facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If an Australian business, government agency, or credit provider has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide explains exactly how the OAIC complaints process works, what qualifies as a privacy breach under the Privacy Act 1988, and the practical steps to lodge a strong, well-documented complaint.

What Is the OAIC and What Does It Do?

The Office of the Australian Information Commissioner (OAIC) is the independent federal regulator responsible for privacy, freedom of information, and government information policy in Australia. It enforces the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs), and it investigates complaints from individuals whose personal information may have been mishandled.

The OAIC has authority over most Australian Government agencies, private-sector organisations with an annual turnover of more than $3 million, all health service providers, credit reporting bodies, and organisations that trade in personal information. Small businesses are generally exempt, though several important exceptions apply.

Powers of the Information Commissioner

  • Investigate complaints and conduct own-motion investigations
  • Make binding determinations, including compensation orders
  • Accept enforceable undertakings from organisations
  • Seek civil penalties in the Federal Court for serious or repeated interferences with privacy
  • Oversee the Notifiable Data Breaches (NDB) scheme

What Counts as a Privacy Breach Under Australian Law?

A privacy breach occurs when an entity covered by the Privacy Act mishandles your personal information in a way that contravenes the Australian Privacy Principles. This can include unauthorised access, disclosure, loss of data, or collection and use of information beyond what was consented to.

Common examples of reportable conduct include:

  1. Data breaches — hackers accessing customer records, or an employee emailing a spreadsheet of personal details to the wrong recipient.
  2. Unauthorised disclosure — a company sharing your details with a third party without your consent.
  3. Excessive collection — a business asking for identity documents it does not reasonably need.
  4. Failure to secure information — poor storage practices, unencrypted databases, or lost devices containing personal data.
  5. Refusal to provide access or correction — an organisation refusing to let you see or fix the personal information it holds about you.
  6. Direct marketing without consent — using your details for marketing when you never opted in, or ignoring opt-out requests.
  7. Credit reporting errors — inaccurate default listings or repayment history information.

Before You Complain: Contact the Organisation First

The OAIC generally will not investigate a complaint unless you have first raised the issue directly with the organisation involved and given them a reasonable opportunity to respond — usually 30 days. This step is mandatory in most cases and often resolves the matter quickly.

How to Complain to the Organisation

  1. Find the organisation's privacy officer or privacy policy — every APP entity must publish one.
  2. Put your complaint in writing (email works well because it creates a timestamped record).
  3. Clearly describe what happened, when it happened, and how it affected you.
  4. Reference the Privacy Act 1988 or specific Australian Privacy Principles if you can.
  5. State what outcome you want: an apology, correction, deletion, compensation, or a change in practice.
  6. Give them 30 days to respond substantively.

If they refuse to respond, fail to respond within 30 days, or provide a response you consider inadequate, you can escalate to the OAIC.

How to Lodge an OAIC Complaint: Step-by-Step

Lodging a privacy complaint with the OAIC is free, and you do not need a lawyer. The regulator has designed the process to be accessible to individuals.

Step 1: Gather Your Evidence

Before you start the form, collect:

  • Copies of correspondence with the organisation (emails, letters, chat transcripts)
  • Screenshots of the incident where relevant
  • A timeline of events with dates
  • Any breach notification you received
  • Evidence of harm or loss (financial records, medical reports for stress, etc.)

Step 2: Submit the Privacy Complaint Form

Head to oaic.gov.au and use the online privacy complaint form. You can also submit by post, email, or by phone on 1300 363 992 if you need assistance. The form asks for:

  • Your contact details
  • The name of the organisation you are complaining about
  • A description of what happened
  • Evidence that you contacted the organisation first
  • The outcome you are seeking

Step 3: Acknowledgement and Preliminary Assessment

The OAIC will acknowledge your complaint, usually within a few days, and assess whether it has jurisdiction and whether the matter should be investigated. It may decline to investigate if the complaint is frivolous, out of time (more than 12 months old without good reason), or already dealt with by another body.

Step 4: Conciliation

The most common outcome is conciliation, where the OAIC helps both parties reach a mutually acceptable resolution. This is confidential, without prejudice, and can result in apologies, changes to practices, financial compensation, or staff training.

Step 5: Formal Investigation and Determination

If conciliation fails, the Commissioner can make a formal determination. Determinations can order the organisation to stop the conduct, take specific steps to redress it, or pay compensation. Determinations are enforceable in the Federal Court or Federal Circuit and Family Court.

The Notifiable Data Breaches (NDB) Scheme

Since February 2018, entities covered by the Privacy Act must notify affected individuals and the OAIC when a data breach is likely to result in serious harm. If you have received a data breach notification, it is worth understanding your rights.

What Must Be in a Breach Notification?

  • The identity and contact details of the organisation
  • A description of the breach
  • The kinds of information involved
  • Recommendations for steps you should take in response

What to Do If You Receive One

  1. Change passwords for the affected service and any account reusing that password.
  2. Enable multi-factor authentication wherever possible.
  3. Place a ban or freeze on your credit file through Equifax, illion, and Experian if identity documents were exposed.
  4. Monitor bank statements and consider requesting a new card if payment details were involved.
  5. Report identity theft to IDCARE (1800 595 160), Australia's free national identity support service.
  6. Consider complaining to the OAIC if you believe the breach was caused by poor security practices.

Comparison: OAIC vs Other Australian Complaint Bodies

Not every privacy grievance belongs with the OAIC. Choosing the right body speeds up resolution.

BodyHandlesCostBinding Outcomes?
OAICPrivacy Act breaches, federal FOI, credit reportingFreeYes (determinations)
State privacy commissioners (e.g. IPC NSW, OVIC)State/territory government agenciesFreeVaries by state
Australian Financial Complaints Authority (AFCA)Bank, insurer, super fund privacy issuesFree for consumersYes, up to monetary limits
Telecommunications Industry Ombudsman (TIO)Telco privacy and billing disputesFree for consumersYes, up to $100k
eSafety CommissionerImage-based abuse, cyberbullying, illegal contentFreeYes (takedown notices)
ACCCMisleading privacy conduct under consumer lawFree to reportInvestigative body

Realistic Outcomes and Compensation

Many complainants want to know what they can actually get from the process. Outcomes vary widely, but the following are common:

Non-Financial Remedies

  • A formal written apology
  • Correction or deletion of inaccurate records
  • Changes to policies, staff training, or systems
  • An enforceable undertaking published on the OAIC website

Financial Compensation

Compensation is possible but usually modest. Awards commonly fall in the range of $1,000 to $20,000 for non-economic loss (stress, humiliation, embarrassment), with higher amounts reserved for particularly egregious cases or where clear financial loss can be proven. Aggravated damages may also be awarded where the conduct was especially callous.

Time Limits and Practical Tips

You generally have 12 months from when you became aware of the breach to lodge a complaint. The Commissioner has discretion to accept late complaints, but do not rely on it — act promptly.

Tips for a Strong Complaint

  1. Be specific. Vague complaints get vague responses. Give dates, names, and quote correspondence.
  2. Reference the APPs. If you can identify which Australian Privacy Principle was breached (e.g. APP 6 on use and disclosure, or APP 11 on security), it strengthens your case.
  3. Quantify the harm. Even non-financial harm should be described — sleepless nights, anxiety, embarrassment at work.
  4. Stay professional. Emotional language rarely helps. Calm, factual writing carries more weight.
  5. Keep records. Save everything the OAIC and the organisation send you.

Protecting Your Privacy Going Forward

Filing a complaint addresses past harm, but reducing your exposure is just as important. Practical steps Australians can take include:

  • Use unique, strong passwords stored in a reputable password manager.
  • Turn on multi-factor authentication for email, banking, and social accounts.
  • Switch to an encrypted DNS resolver like Cloudflare 1.1.1.1 or Quad9 for extra network-level protection.
  • Use privacy-focused browsers such as Firefox or Brave with tracking protection enabled.
  • Limit the personal information you share on forms — legally, organisations can only collect what is reasonably necessary.
  • Be careful with the links you click and share. Tools like Lunyb let you create shortened links with click analytics and safer redirects, which is helpful when sharing content publicly without exposing underlying URLs. You can read more in our honest Lunyb review or compare options in our 2026 URL shortener buyer's guide.
  • Request access to and correction of your personal information under APP 12 and APP 13 whenever you suspect inaccuracies.

What Happens If You Are Unhappy With the OAIC's Decision?

If the OAIC declines to investigate or you disagree with the determination, you have several options:

  • Request an internal review or written reasons for the decision.
  • Apply to the Administrative Review Tribunal (ART) for merits review of certain decisions.
  • Seek judicial review in the Federal Court on legal grounds.
  • Explore parallel remedies through state tribunals or the courts for common law breach of confidence or the new statutory tort of serious invasion of privacy (commencing 2025 under the Privacy and Other Legislation Amendment Act 2024).

Frequently Asked Questions

How long does an OAIC complaint take to resolve?

Timeframes vary. Simple matters resolved through conciliation may conclude within 3–6 months. Complex investigations leading to a formal determination can take 12–24 months or longer. The OAIC has a significant backlog, so patience is required.

Do I need a lawyer to lodge an OAIC complaint?

No. The process is designed for individuals to use directly. However, if the breach caused significant financial loss or you are considering court action alongside the complaint, legal advice can be valuable. Community legal centres and Legal Aid may assist eligible complainants for free.

Can I complain about a small business?

Generally, businesses with turnover under $3 million are exempt from the Privacy Act. However, exceptions apply to health service providers, businesses that trade in personal information, contractors to the Commonwealth, credit reporting bodies, and related entities of larger businesses. Check the exception list before assuming you cannot complain.

Will my complaint be made public?

Most complaints are handled confidentially. However, if the matter proceeds to a formal determination, the Commissioner may publish anonymised or identified reasons. Enforceable undertakings and civil penalty proceedings are also public. Conciliations remain confidential.

What is the difference between an OAIC complaint and a data breach notification?

A data breach notification is something the organisation sends to you (and the OAIC) when they suffer a breach likely to cause serious harm. An OAIC complaint is something you initiate when you believe your privacy rights have been breached. Receiving a notification does not automatically mean you should complain, but it can be evidence supporting one.

Final Thoughts

The OAIC complaints process is one of the most accessible privacy enforcement mechanisms available to Australians. While outcomes are not always dramatic, the process pressures organisations to take privacy seriously and can secure meaningful remedies for individuals. Combined with good personal security hygiene — strong passwords, multi-factor authentication, careful link handling, and mindful information sharing — it forms a practical toolkit for defending your personal data in an increasingly connected economy.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles