facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··9 min read

If an Australian organisation has mishandled your personal information, you have the right to lodge a formal complaint with the Office of the Australian Information Commissioner (OAIC). This guide walks you through exactly how the OAIC complaints process works, when to use it, what evidence to gather, and what outcomes you can realistically expect when reporting a privacy breach.

What Is the OAIC and What Does It Do?

The Office of the Australian Information Commissioner (OAIC) is the independent federal agency responsible for regulating privacy and freedom of information in Australia. It oversees compliance with the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs), and it investigates complaints from individuals whose personal information may have been mishandled.

The OAIC has jurisdiction over most Australian Government agencies, private sector organisations with an annual turnover of more than $3 million, all health service providers, credit reporting bodies, and businesses that trade in personal information. Small businesses under the turnover threshold are generally exempt, though there are important exceptions.

What Counts as a Privacy Breach?

A privacy breach occurs when personal information is accessed, disclosed, altered, lost, or misused in a way that contravenes the Privacy Act. Common examples include:

  • A company emailing your personal details to the wrong recipient.
  • A data breach exposing your name, address, Medicare number, or financial data.
  • An organisation collecting more information than it reasonably needs.
  • Refusal to give you access to, or correct, personal information they hold.
  • Using your data for direct marketing without valid consent.
  • Sharing your information overseas without appropriate safeguards.

Before You Lodge an OAIC Complaint

The OAIC generally will not investigate a complaint unless you have first tried to resolve the issue directly with the organisation involved. This is a mandatory step for most cases, and skipping it will usually result in your complaint being sent back to you.

Step 1: Complain Directly to the Organisation

  1. Identify the correct entity. Find the legal name of the business or agency, not just the trading name.
  2. Locate their privacy officer. Under APP 1, every APP entity must publish a clear privacy policy that includes complaint contact details.
  3. Put your complaint in writing. Email is ideal because it creates a timestamped record. Clearly describe what happened, when, and what you want the organisation to do (apologise, delete data, compensate you, change procedures).
  4. Give them 30 days to respond. This is the standard window the OAIC expects before escalation.

Step 2: Evaluate Their Response

If the organisation refuses to respond, ignores you, or provides an outcome you consider inadequate after 30 days, you can then escalate the matter to the OAIC. Keep every email, letter, screenshot, and reference number — the regulator will ask for them.

How to Lodge a Complaint With the OAIC

The OAIC accepts complaints online, by post, by email, or by phone (with assistance for people who need translation or accessibility support). The fastest and most reliable method is the online privacy complaint form on oaic.gov.au.

Information You'll Need to Provide

  • Your full name and contact details.
  • The name of the organisation or agency you are complaining about.
  • A clear, chronological description of what happened.
  • The date(s) of the incident and when you discovered it.
  • Copies of any correspondence with the organisation.
  • Details of the harm or distress caused.
  • What outcome you are seeking.

Complaint Lodgement Methods Compared

Method Best For Typical Turnaround Notes
Online form Most individuals Fastest acknowledgement Allows document uploads and gives you a case reference immediately.
Email Complex cases with many attachments 1–2 weeks Send to enquiries@oaic.gov.au with all documents attached.
Post Those without digital access Slowest GPO Box 5288, Sydney NSW 2001.
Phone (1300 363 992) Initial questions and vulnerable complainants Same day Staff can guide you through the process but written complaint still required.

What Happens After You Lodge a Complaint

Once the OAIC receives your complaint, it moves through several distinct stages. Understanding this workflow helps set realistic expectations — privacy investigations are rarely fast.

1. Acknowledgement and Assessment

You will typically receive an acknowledgement within a few business days. The OAIC then assesses whether the complaint falls within its jurisdiction and whether you have attempted to resolve it directly with the respondent first.

2. Early Resolution

Many complaints are handled through early resolution or conciliation rather than formal investigation. The OAIC contacts the organisation, shares your complaint, and asks them to respond. A negotiated outcome — such as an apology, a data correction, or a modest compensation payment — often results.

3. Formal Investigation

If early resolution fails, the Commissioner can open a formal investigation under section 40 of the Privacy Act. The OAIC has coercive powers to require documents, examine witnesses, and enter premises. Formal investigations can take 12 months or more.

4. Determination

The Commissioner can make a legally enforceable determination under section 52. This may include declarations that the organisation engaged in an interference with privacy, orders to take specific steps, and compensation for loss or damage — including for non-economic harm such as humiliation or distress.

Notifiable Data Breaches: A Separate but Related Scheme

Under the Notifiable Data Breaches (NDB) scheme, organisations covered by the Privacy Act must notify both the OAIC and affected individuals when an eligible data breach occurs — that is, one likely to result in serious harm.

If you receive a data breach notification (or discover one that was never disclosed), you can still lodge an individual complaint. The NDB scheme is a reporting obligation on the organisation; it does not replace your personal right to seek a remedy.

Signs Your Data May Have Been Breached

  • Unexpected password reset emails.
  • Login alerts from unfamiliar locations.
  • Suspicious credit enquiries on your file.
  • Targeted scam calls referencing accurate personal details.
  • Notifications from services like Have I Been Pwned.

Strengthening Your Privacy While You Wait

OAIC investigations can take months. In the meantime, take practical steps to limit further exposure. Enable multi-factor authentication on every important account, place a temporary ban on your credit file with Equifax, Experian, and illion, and rotate any passwords that may have been exposed. Consider switching to a privacy-respecting browser and encrypted DNS resolver to reduce ongoing tracking.

Be equally cautious about the links you click and share. Shortened links from unknown sources are a common phishing vector, so use a reputable service like Lunyb when you need to shorten and share links securely — and when in doubt about a link you have received, expand it before clicking. You can read our honest review of Lunyb for more context, or compare options in our 2026 buyer's guide to URL shorteners.

Possible Outcomes of an OAIC Complaint

The OAIC has a broad toolkit of remedies. Not every complaint results in compensation — in fact, most are resolved through non-monetary outcomes — but the regulator's determinations are enforceable in the Federal Court.

Typical Remedies

  • Apology: A written or public apology from the organisation.
  • Corrective action: Deletion, correction, or return of your personal information.
  • Policy changes: Updated procedures, staff training, or system fixes.
  • Compensation: For economic loss (identity theft costs, lost income) and non-economic loss (distress, humiliation, injury to feelings). Awards typically range from a few hundred dollars to tens of thousands in serious matters.
  • Civil penalties: For serious or repeated interferences with privacy, the Federal Court can impose substantial fines on the organisation.

Timeframes at a Glance

Stage Typical Duration
Acknowledgement3–10 business days
Initial assessment4–8 weeks
Conciliation / early resolution3–6 months
Formal investigation6–18 months
DeterminationAdditional 3–6 months

Pros and Cons of Lodging an OAIC Complaint

Pros

  • Free to lodge — no filing fees or legal costs required.
  • Regulator has coercive investigative powers.
  • Determinations are enforceable in the Federal Court.
  • Can result in real systemic change, not just individual remedies.
  • Works alongside the Notifiable Data Breaches scheme.

Cons

  • Process can take a year or more for complex matters.
  • You must attempt direct resolution first.
  • Compensation, when awarded, is often modest.
  • Small business exemption limits which organisations are covered.
  • OAIC has discretion to decline complaints it considers vexatious or already adequately dealt with.

Alternatives and Complementary Options

Depending on the nature of the breach, other bodies may also be relevant:

  • State and territory privacy regulators (e.g. IPC NSW, OVIC Victoria) for state government agencies.
  • Australian Financial Complaints Authority (AFCA) for breaches by banks, insurers, or financial advisers.
  • Telecommunications Industry Ombudsman (TIO) for telcos and internet providers.
  • Australian Cyber Security Centre (ACSC / ReportCyber) for suspected criminal cybercrime.
  • IDCARE for free identity and cyber support if your data has been compromised.

Tips for a Strong Complaint

  1. Be chronological. Set out events by date so the case officer can follow them easily.
  2. Cite the APPs where possible. Referring to specific principles (e.g. APP 6 use and disclosure, APP 11 security) shows the OAIC exactly which obligation you say was breached.
  3. Quantify the harm. Include out-of-pocket costs, time spent, and evidence of distress such as medical records if relevant.
  4. State the outcome you want. Vague complaints get vague responses. Specify apology, deletion, compensation, or systemic change.
  5. Keep communications professional. Emotional language is understandable but calm, factual writing carries more weight.

Frequently Asked Questions

How much does it cost to lodge an OAIC complaint?

Nothing. Lodging a privacy complaint with the OAIC is free, and you do not need a lawyer. The OAIC provides guidance materials and case officers who can help you understand the process, though for complex matters some people choose to engage a privacy lawyer at their own cost.

How long do I have to lodge a complaint?

There is no strict statutory time limit, but the OAIC may decline to investigate complaints made more than 12 months after you became aware of the incident. Lodging promptly increases the chance the regulator will accept and act on your matter.

Can I complain about a small business?

Generally the Privacy Act does not cover businesses with an annual turnover under $3 million. However, exceptions apply — health service providers of any size, businesses that trade in personal information, credit reporting bodies, and contractors to the Commonwealth are all covered regardless of turnover.

Will my name be shared with the organisation?

Yes. To investigate and attempt resolution, the OAIC generally needs to share your identity and complaint details with the respondent organisation. If you have safety concerns, raise them with the case officer — anonymised handling may be possible in limited circumstances.

Can I get compensation for stress or embarrassment?

Yes. The Commissioner can award compensation for non-economic loss such as humiliation, injury to feelings, and psychological distress, in addition to any economic loss you have suffered. Amounts vary widely depending on the seriousness and duration of the interference with privacy.

Final Thoughts

Lodging an OAIC complaint is one of the strongest privacy rights available to Australians. The process rewards patience and preparation: try to resolve matters directly first, keep meticulous records, cite the Australian Privacy Principles where relevant, and be specific about the outcome you want. Combined with sensible everyday privacy hygiene — strong passwords, multi-factor authentication, careful link handling, and monitoring of your credit file — a well-prepared complaint can deliver both personal remedy and lasting systemic change.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles