What the Wine Wholesaler Teaches Every Business Sitting on Customer Data

Published
29 Jul 2026
Read time
5 min read
Category

Key Takeaways 

  • Privacy Commissioner Carly Kind found that online wine wholesaler Vinomofo Pty Ltd breached Australian Privacy Principle (APP) 11.1 by failing to take reasonable steps to protect the personal information of around 928,760 customers and members. 
  • In considering what controls should have reasonably been in place, the Commissioner referred to the NIST CSF, ISO 27000 series, the Essential 8 and the Information Security Manual.   
  • The Determination criticised Vinomofo’s culture, pointing to missing security policies, an under-qualified security team, and a general failure to embed privacy as a business priority. 
  • The Commissioner ordered Vinomofo to implement logging, access controls and monitoring across its AWS environments, formalise written security policies, review its security staffing, upgrade staff training, and bring in an independent reviewer within six months to check the fixes actually worked. 
  • The decision is a significant, practical guide to what “reasonable steps” under APP 11.1 looks like specifically for cloud migration and data transformation projects. 

What Happened 

In late 2018, Vinomofo began a project to migrate data in stages, from its legacy environment to a new platform. To support this, it copied its customer database into an AWS-hosted temporary migration database. 

Unfortunately this database was sitting on an old AWS account that predated Amazon’s default use of virtual private clouds, meaning it was never properly walled off from the wider internet. 

The first data tranche was transferred in April 2022, followed by customer lists in August 2022.  

On 25 September 2022, a threat actor accessed and exfiltrated data from this database, comprising around 17GB relating to roughly 928,760 individuals, including identity, contact and financial information. The hacker sought a ransomware payment from Vinomofo. The stolen data was listed for sale on the dark web on 16 October, with a sample sold on 20 October 2022. 

Vinomofo notified the OAIC on 17 October 2022 (some 22 days after the ransomware incident occurred). 

The Determination 

That notification kicked off a formal investigation by the OAIC, eventually resulting in the Determination being handed down in October 2025. 

Privacy Commissioner Carly Kind concluded that the “totality of steps” Vinomofo had taken simply didn’t amount to “reasonable steps” to protect the personal information they held, given what was at stake: the sensitivity and volume of the information, the resources a business like Vinomofo had available, and the very real risk of exactly this kind of breach occurring.  

In other words, having some security measures isn’t the test. The test is whether what you did was proportionate to what you were protecting. 

In determining what would have been reasonable, the OAIC had regard to: 

  • The personal information held (types and quantity) 
  • The nature of the entity, in this case it was a ‘for-profit’’ with an income of approximately $72 million per year and 120 employees. 
  • Possible adverse consequences. 

In considering the controls that should have been in place, reference was made to industry Standards – specifically the NIST CSF, ISO 27000 series, the Essential 8 and the Information Security Manual.   

What’s Interesting About the Decision 

Technical Controls and Procedures 

The decision provides some clear direction on the sort of controls the Commissioner might expect an organisation like Vinomofo to have in place, covering technical controls, policies and procedures, internal cyber skills and a culture of security awareness. These expectations are clear from the orders that required Vinomofo to take a number of steps including: 

  • implementing security logging in its AWS environments that store personal information;  
  • applying appropriate security access settings to any database that holds the personal information;  
  • implementing systems or controls to monitor its systems for signs of unauthorised activity;  
  • implementing written policies and procedures that meet the minimum security baseline requirements as set out in industry standards. 

People and Culture 

On the people and culture side, the Commissioner found that Vinomofo’s business posture simply didn’t value or nurture attention to customer privacy.  

A 2021 audit had found no formal security policies existed at all, no documentation on things as basic as acceptable use of laptops or passwords. The team responsible for cyber security at the time of the breach was just three people, and none held formal cyber security qualifications.  

Vinomofo pointed to some mitigating factors, including staff privacy training through a program called Safetrac, and the disruption COVID had caused to its operations.  

The Commissioner accepted those points, but didn’t accept they excused the delay in getting the fundamentals sorted before customer data was moved into a new, more exposed environment. 

In this Determination the Commissioner therefore ordered an independent review of whether the security team is adequately resourced and qualified, and a refreshed staff training program. Vinomofo also was ordered to bring in an independent reviewer within six months to check all of this has actually been done properly. 

The Lesson for All Businesses 

The bigger lesson for anyone reading this outside the wine industry is that APP 11.1 isn’t a box you tick once. It’s a standard that gets reassessed every time your data footprint changes. A cloud migration project is exactly the kind of moment regulators will now expect you to have handled with diligence that is proportionate to the risk. 

Ready to turn insight into action?
Connect with Privacy 108.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Privacy 108 collects your name and contact details to respond to your enquiry and communicate with you about it. If you do not provide this information, we may be unable to respond. We do not disclose this information to third parties. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au.
Related articles
Subscribe to our Newsletter

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.