OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide walks you through the entire process — from your first contact with the organisation, to lodging a formal OAIC complaint, to understanding what remedies you can expect under the Privacy Act 1988.
What Is the OAIC and When Can You Complain?
The Office of the Australian Information Commissioner (OAIC) is the independent Commonwealth regulator that oversees privacy and freedom of information law in Australia. You can complain to the OAIC when an entity covered by the Privacy Act 1988 has interfered with your personal information in a way that breaches the Australian Privacy Principles (APPs), a registered APP code, or the credit reporting or tax file number rules.
The OAIC handles complaints against:
- Australian Government agencies
- Private sector organisations with an annual turnover of more than $3 million
- All private health service providers, regardless of turnover
- Small businesses that trade in personal information, are contracted service providers to the Commonwealth, or otherwise opt in
- Credit reporting bodies and credit providers
- Tax file number recipients
What Counts as a Privacy Breach?
A privacy breach — technically an "interference with privacy" under the Act — can include:
- An organisation collecting personal information it didn't need or without a lawful basis
- Using or disclosing your data for a purpose you didn't agree to
- Failing to keep your information secure, resulting in a data breach
- Refusing to give you access to your own personal information
- Refusing to correct inaccurate information
- Sending your data overseas without proper safeguards
- Using government identifiers (like Medicare numbers) improperly
Step 1: Complain to the Organisation First
Before the OAIC will investigate, you must generally give the organisation a chance to respond. This is a strict procedural requirement, not just a suggestion. The OAIC will usually redirect you back if you skip this step.
- Locate the privacy officer. Most Australian organisations publish a privacy policy that names a privacy officer or contact email (often privacy@company.com.au).
- Write a clear, dated complaint. State what happened, what personal information was involved, when you became aware of the issue, and what you want the organisation to do about it.
- Keep records. Save the email, letter, or online form submission along with any acknowledgements you receive.
- Wait 30 days. The organisation has a reasonable time — the OAIC generally treats 30 days as the benchmark — to respond substantively.
If the organisation ignores you, refuses to engage, or gives a response you're not satisfied with, you can escalate to the OAIC.
Step 2: Lodge a Complaint With the OAIC
An OAIC complaint is a formal, written request for the Information Commissioner to investigate an interference with your privacy. It's free to lodge and you don't need a lawyer, although complex matters can benefit from legal advice.
How to Submit
You can lodge a complaint through any of these channels:
- Online form at oaic.gov.au — the fastest and most common method
- Email to enquiries@oaic.gov.au with a completed privacy complaint form attached
- Post to GPO Box 5218, Sydney NSW 2001
- Phone 1300 363 992 if you need help lodging or have accessibility requirements
What to Include in Your Complaint
- Your name and contact details
- The name of the organisation or agency you're complaining about
- A clear description of what happened, in chronological order
- The dates the events occurred and when you found out
- Copies of your original complaint to the organisation and their response (or evidence they didn't respond)
- Any supporting documents: screenshots, emails, letters, contracts, data breach notifications
- What you want to resolve the complaint — an apology, correction, compensation, or a change in the organisation's practices
Step 3: What Happens After You Lodge
The OAIC receives thousands of privacy enquiries and complaints each year, so the process can take time. Here's a realistic view of what to expect.
Initial Assessment
The OAIC first assesses whether your complaint is within its jurisdiction and whether it's been properly made. They may contact you for more information or ask you to try resolving the issue with the organisation again if you haven't given them enough time.
Conciliation
Most OAIC complaints are resolved through conciliation — a facilitated negotiation between you and the organisation. The OAIC acts as a neutral intermediary and helps both sides reach a mutually acceptable outcome. Conciliation is confidential and non-binding until an agreement is signed.
Formal Investigation and Determination
If conciliation fails or isn't appropriate, the Commissioner can conduct a formal investigation and issue a determination under section 52 of the Privacy Act. A determination can order the organisation to:
- Stop the conduct that breached your privacy
- Take specific steps to prevent recurrence
- Correct or destroy the information involved
- Pay compensation for financial loss and non-economic harm (such as distress or humiliation)
- Apologise formally
Timeline: How Long Does an OAIC Complaint Take?
Timelines vary depending on complexity, but here's a general guide:
| Stage | Typical Duration | What Happens |
|---|---|---|
| Acknowledgement | 1–4 weeks | OAIC confirms receipt and opens a file |
| Initial assessment | 1–3 months | Jurisdictional checks and referral back to the organisation if needed |
| Conciliation | 3–9 months | Negotiated resolution attempts |
| Formal investigation | 6–18 months | Evidence gathering, submissions, findings |
| Determination | Add 3–6 months | Written decision and orders |
Straightforward matters — such as failure to respond to an access request — can be resolved in a few months. Complex disputes involving multiple parties or large data breaches often take a year or more.
Notifiable Data Breaches: A Separate but Related Process
Since February 2018, the Notifiable Data Breaches (NDB) scheme requires covered entities to notify both the OAIC and affected individuals when a data breach is likely to result in serious harm. If you've received a data breach notification and believe the organisation didn't respond appropriately — for example, they delayed notifying you or downplayed the risk — that can itself be the basis of a privacy complaint.
What a Good Breach Notification Looks Like
- A description of the breach and when it occurred
- The kinds of personal information involved
- Recommended steps you should take to protect yourself
- Contact details for follow-up questions
If a notification is missing these elements, keep it as evidence for your OAIC complaint.
What Compensation Can You Get?
OAIC determinations have awarded compensation ranging from a few hundred dollars for minor distress to tens of thousands for serious breaches involving sensitive information (such as health, financial, or family violence–related data). Class-style representative complaints — where many people are affected by the same conduct — can result in significant collective payouts, particularly following large-scale data breaches at major Australian companies in recent years.
Compensation typically covers:
- Economic loss — money spent on credit monitoring, identity restoration, or losses from fraud
- Non-economic loss — distress, embarrassment, anxiety, and loss of dignity
- Aggravated damages — where the organisation's conduct was particularly egregious
Protecting Yourself Before a Breach Happens
Complaint processes are important, but prevention is easier than remediation. A few habits that reduce your exposure:
- Minimise the data you share. Only give organisations information they genuinely need.
- Use unique, strong passwords stored in a reputable password manager.
- Enable multi-factor authentication on every account that supports it.
- Be cautious with links. Shortened URLs from unknown senders can hide phishing pages. Privacy-conscious tools like Lunyb let you preview, control, and revoke shortened links you create so recipients aren't sent somewhere unexpected.
- Use encrypted DNS and privacy-focused browsers to reduce passive data collection.
- Review your credit report annually through the free channels provided by Australian credit bureaus.
If you manage links or share sensitive documents at work, choosing tooling that respects privacy matters. Our 2026 buyer's guide to URL shorteners compares platforms on privacy and analytics practices, and our honest review of Lunyb covers what to look for.
Alternatives and Complementary Options
Depending on what happened, other regulators may also be relevant:
| Situation | Where to Complain |
|---|---|
| Spam SMS, email, or unlawful marketing calls | Australian Communications and Media Authority (ACMA) |
| Scams and identity fraud | Scamwatch and IDCARE |
| Cybercrime | ReportCyber (Australian Cyber Security Centre) |
| Consumer contract or misleading conduct issues | ACCC or state fair trading office |
| Telco privacy issues | Telecommunications Industry Ombudsman (after OAIC in some cases) |
| State/territory government agency privacy | State privacy commissioner (NSW, VIC, QLD, etc.) |
Common Mistakes to Avoid
- Skipping the internal complaint. The OAIC will send you back to the organisation first in most cases.
- Being vague. "They misused my data" isn't enough — be specific about what, when, and how.
- Missing the 12-month window. Complaints should generally be made within 12 months of when you became aware of the breach. Late complaints can be declined.
- Not keeping evidence. Screenshots, emails, and receipts are essential.
- Demanding unrealistic outcomes. Focus on what will actually resolve the harm — not punitive amounts unlikely to be awarded.
Frequently Asked Questions
How much does it cost to lodge an OAIC complaint?
Lodging a privacy complaint with the OAIC is completely free. You don't need to hire a lawyer, though you can if the matter is complex. The OAIC also provides free assistance if you have accessibility needs or trouble putting your complaint into writing.
Can I complain about a small business?
Generally, small businesses with annual turnover under $3 million aren't covered by the Privacy Act. However, exceptions apply — including private health providers, businesses that trade in personal information, Commonwealth contractors, and businesses that have opted in. If you're unsure, check the OAIC's small business tool or lodge anyway and let them assess jurisdiction.
What if the organisation is based overseas?
The Privacy Act can apply to overseas organisations that carry on business in Australia and collect Australian residents' personal information. The OAIC can and does investigate global companies with an Australian presence, though enforcement against purely foreign entities is harder. Include as much detail as possible about the organisation's Australian activities.
Can I withdraw my complaint later?
Yes. You can withdraw an OAIC complaint at any stage. If you reach a settlement with the organisation directly during conciliation, the complaint is typically closed by agreement. Withdrawing doesn't prevent you from complaining again if the same conduct continues.
What if I disagree with the Commissioner's decision?
You can apply to the Administrative Review Tribunal (ART, formerly the AAT) for review of a determination. Time limits are tight — usually 28 days from receiving the decision — so seek legal advice quickly if you plan to appeal. The organisation you complained about can also seek review, so a favourable determination isn't final until any appeal window closes.
Final Thoughts
The OAIC complaints process is one of the strongest privacy protections available to Australians. It's free, doesn't require a lawyer, and can result in real remedies including apologies, changed practices, and compensation. The most important things are to complain to the organisation first, keep good records, be specific about what happened, and act within 12 months of discovering the breach. With Australian privacy law under active reform and larger penalties on the horizon, organisations are paying closer attention to complaints than ever — which means a well-prepared complaint has a genuine chance of driving change.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act reshapes how platforms handle content, age verification, and private messages — with real consequences for your personal data. Here's a plain-English guide to what it means for British internet users and how to protect your privacy in practice.
Data Protection Act 2018 Ireland: Complete Guide for Businesses
A complete guide to Ireland's Data Protection Act 2018, covering scope, individual rights, DPC enforcement powers, penalties, and practical compliance steps for Irish businesses. Learn how the Act works with GDPR and what your organisation needs to do.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 introduces powerful new rights for Australians, including erasure, de-indexing, and the ability to sue for serious privacy breaches. This plain-English guide explains what's changed, what businesses must do, and how to exercise your rights.
GDPR in Ireland: Your Privacy Rights Explained
Ireland enforces some of the strongest data protection laws in the world through the GDPR and the Data Protection Commission. This guide explains your eight core privacy rights, how to file a complaint, and practical steps to safeguard your personal data.