facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If your personal information has been mishandled, leaked or accessed without authorisation by an Australian business or federal government agency, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide explains exactly how OAIC complaints work, what qualifies as a privacy breach under the Privacy Act 1988, and how to build a complaint that regulators can act on.

What Is the OAIC and When Should You Complain?

The Office of the Australian Information Commissioner is the independent national regulator that oversees privacy and freedom of information in Australia. It enforces the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs), which set the rules for how organisations must handle personal information.

You should consider lodging an OAIC complaint when an organisation covered by the Privacy Act has:

  • Collected personal information about you without a lawful reason or consent.
  • Used or disclosed your information for a purpose you did not agree to.
  • Failed to keep your data secure, resulting in unauthorised access or loss.
  • Refused to give you access to your own personal information or correct inaccurate records.
  • Sent unsolicited marketing communications without a lawful basis.
  • Suffered a notifiable data breach that has caused you serious harm.

The OAIC covers most Australian businesses with an annual turnover above A$3 million, all health service providers regardless of size, credit reporting bodies, tax file number recipients, and Australian Government agencies. State and territory government agencies are usually handled by state privacy regulators instead.

What Counts as a Privacy Breach Under Australian Law

A privacy breach occurs when personal information is accessed, used, disclosed or lost in a way that contravenes the Australian Privacy Principles. Not every unpleasant experience with an organisation is legally a breach, so it helps to know where the line sits before you file OAIC complaints.

Common examples of reportable breaches

  • Data leaks: A company database is hacked and your name, address, Medicare number or passport details are exposed.
  • Misdirected communications: A hospital or law firm emails your medical records or file to the wrong recipient.
  • Insider misuse: A staff member accesses your account or file when they had no business reason to do so.
  • Excessive collection: A retailer demands your driver's licence to process a return when it is not reasonably necessary.
  • Unlawful disclosure: A telco confirms your home address to a caller without verifying their identity.

The Notifiable Data Breaches scheme

Under the Notifiable Data Breaches (NDB) scheme, organisations must notify both the OAIC and affected individuals when a data breach is likely to result in serious harm. If you have received an NDB notification, that is strong evidence you can use in an OAIC complaint if you believe the organisation's response was inadequate.

Step 1: Complain to the Organisation First

Before the OAIC will investigate, you generally must give the organisation a chance to fix the problem. This is a mandatory first step for almost all OAIC complaints and is set out in section 40(1A) of the Privacy Act.

  1. Identify the right contact. Most organisations have a Privacy Officer or a dedicated privacy email address (often privacy@company.com.au). Check their privacy policy or website footer.
  2. Put it in writing. Send an email or letter clearly labelled as a formal privacy complaint. Verbal complaints are harder to prove later.
  3. State the facts. Include dates, what happened, which Australian Privacy Principle you believe was breached, and how it affected you.
  4. Say what you want. Ask for a specific outcome — an apology, correction of records, deletion of data, compensation, or changes to their practices.
  5. Give them 30 days. The Privacy Act allows organisations a reasonable time (typically 30 days) to respond before you can escalate.

Keep copies of every message. If the organisation ignores you, refuses to act, or gives an inadequate response, you can then escalate to the OAIC.

Step 2: Prepare Your Evidence

Strong OAIC complaints are backed by clean, chronological evidence. Regulators receive thousands of submissions each year, and the ones that get investigated first are those where the complainant has done the legwork.

Documents to gather

  • Copies of the original privacy complaint sent to the organisation and their reply.
  • Any data breach notification letter or email you received.
  • Screenshots of the offending disclosure, marketing message, or website page.
  • A timeline document listing every relevant date and event.
  • Evidence of harm — financial loss statements, medical letters describing stress, or records of identity theft attempts.
  • The organisation's privacy policy at the time of the incident (use the Wayback Machine if it has since changed).

Protect yourself while collecting evidence

When you are documenting a breach, be careful how you share sensitive files. Use encrypted email where possible, avoid uploading unredacted documents to public forums, and if you need to share long links to evidence pages, use a reputable link management tool like Lunyb to create trackable, revocable short URLs rather than exposing raw file paths. A short, controllable link is far safer than pasting a full Dropbox or Google Drive URL into public correspondence.

Step 3: Lodge Your Complaint With the OAIC

Once the organisation has failed to resolve your issue, or 30 days have passed without an adequate response, you can formally lodge one of the OAIC complaints through their official channels.

How to submit

  1. Online form: The fastest option is the Privacy Complaint Form on oaic.gov.au. It walks you through mandatory fields.
  2. Post: Print the form and mail it to GPO Box 5288, Sydney NSW 2001.
  3. Phone or interpreter: Call 1300 363 992 if you need help completing the form or require an interpreter through TIS National.
  4. Accessibility support: The National Relay Service is available for people who are deaf or have hearing or speech impairments.

What the form asks

  • Your full name, contact details and preferred method of contact.
  • The name and details of the organisation you are complaining about.
  • A description of what happened, in chronological order.
  • What steps you have already taken with the organisation.
  • The outcome you are seeking.
  • Attachments — evidence, correspondence and any breach notifications.

There is no fee to lodge a privacy complaint with the OAIC.

What Happens After You Lodge

Once submitted, your complaint moves through a defined pipeline. Understanding the stages helps set realistic expectations, because OAIC complaints can take several months to resolve.

The OAIC investigation process

StageWhat HappensTypical Timeframe
1. AcknowledgementOAIC confirms receipt and assigns a case reference.1–2 weeks
2. Preliminary assessmentCase officer checks jurisdiction and whether you complained to the organisation first.4–8 weeks
3. ConciliationOAIC facilitates negotiation between you and the organisation.2–6 months
4. Formal investigationIf conciliation fails, the Commissioner may investigate under s.40(2).6–12 months
5. DeterminationCommissioner issues a binding determination if a breach is found.Varies

Possible outcomes

  • A formal apology from the organisation.
  • Correction, deletion or return of your personal information.
  • Compensation for financial loss or non-economic loss (stress, humiliation).
  • An enforceable undertaking that the organisation will change its practices.
  • In serious cases, civil penalties of up to A$50 million per contravention for corporations under the strengthened Privacy Act penalties.

Pros and Cons of Lodging OAIC Complaints

Pros

  • Free to lodge and does not require a lawyer.
  • Can result in real compensation and systemic change.
  • Conciliation is often quicker than court.
  • Puts the incident on the regulator's radar, protecting others.
  • Determinations are enforceable in the Federal Court.

Cons

  • Process can be slow — several months at minimum.
  • OAIC may decline to investigate if the matter is trivial, out of time, or already before another body.
  • You must attempt to resolve directly with the organisation first.
  • Compensation, when awarded, is often modest.
  • You cannot complain about most state government agencies through the OAIC.

Time Limits and Common Reasons Complaints Are Rejected

Under section 41 of the Privacy Act, the Commissioner may decline to investigate if the complaint is lodged more than 12 months after you became aware of the act or practice. Lodge early — do not wait.

Other common rejection reasons include:

  1. The organisation is not covered by the Privacy Act (for example, a small business under A$3 million turnover with no health data).
  2. You did not complain to the organisation first.
  3. The conduct occurred before the Privacy Act applied to that entity.
  4. The matter is more appropriately handled by another regulator (ACMA for spam, ASIC for credit issues, or a state privacy authority).
  5. The complaint is vexatious or lacks substance.

Reducing Your Exposure Before the Next Breach

Filing OAIC complaints is a reactive remedy. The best long-term protection is minimising how much personal information you hand over in the first place, and controlling how you share links and files online.

  1. Use unique email aliases when signing up for services so a breach at one vendor does not leak your primary inbox.
  2. Turn on multi-factor authentication on every account that supports it.
  3. Encrypt sensitive attachments before emailing them, even to trusted parties.
  4. Shorten and monitor outbound links using services like Lunyb so you can revoke access if a shared document is later exposed. If you want a deeper comparison of link management tools with privacy features, see our 2026 buyer's guide to URL shorteners.
  5. Check organisational privacy policies before providing ID documents — reject requests that fail the "reasonably necessary" test in APP 3.

For further reading on tools that respect user privacy, our team also maintains an honest review of Lunyb and a detailed Rebrandly review that examines what these platforms do with your data.

Frequently Asked Questions

How long do I have to lodge an OAIC complaint?

You should lodge within 12 months of becoming aware of the privacy breach. The Commissioner has discretion to accept late complaints if there are good reasons for the delay, but relying on that discretion is risky. File as soon as the organisation's response is inadequate.

Can I get compensation through an OAIC complaint?

Yes. If conciliation succeeds, the organisation may agree to pay compensation. If the matter proceeds to a formal determination, the Commissioner can order compensation for financial loss, expenses, and non-economic loss such as stress and humiliation. Amounts have historically ranged from a few hundred dollars to tens of thousands, depending on severity.

What if the organisation is based overseas?

The Privacy Act has extraterritorial reach under section 5B. If an overseas organisation has an Australian link — for example, it collects data from people in Australia through a website or app — the OAIC can still investigate. Enforcement is harder in practice, but complaints against major global platforms are regularly accepted.

Do I need a lawyer to lodge a complaint?

No. The process is designed to be accessible without legal representation. However, if your case involves significant financial loss, complex evidence, or you are considering a representative complaint on behalf of multiple people, engaging a privacy lawyer or a community legal centre is worthwhile.

What is the difference between an OAIC complaint and a class action?

An OAIC complaint is a regulatory process handled administratively by the Commissioner and is free. A class action is a court proceeding, usually run by a law firm on a no-win-no-fee basis, aggregating claims from many affected people. After the 2022 Privacy Act reforms and following high-profile Australian breaches, class actions have become more common — but the OAIC complaint pathway remains the fastest and cheapest first step for most individuals.

Final Thoughts

OAIC complaints are one of the most powerful tools Australians have to hold organisations accountable when their personal information is mishandled. The process rewards preparation: complain to the organisation first, gather clean evidence, lodge within the 12-month window, and be specific about the outcome you want. Combined with sensible personal data hygiene, this framework gives you both a remedy when things go wrong and a deterrent that pushes organisations to treat your information with the care the law requires.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles