facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··11 min read

If an Australian business, government agency or organisation has mishandled your personal information, you have the right to make a formal complaint to the Office of the Australian Information Commissioner (OAIC). Understanding how the complaints process works — and what evidence to prepare — can make the difference between a complaint that gets resolved and one that stalls. This guide walks you through the entire process, from identifying a privacy breach to escalation and remedies.

What Is the OAIC and What Does It Do?

The Office of the Australian Information Commissioner (OAIC) is the independent Commonwealth regulator responsible for privacy and freedom of information in Australia. It enforces the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs), which govern how personal information is collected, used, stored and disclosed by covered entities.

The OAIC has three core functions relevant to individuals:

  • Investigating complaints from individuals about interference with their privacy.
  • Receiving notifications of eligible data breaches under the Notifiable Data Breaches (NDB) scheme.
  • Regulating and educating organisations about their obligations under Australian privacy law.

If you believe an organisation has breached your privacy — for example, by leaking your data, refusing you access to your own records, or using your information without consent — the OAIC is the primary avenue for redress at the federal level.

What Counts as a Privacy Breach Under Australian Law?

A privacy breach occurs when an organisation covered by the Privacy Act mishandles personal information in a way that contravenes the Australian Privacy Principles. Not every mistake or unwanted contact qualifies as a legal breach, so it helps to understand the scope before lodging a complaint.

Common Examples of Privacy Breaches

  • Unauthorised disclosure of your personal information to a third party.
  • A data breach resulting from a cyberattack, lost device or misdirected email.
  • Collection of information you didn't consent to, or that isn't reasonably necessary.
  • Refusal to give you access to, or correct, personal information the organisation holds about you.
  • Use of your information for direct marketing without a lawful basis or opt-out.
  • Failure to keep personal information reasonably secure.
  • Sending personal data overseas without appropriate safeguards.

Who Is Covered by the Privacy Act?

The Privacy Act generally applies to:

  • Australian Government agencies.
  • Private sector organisations with an annual turnover of more than AUD $3 million.
  • Health service providers of any size.
  • Businesses that trade in personal information, credit providers, and certain small businesses that opt in.

Many small businesses under the $3 million threshold are exempt, which is an important limitation to check before filing. State and territory government agencies are usually covered by state-based privacy laws rather than the OAIC.

Before You Complain: Contact the Organisation First

The OAIC generally will not investigate your complaint unless you have first complained directly to the organisation and given it a reasonable opportunity to respond — usually 30 days. This step is mandatory in most cases and often resolves the issue faster than a formal regulatory process.

How to Complain to the Organisation

  1. Find the privacy officer or privacy contact. Most APP entities must publish a privacy policy that includes contact details for privacy complaints.
  2. Put your complaint in writing. Email is ideal because it creates a timestamped record. Clearly describe what happened, when, and what outcome you want.
  3. Reference the Privacy Act or specific APPs if you can, but plain-English descriptions are also acceptable.
  4. Set a reasonable deadline — 30 days is the standard the OAIC expects.
  5. Keep copies of every message, including bounce-backs and read receipts.

If the organisation refuses to respond, provides an unsatisfactory answer, or ignores you beyond 30 days, you are then in a position to escalate to the OAIC.

How to Lodge an OAIC Complaint: Step-by-Step

An OAIC complaint is a formal request for the Commissioner to investigate an act or practice that may be an interference with your privacy. The process is free, and you do not need a lawyer.

Step 1: Confirm You're Eligible to Complain

You can complain if:

  • The act or practice affected your own personal information (or you are authorised to act on someone else's behalf).
  • The organisation is covered by the Privacy Act.
  • You have complained to the organisation first and given it 30 days to respond.
  • The incident happened recently — the OAIC may decline to investigate complaints made more than 12 months after you became aware of the issue.

Step 2: Gather Your Evidence

Strong complaints are built on documentation. Before filing, collect:

  • Copies of correspondence with the organisation (emails, letters, chat logs).
  • Screenshots of any exposed data, notification emails from the organisation, or online sources.
  • A clear timeline of events, with dates.
  • Any evidence of harm — financial loss, identity theft attempts, emotional distress, or reputational damage.
  • Reference numbers or case IDs the organisation has provided.

Step 3: Complete the OAIC Privacy Complaint Form

Complaints are lodged through the OAIC website using its online privacy complaint form. Alternatives include email, post, or the National Relay Service for people with hearing or speech impairments. Translation services are available.

The form asks for:

  1. Your contact details.
  2. The organisation's name and contact details.
  3. A description of what happened and when.
  4. Evidence of your complaint to the organisation and their response (or lack of one).
  5. The outcome you're seeking — for example, an apology, correction of records, deletion of data, or compensation.

Step 4: Wait for Acknowledgement

The OAIC typically acknowledges complaints within a few business days. It will then assess whether it has jurisdiction and whether the matter is suitable for investigation. Some complaints are declined at this early stage if they fall outside the Privacy Act.

What Happens After You Lodge a Complaint?

Once accepted, the OAIC follows a structured process aimed at resolving matters cooperatively before escalating to formal determinations.

Preliminary Enquiries and Conciliation

The Commissioner will usually contact the organisation, share your complaint, and invite a response. Many complaints are resolved at this stage through conciliation — a facilitated negotiation where both sides propose remedies. Outcomes can include apologies, staff retraining, changes to the organisation's practices, financial compensation, or corrections to your records.

Formal Investigation

If conciliation fails, or the matter is serious, the Commissioner can conduct a formal investigation. This can involve compelling documents, taking evidence, and ultimately issuing a determination under section 52 of the Privacy Act. Determinations may require the organisation to take specific steps, pay compensation, or cease certain conduct.

Typical Timelines

StageTypical Duration
Acknowledgement of complaint1–2 weeks
Initial assessment and jurisdiction check4–8 weeks
Conciliation with the organisation3–6 months
Formal investigation and determination6–18 months

Complex or high-profile matters — such as those involving large-scale data breaches — can take considerably longer.

The Notifiable Data Breaches (NDB) Scheme

Separate from individual complaints, Australia operates a mandatory data breach reporting regime. Under the NDB scheme, APP entities must notify both the OAIC and affected individuals when an eligible data breach occurs — that is, one likely to result in serious harm.

What You Should Receive as an Affected Individual

  • A description of the breach.
  • The kinds of information involved (e.g. name, address, Medicare number, banking details).
  • Recommendations for what you should do — such as changing passwords, monitoring credit, or watching for phishing.
  • Contact details for further information.

If you receive a data breach notification and are unhappy with how the organisation handled the incident, you can still lodge an OAIC complaint. Being notified of a breach does not remove your rights.

Reducing Your Exposure After a Privacy Breach

While you wait for the regulatory process to play out, take practical steps to reduce further harm and tighten your personal data hygiene.

Immediate Actions

  1. Change passwords on affected accounts and any others reusing the same password. Use a password manager.
  2. Enable multi-factor authentication everywhere it's offered.
  3. Place a credit ban with the major Australian credit bureaus if financial data was involved.
  4. Watch for phishing — breached data is often reused in targeted scam messages by phone, SMS and email.
  5. Report identity theft to IDCARE, Australia's national identity and cyber support service.

Longer-Term Habits

  • Minimise how much personal information you share online — provide only what is strictly required.
  • Use encrypted DNS resolvers and privacy-respecting browsers to reduce passive tracking.
  • Be selective about link-tracking tools. When sharing links, choose services that publish clear privacy policies and don't harvest excessive analytics on click-through. Privacy-conscious link shorteners like Lunyb can help keep your sharing habits leaner. For a broader comparison, see our 2026 buyer's guide to URL shorteners.
  • Regularly review app permissions on your phone and revoke ones that no longer make sense.

Possible Outcomes of an OAIC Complaint

The OAIC has a broad remedial toolkit. It rarely imposes headline-grabbing fines on individuals' behalf, but it can secure meaningful outcomes.

RemedyWhat It Means for You
ApologyFormal written acknowledgement of the breach.
Correction or deletionYour personal information is fixed or removed.
Access to recordsYou receive information the organisation previously refused.
CompensationMonetary payment for financial loss, distress or humiliation.
Changes to practicesThe organisation updates policies, systems or staff training.
Enforceable undertakingsLegally binding commitments to improve compliance.

Compensation amounts vary widely and are typically modest — often in the hundreds to low tens of thousands of dollars — depending on the severity of harm and the sensitivity of the information involved.

When the OAIC May Decline to Investigate

The Commissioner has discretion to decline complaints in several circumstances, including where:

  • The complaint is frivolous, vexatious, or lacks substance.
  • You did not first complain to the organisation.
  • The complaint was made more than 12 months after you became aware of the issue.
  • Another body, such as a state privacy commissioner, is better placed to handle it.
  • The matter has already been adequately dealt with.

If your complaint is declined, you may be able to escalate to the Administrative Review Tribunal (which replaced the AAT) or, in some cases, pursue a private right of action under recent Privacy Act reforms.

Tips for a Strong OAIC Complaint

  1. Be specific. Vague complaints get vague responses. State exactly what personal information was involved and how.
  2. Stick to facts. Keep emotional language to a minimum and let the evidence speak.
  3. Quantify harm. Even non-financial harm — anxiety, embarrassment, wasted time — should be described concretely.
  4. Propose a realistic remedy. Ask for something specific, such as deletion of data, an apology and $X in compensation for distress.
  5. Respond promptly to any OAIC requests for further information — delays on your side slow everything down.

Frequently Asked Questions

How much does it cost to lodge an OAIC complaint?

Lodging a privacy complaint with the OAIC is free. You do not need to hire a lawyer, though you can if you wish. The process is designed to be accessible to individuals without legal representation.

Can I complain anonymously?

You can raise concerns anonymously with the OAIC, but a formal complaint that seeks investigation and remedies generally requires your identity so the Commissioner can contact you and the organisation can respond. Your details are handled confidentially.

What if the small business that mishandled my data isn't covered by the Privacy Act?

Small businesses with a turnover under AUD $3 million are often exempt, unless they fall into a special category such as health providers. If the Privacy Act doesn't apply, you may still have options under Australian Consumer Law, defamation law, state-based frameworks, or by reporting scams and identity crime to ScamWatch and IDCARE.

Can I claim compensation for stress caused by a data breach?

Yes. Compensation under the Privacy Act can include amounts for non-economic loss such as distress, humiliation and anxiety, not just direct financial loss. You will need to describe the impact clearly and, ideally, provide supporting evidence such as medical records or a written personal statement.

How long do I have to make a complaint?

You should complain as soon as reasonably possible. The OAIC may decline to investigate complaints made more than 12 months after you became aware of the act or practice. If there is a good reason for the delay — such as only recently discovering the breach — explain it clearly in your complaint.

Final Thoughts

Making an OAIC complaint is one of the most effective tools Australians have to hold organisations accountable for mishandling personal information. The process rewards preparation: complain to the organisation first, document everything, be specific about the harm, and propose a concrete remedy. Combined with sensible personal privacy habits — strong authentication, minimal data sharing, and careful choice of the tools you use to share information online — a well-crafted complaint can drive real change, not just for you but for future customers of the organisation involved.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles