OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). The OAIC is the national regulator responsible for enforcing the Privacy Act 1988 and the Australian Privacy Principles (APPs). This guide explains, step by step, how to report a privacy breach, what evidence to gather, and what to expect once your complaint is lodged.
What Is the OAIC and What Does It Regulate?
The Office of the Australian Information Commissioner (OAIC) is the independent Commonwealth agency that oversees privacy, freedom of information, and government information policy in Australia. It handles complaints against most Australian Government agencies and private sector organisations with an annual turnover of more than $3 million, along with some smaller businesses (such as health service providers and credit reporting bodies).
The OAIC's key functions include:
- Investigating complaints about mishandling of personal information
- Regulating the Notifiable Data Breaches (NDB) scheme
- Issuing guidance and determinations under the Privacy Act
- Taking enforcement action, including seeking civil penalties
When You Can Complain to the OAIC
You can lodge a complaint if you believe an APP entity has breached your privacy — for example, by disclosing your personal information without consent, refusing you access to your own data, failing to secure it adequately, or using it for a purpose you never agreed to.
What Counts as a Privacy Breach Under Australian Law?
A privacy breach occurs when personal information is accessed, used, disclosed, or lost in a way that contravenes the Privacy Act or the Australian Privacy Principles. Personal information is broadly defined and includes anything that can identify you, such as your name, address, phone number, email, health records, financial details, biometric data, or online identifiers.
Common Examples of Privacy Breaches
- A retailer emailing your order details to the wrong customer
- A hospital losing a USB drive containing patient records
- A bank being hacked and customer data being posted on the dark web
- An employer sharing your medical certificate with colleagues
- A telco selling your contact details to a third party without consent
- An organisation refusing to correct inaccurate information they hold about you
Serious vs. Eligible Data Breaches
Under the Notifiable Data Breaches scheme, organisations must notify both the OAIC and affected individuals when an eligible data breach occurs — that is, when unauthorised access, disclosure or loss is likely to result in serious harm. If you were notified of such a breach, you may still lodge a complaint about how the organisation handled it.
Step 1: Complain to the Organisation First
Before the OAIC will formally investigate, you generally need to complain directly to the organisation and give them a reasonable opportunity to respond — usually 30 days.
- Identify the right contact. Most organisations must publish a privacy policy that lists a Privacy Officer or complaints contact. Check their website footer or "Privacy" page.
- Put your complaint in writing. Email or a written letter creates a clear record. State that you are making a formal privacy complaint under the Privacy Act 1988.
- Describe the breach clearly. Include dates, what personal information was involved, how you found out, and any harm caused.
- State what you want. This might be an apology, correction of records, deletion of data, changes to systems, or compensation.
- Set a deadline. Request a substantive response within 30 days.
What If the Organisation Doesn't Respond?
If you receive no response within 30 days, or the response is inadequate, you can escalate to the OAIC. Keep copies of everything — emails, letters, screenshots, and any reference numbers.
Step 2: Gather Your Evidence
A well-documented complaint is far more likely to progress quickly. Before submitting to the OAIC, collect:
- A timeline of events with specific dates
- Copies of correspondence with the organisation
- Screenshots of any misdirected emails, exposed data, or online listings
- The organisation's privacy policy (download a copy in case it changes)
- Any breach notification letter you received
- Evidence of harm — financial loss, identity theft reports, medical records for stress-related impact, or lost business opportunities
Tips for Preserving Digital Evidence
Take full-page screenshots including URLs and timestamps. If a suspicious link was involved in the breach (for example, a phishing message that scraped your data), preserve the original URL. Analytics-enabled shortening tools like Lunyb can also help you safely archive and share suspicious links with investigators without exposing others to the raw destination.
Step 3: Lodge Your Complaint With the OAIC
Once you've given the organisation a chance to respond, you can submit your complaint to the OAIC. There is no fee to lodge a privacy complaint.
How to Submit
- Online form: The fastest method. Visit oaic.gov.au and complete the Privacy Complaint Form.
- Email or post: Download the form and send it to the OAIC's Sydney office.
- Phone: Call the OAIC enquiries line on 1300 363 992 if you need help lodging or have accessibility requirements.
Information the OAIC Will Ask For
| Category | Details Required |
|---|---|
| Your details | Name, contact information, preferred method of communication |
| The respondent | Name of the organisation or agency you're complaining about |
| The breach | What happened, when, and what personal information was involved |
| Prior contact | Evidence you complained to the organisation and their response (or lack of one) |
| Impact | How the breach affected you — financial, emotional, reputational |
| Desired outcome | What resolution you're seeking |
Step 4: What Happens After You Lodge
The OAIC follows a structured process, though timeframes vary depending on complexity and current caseload.
Initial Assessment
An officer reviews whether your complaint falls within the OAIC's jurisdiction and meets the threshold requirements (for example, whether you first raised it with the organisation). This stage can take several weeks.
Conciliation
The OAIC's preferred approach is conciliation — helping both parties reach a mutually acceptable outcome without a formal determination. This might include an apology, policy changes, staff retraining, or a compensation payment.
Investigation and Determination
If conciliation fails or the matter is serious, the Commissioner may formally investigate and issue a determination under section 52 of the Privacy Act. Determinations are legally enforceable and can order:
- The organisation to stop the offending conduct
- Corrective actions to prevent recurrence
- Compensation for financial loss and non-economic harm (such as distress)
- Publication of an apology
Civil Penalties
For serious or repeated interferences with privacy, the OAIC can seek civil penalties in the Federal Court. Following 2022 reforms, maximum penalties for body corporates are the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover during the breach period.
Realistic Timelines and Outcomes
Simple complaints resolved through conciliation can be finalised within a few months. Complex matters involving formal investigation may take a year or more. The OAIC publishes yearly statistics showing typical resolution times — checking these before you lodge can help set expectations.
What the OAIC Cannot Do
- Impose criminal penalties (that's a matter for police and the DPP)
- Award unlimited compensation — awards are typically modest, in the low thousands to low tens of thousands
- Investigate small businesses under $3 million turnover unless an exception applies
- Handle complaints about state or territory government agencies (contact your state privacy regulator instead)
State and Territory Alternatives
If your complaint is against a state or territory government body, you'll need to go to the relevant state regulator:
| Jurisdiction | Regulator |
|---|---|
| NSW | Information and Privacy Commission NSW |
| Victoria | Office of the Victorian Information Commissioner |
| Queensland | Office of the Information Commissioner Queensland |
| WA | No standalone privacy Act (health only via HaDSCO) |
| SA | Privacy Committee of South Australia |
| Tasmania | Tasmanian Ombudsman |
| ACT | OAIC (handles ACT public sector under an agreement) |
| NT | Office of the Information Commissioner NT |
Protecting Yourself After a Breach
While the OAIC handles the regulatory side, you should take immediate practical steps to reduce ongoing harm from a breach.
Immediate Actions
- Change compromised passwords and enable multi-factor authentication on affected accounts.
- Place a credit ban with all three Australian credit reporting bodies (Equifax, Experian, illion) if financial details were exposed. A ban lasts 21 days and can be extended.
- Contact IDCARE (1800 595 160) — Australia's free national identity and cyber support service.
- Report scams to Scamwatch if you receive phishing attempts following the breach.
- Monitor your accounts and credit reports for suspicious activity for at least 12 months.
Longer-Term Privacy Hygiene
Use a password manager, keep separate email addresses for high-risk accounts, and be conservative about what you share online. When sharing links containing tracking parameters or session data, use a privacy-conscious shortener — you can see how a service like Lunyb approaches user privacy in this honest review, or compare options in our 2026 buyer's guide.
Getting Help With Your Complaint
You don't need a lawyer to lodge an OAIC complaint, and most people handle the process themselves. However, free help is available from:
- Community legal centres — many offer free advice on consumer and privacy matters
- Legal Aid in your state or territory
- IDCARE case managers for identity crime and data breach support
- The OAIC enquiries line (1300 363 992) for procedural questions
Frequently Asked Questions
How much does it cost to lodge an OAIC complaint?
Nothing. Lodging a privacy complaint with the OAIC is completely free. There are no filing fees, and you don't need legal representation. If a matter proceeds to Federal Court for enforcement, costs may apply, but the OAIC — not you — runs those proceedings.
How long do I have to make a complaint?
There is no strict statutory limit, but the OAIC may decline to investigate complaints made more than 12 months after you became aware of the breach unless there are good reasons for the delay. Lodge as soon as reasonably possible after giving the organisation their 30-day response window.
Can I get compensation for a privacy breach?
Yes. The Commissioner can order compensation for financial loss, expenses reasonably incurred, and non-economic loss such as humiliation, distress, or injury to feelings. Awards are typically modest — often between $3,000 and $20,000 for individual complaints — but larger amounts have been awarded in serious cases.
What if the organisation is based overseas?
The Privacy Act has extraterritorial reach. If an overseas organisation has an "Australian link" — for example, it carries on business in Australia and collects information here — the OAIC can investigate. Enforcement against purely offshore entities is harder in practice, but the OAIC cooperates with overseas regulators.
Do I have to notify the OAIC if I'm the victim of a breach?
No. The obligation to notify the OAIC under the Notifiable Data Breaches scheme falls on the organisation that suffered the breach, not the individuals affected. You can, however, lodge a complaint if you believe your privacy has been interfered with — including by the organisation's failure to notify you.
Final Thoughts
The OAIC complaints process is designed to be accessible without legal help. The keys to a successful outcome are complaining to the organisation first, gathering solid evidence, being specific about the harm you've suffered, and being clear about the remedy you want. Australia's privacy framework isn't perfect, but it gives individuals real leverage — and every well-documented complaint helps improve the standards organisations are held to.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and GDPR both protect personal data, but they differ sharply in consent rules, individual rights, breach timelines, and penalties. This guide explains the key differences and shows Canadian businesses how to build a compliance program that satisfies both laws in 2026.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR both protect personal data, but they differ significantly in consent, penalties, breach notification, and cross-border transfers. This guide breaks down the key differences so businesses can build a unified compliance strategy.
GDPR After Brexit: What Changed for UK Businesses and Data Protection
GDPR did not disappear after Brexit—it split into two parallel regimes. This guide explains how UK GDPR differs from EU GDPR, what adequacy decisions mean for data transfers, and the practical compliance steps every British business should take in 2026.
Data Protection Act 2018 Ireland: Complete Guide
Ireland's Data Protection Act 2018 gives effect to the GDPR under Irish law and empowers the Data Protection Commission to enforce it. This complete guide covers scope, individual rights, penalties, breach notification, and a step-by-step compliance roadmap for Irish organisations.