Nearly two million Australians just learned a lesson about data retention the hard way. Quest Apartment Hotels has confirmed that a breach through a third-party technology provider exposed records for roughly 1,991,613 customers — names and contact details mostly, but also passport and licence numbers, vehicle registrations, and hundreds of thousands of credit card numbers. The detail that should stop every small business owner cold is buried a few paragraphs down: all of the affected information relates to records from before June 2025. This was old data. It was still just sitting there.
Two failures, only one of them Quest’s
The attack came through a vulnerability in a third-party provider’s software, which is the part you can’t fully control. Vendors get breached; that’s the world we live in. But the blast radius of a vendor breach is entirely decided by what you kept. The forensic breakdown tells the story: 297,739 credit card numbers without CVV and another 46,727 with CVV, including expired cards. Passport numbers for guests who checked out years ago. The third-party software opened the door — the data hoard determined how much walked out of it.
As one security commentator put it in the coverage: audit your data holdings, know what you have and why, and remember that data you no longer hold cannot be stolen in a breach. That last sentence is the whole article, really. Everything else is implementation detail.
Storing CVV is not a retention oops — it is a rule violation
A quick word on those 46,727 cards with CVV, because it matters for anyone taking payments. PCI DSS has forbidden storing the card verification value after authorisation for as long as the standard has existed. There is no innocent retention-policy story where CVVs end up in a database; that data should never have been written in the first place. If your booking form, POS export, or “just in case” spreadsheet pipeline is writing full card details anywhere, that is not a cleanup task for next quarter. It is a today problem.
Retention is a security control, and Australian law now agrees
After the Optus breach, Australian privacy law was tightened to require organisations to destroy or de-identify personal information once it is no longer needed. Which sounds like compliance paperwork until you frame it the way an attacker would: every month you keep data past its useful life, you are holding inventory for someone else’s incident. Retention policy is not a records-management nicety. It is attack-surface reduction, and unlike most security spending, deletion is free.
A retention audit a small business can actually finish
Enterprise data governance frameworks are a waste of your time. Here is the version I would run for a ten-person business, doable in an afternoon:
- Inventory by category, not by system. Not “the booking database” but the categories inside it: names, contact details, payment identifiers, ID numbers. List where each category lives — including exports, shared drives, email archives, and that spreadsheet an contractor made in 2023.
- Give every category a TTL and a reason. If you cannot articulate why you still hold a category of data, that is your answer: it goes. Contact details for past customers? Fine, with a marketing-consent story. Passport numbers from a 2019 booking? There is no story.
- Automate the purge so it sticks. A retention rule that depends on someone remembering is not a rule. One cron job beats one heroic cleanup:
# monthly: remove guest exports older than 24 months
0 3 1 * * find /srv/exports/guests -type f -mtime +730 -print -delete >> /var/log/retention.log 2>&1
The -print before the -delete matters: you want an audit trail of what the policy removed, because “we delete old data” is also something you will need to demonstrate.
- Fix collection at the source. The cheapest record to retain is the one you never collected. Walk your forms and checkout flow with a hostile eye: is every field justified? Every optional ID field you delete from the form is a category that can never leak.
- Ask your vendors the same question. Quest’s path in was third-party software. Ask yours what they retain, for how long, and who has access. A vendor who cannot answer is telling you something.
- Remember that backups count. The awkward one. Your snapshots and offsite copies faithfully preserve every PII field you “deleted” in production. If you purge a category, note it and make sure the next backup cycle ages it out too, or your retention policy has an asterisk the size of a restore.
The cheapest breach response is no data to respond about
Quest is now doing what every breached company does: forensic analysis, regulator notifications, apology letters to two million people, a support line. Nearly all of that cost scales with how much data was sitting in the room when the door got kicked in. The records from before June 2025 should have been gone years before the attacker arrived. They were not, and two million people are dealing with the consequences.
You cannot prevent a vendor’s software from having a vulnerability. You can absolutely decide that when something gets into your systems, it finds a sparse target. Hoarding customer data past its useful life is unsecured debt — it accrues quietly, and it comes due at the worst possible moment. Stop keeping it.

