facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If an Australian business, agency or organisation has mishandled your personal information, you have the right to lodge a formal complaint with the Office of the Australian Information Commissioner (OAIC). This guide explains exactly how to report a privacy breach, what evidence you need, how long the process takes, and what outcomes you can realistically expect.

What Is the OAIC?

The Office of the Australian Information Commissioner (OAIC) is the independent federal regulator responsible for enforcing the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs). It investigates complaints against APP entities — most Australian Government agencies, private-sector organisations with an annual turnover above AU$3 million, health service providers, credit reporting bodies, and some small businesses that trade in personal information.

The OAIC has powers to conciliate disputes, make determinations, issue infringement notices, seek civil penalties through the Federal Court, and require organisations to change their practices. Since the Notifiable Data Breaches (NDB) scheme commenced in February 2018, it also oversees mandatory breach notifications for eligible data breaches.

What Counts as a Privacy Breach?

A privacy breach occurs when personal information is collected, used, disclosed, stored or destroyed in a way that contravenes the Australian Privacy Principles or another provision of the Privacy Act. Common examples include:

  • An organisation collecting more personal data than reasonably necessary for its stated function.
  • Using your data for a secondary purpose you never consented to (for example, selling contact details to a marketing partner).
  • Disclosing your information to a third party without lawful basis.
  • Failing to secure records, resulting in unauthorised access, loss or leakage.
  • Refusing a reasonable request to access or correct your personal information.
  • Sending marketing communications after you opted out.
  • Retaining data beyond the period allowed under APP 11.2.

Not every mistake amounts to a breach worth escalating — but if the conduct has caused you distress, financial harm, reputational damage, or an increased risk of identity fraud, an OAIC complaint is a legitimate remedy.

Before You Complain: The Mandatory First Step

The OAIC will almost always refuse to investigate until you have complained directly to the organisation first and given them a reasonable opportunity to respond — usually 30 days. This is a statutory expectation under section 40(1A) of the Privacy Act.

How to Complain to the Organisation

  1. Find the Privacy Officer. Every APP entity must publish a privacy policy naming a contact point. Check the organisation's website footer or privacy page.
  2. Put it in writing. Email is best because it creates a timestamped record. Clearly label the message "Formal Privacy Complaint".
  3. Describe the incident factually. Include dates, the personal information involved, who did what, and how you found out.
  4. State the outcome you want. This could be an apology, deletion of your data, correction of a record, compensation, or a change in the organisation's procedures.
  5. Set a response deadline. Thirty days from the date they receive your complaint is the accepted benchmark.
  6. Keep copies of everything. Save the original email, any read receipts, and every reply.

If the organisation ignores you, responds inadequately, or the 30 days lapse without a satisfactory outcome, you can escalate to the OAIC.

How to Lodge an OAIC Complaint: Step by Step

Lodging a complaint with the OAIC is free and can be done entirely online. The process typically takes 20 to 40 minutes if you have your documents ready.

Step 1: Gather Your Evidence

Before you start the form, collect:

  • Your full name, contact details and preferred method of contact.
  • The full legal name of the organisation (as shown on ASIC or their privacy policy).
  • A chronological summary of what happened, with dates.
  • Copies of your complaint to the organisation and their response (or proof that no response was received).
  • Any supporting documents — screenshots, emails, letters, breach notification notices, medical records showing distress, or evidence of financial loss.
  • A clear statement of the remedy you are seeking.

Step 2: Complete the Online Complaint Form

Go to oaic.gov.au and select "Privacy complaint". The online form walks you through each section: complainant details, respondent details, description of the breach, prior contact with the organisation, supporting documents and desired outcome. You can also lodge by post or, if you have a disability or language barrier, by phone on 1300 363 992.

Step 3: Submit and Receive Acknowledgement

The OAIC generally sends an acknowledgement within 10 business days, along with a reference number. Keep this number for all future correspondence.

Step 4: Preliminary Assessment

An OAIC officer reviews the complaint to check jurisdiction, whether you complained to the organisation first, and whether the matter has merit. They may ask for more information or clarification.

Step 5: Conciliation

Most complaints (around 70%) are resolved through conciliation — an informal negotiation facilitated by the OAIC. You and the organisation exchange positions and, ideally, reach a mutually acceptable outcome such as an apology, compensation or a corrective action.

Step 6: Investigation and Determination

If conciliation fails and the Commissioner considers the matter serious, a formal investigation may be opened under section 40 of the Privacy Act. This can result in a binding determination requiring the organisation to take specific steps, pay compensation, or refrain from repeating the conduct.

Timeframes: How Long Does It Take?

OAIC complaint timelines vary considerably depending on complexity, cooperation from the respondent and the OAIC's caseload.

StageTypical Duration
Complaint to organisation (mandatory first step)30 days
OAIC acknowledgementUp to 10 business days
Preliminary assessment4–8 weeks
Conciliation3–6 months
Formal investigation and determination6–18 months
Total end-to-end (contested matters)Often 12+ months

What Outcomes Can You Realistically Expect?

The OAIC cannot fine you personally, order criminal charges or force an organisation into liquidation. Its remedies focus on restoration, correction and, where warranted, monetary compensation.

  • Written apology — the most common outcome in conciliation.
  • Correction or deletion of records under APP 13.
  • Procedural change — the organisation updates staff training, technology or policies.
  • Compensation — typically AU$1,000–$20,000 for non-economic loss such as distress, though determinations have gone significantly higher for egregious breaches.
  • Civil penalties — for serious or repeated interferences with privacy, the OAIC may seek Federal Court orders. Since December 2022, maximum penalties for corporations are the greater of AU$50 million, three times the benefit obtained, or 30% of adjusted turnover.

The Notifiable Data Breaches (NDB) Scheme

Separate from individual complaints, the NDB scheme requires APP entities to notify both the OAIC and affected individuals when an "eligible data breach" occurs — that is, unauthorised access, disclosure or loss of personal information likely to result in serious harm. If you have received a data breach notification letter and are dissatisfied with the organisation's response, this is a strong basis for a formal complaint.

You can also check the OAIC's quarterly NDB statistics reports, which publicly track sectors and causes. Health service providers, finance, and Australian Government agencies have consistently topped the list for reported breaches.

Protecting Your Privacy While a Complaint Is on Foot

A complaint doesn't undo the breach — your data may already be in circulation. Sensible protective steps include:

  • Placing a credit ban with Equifax, illion and Experian if financial data was exposed.
  • Enabling multi-factor authentication on all critical accounts.
  • Using unique, strong passwords via a reputable password manager.
  • Switching to an encrypted DNS resolver and a privacy-respecting browser to reduce future data leakage.
  • Being cautious with the links you click and share. If you regularly share links (for work, community groups or marketing), a privacy-conscious link shortener such as Lunyb lets you control redirects, monitor analytics and revoke compromised URLs — see our honest review of Lunyb or compare it against the market in our 2026 buyer's guide.

Common Mistakes That Weaken OAIC Complaints

Several avoidable errors regularly lead to complaints being dismissed or under-compensated:

  1. Skipping the organisation-first step. The OAIC will bounce your complaint back.
  2. Complaining outside jurisdiction. State government agencies (except in the ACT and Norfolk Island), most small businesses under AU$3 million turnover, and registered political parties are generally exempt.
  3. Emotional rather than evidentiary language. Stick to facts and documents.
  4. No articulation of harm. Compensation depends on demonstrable distress, financial loss or risk. Vague grievances rarely attract awards.
  5. Delaying too long. The OAIC may decline complaints lodged more than 12 months after you became aware of the conduct.
  6. Overstating the remedy. Asking for AU$500,000 for a marketing email received twice damages your credibility.

When to Get Legal Advice

OAIC complaints don't require a lawyer, and most complainants handle them unassisted. However, professional advice is worth considering when:

  • The breach involves sensitive information (health, sexuality, criminal record, biometric data).
  • Financial loss exceeds a few thousand dollars.
  • The respondent is a large corporation with in-house legal representation.
  • You are considering a representative (class) complaint under section 38.
  • The matter may progress to the Federal Court or Administrative Review Tribunal.

Community legal centres, Legal Aid in your state, and the Australian Privacy Foundation can often provide free initial guidance.

Alternatives and Escalation Paths

Depending on the nature of your issue, other regulators may also be appropriate — sometimes in parallel with the OAIC:

  • Australian Communications and Media Authority (ACMA) — spam, unsolicited marketing calls, Do Not Call Register breaches.
  • Australian Financial Complaints Authority (AFCA) — banks, insurers, superannuation and credit providers.
  • Telecommunications Industry Ombudsman (TIO) — phone and internet providers.
  • State-based privacy commissioners — NSW, Victoria, Queensland and the Northern Territory have their own regulators for state agencies.
  • Australian Cyber Security Centre (ACSC) — reporting cybercrime via ReportCyber.

Frequently Asked Questions

How much does it cost to lodge an OAIC complaint?

Nothing. Lodging a privacy complaint with the OAIC is entirely free, whether you submit online, by post or by phone. There are no filing fees, no hearing fees and no adverse cost orders against unsuccessful complainants.

Can I complain anonymously?

You can raise concerns anonymously, but the OAIC generally cannot investigate a formal complaint without knowing who you are, because it needs to correspond with you, verify the facts and — if compensation is awarded — pay it to someone. You can, however, request that your identity not be disclosed to the respondent in limited circumstances.

What if the organisation is based overseas?

The Privacy Act has extraterritorial reach under section 5B. Foreign organisations that carry on business in Australia and collect personal information here are covered — this includes major overseas cloud providers, social networks and e-commerce platforms. Enforcement is more complex, but the OAIC has successfully pursued global companies.

How long do I have to lodge a complaint?

There is no strict statute of limitations, but under section 41 the Commissioner may decline to investigate a complaint made more than 12 months after you became aware of the act or practice complained about. Lodge as soon as reasonably possible.

Will making a complaint affect my relationship with the organisation?

The Privacy Act prohibits victimisation. However, in practice, ongoing commercial or service relationships can become strained. If you are worried about retaliation — for instance, from an employer or health provider — mention this in your complaint so the OAIC can factor it into how the matter is handled.

Final Thoughts

Reporting a privacy breach to the OAIC is one of the strongest consumer protections available under Australian law. The process rewards preparation: complain to the organisation first, document everything, quantify your harm, and be realistic about outcomes. Even where compensation is modest, a successful complaint can force meaningful procedural change — and Australia's privacy regulator has become considerably more assertive since the 2022 penalty reforms. Treat your personal information as an asset worth defending, and use the mechanisms Parliament built for exactly this purpose.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles