facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··9 min read

If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). Whether your data was exposed in a large-scale breach, disclosed without consent, or simply held in a way that felt wrong, the OAIC is the federal regulator empowered under the Privacy Act 1988 to investigate and enforce Australian privacy law.

This guide walks you through exactly how to lodge an OAIC complaint about a privacy breach, what happens after you submit it, and how to protect yourself while the process unfolds.

What Is an OAIC Complaint?

An OAIC complaint is a formal submission to the Office of the Australian Information Commissioner alleging that an entity covered by the Privacy Act 1988 has interfered with your privacy. The OAIC can investigate, conciliate, make determinations, issue enforceable undertakings, and — in serious or repeated cases — seek civil penalties in the Federal Court.

Complaints usually relate to one of the 13 Australian Privacy Principles (APPs), which govern how personal information must be collected, stored, used, disclosed, and secured.

Who Can You Complain About?

The OAIC has jurisdiction over:

  • Australian Government agencies
  • Private sector organisations with an annual turnover above AUD 3 million
  • All private health service providers, regardless of size
  • Businesses that trade in personal information
  • Credit reporting bodies and credit providers
  • Tax File Number (TFN) recipients

Small businesses under the AUD 3 million threshold are generally exempt, though there are important exceptions. State and territory government agencies fall under state-based privacy regulators instead (for example, the IPC in NSW or OVIC in Victoria).

What Counts as a Privacy Breach Under Australian Law?

A privacy breach — sometimes called an "interference with privacy" — occurs when a covered entity fails to comply with the Privacy Act or an APP. Common examples include:

  • Unauthorised disclosure: An organisation shares your personal information without your consent or a lawful basis.
  • Data breach: A cyberattack, lost device, or misconfigured database exposes your information.
  • Collection without notice: Personal data is collected without you being told why, how, or by whom.
  • Refusal of access: A company won't let you access or correct personal information they hold about you.
  • Direct marketing misuse: Your details are used for marketing you never opted into.
  • Improper handling of TFNs or credit information.

Under the Notifiable Data Breaches (NDB) scheme, organisations must also notify the OAIC and affected individuals when a data breach is likely to result in serious harm. If you learn about a breach through such a notification, that letter or email is powerful evidence for your complaint.

Step 1: Complain to the Organisation First

Before the OAIC will consider your complaint, you generally must give the organisation itself a chance to respond. This isn't just bureaucracy — many issues genuinely get resolved at this stage.

  1. Identify the right contact. Look for a "Privacy Officer," "Data Protection Officer," or privacy contact in the organisation's privacy policy.
  2. Put it in writing. Send an email or letter clearly describing the breach, when it occurred, what personal information was involved, and what outcome you want (e.g. deletion, apology, compensation, corrective action).
  3. Keep records. Save copies of your complaint, delivery receipts, and any responses.
  4. Wait 30 days. The organisation has a reasonable time — usually 30 days — to respond. If they don't reply, or you're unhappy with the response, you can escalate to the OAIC.

Step 2: Gather Your Evidence

A well-documented complaint is far more likely to progress. Before you file with the OAIC, gather:

  • A clear timeline of events
  • Copies of any breach notification you received
  • Screenshots of exposed information, emails, or web pages
  • Correspondence with the organisation (both your complaint and their response)
  • Evidence of harm — financial loss, identity theft attempts, emotional distress, embarrassment, or reputational damage
  • Any relevant contracts, terms of service, or privacy policies that were in force at the time

If shortened links were used to phish you or spread your leaked data, capture those URLs too. Reputable link platforms like Lunyb log click analytics and can help investigators trace suspicious redirects when law enforcement or the regulator becomes involved.

Step 3: Lodge Your Complaint with the OAIC

Once you've given the organisation a chance to respond, you can formally complain to the OAIC. There are three main ways:

  1. Online: Use the OAIC's Privacy Complaint Form at oaic.gov.au.
  2. By post: Send a written complaint to GPO Box 5288, Sydney NSW 2001.
  3. By phone: Call 1300 363 992 for guidance, though a written follow-up is typically required.

Your complaint must be in writing and should include your contact details, the organisation you're complaining about, a description of what happened, evidence of your attempt to resolve it directly, and the outcome you're seeking.

Time Limits

There is no strict statutory deadline, but the OAIC may decline to investigate complaints made more than 12 months after you became aware of the issue. Lodge as soon as reasonably possible.

Step 4: What Happens After You Lodge

The OAIC's complaint process typically follows these stages:

Stage What Happens Typical Timeframe
Acknowledgement OAIC confirms receipt and assigns a case officer 1–4 weeks
Preliminary assessment OAIC decides whether it has jurisdiction and whether the complaint should proceed 1–3 months
Conciliation OAIC helps both parties reach a negotiated resolution 3–6 months
Investigation Formal investigation if conciliation fails and the matter warrants it 6–12+ months
Determination Commissioner makes a binding determination, potentially awarding compensation Varies

Most complaints are resolved through conciliation rather than formal determinations. Common outcomes include an apology, deletion or correction of records, changes to organisational practices, staff training commitments, and — in some cases — monetary compensation for financial loss or non-economic harm such as distress.

Possible Outcomes and Remedies

The OAIC has a wide range of powers when a complaint is substantiated. These include:

  • Requiring the organisation to stop the offending conduct
  • Ordering steps to remedy the breach (deletion, correction, security upgrades)
  • Awarding compensation for loss or damage, including for hurt feelings
  • Accepting enforceable undertakings
  • Issuing infringement notices
  • Applying to the Federal Court for civil penalty orders — up to AUD 50 million or more for serious or repeated interferences by corporations

Individual compensation awards have historically ranged from a few hundred dollars for minor distress to tens of thousands for serious cases involving significant harm.

Protecting Yourself After a Breach

Filing an OAIC complaint is important, but it doesn't undo the exposure of your data. Take practical steps to limit ongoing risk:

  1. Change passwords on any affected accounts and enable multi-factor authentication.
  2. Place a credit ban with Equifax, Experian, and illion if financial information was exposed. Bans are free and last 21 days (extendable).
  3. Monitor your accounts for unusual transactions or login attempts.
  4. Beware of follow-up scams. Attackers often target breach victims with tailored phishing. Be cautious of unexpected links and verify sender addresses.
  5. Use encrypted DNS and privacy-respecting browsers to reduce network-level tracking.
  6. Consider IDCARE — Australia's free national identity and cyber support service — for personalised recovery guidance.

For anything you publish or share online during a recovery period, use link tools that give you visibility and control. A managed shortener like Lunyb lets you see who's clicking your links and deactivate any that later become suspicious — a small habit that pays off if your details are already circulating.

What If the OAIC Declines Your Complaint?

The OAIC can decline to investigate for reasons such as the complaint being outside jurisdiction, lacking substance, being frivolous or vexatious, or being better handled by another body. If your complaint is declined, options include:

  • Requesting internal review of the decision
  • Applying to the Administrative Review Tribunal (ART) for review of certain decisions
  • Pursuing a civil claim, particularly under the new statutory tort of serious invasions of privacy that came into effect in 2025
  • Complaining to an industry ombudsman (e.g. the Telecommunications Industry Ombudsman for telcos, or AFCA for financial services)

OAIC vs Other Complaint Bodies

Sometimes another regulator is a better fit. Here's a quick comparison:

Body Best For Jurisdiction
OAIC Federal privacy law breaches, data breaches, APP violations National
State privacy regulators (IPC NSW, OVIC, etc.) Breaches by state government agencies State/territory
AFCA Financial services privacy issues National
TIO Telecommunications complaints National
ACMA Spam, unsolicited marketing, Do Not Call breaches National
Australian Cyber Security Centre (ACSC) Reporting cybercrime incidents National

Tips for a Stronger OAIC Complaint

  • Be specific. Vague allegations rarely progress. Name dates, systems, and people where possible.
  • Link to the APPs. Referencing the specific Australian Privacy Principle you believe was breached shows you've done your homework.
  • Quantify harm. If you experienced financial loss, list amounts. If distress, describe the impact honestly.
  • Stay calm and factual. Emotional language can weaken an otherwise strong complaint.
  • Follow up. Politely check in with your case officer if you haven't heard back in the expected timeframe.

Frequently Asked Questions

Is there a fee to lodge an OAIC complaint?

No. Lodging a privacy complaint with the OAIC is free. You do not need a lawyer, though legal advice can help in complex matters or where significant compensation is sought.

How long does an OAIC complaint take?

Simple matters resolved through conciliation may take 3–6 months. Complex investigations, especially those involving large data breaches, can take 12 months or more. The OAIC will keep you informed throughout the process.

Can I complain about a breach that happened years ago?

The OAIC may decline complaints made more than 12 months after you became aware of the breach. If there's a good reason for the delay — for example, you only recently discovered the breach — explain that clearly in your complaint.

Can I get compensation for a privacy breach?

Yes. The OAIC can require organisations to pay compensation for financial loss and for non-economic harm such as distress, humiliation, or damage to reputation. Amounts vary widely based on severity and evidence of harm.

What if my data was exposed by an overseas company?

If the overseas organisation has an "Australian link" — for example, it carries on business in Australia and collects personal information here — it may still be covered by the Privacy Act. The OAIC can investigate, though enforcement across borders can be more complex.

Final Thoughts

Reporting a privacy breach to the OAIC is one of the strongest tools Australians have to hold organisations accountable for how they handle personal information. The process rewards preparation: complain to the organisation first, gather solid evidence, be clear about the outcome you want, and be patient with the timeline.

For more on managing your digital footprint safely, see our 2026 buyer's guide to URL shorteners and other privacy guides on the Lunyb blog.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles