OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian business or federal government agency has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). The OAIC is the national regulator responsible for enforcing the Privacy Act 1988 and the Australian Privacy Principles (APPs). This guide explains, step by step, how to report a privacy breach, what evidence you need, how long the process takes, and what outcomes you can realistically expect.
What Is the OAIC and When Should You Complain?
The Office of the Australian Information Commissioner (OAIC) is the independent Commonwealth regulator that oversees privacy, freedom of information, and government information policy in Australia. If you believe an organisation covered by the Privacy Act has interfered with your personal information, you can lodge a formal complaint with the OAIC after first raising it with the organisation itself.
You should consider making an OAIC complaint when:
- Your personal information has been collected, used, or disclosed without your consent.
- An organisation has refused to give you access to your own personal information.
- A business will not correct inaccurate data it holds about you.
- Your data has been exposed in a data breach and the entity has not handled it appropriately.
- You suspect unlawful marketing, credit reporting misuse, or misuse of your Tax File Number.
Who Is Covered by the Privacy Act?
The Privacy Act applies to most Australian Government agencies and to private sector organisations with an annual turnover of more than AUD $3 million, as well as certain small businesses (health service providers, credit reporting bodies, businesses that trade in personal information, and contracted service providers for Commonwealth contracts). State and territory government agencies are usually covered by state-based privacy laws instead.
What Counts as a Privacy Breach Under Australian Law?
A privacy breach, sometimes called an "interference with privacy," occurs when an APP entity acts in a way that is inconsistent with the Australian Privacy Principles or another obligation under the Privacy Act. Not every annoyance is a breach — the conduct must involve personal information and fall within the Act's scope.
Common examples of privacy breaches include:
- Unauthorised disclosure: An employee shares your medical records with a third party without consent.
- Data breach: A company database is hacked and your name, address, and identity documents are leaked.
- Excessive collection: A retailer demands your driver's licence to complete a basic purchase.
- Refusal of access: An organisation refuses to show you the personal information it holds about you.
- Direct marketing without consent: You receive marketing emails after unsubscribing multiple times.
- Failure to secure data: Sensitive files are left publicly accessible on a website or cloud bucket.
Notifiable Data Breaches (NDB) Scheme
Since 2018, entities covered by the Privacy Act must notify affected individuals and the OAIC about "eligible data breaches" that are likely to result in serious harm. If you receive such a notification, you can still make a complaint — the NDB scheme does not remove your right to seek a remedy.
Step 1: Complain Directly to the Organisation First
Before the OAIC will investigate, they generally require you to give the organisation a chance to respond. This is a mandatory step in most cases and often resolves the issue faster than a formal regulatory process.
Here is how to raise your concern with the entity:
- Find their privacy contact. Look on their website for a privacy policy — it must include contact details for privacy enquiries.
- Put your complaint in writing. Email or a written letter creates a paper trail. Clearly state what happened, when, and what outcome you want (an apology, deletion of data, compensation, etc.).
- Give them 30 days to respond. This is the standard timeframe the OAIC expects before it will accept a complaint.
- Keep every reply. Save emails, reference numbers, screenshots, and letters. You will need these later.
Step 2: Gather Evidence Before Lodging With the OAIC
Strong complaints are built on documentation. The OAIC handles thousands of matters each year, and clear evidence helps them assess your case quickly.
Try to collect the following before you submit:
- A timeline of events, with dates, times, and names where possible.
- Copies of the organisation's privacy policy at the time of the incident.
- Any notifications, emails, or letters you received about the breach.
- Screenshots of exposed data, marketing messages, or system errors.
- Records of your complaint to the organisation and their reply (or evidence they failed to reply within 30 days).
- Details of any harm suffered — financial loss, identity theft, emotional distress, missed opportunities.
Step 3: Lodge Your Complaint With the OAIC
Once the organisation has had its 30 days, you can lodge a formal complaint. The OAIC offers several ways to do this, and the process is free.
How to Submit
| Method | Best For | Where |
|---|---|---|
| Online form | Most individuals | oaic.gov.au privacy complaint form |
| Post | Sensitive documents or no internet access | GPO Box 5288, Sydney NSW 2001 |
| Attaching evidence files | enquiries@oaic.gov.au | |
| Phone | Initial guidance | 1300 363 992 |
| Interpreter service | Non-English speakers | TIS National 131 450 |
Information the OAIC Will Ask For
- Your full name and contact details.
- The name of the organisation you are complaining about.
- A clear description of what happened and when.
- What steps you have already taken with the organisation.
- What outcome or remedy you are seeking.
- Any supporting documents or evidence.
Step 4: What Happens After You Lodge
Once your complaint is received, the OAIC typically follows a structured assessment and conciliation process rather than a courtroom-style hearing.
- Preliminary assessment: The OAIC checks whether the complaint is within its jurisdiction and whether the organisation has had a chance to respond.
- Early resolution: Many matters are resolved informally — the OAIC contacts the entity, and a fix is negotiated quickly.
- Conciliation: If early resolution fails, a conciliator helps both parties reach a mutually acceptable outcome. This is voluntary but strongly encouraged.
- Investigation: For serious or systemic issues, the Commissioner may formally investigate under section 40 of the Privacy Act.
- Determination: In rare cases the Commissioner issues a binding determination, which can include compensation, an apology, or an order to change practices.
Typical Timeframes
Most straightforward complaints are resolved within 3 to 6 months. Complex investigations, particularly those involving large data breaches or multiple parties, can take 12 months or more. The OAIC publishes performance data in its annual report if you want to check current averages.
Possible Outcomes and Remedies
The OAIC has broad powers to resolve complaints, but it is important to have realistic expectations. It is a regulator, not a court, and its focus is on fixing systemic problems as well as individual harm.
Potential remedies include:
- A written apology from the organisation.
- Correction or deletion of your personal information.
- Changes to the organisation's policies, training, or systems.
- Compensation for financial loss and, in some cases, non-economic loss such as distress or humiliation.
- Public undertakings or enforceable determinations against the entity.
- Civil penalties issued by the Federal Court for serious or repeated interferences with privacy.
What the OAIC Cannot Do
Understanding the limits of the process helps you decide whether to escalate elsewhere.
- The OAIC generally cannot handle complaints about state or territory agencies — use your state privacy commissioner instead.
- It does not deal with employee records held by private employers about their current or former employees.
- It cannot award unlimited damages — outcomes are proportionate and evidence-based.
- It cannot prosecute criminal offences; those are handled by police or the CDPP.
Protecting Yourself After a Breach
While the OAIC handles the regulatory side, you should take practical steps immediately to limit further harm. Data exposed in a breach can circulate for years, so early action matters.
- Change passwords for the affected account and any account that shared the same password. Use a password manager to generate unique credentials.
- Enable multi-factor authentication on email, banking, myGov, and social accounts.
- Place a credit ban with Equifax, Illion, and Experian if identity documents were exposed. A ban is free and lasts 21 days (extendable).
- Monitor bank statements and set up transaction alerts.
- Report identity crime to IDCARE (1800 595 160), Australia's free national identity and cyber support service.
- Reduce your digital footprint going forward — share less, use privacy-focused browsers, and be cautious about which links you click. Tools such as Lunyb allow you to share links without exposing tracking parameters that can reveal your habits or location, which is useful when you are trying to tighten up your online privacy after an incident.
Reducing Future Risk
Long term, the best protection is data minimisation: give organisations only what they truly need. Question requests for ID copies, avoid oversharing on social platforms, and review app permissions regularly. If you manage a website or share links professionally, consider link management platforms that respect user privacy — our 2026 URL shortener buyer's guide compares the leading options on privacy, analytics, and security features.
Special Situations
Complaints About Government Agencies
Federal agencies — including Services Australia, the ATO, and Home Affairs — are all covered. The process is the same, but agencies often have internal review pathways you may want to exhaust first. For state agencies (police, hospitals, schools) use your state's privacy regulator such as the IPC NSW, OVIC Victoria, or OIC Queensland.
Complaints About Credit Reporting
Errors on your credit file are handled under Part IIIA of the Privacy Act. You must first complain to the credit provider or reporting body, then to an external dispute resolution scheme (such as AFCA), and only then, if unresolved, to the OAIC.
Complaints About Overseas Companies
The OAIC can act against overseas entities that carry on business in Australia and collect personal information from Australians — for example, global social media platforms. Jurisdictional questions can slow these matters down, but the Commissioner has successfully taken action against major international companies in recent years.
Tips for a Strong OAIC Complaint
- Be concise. A clear two-page summary is more effective than 50 pages of attachments.
- Stick to facts. Emotional language weakens otherwise strong evidence.
- Reference the APPs where possible (e.g., "This appears to breach APP 6 — use or disclosure").
- State clearly what you want — apology, compensation amount, systemic change.
- Respond promptly to OAIC requests for more information; delays can result in the file being closed.
Frequently Asked Questions
How much does it cost to lodge an OAIC complaint?
Nothing. Lodging a privacy complaint with the OAIC is completely free. You do not need a lawyer, although you can use one if you wish. The conciliation and investigation process is also free of charge.
Is there a time limit for making a complaint?
The OAIC generally expects complaints within 12 months of when you became aware of the issue. Older complaints can still be accepted at the Commissioner's discretion, particularly if there is a good reason for the delay, such as ongoing harm or late discovery of the breach.
Can I get compensation through the OAIC?
Yes, but it is not guaranteed. Compensation is available for financial loss and, in appropriate cases, non-economic loss (such as distress, humiliation, or anxiety). Amounts vary widely — from a few hundred dollars up to tens of thousands in serious cases — and depend on evidence of actual harm.
Can I stay anonymous when complaining?
You can make an initial enquiry anonymously, and the OAIC will offer general advice. However, to formally investigate a complaint the OAIC generally needs to know who you are and share relevant details with the organisation. Your identity is otherwise kept confidential and not made public.
What if I disagree with the OAIC's decision?
If the OAIC declines to investigate or you disagree with a determination, you can seek review by the Administrative Review Tribunal (which replaced the AAT in 2024). For determinations involving compensation, either party can also apply to the Federal Court or Federal Circuit and Family Court to enforce or challenge the decision.
Should I still complain if the organisation has already apologised?
That is your choice. If the apology addresses the harm and the organisation has taken genuine remedial action, further complaint may not be necessary. But if you believe there is a systemic issue, or the response was inadequate, lodging a complaint helps the regulator identify patterns and protect other Australians.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR both protect personal data but differ significantly in consent rules, DPO requirements, penalties, and individual rights. This guide breaks down the key differences so businesses operating across both jurisdictions can build a smart, unified compliance strategy.
Singapore Online Safety Act 2026: Complete Guide for Businesses and Users
Singapore's Online Safety Act 2026 introduces tougher obligations for online platforms, new protections against scams and deepfakes, and stricter penalties reaching 10% of local turnover. This complete guide breaks down who's affected, what's changed, and how to stay compliant.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a layered privacy landscape in 2026, from PIPEDA to Quebec's strict Law 25. This guide breaks down consent, safeguards, breach response, and cross-border transfers into a practical action plan any organization can follow.
UK Online Safety Act: What It Means for Your Privacy in 2026
The UK Online Safety Act reshapes how platforms handle content, age checks and encryption. Here's a plain-English guide to what it really means for your privacy, and the practical steps you can take today to stay in control of your data.