OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian business, government agency or organisation has mishandled your personal information, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC). This guide walks you through exactly how to report a privacy breach, what evidence to gather, and what happens after you submit your complaint.
What Is the OAIC and What Does It Do?
The Office of the Australian Information Commissioner (OAIC) is the independent federal regulator responsible for privacy and freedom of information in Australia. It enforces the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs), which govern how personal information must be collected, stored, used and disclosed.
The OAIC has the power to investigate complaints, conduct own-motion investigations, issue determinations, accept enforceable undertakings, and — following the 2022 reforms — seek civil penalties of up to $50 million (or more) for serious or repeated interferences with privacy.
Who Can You Complain About?
You can lodge an OAIC complaint about:
- Australian Government agencies and departments
- Private sector organisations with an annual turnover of more than $3 million
- Small businesses that handle health information, sell personal information, or are contracted service providers to the Commonwealth
- Credit reporting bodies and credit providers
- Tax file number (TFN) recipients
What Counts as a Privacy Breach Under Australian Law?
A privacy breach occurs when an entity covered by the Privacy Act mishandles your personal information in a way that contravenes the Australian Privacy Principles. This includes unauthorised access, disclosure, loss, or misuse of data.
Common examples of reportable privacy breaches include:
- Data breaches: Your details were exposed in a cyberattack or accidental leak (think Optus, Medibank or Latitude-style incidents).
- Unauthorised disclosure: An organisation shared your personal information with a third party without your consent.
- Excessive collection: A business demanded personal information that wasn't reasonably necessary for its function.
- Refusal to provide access: A company refused to give you access to the personal information it holds about you.
- Refusal to correct records: An entity refused to correct inaccurate personal information.
- Direct marketing without consent: You received marketing you didn't opt into and couldn't easily opt out of.
- Overseas disclosure: Your data was sent overseas without appropriate safeguards.
Step 1: Complain to the Organisation First
Before the OAIC will investigate, you generally must give the organisation a chance to respond. This is a mandatory precondition set out in section 40(1A) of the Privacy Act.
How to Lodge an Internal Complaint
- Find the privacy officer: Every APP entity must have a privacy policy that includes contact details for complaints. Check the organisation's website footer or "Privacy" page.
- Put it in writing: Send an email or letter clearly labelled "Privacy Complaint". Verbal complaints are harder to prove later.
- Describe the breach: Explain what happened, when, and which APP you believe was breached.
- State what you want: An apology, deletion of data, correction, compensation, or a change in practice.
- Give a deadline: The OAIC expects organisations to respond within 30 days. State this clearly.
Keep copies of everything you send and receive. If the organisation ignores you, gives an inadequate response, or the 30 days expires, you can escalate to the OAIC.
Step 2: Prepare Your OAIC Complaint
A well-prepared complaint moves faster and is more likely to result in a favourable outcome. The OAIC receives thousands of complaints each year, so clarity and evidence matter.
Evidence to Gather
- A copy of your original complaint to the organisation and any response received
- Emails, letters, screenshots or transcripts showing the breach
- The date you became aware of the breach
- Any notification letters (for example, mandatory data breach notifications)
- Evidence of harm — financial loss, distress, identity theft attempts, medical records if stress-related
- The organisation's privacy policy at the time of the breach (use archive.org if it has changed)
Time Limits
You should lodge your OAIC complaint within 12 months of becoming aware of the breach. The Commissioner can decline to investigate older matters unless there is a good reason for the delay.
Step 3: Lodge the Complaint With the OAIC
The OAIC accepts complaints through several channels, but the online form is the fastest and most trackable option.
Ways to Lodge
| Method | Details | Best For |
|---|---|---|
| Online form | Available at oaic.gov.au | Most complainants — fastest processing |
| Post | GPO Box 5218, Sydney NSW 2001 | Complex cases with lots of documents |
| enquiries@oaic.gov.au | Initial enquiries before formal complaint | |
| Phone | 1300 363 992 | People needing assistance to lodge |
| National Relay Service | 133 677 | People who are deaf or have hearing/speech impairment |
Information You'll Need to Provide
- Your full name and contact details
- The name of the organisation or agency you're complaining about
- A clear description of what happened and when
- Copies of your correspondence with the organisation
- The outcome you're seeking
- Whether you have complained to any other body (for example, a state privacy commissioner or the ACMA)
Step 4: What Happens After You Lodge
Once the OAIC receives your complaint, it goes through several stages. Understanding the process helps you set realistic expectations.
The OAIC Complaint Process
- Acknowledgement (1–2 weeks): You receive confirmation that your complaint has been received and a case reference number.
- Preliminary assessment: The OAIC decides whether the matter falls within its jurisdiction and whether to accept it. Complaints may be declined if the organisation isn't covered, the issue is trivial, or you haven't first complained to the entity.
- Conciliation: The OAIC's preferred approach. A conciliator works with both parties to reach an agreed outcome — often an apology, compensation, deletion of data, or a change in practice.
- Investigation: If conciliation fails or the matter is serious, the Commissioner may open a formal investigation with powers to compel documents and evidence.
- Determination: For unresolved matters, the Commissioner can issue a legally binding determination, potentially including compensation orders.
Typical Timeframes
Most complaints are resolved within 12 months, but complex matters can take significantly longer. Data breach cases involving large numbers of individuals (such as class-action-style complaints) may take 18 to 24 months or more.
Possible Outcomes and Remedies
The OAIC cannot impose criminal penalties on individuals, but it has a wide range of remedies available for privacy breaches.
Remedies You Can Seek
- Apology: A written or public apology from the organisation
- Correction or deletion: Amendment of inaccurate records or destruction of unlawfully held data
- Access: Being given a copy of your personal information
- Compensation: Payment for financial loss and/or non-economic loss (distress, humiliation, embarrassment)
- Systemic change: The organisation agrees to change its policies, training or systems
- Enforceable undertakings: Legally binding commitments to fix specific issues
Compensation Amounts
Compensation for non-economic loss in OAIC determinations has historically ranged from around $3,000 for minor distress to over $20,000 for serious cases involving significant psychological harm. The 2022 Privacy Legislation Amendment increased maximum civil penalties for entities substantially, but individual complainant compensation remains modest by international standards.
Notifiable Data Breaches Scheme
Separate from the individual complaints process, Australia's Notifiable Data Breaches (NDB) scheme requires APP entities to notify both the OAIC and affected individuals when an eligible data breach is likely to result in serious harm.
What Triggers Notification?
An eligible data breach occurs when there is:
- Unauthorised access to, disclosure of, or loss of personal information
- That is likely to result in serious harm to affected individuals
- And the entity has not been able to prevent that harm through remedial action
If you receive a data breach notification letter, keep it. It's powerful evidence if you later lodge an OAIC complaint about the same incident.
Protecting Yourself After a Privacy Breach
While you're pursuing your OAIC complaint, take practical steps to limit further harm. Data breaches often lead to phishing, identity theft attempts and account takeovers.
Immediate Protective Steps
- Change compromised passwords and enable two-factor authentication on important accounts.
- Place a credit ban with Equifax, illion and Experian — this prevents new credit being opened in your name for up to 21 days (renewable).
- Monitor your bank and superannuation accounts for unauthorised activity.
- Report to IDCARE (1800 595 160) — Australia's free national identity and cyber support service.
- Be alert to phishing: Attackers often follow big breaches with targeted scam emails and SMS. Use link-checking tools before clicking suspicious URLs — services like Lunyb let you inspect where a shortened link actually leads before you visit it.
- Consider a name change on documents only in extreme cases, and after seeking legal advice.
Long-Term Privacy Hygiene
Beyond the immediate breach, reducing your general digital footprint makes future breaches less damaging. Use a password manager, enable privacy settings on social media, opt out of the Integrated Public Number Database (IPND), and think carefully before handing over personal information. Encrypted DNS resolvers and privacy-focused browsers can also reduce how much data is exposed to third parties in the first place. For safer link handling day-to-day, tools such as Lunyb and other reputable URL shorteners help you avoid tracking-heavy redirects — see our 2026 buyer's guide for a full comparison.
When to Consider Other Options
The OAIC isn't the only avenue for privacy grievances, and in some cases it isn't the right one.
Other Bodies That May Help
| Body | Jurisdiction |
|---|---|
| State/Territory Privacy Commissioners | State government agencies (NSW, VIC, QLD, etc.) |
| Australian Communications and Media Authority (ACMA) | Spam, telemarketing, Do Not Call Register breaches |
| Australian Financial Complaints Authority (AFCA) | Privacy breaches by banks, insurers, super funds |
| Telecommunications Industry Ombudsman (TIO) | Telco privacy issues |
| Australian Human Rights Commission | Where the breach also involves discrimination |
| Police (ACORN/ReportCyber) | Where the breach involves criminal conduct |
Class Actions
Following the Optus and Medibank breaches, representative complaints and civil class actions have become a significant avenue for compensation. If a class action has been announced covering your breach, you may want to register with the law firm running it — this doesn't prevent you also lodging an OAIC complaint, but the two processes may interact.
Tips for a Strong OAIC Complaint
- Be factual and chronological — avoid emotional language, focus on what happened and when
- Cite the APPs where you can (for example, "this appears to breach APP 6 — use or disclosure")
- Quantify harm with receipts, medical certificates, or bank statements where relevant
- Be reasonable about the remedy you seek — realistic requests are more likely to succeed at conciliation
- Respond promptly to OAIC requests for further information to avoid delays
- Keep your contact details up to date throughout the process
Frequently Asked Questions
How much does it cost to lodge an OAIC complaint?
Nothing. The OAIC complaints process is completely free. You don't need a lawyer, although you can engage one if the matter is complex or involves significant compensation claims.
Can I lodge an OAIC complaint anonymously?
Not for a formal complaint — the OAIC needs to be able to communicate with you and share necessary details with the respondent organisation. However, you can make an anonymous enquiry or tip-off, which may prompt the Commissioner to open an own-motion investigation.
How long do OAIC complaints take to resolve?
Simple matters resolved through conciliation typically take 3 to 9 months. More complex investigations, especially those involving large data breaches, can take 12 to 24 months or longer. The OAIC publishes annual reports with average resolution times.
Can I sue an organisation directly for a privacy breach?
Australia does not yet have a general statutory tort of serious invasion of privacy, although reforms in this direction have been recommended. You may have other causes of action (breach of confidence, negligence, breach of contract, or under the Australian Consumer Law). Class actions have become an increasingly common route following major data breaches.
What if I'm unhappy with the OAIC's decision?
If the Commissioner makes a determination, either party can apply to the Administrative Review Tribunal (ART, which replaced the AAT in 2024) for merits review. If the OAIC declines to investigate your complaint, you can request internal review, and in some cases seek judicial review in the Federal Court.
Final Thoughts
Lodging an OAIC complaint is one of the most effective tools Australians have to hold organisations accountable for privacy failures. The process is free, doesn't require a lawyer, and can result in meaningful remedies including compensation, apologies and systemic change. The keys to success are clear evidence, giving the organisation the first chance to fix things, and lodging within the 12-month window.
Privacy protection isn't just about complaining after the fact — it's also about reducing your exposure in the first place. Combine strong personal security practices with the willingness to exercise your rights under the Privacy Act, and you'll be far better placed than most Australians to handle whatever the next big breach throws at you.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Data Protection Act 2018 Ireland: Complete Guide
A comprehensive guide to Ireland's Data Protection Act 2018, covering how it interacts with the GDPR, individual rights, business obligations, DPC enforcement powers, and practical compliance steps. Learn how to protect personal data and avoid fines under Irish law.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a complex privacy landscape in 2026, from PIPEDA to Quebec's Law 25. This guide covers everything from building a privacy program and implementing safeguards to breach notification and CASL compliance.
Bill C-27 Digital Charter: What You Need to Know
Bill C-27, Canada's Digital Charter Implementation Act, overhauls federal privacy law and introduces the country's first AI statute. Here's what the CPPA, AIDA, and the new Data Protection Tribunal mean for businesses and consumers in 2026.
ePrivacy Regulations Ireland: Latest Updates for 2026
Ireland's ePrivacy landscape has shifted dramatically, with the DPC intensifying enforcement on cookies and direct marketing while the EU ePrivacy Regulation continues to develop. This comprehensive guide covers the latest updates, compliance requirements, and practical steps Irish businesses need to take in 2026.