ones who've stopped working for you. |
Against each one, write two things: what personal information it holds, and whether you still use it. The second column is where the quick wins are. Almost every business finds a tool nobody has opened in two years, still holding a full customer list, still one password away from a stranger. Deleting the data and closing the account is a genuine reduction in risk that takes ten minutes and costs nothing.
Then check one more thing: does your privacy policy tell customers this is happening? The Australian Privacy Principles expect a policy to say whether personal information goes to third parties or overseas. If your policy is a template that has never been updated to mention the tools you actually use, it's describing a business other than yours.
Five questions worth asking a supplier
You won't audit a software company, and you shouldn't try. But asking is not nothing — the answers, and how fast they come, tell you which suppliers have thought about this and which haven't.
What personal information about our customers do you hold, and where is it stored?
Specifically: which country. That's the question that determines whether APP 8 and cross-border accountability are in play for you.
How and how quickly will you tell us if you have a security incident affecting our data?
You need this in hours, not weeks, because your own assessment clock starts when you become aware. Confirm they have a current email address for you.
Who notifies our customers if there's a breach — you or us?
Get the answer before you need it. The OAIC's general position is that whoever has the most direct relationship with the customer should notify, which usually means you.
How long do you keep our data after we stop using you, and can you delete it on request?
Data you no longer need is pure liability. The OAIC has said it prioritises regulatory action where organisations hold onto data much longer than necessary.
Do you hold a recognised security certification, or can you share a summary of your controls?
A real answer names something specific. "We use bank-level encryption" is marketing, not an answer — but a supplier who can point to an actual standard is one you can reasonably rely on.
Subject: Privacy and data handling questions for our account
Hi,
We're documenting which suppliers hold personal information for our business. Could you confirm the following for our account:
- What personal information about our customers does your service store, and in which country is it stored?
- How, and within what timeframe, would you notify us of a security incident affecting our data? Which email address do you have on file for that?
- In the event of a breach affecting our customers, who notifies the affected individuals — you or us?
- How long is our data retained after an account is closed, and can it be deleted on request?
- Do you hold a recognised information security certification, or can you provide a summary of your security controls?
Thanks very much,
[Your name]
What a website scan can and can't see
Being precise about the limits, because this is exactly the kind of topic where a security company would be tempted to overclaim.
AegorIQ cannot see inside your suppliers' systems. Nobody outside them can. We can't tell you whether your booking provider is patched, whether your email platform has been breached, or what's in their contract with you. That information only comes from asking them, which is why the email above is the substantive action in this guide.
What a scan can do is show you the third parties that are visibly running on your site, which is usually more than the owner expects. Every AegorIQ tier, including the free Scorecard, names the analytics and tracking tools actually loading on your pages rather than just counting them, and reads your privacy policy against the elements the Australian Privacy Principles expect — including whether it discloses that information goes to third parties or overseas. Every tier also checks your site's software, including plugins from third-party developers, against a live vulnerability feed. Our Expert report adds a check for third-party scripts loading without integrity protection, which is the mechanism behind checkout-skimming attacks, and for subdomains pointing at services you no longer own. The complete itemised list, including everything we don't check, is published here.
The honest summary: a scan gives you the visible half of the picture and a starting list of names. The other half comes from a page, a pen, and five emails you can send before lunch.
Sources
- ABC News — Quest Apartment Hotels customers' personal data exposed in security breach (19 August 2026)
- The Register — Australian hotel chain leaks guests' PII after breach at third-party database operator
- Cyber Daily — Quest hotel chain discloses third-party customer data breach
- Australian Cyber Security Magazine — Quest confirms customer data breach linked to third-party vulnerability
- OAIC — Latest Notifiable Data Breach statistics for January to June 2025 (Privacy Commissioner Carly Kind, 4 November 2025: 532 notifications; responsibility for third-party providers; supplier risk case study)
- OAIC — Data breach report highlights supply chain risks (multi-party breaches mostly from cloud or software providers; 30-day assessment and "as soon as practicable" notification)
- OAIC — About the Notifiable Data Breaches scheme
- OAIC — APP Guidelines Chapter 8: cross-border disclosure and accountability under s 16C
- OAIC — Small business and the Privacy Act (the $3m turnover exemption and its exceptions)
- OAIC — Guide to securing personal information