facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If your personal information has been mishandled by an Australian business, government agency or organisation, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). Understanding how to lodge an OAIC complaint about a privacy breach can be the difference between having your concern quietly ignored and forcing a regulated entity to take meaningful action. This guide walks Australians through the process step by step, explaining what qualifies as a breach, how to prepare your evidence and what outcomes you can realistically expect.

What Is the OAIC and What Does It Do?

The Office of the Australian Information Commissioner (OAIC) is Australia's independent national regulator for privacy and freedom of information. It administers the Privacy Act 1988 (Cth) and enforces the 13 Australian Privacy Principles (APPs) that govern how organisations handle personal information.

The OAIC has powers to investigate complaints, conduct assessments, accept enforceable undertakings, seek civil penalties through the Federal Court and issue determinations that can require organisations to pay compensation. Since the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022, penalties for serious or repeated interferences with privacy can reach the greater of A$50 million, three times the benefit obtained from the misuse, or 30% of adjusted turnover during the relevant period.

Who the OAIC Regulates

  • Australian Government agencies
  • Private sector organisations with an annual turnover of more than A$3 million
  • Health service providers of any size
  • Businesses that trade in personal information
  • Credit reporting bodies and credit providers
  • Tax File Number (TFN) recipients

What Counts as a Privacy Breach Under Australian Law?

A privacy breach occurs when personal information is accessed, used, disclosed, lost or altered in a way that is inconsistent with the Australian Privacy Principles or another applicable privacy obligation. Not every mistake is a breach, but many common incidents are.

Common Examples of Privacy Breaches

  • An organisation collects more personal information than it needs (breach of APP 3)
  • Your data is used for marketing without your consent (breach of APP 6 or 7)
  • An email containing customer details is sent to the wrong recipient
  • A database is left publicly accessible on the internet
  • Employees access records they have no legitimate reason to view ("browsing")
  • A company refuses to give you access to, or correct, your own information (breach of APP 12 or 13)
  • Personal data is sent overseas without appropriate safeguards (breach of APP 8)
  • A cyberattack results in customer records being stolen and posted online

Notifiable Data Breaches

Under the Notifiable Data Breaches (NDB) scheme, organisations covered by the Privacy Act must notify affected individuals and the OAIC when a data breach is likely to result in serious harm. If you have received a data breach notification email or letter, that is itself evidence you may be able to use in a complaint if the organisation failed to protect your information.

Before You Complain: Try to Resolve It Directly First

The OAIC will generally not accept a complaint unless you have first raised the issue with the organisation involved and given them a reasonable opportunity to respond — usually 30 days.

Step 1: Complain to the Organisation

  1. Find the organisation's privacy officer or privacy contact (usually listed in their privacy policy).
  2. Put your complaint in writing — email is fine and creates a paper trail.
  3. Clearly describe what happened, when it happened and what personal information was involved.
  4. Explain how the incident has affected you (financial loss, distress, identity theft risk, reputational harm).
  5. State what outcome you want: an apology, deletion of your data, correction, compensation, changes to their practices, or all of these.
  6. Give them a deadline — 30 days is standard and aligns with OAIC expectations.

Step 2: Wait for a Response

The organisation may resolve the matter, offer an explanation you accept, or fail to respond adequately. Keep every reply, including automated acknowledgements. If they refuse to engage, take more than 30 days, or provide an unsatisfactory outcome, you can escalate to the OAIC.

How to Lodge an OAIC Complaint: Step-by-Step

Lodging a complaint with the OAIC is free. You do not need a lawyer, though you can have one. The process is designed to be accessible to ordinary consumers.

Step 1: Gather Your Evidence

Strong complaints are backed by documents. Before you start the form, collect:

  • A clear timeline of events with dates
  • Copies of all correspondence with the organisation
  • Screenshots of relevant web pages, emails, SMS or app notifications
  • Any data breach notification you received
  • Evidence of harm (bank statements, medical letters, credit reports)
  • The organisation's privacy policy at the time of the incident (use the Wayback Machine if it has changed)

Step 2: Complete the Online Complaint Form

Visit oaic.gov.au and select "Make a privacy complaint." You can complete the form online, download a PDF, or request a paper copy. You will need to provide:

  • Your contact details
  • The name and contact details of the organisation you are complaining about
  • A description of the alleged interference with your privacy
  • Copies of your correspondence with the organisation
  • The outcome you are seeking

Step 3: Submit Supporting Documents

Attach your evidence to the form. If you have a large volume of material, the OAIC may request it later, but including key documents up front speeds up assessment.

Step 4: Wait for Acknowledgement and Assessment

The OAIC will acknowledge your complaint, usually within a few business days. An officer will then assess whether it falls within jurisdiction and whether it should be investigated, referred, conciliated or declined.

What Happens After You Lodge a Complaint?

The OAIC has several pathways depending on the complexity and seriousness of the matter. The table below summarises the main outcomes.

PathwayWhat It MeansTypical Timeframe
Early resolutionOAIC contacts the organisation and helps broker a quick outcome1–3 months
ConciliationFormal negotiation between you and the organisation, facilitated by the OAIC3–9 months
InvestigationOAIC formally investigates, may compel documents and issue a determination6–18 months
DeterminationLegally binding decision, can order compensation and changes to practicesEnd of investigation
DeclinedComplaint outside jurisdiction, trivial, vexatious or already dealt withWithin weeks

Possible Remedies

  • A formal apology
  • Correction or deletion of your personal information
  • Financial compensation for economic loss and non-economic loss (hurt, humiliation, distress)
  • An enforceable undertaking requiring the organisation to change its practices
  • Publication of a determination on the OAIC website
  • Referral for civil penalty proceedings in serious cases

Compensation amounts in OAIC determinations have historically ranged from a few hundred dollars to tens of thousands for individuals, and class action-style representative complaints can result in much larger aggregate payouts.

Pros and Cons of Making an OAIC Complaint

Pros

  • Free to lodge — no filing fees or lawyer required
  • Independent regulator with real enforcement powers
  • Can result in compensation and systemic change
  • Written outcomes create precedent and improve industry practice
  • Confidential process — your details are not made public

Cons

  • Can take many months, sometimes over a year
  • Compensation amounts are modest compared with overseas jurisdictions
  • OAIC has limited resources and prioritises systemic issues
  • Some matters (like state government agencies) fall outside its jurisdiction and go to state regulators instead
  • You cannot generally sue directly under the Privacy Act — you must go through the OAIC first

State and Territory Privacy Regulators

The OAIC covers federal agencies and most private sector organisations, but state and territory public sector bodies are covered by separate regulators. If your complaint is about a state school, hospital, police force or council, you may need to contact one of these instead:

JurisdictionRegulator
NSWInformation and Privacy Commission NSW (IPC)
VictoriaOffice of the Victorian Information Commissioner (OVIC)
QueenslandOffice of the Information Commissioner Queensland
Western AustraliaNo general privacy law; complaints go to the relevant agency or Ombudsman
South AustraliaSA Privacy Committee
TasmaniaTasmanian Ombudsman
ACTOAIC (under service arrangement)
Northern TerritoryNT Information Commissioner

How to Reduce Your Risk of a Future Privacy Breach

Complaining after the fact is important, but reducing your exposure in the first place matters more. Simple habits can significantly limit the amount of personal information that ends up in vulnerable third-party databases.

Practical Steps for Australians

  1. Use a separate email address for signups, newsletters and one-off purchases.
  2. Turn on multi-factor authentication for every account that offers it.
  3. Use a password manager and never reuse passwords across services.
  4. Review the permissions on your phone apps every few months.
  5. Request deletion of your data from services you no longer use, using your APP 12 and APP 13 rights.
  6. Use encrypted DNS resolvers and privacy-respecting browsers to reduce tracking.
  7. Be wary of shortened links from unknown senders — use trusted, transparent link shorteners like Lunyb when you need to share URLs, and preview unfamiliar short links before clicking.
  8. Monitor your credit file with Equifax, Experian or illion — free reports are available annually.

If you are researching link-based tools for a small business, our roundup of the best URL shorteners in 2026 outlines which providers respect user data and which harvest it, and our honest review of Lunyb details how a privacy-first approach compares to legacy alternatives like those covered in our Rebrandly review.

Common Mistakes to Avoid When Lodging a Complaint

  • Skipping the internal complaint step. The OAIC will almost always send you back to complain to the organisation first.
  • Being vague. "They mishandled my data" is not enough. Specify which APP you believe was breached and how.
  • Not quantifying harm. Even non-financial harm (anxiety, sleeplessness, embarrassment) should be described.
  • Missing time limits. The OAIC may decline complaints made more than 12 months after you became aware of the issue, unless there is good reason.
  • Emotional language over evidence. Stay factual. Attach documents. Let the paper trail do the talking.

FAQ: OAIC Complaints and Privacy Breaches

How long do I have to make an OAIC complaint?

The OAIC generally expects complaints within 12 months of you becoming aware of the alleged interference with your privacy. Older complaints can still be accepted if there is a reasonable explanation for the delay, such as ongoing concealment by the organisation or continuing harm.

Does it cost anything to complain to the OAIC?

No. Lodging a privacy complaint with the OAIC is free, and you do not need a lawyer. The regulator is designed to be accessible to individual consumers without legal representation.

Can I get compensation for a privacy breach in Australia?

Yes. If your complaint results in a determination or negotiated settlement, you can receive compensation for financial loss, out-of-pocket expenses and non-economic loss such as distress and humiliation. Awards are typically modest compared to overseas jurisdictions but can be significant in serious cases.

What if my complaint is about a state government agency?

State public sector bodies are usually covered by state-based regulators such as the IPC in NSW or OVIC in Victoria, not the OAIC. The OAIC will redirect you if you lodge a complaint outside its jurisdiction, so it is worth checking first.

Can I remain anonymous when complaining?

You can raise concerns anonymously, but formal complaints generally require your identity so that the OAIC and the respondent organisation can investigate properly. Your identity is not made public in the process, and determinations can be de-identified in some cases.

Final Thoughts

Australia's privacy framework is stronger than it has ever been, and the OAIC has increasingly used its enforcement powers against major organisations that mishandle personal information. If you believe your privacy has been breached, do not assume nothing can be done. Complain to the organisation first, keep meticulous records, and escalate to the OAIC if you are not satisfied. Combined with sensible personal privacy habits — strong passwords, minimal data sharing and cautious online behaviour — the complaint process is one of the most effective tools Australians have to hold organisations accountable for how they treat our data.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles