OAIC Complaints: How to Report a Privacy Breach in Australia
If your personal information has been mishandled by an Australian organisation, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). The OAIC is the national regulator responsible for enforcing the Privacy Act 1988 and the Australian Privacy Principles (APPs). This guide explains exactly how to report a privacy breach, what evidence you need, how long the process takes, and what remedies you can realistically expect.
What Is the OAIC and When Can You Complain?
The OAIC (Office of the Australian Information Commissioner) is Australia's independent privacy and freedom-of-information regulator. It investigates complaints against most Australian Government agencies and private-sector organisations with an annual turnover of more than A$3 million, as well as some smaller businesses that handle sensitive information (such as health service providers).
You can lodge a complaint with the OAIC when you believe an entity covered by the Privacy Act has:
- Collected personal information unfairly or without consent
- Used or disclosed your data for a purpose you did not agree to
- Failed to keep your personal information secure, leading to a data breach
- Refused to give you access to, or correct, your own personal information
- Sent unwanted direct marketing without a valid opt-out
- Sent personal data overseas without appropriate safeguards
Who the OAIC Cannot Help With
The OAIC generally does not handle complaints about state or territory government agencies (these have their own privacy commissioners), small businesses under the A$3 million threshold that are not otherwise covered, employee records handled by an employer, or media organisations acting in the course of journalism.
Step 1: Complain to the Organisation First
Before the OAIC will investigate, you must give the organisation a reasonable opportunity to respond — usually 30 days. This is a mandatory step under section 40 of the Privacy Act, and skipping it is the most common reason complaints get bounced back.
- Find the privacy officer. Every APP entity must publish a privacy policy that includes contact details for privacy complaints.
- Put your complaint in writing. Email is fine. Clearly describe what happened, when, and what you want the organisation to do.
- Set a deadline. Ask for a written response within 30 days.
- Keep copies of everything. Save emails, screenshots, letters and any acknowledgement numbers.
If the organisation does not respond within 30 days, gives you an inadequate response, or refuses to fix the problem, you can then escalate to the OAIC.
Step 2: Gather Your Evidence
The strength of your OAIC complaint depends almost entirely on the quality of evidence you provide. The Commissioner cannot compel information from an organisation on speculation alone.
Documents to Collect
- A timeline of events with specific dates and times
- Copies of the organisation's privacy policy at the time of the breach (use the Wayback Machine if it has changed)
- All correspondence between you and the organisation
- Screenshots of the exposed data, breach notification emails, or media reports
- Evidence of any harm suffered — financial loss, identity theft reports, medical records for stress-related conditions, or missed opportunities
- Details of any third parties who received your information without consent
Documenting Harm
The OAIC can award compensation for both economic and non-economic loss (including humiliation and injury to feelings). Even if you cannot quantify a dollar figure, describe the impact in concrete terms: hours spent changing passwords, anxiety about identity fraud, damage to reputation, or costs of credit monitoring services.
Step 3: Lodge Your Complaint With the OAIC
Complaints can be lodged online, by post, or by phone. The online form at oaic.gov.au is the fastest route and gives you an immediate reference number.
Information You Will Need to Provide
- Your full name and contact details
- The name of the organisation you are complaining about
- A clear description of what happened, in chronological order
- Evidence that you complained to the organisation and their response (or lack of response)
- What outcome you are seeking — apology, correction, compensation, or systemic change
- Any supporting documents attached as PDFs or images
Time Limits
You should generally lodge your complaint within 12 months of becoming aware of the alleged breach. The Commissioner has discretion to accept late complaints where there are good reasons, but the fresher the evidence, the better your chances.
Step 4: What Happens After You Lodge
Once your complaint is received, the OAIC follows a structured assessment and conciliation process. Understanding each stage helps you manage expectations.
| Stage | Typical Duration | What Happens |
|---|---|---|
| Preliminary assessment | 2–6 weeks | OAIC checks jurisdiction, completeness and whether you complained to the organisation first. |
| Early resolution | 1–3 months | Informal contact with the respondent to seek a quick fix. |
| Conciliation | 3–9 months | Formal negotiated settlement facilitated by the OAIC. |
| Investigation and determination | 6–18 months | Where conciliation fails, the Commissioner may make a binding determination under s 52. |
| Review or enforcement | Varies | Either party can seek review at the Administrative Review Tribunal, or the Commissioner can enforce in the Federal Court. |
Possible Outcomes and Remedies
The OAIC has broad remedial powers. A determination under section 52 of the Privacy Act can require the organisation to:
- Stop the conduct that breached the APPs
- Take specific steps to redress loss or damage
- Pay compensation for economic loss (out-of-pocket costs)
- Pay compensation for non-economic loss (stress, humiliation, injury to feelings) — typically A$3,000 to A$20,000 in individual cases, though larger amounts are possible
- Issue an apology
- Change internal policies, staff training, or security controls
Class Actions and Representative Complaints
Where a breach affects many people — as with the Optus, Medibank and Latitude incidents — the OAIC can accept a representative complaint on behalf of a group. Following 2022 amendments, the maximum civil penalty for serious or repeated interferences with privacy is now the greater of A$50 million, three times the benefit obtained, or 30% of adjusted turnover.
Notifiable Data Breaches: The Organisation's Side
Since February 2018, the Notifiable Data Breaches (NDB) scheme requires APP entities to notify the OAIC and affected individuals of any "eligible data breach" likely to result in serious harm. If you have received a data breach notification, you have already met most of the evidential threshold for a complaint.
What a Compliant Breach Notification Must Contain
- The identity and contact details of the organisation
- A description of the breach
- The kinds of information involved
- Recommendations about the steps individuals should take in response
If the notification you received was vague, late (more than 30 days after the entity became aware), or omitted key information, that itself can form part of your complaint.
Protecting Yourself While the Complaint Is Pending
OAIC investigations can take many months. In the meantime, you should take practical steps to limit further harm from the breach.
- Change passwords on any account that shared the exposed credentials, and enable multi-factor authentication.
- Place a credit ban with Equifax, Experian and illion — this is free in Australia and prevents new credit being opened in your name.
- Replace compromised identity documents such as your driver's licence or Medicare card where the state or federal issuer offers reissue programs.
- Watch for phishing. Attackers often exploit publicised breaches with targeted scam emails and SMS.
- Limit what you share going forward. When sharing links or files, use tools that give you control over expiry and access — for example, a privacy-respecting link shortener like Lunyb lets you rotate or disable links if a channel is later compromised.
For a broader view of secure link tooling options, our 2026 URL shortener buyer's guide compares the main providers on security, tracking and compliance features.
Common Mistakes That Weaken Complaints
Even valid complaints fail when procedural or evidential basics are missed. Avoid these pitfalls:
- Skipping the organisation. The OAIC will almost always refer you back to complain internally first.
- Emotional rather than factual framing. Stick to what happened, what breached which APP, and what harm resulted.
- Missing the 12-month window without a good explanation for the delay.
- Naming the wrong entity — a subsidiary or franchisee may not be the responsible APP entity.
- No evidence of harm. While technical breaches can succeed, remedies are far stronger when tangible harm is documented.
Alternative and Complementary Avenues
An OAIC complaint is not always the only or best remedy. Depending on the facts, you might also consider:
- Australian Financial Complaints Authority (AFCA) for privacy breaches involving banks, insurers or superannuation funds — often faster and can award binding compensation up to A$1.2 million.
- Telecommunications Industry Ombudsman (TIO) for telco data breaches.
- State or territory privacy commissioners where a state agency is involved (for example, the NSW IPC or OVIC in Victoria).
- Direct action in the Federal Court once amendments creating a statutory tort of serious invasion of privacy commence.
- Reporting to the ACCC where the conduct also involves misleading representations about data handling.
Frequently Asked Questions
How much does it cost to lodge an OAIC complaint?
Nothing. Lodging a privacy complaint with the OAIC is completely free, and you do not need a lawyer. The Commissioner runs an inquisitorial rather than adversarial process, so you are not expected to argue the case like a court hearing.
How long does an OAIC investigation take?
Most matters resolve within 3 to 12 months through early resolution or conciliation. Complex cases that proceed to a formal section 52 determination can take 18 months or longer, particularly where the respondent contests the facts or the harm assessment.
Can I get compensation for stress and anxiety, not just money lost?
Yes. The Privacy Act expressly allows compensation for non-economic loss, including humiliation, embarrassment and injury to feelings. Awards typically range from a few thousand dollars for minor breaches to A$20,000 or more where the impact is severe and well-documented with medical or psychological evidence.
What if the organisation is overseas?
The Privacy Act has extraterritorial reach under section 5B. If an overseas entity carries on business in Australia and collects personal information from Australians, it is covered by the APPs. The OAIC has successfully investigated global platforms including Facebook and Clearview AI on this basis.
Can I remain anonymous when complaining?
No. The OAIC needs to identify you to investigate a complaint about your personal information, and it will usually share your identity and the substance of the complaint with the respondent so they can respond. You can, however, ask the OAIC to keep certain sensitive details confidential where practical.
Final Thoughts
An OAIC complaint is a powerful and free mechanism for holding Australian organisations accountable when they mishandle your personal information. Success comes down to three things: complain to the organisation first, document everything, and be specific about the harm you have suffered. With the penalty regime now among the toughest in the world and the OAIC actively pursuing systemic investigations, individual complaints genuinely drive better privacy practices across the country.
Whether your matter is a single frustrating incident or part of a major breach affecting millions, taking the time to lodge a well-prepared complaint contributes to a stronger privacy culture in Australia — and can deliver meaningful redress for you personally.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore Online Safety Act 2026: Complete Guide for Users and Businesses
Singapore's Online Safety Act 2026 introduces sweeping new rules for platforms, deepfakes, and scam content. This complete guide explains who must comply, the new obligations, penalties, and practical steps businesses and users should take to prepare.
ePrivacy Regulations Ireland: Latest Updates for 2026
A practical 2026 guide to ePrivacy Regulations in Ireland — covering cookie consent, direct marketing rules, DPC enforcement trends, and what's next as the EU ePrivacy Regulation approaches. Includes a compliance checklist for Irish organisations.
Bill C-27 Digital Charter: What You Need to Know in 2026
Bill C-27, Canada's Digital Charter Implementation Act, overhauls federal privacy law with the CPPA, creates a new data tribunal, and introduces AIDA — the country's first AI-specific legislation. Here's what businesses and Canadians need to know to prepare.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 delivers the biggest overhaul of Australian privacy law in nearly 40 years. Discover your new rights—including erasure, portability, and the right to sue directly—plus what businesses must do to comply.