OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian business, government agency, or organisation has mishandled your personal information, you have the right to make a formal complaint to the Office of the Australian Information Commissioner (OAIC). Understanding how the process works — from initial complaint to investigation and resolution — can make the difference between a frustrating dead end and a meaningful outcome. This guide walks you through everything you need to know about lodging an OAIC complaint, what qualifies as a privacy breach under Australian law, and how to gather the evidence that supports your case.
What Is the OAIC and What Does It Do?
The Office of the Australian Information Commissioner (OAIC) is the independent national regulator responsible for privacy and freedom of information in Australia. It enforces the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs), which govern how organisations must collect, use, disclose, and store personal information.
The OAIC handles complaints from individuals who believe their privacy rights have been breached, investigates systemic issues, and can make determinations that require organisations to change practices, pay compensation, or issue apologies. It also administers the Notifiable Data Breaches (NDB) scheme, which requires organisations to notify the OAIC and affected individuals of eligible data breaches.
Who the OAIC Regulates
Not every organisation falls under the OAIC's jurisdiction. Generally, the Privacy Act applies to:
- Australian government agencies
- Private sector organisations with an annual turnover of more than $3 million
- Health service providers of any size
- Credit reporting bodies and credit providers
- Tax file number recipients
- Businesses that trade in personal information
Small businesses under the $3 million threshold are generally exempt unless they fall into one of the categories above. State government agencies are typically covered by state-based privacy laws instead.
What Counts as a Privacy Breach Under Australian Law?
A privacy breach occurs when personal information is accessed, used, disclosed, or lost in a way that contravenes the Australian Privacy Principles. Personal information includes anything that identifies you — your name, address, phone number, email, financial details, health records, or even opinions expressed about you.
Common Types of Privacy Breaches
- Unauthorised disclosure — Your information was shared with a third party without your consent.
- Data breaches — A cyberattack, lost device, or insider incident exposed your data.
- Collection without consent — An organisation collected sensitive information (like health data) without a lawful basis.
- Failure to provide access — You requested access to your personal information and were refused or ignored.
- Refusal to correct inaccurate data — You asked for incorrect information to be fixed and were denied.
- Direct marketing without consent — You received marketing communications after opting out.
- Misuse of government identifiers — Your tax file number or Medicare number was used inappropriately.
Step-by-Step: How to Lodge an OAIC Complaint
Making a privacy complaint follows a structured path. The OAIC generally requires you to complain to the organisation first before escalating. Here is the full process.
Step 1: Complain Directly to the Organisation
Before the OAIC will accept your complaint, you must give the organisation an opportunity to respond. Contact their privacy officer in writing, describe what happened, and state what outcome you want (an apology, correction of records, compensation, or changed practices). The organisation has 30 days to respond.
Step 2: Wait 30 Days or Receive an Unsatisfactory Response
If the organisation does not respond within 30 days, or if their response does not resolve your concerns, you can escalate to the OAIC. Keep copies of your original complaint and any correspondence — you will need to submit these.
Step 3: Gather Your Evidence
Strong complaints are backed by clear documentation. Collect:
- A written timeline of events
- Copies of emails, letters, or messages
- Screenshots of websites, apps, or notifications
- Data breach notification letters (if received)
- Records of financial loss, distress, or other harm suffered
- Any responses from the organisation
Step 4: Submit the Complaint to the OAIC
You can lodge a complaint through the OAIC's online form at oaic.gov.au, by post, or by email. There is no fee to make a privacy complaint. You will need to provide your identity and contact details — anonymous complaints generally cannot be investigated as formal complaints, though tip-offs can be made confidentially.
Step 5: Preliminary Assessment
The OAIC reviews your complaint to determine whether it has jurisdiction, whether you have complained to the organisation first, and whether the matter appears to raise a privacy issue. This triage stage can take several weeks.
Step 6: Conciliation
The OAIC's preferred approach is conciliation — a facilitated negotiation between you and the organisation. Most complaints are resolved at this stage without a formal investigation. Outcomes can include apologies, corrections, staff training, policy changes, or compensation.
Step 7: Formal Investigation and Determination
If conciliation fails, the Commissioner may open a formal investigation and issue a binding determination. Determinations can require the organisation to stop conduct, correct records, or pay compensation for financial loss and non-economic harm (such as humiliation or distress).
Timeframes: How Long Does an OAIC Complaint Take?
Timeframes vary depending on complexity, but here is a general guide.
| Stage | Typical Duration |
|---|---|
| Complaint to organisation (mandatory first step) | Up to 30 days |
| OAIC preliminary assessment | 4–8 weeks |
| Conciliation | 3–6 months |
| Formal investigation | 6–18 months |
| Determination and any appeal | Additional 3–12 months |
Most privacy complaints are resolved within 12 months, but complex matters involving large data breaches or multiple parties can take significantly longer.
The Notifiable Data Breaches (NDB) Scheme
Since 2018, organisations covered by the Privacy Act must notify the OAIC and affected individuals when an "eligible data breach" occurs. An eligible breach is one that is likely to result in serious harm — such as identity theft, financial loss, or significant emotional distress.
What to Do If You Receive a Data Breach Notification
- Read the notification carefully — Identify exactly what information was exposed.
- Change compromised passwords immediately — Use unique, strong passwords for each account.
- Enable multi-factor authentication — Wherever possible, add a second verification step.
- Monitor financial accounts — Watch for suspicious transactions.
- Consider a credit ban — Contact Equifax, Experian, or illion to place a temporary credit ban.
- Report identity theft — Contact IDCARE (1800 595 160), Australia's free identity support service.
- Preserve the notification — Keep it as evidence if you later lodge a complaint.
Practical Ways to Reduce Your Privacy Exposure
Filing a complaint is a reactive step. Reducing what you share in the first place is a stronger defence. A few habits that meaningfully reduce your privacy footprint:
- Use disposable or forwarding email addresses when signing up for services you don't fully trust.
- Enable encrypted DNS (such as DNS-over-HTTPS) in your browser to prevent your internet provider from logging every domain you visit.
- Prefer privacy-respecting browsers with built-in tracker blocking.
- Use a trusted link shortener when sharing URLs publicly — services like Lunyb let you share links without exposing tracking parameters or your original source URL. For more on choosing one, see our 2026 buyer's guide to URL shorteners.
- Regularly audit which apps have access to your Google, Apple, and Facebook accounts, and revoke anything you no longer use.
- Request access to and deletion of your data from organisations you no longer engage with — this is your right under APP 12 and APP 13.
What Outcomes Can the OAIC Order?
If your complaint is upheld, the Commissioner has broad powers under section 52 of the Privacy Act. Possible outcomes include:
| Outcome | Description |
|---|---|
| Declaration of interference | Formal finding that the organisation breached the Privacy Act |
| Injunction | Order to stop specific conduct |
| Corrective action | Requirement to correct or destroy inaccurate records |
| Apology | Written or public apology to affected individuals |
| Compensation for financial loss | Reimbursement of quantifiable losses |
| Compensation for non-economic loss | Payment for distress, humiliation, or injury to feelings (typically $1,000–$20,000, sometimes higher) |
| Civil penalties | For serious or repeated interferences, penalties up to $50 million per contravention for corporations |
Common Reasons Complaints Are Rejected
Not every complaint proceeds. Understanding why complaints get closed early can help you strengthen yours.
- You didn't complain to the organisation first — This is the most common reason for early closure.
- The organisation isn't covered by the Privacy Act — Small businesses under the turnover threshold are usually exempt.
- The complaint is out of time — Complaints must generally be lodged within 12 months of becoming aware of the breach.
- No privacy issue is raised — For example, a service complaint dressed up as a privacy issue.
- The matter is already being dealt with elsewhere — Court proceedings or another regulator (like AHPRA) may take precedence.
- The complaint is frivolous or vexatious — Rare, but the Commissioner can decline on this basis.
Alternatives to an OAIC Complaint
Depending on the situation, other bodies may be better placed to help:
- Australian Financial Complaints Authority (AFCA) — For privacy issues involving banks, insurers, or superannuation funds.
- Telecommunications Industry Ombudsman (TIO) — For phone and internet provider issues.
- State privacy regulators — For state government agencies (e.g., IPC NSW, OVIC in Victoria).
- Australian Human Rights Commission — For discrimination-related privacy issues.
- Australian Cyber Security Centre (ACSC) — To report cybercrime through ReportCyber.
- IDCARE — Free case management support for identity compromise.
Tips for a Successful OAIC Complaint
- Be specific and factual. Stick to what happened, when, and who was involved. Avoid emotive language.
- Identify the APP breached. Referencing the specific Australian Privacy Principle strengthens your case.
- Quantify harm where possible. If you suffered financial loss, provide receipts or statements.
- State a clear remedy. Tell the OAIC what outcome would resolve the matter for you.
- Respond promptly. The OAIC may close complaints if you don't reply to requests for information within set timeframes.
- Keep records of everything. Every email, every phone call, every screenshot.
Frequently Asked Questions
How much does it cost to lodge an OAIC complaint?
There is no fee to lodge a privacy complaint with the OAIC. The process is designed to be accessible to all Australians regardless of financial means. You do not need a lawyer, although you can engage one if the matter is complex.
Can I remain anonymous when complaining to the OAIC?
Formal complaints require you to identify yourself so the OAIC can investigate and communicate outcomes. However, you can make anonymous tip-offs about systemic privacy issues, which the OAIC may use to launch own-motion investigations. Your identity is not disclosed to the organisation without your consent during preliminary stages.
What if the organisation ignores the OAIC's determination?
OAIC determinations are legally binding. If an organisation fails to comply, the OAIC (or you as the complainant) can apply to the Federal Court or Federal Circuit and Family Court to enforce the determination. The court can also order civil penalties for non-compliance.
How long do I have to make a complaint?
You generally must lodge a complaint within 12 months of becoming aware of the alleged breach. The Commissioner has discretion to accept late complaints in exceptional circumstances, but it is best to act promptly. The clock starts from when you knew or should reasonably have known about the incident.
Can I claim compensation for stress and anxiety caused by a data breach?
Yes. The OAIC can award compensation for non-economic loss, including humiliation, injury to feelings, and psychological distress. Amounts typically range from $1,000 for minor distress to $20,000 or more for serious harm. In large-scale data breach class actions, per-person compensation can be higher, but individual OAIC determinations tend to sit within these bands.
Final Thoughts
The OAIC complaints process is one of the most important tools Australians have for holding organisations accountable for how they handle personal information. It's free, structured, and — while not always fast — it produces real outcomes ranging from apologies and record corrections to substantial compensation and enforceable determinations. If you believe your privacy has been breached, the key steps are simple: complain to the organisation first, gather your evidence, and escalate to the OAIC if you don't get a satisfactory response within 30 days.
Prevention still beats cure. Reducing what you share, using privacy-respecting tools for everyday tasks like link sharing, and regularly auditing your digital footprint all reduce the chance you'll ever need to file a complaint in the first place.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Data Protection Act 2018 Ireland: The Complete Guide
Ireland's Data Protection Act 2018 works alongside the GDPR to protect personal data and create the Data Protection Commission. This complete guide covers scope, rights, obligations, enforcement, and practical compliance steps for Irish businesses.
Bill C-27 Digital Charter: What You Need to Know
Bill C-27, Canada's Digital Charter Implementation Act, will replace PIPEDA with the CPPA, launch a new Data Tribunal, and introduce AIDA to regulate artificial intelligence. This guide explains what's inside the bill, how it compares to GDPR, and how Canadian organizations should prepare.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A complete 2026 guide to filing a privacy complaint with the Data Protection Commission (DPC) Ireland. Learn the steps, evidence needed, timelines, and what outcomes to expect under GDPR and the Data Protection Act 2018.
ePrivacy Regulations Ireland: Latest Updates and 2026 Compliance Guide
Ireland's ePrivacy Regulations are being enforced more strictly than ever, with new DPC guidance on cookie consent, direct marketing, and tracking. This 2026 guide covers the latest updates and practical compliance steps for Irish businesses.