OAIC Complaints: How to Report a Privacy Breach in Australia
If your personal information has been mishandled by an Australian business or government agency, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide explains exactly how the OAIC complaints process works, when to use it, what evidence to gather, and how to maximise your chances of a favourable outcome.
What Is the OAIC and What Does It Regulate?
The Office of the Australian Information Commissioner (OAIC) is Australia's independent national privacy regulator. It enforces the Privacy Act 1988 (Cth), including the 13 Australian Privacy Principles (APPs), the Notifiable Data Breaches (NDB) scheme, and the Consumer Data Right (CDR) privacy safeguards.
The OAIC has jurisdiction over:
- Australian Government agencies (including most federal departments)
- Private-sector organisations with an annual turnover above A$3 million
- Smaller businesses that trade in personal information, provide health services, or contract to the Commonwealth
- Credit reporting bodies and credit providers
- Tax File Number (TFN) recipients
State and territory government agencies are generally handled by state privacy regulators (for example, the IPC in NSW or OVIC in Victoria), not the OAIC.
What Counts as a Privacy Breach Under Australian Law?
A privacy breach occurs when personal information is collected, used, disclosed, stored, or accessed in a way that contravenes the Australian Privacy Principles or another obligation under the Privacy Act. Common examples include:
- An organisation losing or leaking your data through a cyber incident
- A company disclosing your details to a third party without consent
- Refusal to give you access to, or correct, your personal information
- Collecting more personal information than is reasonably necessary
- Sending direct marketing after you opted out
- Mishandling of Tax File Numbers or health information
Not every mistake is a legal breach. The OAIC assesses whether the entity's conduct actually breached the Privacy Act, and whether the organisation has already taken reasonable steps to resolve the issue.
Step 1: Complain to the Organisation First
Before the OAIC will accept your complaint, you generally must give the organisation an opportunity to respond. This is a mandatory prerequisite under section 40 of the Privacy Act.
- Identify the right contact. Most APP entities must publish a privacy policy naming a privacy officer or complaints contact.
- Put your complaint in writing. Email is ideal because it creates a timestamped record.
- Describe the issue clearly. Include dates, the information involved, and what outcome you want (an apology, correction, deletion, compensation, or process changes).
- Give them 30 days to respond. This is the standard window the OAIC expects before escalation.
- Keep every reply. Save emails, letters, reference numbers and screenshots.
If the organisation ignores you, refuses to engage, or gives an inadequate response after 30 days, you can escalate to the OAIC.
Step 2: Prepare Your Evidence Bundle
The stronger your documentation, the faster the OAIC can assess your complaint. Prepare the following before lodging:
- Your identity details — full name, contact details, and any account/customer reference numbers
- The respondent's details — the exact legal name of the organisation and the office you dealt with
- A chronology — dated timeline of what happened, in plain language
- The APPs you believe were breached — optional but persuasive (for example APP 6 – use and disclosure, APP 11 – security, APP 12 – access)
- Copies of correspondence — your complaint to the organisation and their response
- Supporting evidence — emails, screenshots, letters, breach notifications, marketing messages, call logs
- The harm suffered — financial loss, identity theft risk, distress, reputational damage
- The outcome you seek — be specific and realistic
Step 3: Lodge Your Complaint With the OAIC
You can lodge a privacy complaint using the OAIC's online form at oaic.gov.au, by post, or by phone if you need accessibility support. There is no fee.
Online lodgement
The online form walks you through personal details, the organisation involved, what happened, and evidence upload. It usually takes 20–40 minutes if your evidence is organised.
Time limits
There is no strict statutory deadline, but the OAIC may decline complaints made more than 12 months after you became aware of the conduct. Lodge as soon as reasonably possible.
Language and accessibility
The OAIC provides interpreters through TIS National and offers the National Relay Service for people who are deaf or have a hearing or speech impairment.
What Happens After You Lodge?
The OAIC follows a structured process designed to resolve most complaints through conciliation rather than formal determination.
| Stage | What Happens | Typical Timeframe |
|---|---|---|
| Acknowledgement | OAIC confirms receipt and assigns a reference number | 1–2 weeks |
| Early assessment | Officer checks jurisdiction, timeliness and whether you complained to the entity first | 4–8 weeks |
| Preliminary inquiries | OAIC asks the organisation for a response and your reply | 1–3 months |
| Conciliation | Parties negotiate an outcome with OAIC assistance | 2–6 months |
| Investigation / determination | Formal investigation and binding determination if conciliation fails | 6–18 months |
Most complaints (over 80%) are resolved without a formal determination. Common remedies include apologies, staff training, policy changes, correction or deletion of records, and compensation payments.
Notifiable Data Breaches: A Special Category
If you have been notified of a data breach under the NDB scheme, you already have written evidence that an eligible data breach occurred. This significantly strengthens any complaint.
Under the NDB scheme, organisations covered by the Privacy Act must notify affected individuals and the OAIC when a data breach is likely to result in serious harm. The notification must include:
- A description of the breach
- The kinds of information involved
- Recommended steps you should take
If you received such a notice and believe the organisation's security was inadequate (APP 11), or the notification was late or incomplete, you can complain to the OAIC.
Reducing Your Exposure While a Complaint Is Underway
A complaint can take months. In the meantime, take practical steps to limit further harm.
- Change compromised passwords and enable multi-factor authentication on important accounts.
- Place a credit ban with Equifax, Illion and Experian if financial identifiers were exposed. Bans are free and last 21 days (extendable).
- Report identity crime to IDCARE (1800 595 160) for a free tailored response plan.
- Watch for phishing. Breach victims are prime targets for follow-up scams. Never click unexpected links; hover to preview the destination.
- Use safer link tools. When sharing sensitive links or receiving suspicious ones, a privacy-first link checker and shortener such as Lunyb lets you preview and manage destinations without leaking metadata to third-party trackers.
- Lock down your browser. Use encrypted DNS (DoH), a hardened browser profile and reputable anti-tracking extensions.
For more on evaluating link tools and their privacy posture, see our 2026 buyer's guide to URL shorteners and our honest review of Lunyb.
Outcomes the OAIC Can Order
If a complaint proceeds to a formal determination under section 52 of the Privacy Act, the Commissioner can:
- Declare that the respondent engaged in conduct that breached the Privacy Act
- Require the respondent to take steps to prevent a repeat
- Require the correction or destruction of records
- Require an apology
- Award compensation for economic and non-economic loss (including for hurt feelings and humiliation)
- Order reimbursement of reasonable expenses
Compensation amounts in individual privacy determinations have historically ranged from a few thousand dollars to tens of thousands, depending on the severity of harm. Large-scale representative complaints can result in significantly higher aggregate awards.
When the OAIC May Decline Your Complaint
Section 41 of the Privacy Act lets the Commissioner decide not to investigate. Common reasons include:
- You did not first complain to the organisation
- The complaint is more than 12 months old without a good reason
- The conduct is not an interference with privacy
- The complaint is frivolous, vexatious, or lacking in substance
- Another regulator (for example, a state privacy commissioner, the ACCC, or ASIC) is a better fit
- The organisation has adequately dealt with the complaint
If your complaint is declined, you can request internal review or, in limited circumstances, seek review by the Administrative Review Tribunal.
Representative and Class Complaints
Where a data breach affects many people, the OAIC accepts representative complaints on behalf of a class. This is common after large breaches involving telcos, health insurers, retailers and government agencies. Individuals affected are usually opted-in automatically or invited to register interest through the OAIC website and law firms running parallel proceedings.
Joining a representative complaint is typically free and does not prevent you from continuing an individual complaint on separate issues.
Practical Tips to Strengthen Your Complaint
- Be factual, not emotional. The OAIC weighs evidence, not adjectives.
- Quantify the harm. "I received 47 scam SMS messages in the fortnight after the breach" is stronger than "lots of scams."
- Cite the APPs. If you can identify APP 6, 11 or 12, do so.
- Propose a reasonable remedy. Modest, specific remedies settle faster than open-ended demands.
- Respond promptly. Delays on your side can lead the OAIC to close a matter.
- Keep records in one folder. A single indexed PDF is more persuasive than scattered emails.
Frequently Asked Questions
How much does it cost to complain to the OAIC?
Nothing. Lodging and pursuing a privacy complaint with the OAIC is free. You do not need a lawyer, though you may choose to engage one for complex matters or to help calculate compensation.
How long does an OAIC privacy complaint take?
Simple complaints that settle at conciliation typically take 3–6 months. Complex investigations resulting in a determination can take 12–24 months. The OAIC publishes performance metrics annually.
Can I complain about a data breach if I have not suffered financial loss?
Yes. The Privacy Act recognises non-economic harm, including anxiety, distress, humiliation and loss of control over your information. You can claim compensation for these even without a direct financial loss.
What is the difference between an OAIC complaint and reporting a scam?
An OAIC complaint targets the organisation that mishandled your data. Scam reports go to Scamwatch, ReportCyber (cyber.gov.au) or the AFP. If your data was breached and then used by scammers, you may need to lodge with both.
Can I complain about a foreign company that leaked my data?
Sometimes. The Privacy Act can apply to overseas organisations that carry on business in Australia and collect or hold personal information here. The OAIC will assess jurisdiction on the facts. If jurisdiction is unclear, it may refer you to an equivalent overseas regulator.
Final Thoughts
The OAIC complaints process is one of the few free, individual-focused enforcement pathways in Australian consumer regulation. It works best when you complain to the organisation first, keep meticulous records, and articulate a specific remedy. Combine that with sensible personal security habits — strong passwords, MFA, encrypted DNS, credit bans where warranted, and privacy-respecting tools for everyday tasks like link sharing — and you will both maximise your recovery and reduce the chance of being harmed again.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation gives people in Ireland powerful rights over their personal data. This guide explains what those rights are, how the Data Protection Commission enforces them, and the practical steps you can take to protect your privacy online.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 gives Australians stronger rights over their personal information, including the right to erasure, a direct right to sue for serious privacy invasions, and enhanced protections for children. This guide explains what's changed, who's covered, and what individuals and businesses need to do now.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a rapidly evolving privacy landscape in 2026, from PIPEDA and Quebec's Law 25 to the anticipated CPPA. This guide covers the laws that apply, common compliance mistakes, and a practical framework for building a defensible data privacy program.
Singapore PDPA vs GDPR: Key Differences Every Business Must Know
Singapore's PDPA and the EU's GDPR both protect personal data, but differ sharply in scope, consent, penalties, and breach rules. This guide compares the two laws side-by-side and shows Singapore businesses how to build a unified compliance strategy.