facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If an Australian business, government agency or organisation has mishandled your personal information, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC). This guide walks you through exactly how to report a privacy breach, what evidence to gather, and what happens after you submit your complaint.

What Is the OAIC and What Does It Do?

The Office of the Australian Information Commissioner (OAIC) is the independent federal regulator responsible for privacy and freedom of information in Australia. It enforces the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs), which govern how personal information must be collected, stored, used and disclosed.

The OAIC has the power to investigate complaints, conduct own-motion investigations, issue determinations, accept enforceable undertakings, and — following the 2022 reforms — seek civil penalties of up to $50 million (or more) for serious or repeated interferences with privacy.

Who Can You Complain About?

You can lodge an OAIC complaint about:

  • Australian Government agencies and departments
  • Private sector organisations with an annual turnover of more than $3 million
  • Small businesses that handle health information, sell personal information, or are contracted service providers to the Commonwealth
  • Credit reporting bodies and credit providers
  • Tax file number (TFN) recipients

What Counts as a Privacy Breach Under Australian Law?

A privacy breach occurs when an entity covered by the Privacy Act mishandles your personal information in a way that contravenes the Australian Privacy Principles. This includes unauthorised access, disclosure, loss, or misuse of data.

Common examples of reportable privacy breaches include:

  1. Data breaches: Your details were exposed in a cyberattack or accidental leak (think Optus, Medibank or Latitude-style incidents).
  2. Unauthorised disclosure: An organisation shared your personal information with a third party without your consent.
  3. Excessive collection: A business demanded personal information that wasn't reasonably necessary for its function.
  4. Refusal to provide access: A company refused to give you access to the personal information it holds about you.
  5. Refusal to correct records: An entity refused to correct inaccurate personal information.
  6. Direct marketing without consent: You received marketing you didn't opt into and couldn't easily opt out of.
  7. Overseas disclosure: Your data was sent overseas without appropriate safeguards.

Step 1: Complain to the Organisation First

Before the OAIC will investigate, you generally must give the organisation a chance to respond. This is a mandatory precondition set out in section 40(1A) of the Privacy Act.

How to Lodge an Internal Complaint

  1. Find the privacy officer: Every APP entity must have a privacy policy that includes contact details for complaints. Check the organisation's website footer or "Privacy" page.
  2. Put it in writing: Send an email or letter clearly labelled "Privacy Complaint". Verbal complaints are harder to prove later.
  3. Describe the breach: Explain what happened, when, and which APP you believe was breached.
  4. State what you want: An apology, deletion of data, correction, compensation, or a change in practice.
  5. Give a deadline: The OAIC expects organisations to respond within 30 days. State this clearly.

Keep copies of everything you send and receive. If the organisation ignores you, gives an inadequate response, or the 30 days expires, you can escalate to the OAIC.

Step 2: Prepare Your OAIC Complaint

A well-prepared complaint moves faster and is more likely to result in a favourable outcome. The OAIC receives thousands of complaints each year, so clarity and evidence matter.

Evidence to Gather

  • A copy of your original complaint to the organisation and any response received
  • Emails, letters, screenshots or transcripts showing the breach
  • The date you became aware of the breach
  • Any notification letters (for example, mandatory data breach notifications)
  • Evidence of harm — financial loss, distress, identity theft attempts, medical records if stress-related
  • The organisation's privacy policy at the time of the breach (use archive.org if it has changed)

Time Limits

You should lodge your OAIC complaint within 12 months of becoming aware of the breach. The Commissioner can decline to investigate older matters unless there is a good reason for the delay.

Step 3: Lodge the Complaint With the OAIC

The OAIC accepts complaints through several channels, but the online form is the fastest and most trackable option.

Ways to Lodge

MethodDetailsBest For
Online formAvailable at oaic.gov.auMost complainants — fastest processing
PostGPO Box 5218, Sydney NSW 2001Complex cases with lots of documents
Emailenquiries@oaic.gov.auInitial enquiries before formal complaint
Phone1300 363 992People needing assistance to lodge
National Relay Service133 677People who are deaf or have hearing/speech impairment

Information You'll Need to Provide

  1. Your full name and contact details
  2. The name of the organisation or agency you're complaining about
  3. A clear description of what happened and when
  4. Copies of your correspondence with the organisation
  5. The outcome you're seeking
  6. Whether you have complained to any other body (for example, a state privacy commissioner or the ACMA)

Step 4: What Happens After You Lodge

Once the OAIC receives your complaint, it goes through several stages. Understanding the process helps you set realistic expectations.

The OAIC Complaint Process

  1. Acknowledgement (1–2 weeks): You receive confirmation that your complaint has been received and a case reference number.
  2. Preliminary assessment: The OAIC decides whether the matter falls within its jurisdiction and whether to accept it. Complaints may be declined if the organisation isn't covered, the issue is trivial, or you haven't first complained to the entity.
  3. Conciliation: The OAIC's preferred approach. A conciliator works with both parties to reach an agreed outcome — often an apology, compensation, deletion of data, or a change in practice.
  4. Investigation: If conciliation fails or the matter is serious, the Commissioner may open a formal investigation with powers to compel documents and evidence.
  5. Determination: For unresolved matters, the Commissioner can issue a legally binding determination, potentially including compensation orders.

Typical Timeframes

Most complaints are resolved within 12 months, but complex matters can take significantly longer. Data breach cases involving large numbers of individuals (such as class-action-style complaints) may take 18 to 24 months or more.

Possible Outcomes and Remedies

The OAIC cannot impose criminal penalties on individuals, but it has a wide range of remedies available for privacy breaches.

Remedies You Can Seek

  • Apology: A written or public apology from the organisation
  • Correction or deletion: Amendment of inaccurate records or destruction of unlawfully held data
  • Access: Being given a copy of your personal information
  • Compensation: Payment for financial loss and/or non-economic loss (distress, humiliation, embarrassment)
  • Systemic change: The organisation agrees to change its policies, training or systems
  • Enforceable undertakings: Legally binding commitments to fix specific issues

Compensation Amounts

Compensation for non-economic loss in OAIC determinations has historically ranged from around $3,000 for minor distress to over $20,000 for serious cases involving significant psychological harm. The 2022 Privacy Legislation Amendment increased maximum civil penalties for entities substantially, but individual complainant compensation remains modest by international standards.

Notifiable Data Breaches Scheme

Separate from the individual complaints process, Australia's Notifiable Data Breaches (NDB) scheme requires APP entities to notify both the OAIC and affected individuals when an eligible data breach is likely to result in serious harm.

What Triggers Notification?

An eligible data breach occurs when there is:

  1. Unauthorised access to, disclosure of, or loss of personal information
  2. That is likely to result in serious harm to affected individuals
  3. And the entity has not been able to prevent that harm through remedial action

If you receive a data breach notification letter, keep it. It's powerful evidence if you later lodge an OAIC complaint about the same incident.

Protecting Yourself After a Privacy Breach

While you're pursuing your OAIC complaint, take practical steps to limit further harm. Data breaches often lead to phishing, identity theft attempts and account takeovers.

Immediate Protective Steps

  1. Change compromised passwords and enable two-factor authentication on important accounts.
  2. Place a credit ban with Equifax, illion and Experian — this prevents new credit being opened in your name for up to 21 days (renewable).
  3. Monitor your bank and superannuation accounts for unauthorised activity.
  4. Report to IDCARE (1800 595 160) — Australia's free national identity and cyber support service.
  5. Be alert to phishing: Attackers often follow big breaches with targeted scam emails and SMS. Use link-checking tools before clicking suspicious URLs — services like Lunyb let you inspect where a shortened link actually leads before you visit it.
  6. Consider a name change on documents only in extreme cases, and after seeking legal advice.

Long-Term Privacy Hygiene

Beyond the immediate breach, reducing your general digital footprint makes future breaches less damaging. Use a password manager, enable privacy settings on social media, opt out of the Integrated Public Number Database (IPND), and think carefully before handing over personal information. Encrypted DNS resolvers and privacy-focused browsers can also reduce how much data is exposed to third parties in the first place. For safer link handling day-to-day, tools such as Lunyb and other reputable URL shorteners help you avoid tracking-heavy redirects — see our 2026 buyer's guide for a full comparison.

When to Consider Other Options

The OAIC isn't the only avenue for privacy grievances, and in some cases it isn't the right one.

Other Bodies That May Help

BodyJurisdiction
State/Territory Privacy CommissionersState government agencies (NSW, VIC, QLD, etc.)
Australian Communications and Media Authority (ACMA)Spam, telemarketing, Do Not Call Register breaches
Australian Financial Complaints Authority (AFCA)Privacy breaches by banks, insurers, super funds
Telecommunications Industry Ombudsman (TIO)Telco privacy issues
Australian Human Rights CommissionWhere the breach also involves discrimination
Police (ACORN/ReportCyber)Where the breach involves criminal conduct

Class Actions

Following the Optus and Medibank breaches, representative complaints and civil class actions have become a significant avenue for compensation. If a class action has been announced covering your breach, you may want to register with the law firm running it — this doesn't prevent you also lodging an OAIC complaint, but the two processes may interact.

Tips for a Strong OAIC Complaint

  • Be factual and chronological — avoid emotional language, focus on what happened and when
  • Cite the APPs where you can (for example, "this appears to breach APP 6 — use or disclosure")
  • Quantify harm with receipts, medical certificates, or bank statements where relevant
  • Be reasonable about the remedy you seek — realistic requests are more likely to succeed at conciliation
  • Respond promptly to OAIC requests for further information to avoid delays
  • Keep your contact details up to date throughout the process

Frequently Asked Questions

How much does it cost to lodge an OAIC complaint?

Nothing. The OAIC complaints process is completely free. You don't need a lawyer, although you can engage one if the matter is complex or involves significant compensation claims.

Can I lodge an OAIC complaint anonymously?

Not for a formal complaint — the OAIC needs to be able to communicate with you and share necessary details with the respondent organisation. However, you can make an anonymous enquiry or tip-off, which may prompt the Commissioner to open an own-motion investigation.

How long do OAIC complaints take to resolve?

Simple matters resolved through conciliation typically take 3 to 9 months. More complex investigations, especially those involving large data breaches, can take 12 to 24 months or longer. The OAIC publishes annual reports with average resolution times.

Can I sue an organisation directly for a privacy breach?

Australia does not yet have a general statutory tort of serious invasion of privacy, although reforms in this direction have been recommended. You may have other causes of action (breach of confidence, negligence, breach of contract, or under the Australian Consumer Law). Class actions have become an increasingly common route following major data breaches.

What if I'm unhappy with the OAIC's decision?

If the Commissioner makes a determination, either party can apply to the Administrative Review Tribunal (ART, which replaced the AAT in 2024) for merits review. If the OAIC declines to investigate your complaint, you can request internal review, and in some cases seek judicial review in the Federal Court.

Final Thoughts

Lodging an OAIC complaint is one of the most effective tools Australians have to hold organisations accountable for privacy failures. The process is free, doesn't require a lawyer, and can result in meaningful remedies including compensation, apologies and systemic change. The keys to success are clear evidence, giving the organisation the first chance to fix things, and lodging within the 12-month window.

Privacy protection isn't just about complaining after the fact — it's also about reducing your exposure in the first place. Combine strong personal security practices with the willingness to exercise your rights under the Privacy Act, and you'll be far better placed than most Australians to handle whatever the next big breach throws at you.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles