The post-cookie playbook told Australian marketers to collect more first-party data and said nothing about governing it. The Oz Hair and Beauty breach shows the payoff: customer records sitting in a third-party system the business never controlled. Collection is the easy part. The marketer, not the vendor, wears the risk when it leaks.
Collection is a checkbox. Governance is a discipline. A lot of Australian businesses bought the checkbox and skipped the discipline.
The Take: First-party data is not the asset your martech vendor sold you. For most Australian businesses it is a liability sitting in a system they do not own and cannot lock. When it leaks, and the numbers say it will, the marketer who signed off on the collection carries it, not the platform that promised the world.
How did the asset every marketer chased become the thing you cannot secure?
In August 2026 roughly 2 million email addresses tied to Oz Hair and Beauty customers were exposed, with names, mobile numbers, suburbs and purchase histories. The data was not on the retailer's own systems.
That last detail is the entire story. Every marketer spent the last three years hearing the same instruction. The third-party cookie is dying, so build your own data. Capture emails, record behaviour, stitch it into a customer profile you control. Sensible advice as far as it goes. What almost no marketer in that chorus said out loud is that collecting data and controlling data are two separate jobs, and the second one is much harder than the first.
What actually happened at Oz Hair and Beauty
The Oz Hair and Beauty breach surfaced through Have I Been Pwned in August 2026. Inside Retail reported the exposed records covered names, contact details, suburb and postcode and order history, with no card or password data involved. Cyber Daily confirmed the incident hit a third-party provider rather than the retailer's own infrastructure.
Read that again. The retailer did what the post-cookie advice asked. It built a first-party database. Then it handed that database to a provider, and the provider is where the wall came down. The customer does not care about that distinction. The regulator does not care much either. The brand on the emails is the brand that wears it.
WPP Media forecasts the Australian ad market at $31.1 billion in 2026, up 7.4%, led by retail media. A growing share of that spend now runs on first-party data businesses raced to collect and never learned to secure. Across the Australian businesses we score on our Data and Tracking dimension, collection is rarely the gap. The majority we see can capture an email. Far fewer can tell you where it is stored, who else can read it, whether consent was recorded or what happens to it once it lands.
That is the split hardly a vendor priced in. Collecting first-party data is the easy 20%. Governing it, securing it and turning it into something that moves the business is the 80%.
The breach record backs the split. The OAIC logged 532 data breach notifications in the first half of 2025, with malicious or criminal attacks the single largest source at 59%. The second half of 2024 set a record high.
Malicious or criminal attacks were the single largest source of Australian data breaches in the first half of 2025
Who wears the risk when it leaks?
The marketer. Not the vendor, not IT, not the provider whose server failed.
SCX.AI managing director David Keane, speaking at TechLeaders in Bowral, made the point that CMOs can no longer treat AI and data infrastructure as an IT-only problem, and should be asking whether the campaign they are running has any connection to the Privacy Act. He is right, and most marketing teams are not set up to answer that question.
If you signed off on the collection, you own the outcome. Outsourcing the storage does not outsource the accountability.
This is where the vendor pitch quietly fails you. The platform sold you collection. It did not sell you custody. When the two get confused, the business ends up calling a pile of exposed records an asset on the strength of someone else's promise, right up until the day that promise is tested.
What I would do about it
Concrete steps, in the order I would run them.
Map where it lives. List every system holding customer data, including third-party providers. If you cannot name the provider, you have found your first problem.
Put the breach clause in the contract. Ask each provider who is liable, what their notification window is and whether they carry cyber cover. Get it in writing before the next renewal.
Record consent at the point of capture. If you cannot show when and how a customer opted in, you are collecting risk, not data.
Minimise on purpose. Stop collecting fields you never activate. Every unused data point is liability with no upside.
Name an owner. One accountable person for customer data governance, sitting in marketing, not buried three levels down in IT.
None of that is glamorous. All of it is cheaper than a breach notification and the week of trust repair that follows.
A note on the data
When I say most or the majority, I mean it directionally, drawn from the businesses New Rebellion scores across its Data and Tracking dimension. I am not quoting a headline count. Where a sample is small we treat the read as directional rather than definitive. The scoring methodology is public at how we score.
The close
Here is my opinion, stated as opinion. The post-cookie era did not hand marketers an asset. It handed them a custody problem most were never resourced to solve. The businesses that win the next few years will not be the ones with the biggest customer database. They will be the ones who can prove they control the one they have. That is the work we do inside NR Studio.
Frequently asked questions
Is first-party data still worth collecting?
Yes, if you can govern it. Collection without governance turns an asset into a liability. Answer honestly whether you can secure and activate what you gather before you gather more of it.
Who is liable when a third-party provider is breached?
The brand the customer dealt with wears the reputational weight, and often the regulatory weight, even when the technical failure sits with a provider. Contracts can shift some liability. They cannot shift how the customer feels.
What is the difference between collecting and governing data?
Collecting is capturing the record. Governing is knowing where it sits, who can access it, whether consent was recorded and how it is used. Most businesses do the first and skip the second.
How does New Rebellion measure this?
Through the Data and Tracking dimension of our scoring, which looks at capture, consent, security signals and activation, not just whether a business owns an email list. The methodology is public at /lens/how-we-score.