facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··9 min read

If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide walks you through the entire process — from your first contact with the organisation, to lodging a formal OAIC complaint, to understanding what remedies you can expect under the Privacy Act 1988.

What Is the OAIC and When Can You Complain?

The Office of the Australian Information Commissioner (OAIC) is the independent Commonwealth regulator that oversees privacy and freedom of information law in Australia. You can complain to the OAIC when an entity covered by the Privacy Act 1988 has interfered with your personal information in a way that breaches the Australian Privacy Principles (APPs), a registered APP code, or the credit reporting or tax file number rules.

The OAIC handles complaints against:

  • Australian Government agencies
  • Private sector organisations with an annual turnover of more than $3 million
  • All private health service providers, regardless of turnover
  • Small businesses that trade in personal information, are contracted service providers to the Commonwealth, or otherwise opt in
  • Credit reporting bodies and credit providers
  • Tax file number recipients

What Counts as a Privacy Breach?

A privacy breach — technically an "interference with privacy" under the Act — can include:

  • An organisation collecting personal information it didn't need or without a lawful basis
  • Using or disclosing your data for a purpose you didn't agree to
  • Failing to keep your information secure, resulting in a data breach
  • Refusing to give you access to your own personal information
  • Refusing to correct inaccurate information
  • Sending your data overseas without proper safeguards
  • Using government identifiers (like Medicare numbers) improperly

Step 1: Complain to the Organisation First

Before the OAIC will investigate, you must generally give the organisation a chance to respond. This is a strict procedural requirement, not just a suggestion. The OAIC will usually redirect you back if you skip this step.

  1. Locate the privacy officer. Most Australian organisations publish a privacy policy that names a privacy officer or contact email (often privacy@company.com.au).
  2. Write a clear, dated complaint. State what happened, what personal information was involved, when you became aware of the issue, and what you want the organisation to do about it.
  3. Keep records. Save the email, letter, or online form submission along with any acknowledgements you receive.
  4. Wait 30 days. The organisation has a reasonable time — the OAIC generally treats 30 days as the benchmark — to respond substantively.

If the organisation ignores you, refuses to engage, or gives a response you're not satisfied with, you can escalate to the OAIC.

Step 2: Lodge a Complaint With the OAIC

An OAIC complaint is a formal, written request for the Information Commissioner to investigate an interference with your privacy. It's free to lodge and you don't need a lawyer, although complex matters can benefit from legal advice.

How to Submit

You can lodge a complaint through any of these channels:

  • Online form at oaic.gov.au — the fastest and most common method
  • Email to enquiries@oaic.gov.au with a completed privacy complaint form attached
  • Post to GPO Box 5218, Sydney NSW 2001
  • Phone 1300 363 992 if you need help lodging or have accessibility requirements

What to Include in Your Complaint

  1. Your name and contact details
  2. The name of the organisation or agency you're complaining about
  3. A clear description of what happened, in chronological order
  4. The dates the events occurred and when you found out
  5. Copies of your original complaint to the organisation and their response (or evidence they didn't respond)
  6. Any supporting documents: screenshots, emails, letters, contracts, data breach notifications
  7. What you want to resolve the complaint — an apology, correction, compensation, or a change in the organisation's practices

Step 3: What Happens After You Lodge

The OAIC receives thousands of privacy enquiries and complaints each year, so the process can take time. Here's a realistic view of what to expect.

Initial Assessment

The OAIC first assesses whether your complaint is within its jurisdiction and whether it's been properly made. They may contact you for more information or ask you to try resolving the issue with the organisation again if you haven't given them enough time.

Conciliation

Most OAIC complaints are resolved through conciliation — a facilitated negotiation between you and the organisation. The OAIC acts as a neutral intermediary and helps both sides reach a mutually acceptable outcome. Conciliation is confidential and non-binding until an agreement is signed.

Formal Investigation and Determination

If conciliation fails or isn't appropriate, the Commissioner can conduct a formal investigation and issue a determination under section 52 of the Privacy Act. A determination can order the organisation to:

  • Stop the conduct that breached your privacy
  • Take specific steps to prevent recurrence
  • Correct or destroy the information involved
  • Pay compensation for financial loss and non-economic harm (such as distress or humiliation)
  • Apologise formally

Timeline: How Long Does an OAIC Complaint Take?

Timelines vary depending on complexity, but here's a general guide:

StageTypical DurationWhat Happens
Acknowledgement1–4 weeksOAIC confirms receipt and opens a file
Initial assessment1–3 monthsJurisdictional checks and referral back to the organisation if needed
Conciliation3–9 monthsNegotiated resolution attempts
Formal investigation6–18 monthsEvidence gathering, submissions, findings
DeterminationAdd 3–6 monthsWritten decision and orders

Straightforward matters — such as failure to respond to an access request — can be resolved in a few months. Complex disputes involving multiple parties or large data breaches often take a year or more.

Notifiable Data Breaches: A Separate but Related Process

Since February 2018, the Notifiable Data Breaches (NDB) scheme requires covered entities to notify both the OAIC and affected individuals when a data breach is likely to result in serious harm. If you've received a data breach notification and believe the organisation didn't respond appropriately — for example, they delayed notifying you or downplayed the risk — that can itself be the basis of a privacy complaint.

What a Good Breach Notification Looks Like

  • A description of the breach and when it occurred
  • The kinds of personal information involved
  • Recommended steps you should take to protect yourself
  • Contact details for follow-up questions

If a notification is missing these elements, keep it as evidence for your OAIC complaint.

What Compensation Can You Get?

OAIC determinations have awarded compensation ranging from a few hundred dollars for minor distress to tens of thousands for serious breaches involving sensitive information (such as health, financial, or family violence–related data). Class-style representative complaints — where many people are affected by the same conduct — can result in significant collective payouts, particularly following large-scale data breaches at major Australian companies in recent years.

Compensation typically covers:

  • Economic loss — money spent on credit monitoring, identity restoration, or losses from fraud
  • Non-economic loss — distress, embarrassment, anxiety, and loss of dignity
  • Aggravated damages — where the organisation's conduct was particularly egregious

Protecting Yourself Before a Breach Happens

Complaint processes are important, but prevention is easier than remediation. A few habits that reduce your exposure:

  1. Minimise the data you share. Only give organisations information they genuinely need.
  2. Use unique, strong passwords stored in a reputable password manager.
  3. Enable multi-factor authentication on every account that supports it.
  4. Be cautious with links. Shortened URLs from unknown senders can hide phishing pages. Privacy-conscious tools like Lunyb let you preview, control, and revoke shortened links you create so recipients aren't sent somewhere unexpected.
  5. Use encrypted DNS and privacy-focused browsers to reduce passive data collection.
  6. Review your credit report annually through the free channels provided by Australian credit bureaus.

If you manage links or share sensitive documents at work, choosing tooling that respects privacy matters. Our 2026 buyer's guide to URL shorteners compares platforms on privacy and analytics practices, and our honest review of Lunyb covers what to look for.

Alternatives and Complementary Options

Depending on what happened, other regulators may also be relevant:

SituationWhere to Complain
Spam SMS, email, or unlawful marketing callsAustralian Communications and Media Authority (ACMA)
Scams and identity fraudScamwatch and IDCARE
CybercrimeReportCyber (Australian Cyber Security Centre)
Consumer contract or misleading conduct issuesACCC or state fair trading office
Telco privacy issuesTelecommunications Industry Ombudsman (after OAIC in some cases)
State/territory government agency privacyState privacy commissioner (NSW, VIC, QLD, etc.)

Common Mistakes to Avoid

  • Skipping the internal complaint. The OAIC will send you back to the organisation first in most cases.
  • Being vague. "They misused my data" isn't enough — be specific about what, when, and how.
  • Missing the 12-month window. Complaints should generally be made within 12 months of when you became aware of the breach. Late complaints can be declined.
  • Not keeping evidence. Screenshots, emails, and receipts are essential.
  • Demanding unrealistic outcomes. Focus on what will actually resolve the harm — not punitive amounts unlikely to be awarded.

Frequently Asked Questions

How much does it cost to lodge an OAIC complaint?

Lodging a privacy complaint with the OAIC is completely free. You don't need to hire a lawyer, though you can if the matter is complex. The OAIC also provides free assistance if you have accessibility needs or trouble putting your complaint into writing.

Can I complain about a small business?

Generally, small businesses with annual turnover under $3 million aren't covered by the Privacy Act. However, exceptions apply — including private health providers, businesses that trade in personal information, Commonwealth contractors, and businesses that have opted in. If you're unsure, check the OAIC's small business tool or lodge anyway and let them assess jurisdiction.

What if the organisation is based overseas?

The Privacy Act can apply to overseas organisations that carry on business in Australia and collect Australian residents' personal information. The OAIC can and does investigate global companies with an Australian presence, though enforcement against purely foreign entities is harder. Include as much detail as possible about the organisation's Australian activities.

Can I withdraw my complaint later?

Yes. You can withdraw an OAIC complaint at any stage. If you reach a settlement with the organisation directly during conciliation, the complaint is typically closed by agreement. Withdrawing doesn't prevent you from complaining again if the same conduct continues.

What if I disagree with the Commissioner's decision?

You can apply to the Administrative Review Tribunal (ART, formerly the AAT) for review of a determination. Time limits are tight — usually 28 days from receiving the decision — so seek legal advice quickly if you plan to appeal. The organisation you complained about can also seek review, so a favourable determination isn't final until any appeal window closes.

Final Thoughts

The OAIC complaints process is one of the strongest privacy protections available to Australians. It's free, doesn't require a lawyer, and can result in real remedies including apologies, changed practices, and compensation. The most important things are to complain to the organisation first, keep good records, be specific about what happened, and act within 12 months of discovering the breach. With Australian privacy law under active reform and larger penalties on the horizon, organisations are paying closer attention to complaints than ever — which means a well-prepared complaint has a genuine chance of driving change.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles