OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). Whether your data was exposed in a large-scale breach, disclosed without consent, or simply held in a way that felt wrong, the OAIC is the federal regulator empowered under the Privacy Act 1988 to investigate and enforce Australian privacy law.
This guide walks you through exactly how to lodge an OAIC complaint about a privacy breach, what happens after you submit it, and how to protect yourself while the process unfolds.
What Is an OAIC Complaint?
An OAIC complaint is a formal submission to the Office of the Australian Information Commissioner alleging that an entity covered by the Privacy Act 1988 has interfered with your privacy. The OAIC can investigate, conciliate, make determinations, issue enforceable undertakings, and — in serious or repeated cases — seek civil penalties in the Federal Court.
Complaints usually relate to one of the 13 Australian Privacy Principles (APPs), which govern how personal information must be collected, stored, used, disclosed, and secured.
Who Can You Complain About?
The OAIC has jurisdiction over:
- Australian Government agencies
- Private sector organisations with an annual turnover above AUD 3 million
- All private health service providers, regardless of size
- Businesses that trade in personal information
- Credit reporting bodies and credit providers
- Tax File Number (TFN) recipients
Small businesses under the AUD 3 million threshold are generally exempt, though there are important exceptions. State and territory government agencies fall under state-based privacy regulators instead (for example, the IPC in NSW or OVIC in Victoria).
What Counts as a Privacy Breach Under Australian Law?
A privacy breach — sometimes called an "interference with privacy" — occurs when a covered entity fails to comply with the Privacy Act or an APP. Common examples include:
- Unauthorised disclosure: An organisation shares your personal information without your consent or a lawful basis.
- Data breach: A cyberattack, lost device, or misconfigured database exposes your information.
- Collection without notice: Personal data is collected without you being told why, how, or by whom.
- Refusal of access: A company won't let you access or correct personal information they hold about you.
- Direct marketing misuse: Your details are used for marketing you never opted into.
- Improper handling of TFNs or credit information.
Under the Notifiable Data Breaches (NDB) scheme, organisations must also notify the OAIC and affected individuals when a data breach is likely to result in serious harm. If you learn about a breach through such a notification, that letter or email is powerful evidence for your complaint.
Step 1: Complain to the Organisation First
Before the OAIC will consider your complaint, you generally must give the organisation itself a chance to respond. This isn't just bureaucracy — many issues genuinely get resolved at this stage.
- Identify the right contact. Look for a "Privacy Officer," "Data Protection Officer," or privacy contact in the organisation's privacy policy.
- Put it in writing. Send an email or letter clearly describing the breach, when it occurred, what personal information was involved, and what outcome you want (e.g. deletion, apology, compensation, corrective action).
- Keep records. Save copies of your complaint, delivery receipts, and any responses.
- Wait 30 days. The organisation has a reasonable time — usually 30 days — to respond. If they don't reply, or you're unhappy with the response, you can escalate to the OAIC.
Step 2: Gather Your Evidence
A well-documented complaint is far more likely to progress. Before you file with the OAIC, gather:
- A clear timeline of events
- Copies of any breach notification you received
- Screenshots of exposed information, emails, or web pages
- Correspondence with the organisation (both your complaint and their response)
- Evidence of harm — financial loss, identity theft attempts, emotional distress, embarrassment, or reputational damage
- Any relevant contracts, terms of service, or privacy policies that were in force at the time
If shortened links were used to phish you or spread your leaked data, capture those URLs too. Reputable link platforms like Lunyb log click analytics and can help investigators trace suspicious redirects when law enforcement or the regulator becomes involved.
Step 3: Lodge Your Complaint with the OAIC
Once you've given the organisation a chance to respond, you can formally complain to the OAIC. There are three main ways:
- Online: Use the OAIC's Privacy Complaint Form at oaic.gov.au.
- By post: Send a written complaint to GPO Box 5288, Sydney NSW 2001.
- By phone: Call 1300 363 992 for guidance, though a written follow-up is typically required.
Your complaint must be in writing and should include your contact details, the organisation you're complaining about, a description of what happened, evidence of your attempt to resolve it directly, and the outcome you're seeking.
Time Limits
There is no strict statutory deadline, but the OAIC may decline to investigate complaints made more than 12 months after you became aware of the issue. Lodge as soon as reasonably possible.
Step 4: What Happens After You Lodge
The OAIC's complaint process typically follows these stages:
| Stage | What Happens | Typical Timeframe |
|---|---|---|
| Acknowledgement | OAIC confirms receipt and assigns a case officer | 1–4 weeks |
| Preliminary assessment | OAIC decides whether it has jurisdiction and whether the complaint should proceed | 1–3 months |
| Conciliation | OAIC helps both parties reach a negotiated resolution | 3–6 months |
| Investigation | Formal investigation if conciliation fails and the matter warrants it | 6–12+ months |
| Determination | Commissioner makes a binding determination, potentially awarding compensation | Varies |
Most complaints are resolved through conciliation rather than formal determinations. Common outcomes include an apology, deletion or correction of records, changes to organisational practices, staff training commitments, and — in some cases — monetary compensation for financial loss or non-economic harm such as distress.
Possible Outcomes and Remedies
The OAIC has a wide range of powers when a complaint is substantiated. These include:
- Requiring the organisation to stop the offending conduct
- Ordering steps to remedy the breach (deletion, correction, security upgrades)
- Awarding compensation for loss or damage, including for hurt feelings
- Accepting enforceable undertakings
- Issuing infringement notices
- Applying to the Federal Court for civil penalty orders — up to AUD 50 million or more for serious or repeated interferences by corporations
Individual compensation awards have historically ranged from a few hundred dollars for minor distress to tens of thousands for serious cases involving significant harm.
Protecting Yourself After a Breach
Filing an OAIC complaint is important, but it doesn't undo the exposure of your data. Take practical steps to limit ongoing risk:
- Change passwords on any affected accounts and enable multi-factor authentication.
- Place a credit ban with Equifax, Experian, and illion if financial information was exposed. Bans are free and last 21 days (extendable).
- Monitor your accounts for unusual transactions or login attempts.
- Beware of follow-up scams. Attackers often target breach victims with tailored phishing. Be cautious of unexpected links and verify sender addresses.
- Use encrypted DNS and privacy-respecting browsers to reduce network-level tracking.
- Consider IDCARE — Australia's free national identity and cyber support service — for personalised recovery guidance.
For anything you publish or share online during a recovery period, use link tools that give you visibility and control. A managed shortener like Lunyb lets you see who's clicking your links and deactivate any that later become suspicious — a small habit that pays off if your details are already circulating.
What If the OAIC Declines Your Complaint?
The OAIC can decline to investigate for reasons such as the complaint being outside jurisdiction, lacking substance, being frivolous or vexatious, or being better handled by another body. If your complaint is declined, options include:
- Requesting internal review of the decision
- Applying to the Administrative Review Tribunal (ART) for review of certain decisions
- Pursuing a civil claim, particularly under the new statutory tort of serious invasions of privacy that came into effect in 2025
- Complaining to an industry ombudsman (e.g. the Telecommunications Industry Ombudsman for telcos, or AFCA for financial services)
OAIC vs Other Complaint Bodies
Sometimes another regulator is a better fit. Here's a quick comparison:
| Body | Best For | Jurisdiction |
|---|---|---|
| OAIC | Federal privacy law breaches, data breaches, APP violations | National |
| State privacy regulators (IPC NSW, OVIC, etc.) | Breaches by state government agencies | State/territory |
| AFCA | Financial services privacy issues | National |
| TIO | Telecommunications complaints | National |
| ACMA | Spam, unsolicited marketing, Do Not Call breaches | National |
| Australian Cyber Security Centre (ACSC) | Reporting cybercrime incidents | National |
Tips for a Stronger OAIC Complaint
- Be specific. Vague allegations rarely progress. Name dates, systems, and people where possible.
- Link to the APPs. Referencing the specific Australian Privacy Principle you believe was breached shows you've done your homework.
- Quantify harm. If you experienced financial loss, list amounts. If distress, describe the impact honestly.
- Stay calm and factual. Emotional language can weaken an otherwise strong complaint.
- Follow up. Politely check in with your case officer if you haven't heard back in the expected timeframe.
Frequently Asked Questions
Is there a fee to lodge an OAIC complaint?
No. Lodging a privacy complaint with the OAIC is free. You do not need a lawyer, though legal advice can help in complex matters or where significant compensation is sought.
How long does an OAIC complaint take?
Simple matters resolved through conciliation may take 3–6 months. Complex investigations, especially those involving large data breaches, can take 12 months or more. The OAIC will keep you informed throughout the process.
Can I complain about a breach that happened years ago?
The OAIC may decline complaints made more than 12 months after you became aware of the breach. If there's a good reason for the delay — for example, you only recently discovered the breach — explain that clearly in your complaint.
Can I get compensation for a privacy breach?
Yes. The OAIC can require organisations to pay compensation for financial loss and for non-economic harm such as distress, humiliation, or damage to reputation. Amounts vary widely based on severity and evidence of harm.
What if my data was exposed by an overseas company?
If the overseas organisation has an "Australian link" — for example, it carries on business in Australia and collects personal information here — it may still be covered by the Privacy Act. The OAIC can investigate, though enforcement across borders can be more complex.
Final Thoughts
Reporting a privacy breach to the OAIC is one of the strongest tools Australians have to hold organisations accountable for how they handle personal information. The process rewards preparation: complain to the organisation first, gather solid evidence, be clear about the outcome you want, and be patient with the timeline.
For more on managing your digital footprint safely, see our 2026 buyer's guide to URL shorteners and other privacy guides on the Lunyb blog.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.