OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian business, government agency, or credit provider has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide explains exactly how to lodge an OAIC complaint about a privacy breach, what evidence you need, the timelines involved, and what outcomes you can realistically expect.
What Is the OAIC and What Does It Do?
The Office of the Australian Information Commissioner (OAIC) is Australia's independent national regulator for privacy and freedom of information. It enforces the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs), which govern how most Australian Government agencies and organisations with an annual turnover of more than $3 million handle personal information.
The OAIC has three broad functions relevant to individuals:
- Investigating complaints about interferences with privacy by APP entities, credit reporting bodies, and tax file number recipients.
- Regulating notifiable data breaches under the Notifiable Data Breaches (NDB) scheme.
- Providing guidance to individuals and organisations on privacy rights and obligations.
If you believe your personal information has been collected, used, disclosed, stored, or destroyed improperly, the OAIC is generally the first external body to contact after the organisation itself.
What Counts as a Privacy Breach Under Australian Law?
A privacy breach (formally called an "interference with privacy") occurs when an APP entity handles your personal information in a way that contravenes the Australian Privacy Principles or another rule under the Privacy Act. Personal information includes anything that identifies you or could reasonably identify you — name, address, phone number, email, health records, financial data, IP addresses in some contexts, and even opinions about you.
Common Examples of Privacy Breaches
- A retailer emails a marketing list with all recipients visible in the "To" field, exposing customer email addresses.
- A hospital releases your medical records to a third party without consent.
- A bank refuses to give you access to your own personal information on request.
- A telco updates a debt on your credit file with incorrect information and refuses to fix it.
- A company suffers a cyberattack that exposes your driver's licence and passport details.
- An employer shares your tax file number with an unauthorised party.
Who the Privacy Act Does Not Cover
Before lodging an OAIC complaint, it helps to know the Privacy Act has some notable exceptions:
- Most small businesses with an annual turnover under $3 million (with exceptions for health service providers, credit reporters, and businesses that trade in personal information).
- State and territory government agencies (each state has its own privacy regulator).
- Individuals acting in a purely personal capacity.
- Registered political parties and media organisations engaged in journalism (in defined circumstances).
Step 1: Complain to the Organisation First
Before the OAIC will accept your complaint, you generally must give the organisation a chance to fix the problem. This is a mandatory step under section 40(1A) of the Privacy Act in most cases.
How to Make an Effective Internal Complaint
- Find the right contact. Every APP entity must have a privacy policy identifying how to make a complaint. Search for "[Company name] privacy officer" or "privacy complaints".
- Put it in writing. Email or letter creates a paper trail. Include the date, your contact details, and a clear description of what happened.
- State what you want. An apology, correction of records, deletion of data, compensation for loss, or improved procedures.
- Set a deadline. The OAIC generally expects organisations to respond within 30 days. Reference this timeframe in your letter.
- Keep copies of everything. Screenshots, emails, delivery receipts, and reference numbers.
If the organisation ignores you, refuses to respond, or their response is unsatisfactory after 30 days, you can escalate to the OAIC.
Step 2: How to Lodge an OAIC Complaint
Lodging a complaint with the OAIC is free and can be done entirely online. There are three primary channels.
Available Lodgement Methods
| Method | Best For | Details |
|---|---|---|
| Online form | Most complainants | Available at oaic.gov.au — allows document uploads and generates a reference number instantly. |
| Post | Complex cases with physical evidence | GPO Box 5288, Sydney NSW 2001. Slower but useful for original signed documents. |
| Phone | Accessibility needs or clarification | Enquiries line: 1300 363 992. Staff can assist you to lodge but you'll usually still need to submit in writing. |
What Information You Need to Provide
A well-prepared complaint dramatically improves your chances of a fast, favourable outcome. Include:
- Your full name, address, phone, and email.
- The name of the organisation you're complaining about.
- A clear, chronological description of what happened.
- Which Australian Privacy Principle you believe was breached (if known — APP 6 covers use and disclosure, APP 11 covers security, APP 12 covers access, etc.).
- Copies of your original complaint to the organisation and any response.
- Supporting evidence: emails, screenshots, letters, contracts, breach notification letters.
- The outcome you're seeking.
- Whether you consent to the OAIC disclosing your identity to the respondent (in practice, they usually need to).
Step 3: What Happens After You Lodge
Once your complaint is received, the OAIC follows a structured assessment and conciliation process. It is not a court — the emphasis is on resolving disputes cooperatively.
The OAIC Complaint Process at a Glance
- Acknowledgement (1–2 weeks): You receive a reference number and initial assessment letter.
- Preliminary enquiries: The OAIC may ask you or the respondent for more information to decide whether to investigate.
- Decision to investigate: The Commissioner can decline complaints under section 41 (for example, if the complaint is frivolous, out of time, or better handled elsewhere).
- Conciliation: The OAIC facilitates a resolution between you and the organisation. Most complaints are resolved at this stage.
- Formal investigation: If conciliation fails, the Commissioner may formally investigate under section 40(1).
- Determination: The Commissioner can issue a binding determination, order compensation (including for non-economic loss such as distress), require changes to practices, or issue a public apology.
The process typically takes 6 to 12 months, though complex matters — particularly those involving large data breaches — can take significantly longer.
Special Case: Notifiable Data Breaches
Since February 2018, Australia's Notifiable Data Breaches (NDB) scheme requires APP entities to notify both affected individuals and the OAIC when an "eligible data breach" occurs. An eligible data breach is one likely to result in serious harm and where the organisation cannot prevent that harm through remedial action.
What to Do If You Receive a Breach Notification
- Read carefully. The notice must tell you what information was compromised, likely consequences, and recommended steps.
- Change credentials. Update passwords for the affected service and any account where you reused that password.
- Enable multi-factor authentication everywhere you can.
- Place a credit ban. If financial identifiers were exposed, contact Equifax, Experian, or illion to request a free 21-day credit ban (extendable).
- Monitor your accounts and consider replacing government identifiers (driver's licence, Medicare, passport) if exposed.
- Contact IDCARE (1800 595 160) — Australia's free national identity and cyber support service.
- Complain to the OAIC if you believe the organisation's response was inadequate or the breach was preventable.
How to Strengthen Your Complaint
Not every OAIC complaint succeeds. The strongest complaints share several characteristics.
Evidence That Carries Weight
- Timestamps and metadata: Original emails with full headers are more persuasive than forwarded screenshots.
- Direct impact: Financial loss, identity theft, harassment, or documented psychological distress caused by the breach.
- The organisation's own admissions: Save any email where they concede fault or promise action.
- Comparison to their privacy policy: Quoting the entity's public commitments against their actions is powerful.
Common Reasons Complaints Are Dismissed
- You didn't complain to the organisation first (or didn't wait 30 days).
- The conduct occurred more than 12 months before you complained without good reason.
- The entity is a small business exempt from the Privacy Act.
- The matter is being handled by another body (such as a state privacy commissioner or the AFCA for financial services).
- The complaint concerns employee records (largely exempt in the private sector).
Possible Outcomes and Remedies
The OAIC has broad remedial powers under section 52 of the Privacy Act. Realistic outcomes include:
| Remedy | Description | Frequency |
|---|---|---|
| Apology | Written apology from the organisation | Very common |
| Data correction or deletion | Records amended or destroyed | Common |
| Staff training / policy changes | Systemic improvements at the entity | Common |
| Compensation for financial loss | Reimbursement of quantifiable costs | Occasional |
| Compensation for non-economic loss | Typically $1,000–$20,000 for distress, though larger awards are possible in class-action determinations | Occasional |
| Civil penalties (against the entity) | Up to $50 million or more for serious/repeated breaches — paid to the Commonwealth, not you | Rare, high-profile cases only |
Protecting Your Privacy Going Forward
Making a complaint is a reactive step. Reducing your exposure in the first place is equally important. A few practical habits go a long way:
- Use a password manager and unique passwords for every account.
- Turn on multi-factor authentication, ideally with an authenticator app rather than SMS.
- Give minimum information when signing up for services — organisations can only lose what they collect.
- Use encrypted DNS (such as DNS over HTTPS) and privacy-respecting browsers to reduce passive tracking.
- When sharing links, use a privacy-conscious link management tool like Lunyb to avoid exposing raw destination URLs, tracking parameters, or referrer data. You can read an honest review of Lunyb here, or compare options in our 2026 URL shortener buyer's guide.
- Regularly review app permissions on your phone and revoke ones you don't need.
What If You're Unhappy With the OAIC's Decision?
If the Information Commissioner makes a determination you disagree with, you can apply to the Administrative Review Tribunal (ART, which replaced the AAT in October 2024) for merits review. Applications generally must be lodged within 28 days of the decision. Legal advice is strongly recommended at this stage, and community legal centres can often assist for free.
You may also, in limited circumstances, commence court proceedings — but this is rare for individual privacy matters and usually reserved for class actions following major data breaches.
Frequently Asked Questions
How much does it cost to complain to the OAIC?
Lodging a complaint with the OAIC is completely free. You do not need a lawyer, and there are no filing fees at any stage of the OAIC's own process. Costs may arise only if you later choose to seek merits review at the Administrative Review Tribunal or take separate court action.
How long do I have to lodge a complaint?
The OAIC generally expects complaints to be lodged within 12 months of you becoming aware of the alleged breach. Late complaints can still be accepted if you can show a good reason for the delay, but earlier is always better because evidence and memories fade.
Can I complain anonymously?
You can raise concerns anonymously through the OAIC's enquiries channel, and the Commissioner may use that information to identify systemic issues. However, to have a personal complaint formally investigated and receive individual remedies such as compensation, you will need to identify yourself — and typically consent to the OAIC disclosing your identity to the organisation you're complaining about.
What's the difference between the OAIC and a state privacy commissioner?
The OAIC regulates federal government agencies and private-sector organisations subject to the Privacy Act. State and territory public sector bodies — such as public schools, state hospitals, and local councils — fall under the relevant state or territory privacy commissioner (for example, the IPC in NSW or OVIC in Victoria). If you complain to the wrong body, they will usually redirect you.
Will I actually receive compensation?
Compensation is possible but not guaranteed. Most OAIC complaints resolve through conciliation with non-monetary outcomes such as an apology, corrected records, or process changes. Monetary compensation typically requires evidence of financial loss or documented distress, and awards for individual complaints commonly range from around $1,000 to $20,000, though determinations following major breaches can be much higher.
Should I still complain if the breach seems minor?
Yes. Even small complaints help the OAIC identify systemic problems, and organisations track internal complaints closely. Your report might be one of many that together trigger a broader investigation or industry-wide guidance. Reporting is also the only way to hold entities accountable to the standards they publicly commit to in their privacy policies.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore Online Safety Act 2026: Complete Guide for Businesses & Users
Singapore's Online Safety Act 2026 reshapes how platforms, businesses, and link-sharing services handle harmful content. This complete guide explains who is covered, what the obligations are, penalty risks, and a practical compliance roadmap for organisations operating in Singapore.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a layered privacy landscape spanning PIPEDA, Quebec's Law 25, and provincial statutes. This guide covers consent, breach response, cross-border transfers, and how to build a defensible privacy program in 2026.
UK Data Protection Act vs GDPR Explained: Key Differences for 2026
The UK Data Protection Act 2018 and UK GDPR work together as an integrated framework, not competing regimes. This guide explains the key differences, overlaps, and practical compliance obligations for UK businesses in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A complete step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission. Learn what evidence to gather, how to submit your complaint, what timelines to expect, and how to maximise your chances of a successful outcome under the GDPR.