facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··9 min read

If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). The OAIC is the national regulator responsible for enforcing the Privacy Act 1988 and the Australian Privacy Principles (APPs). This guide explains, step by step, how to report a privacy breach, what evidence to gather, and what to expect once your complaint is lodged.

What Is the OAIC and What Does It Regulate?

The Office of the Australian Information Commissioner (OAIC) is the independent Commonwealth agency that oversees privacy, freedom of information, and government information policy in Australia. It handles complaints against most Australian Government agencies and private sector organisations with an annual turnover of more than $3 million, along with some smaller businesses (such as health service providers and credit reporting bodies).

The OAIC's key functions include:

  • Investigating complaints about mishandling of personal information
  • Regulating the Notifiable Data Breaches (NDB) scheme
  • Issuing guidance and determinations under the Privacy Act
  • Taking enforcement action, including seeking civil penalties

When You Can Complain to the OAIC

You can lodge a complaint if you believe an APP entity has breached your privacy — for example, by disclosing your personal information without consent, refusing you access to your own data, failing to secure it adequately, or using it for a purpose you never agreed to.

What Counts as a Privacy Breach Under Australian Law?

A privacy breach occurs when personal information is accessed, used, disclosed, or lost in a way that contravenes the Privacy Act or the Australian Privacy Principles. Personal information is broadly defined and includes anything that can identify you, such as your name, address, phone number, email, health records, financial details, biometric data, or online identifiers.

Common Examples of Privacy Breaches

  • A retailer emailing your order details to the wrong customer
  • A hospital losing a USB drive containing patient records
  • A bank being hacked and customer data being posted on the dark web
  • An employer sharing your medical certificate with colleagues
  • A telco selling your contact details to a third party without consent
  • An organisation refusing to correct inaccurate information they hold about you

Serious vs. Eligible Data Breaches

Under the Notifiable Data Breaches scheme, organisations must notify both the OAIC and affected individuals when an eligible data breach occurs — that is, when unauthorised access, disclosure or loss is likely to result in serious harm. If you were notified of such a breach, you may still lodge a complaint about how the organisation handled it.

Step 1: Complain to the Organisation First

Before the OAIC will formally investigate, you generally need to complain directly to the organisation and give them a reasonable opportunity to respond — usually 30 days.

  1. Identify the right contact. Most organisations must publish a privacy policy that lists a Privacy Officer or complaints contact. Check their website footer or "Privacy" page.
  2. Put your complaint in writing. Email or a written letter creates a clear record. State that you are making a formal privacy complaint under the Privacy Act 1988.
  3. Describe the breach clearly. Include dates, what personal information was involved, how you found out, and any harm caused.
  4. State what you want. This might be an apology, correction of records, deletion of data, changes to systems, or compensation.
  5. Set a deadline. Request a substantive response within 30 days.

What If the Organisation Doesn't Respond?

If you receive no response within 30 days, or the response is inadequate, you can escalate to the OAIC. Keep copies of everything — emails, letters, screenshots, and any reference numbers.

Step 2: Gather Your Evidence

A well-documented complaint is far more likely to progress quickly. Before submitting to the OAIC, collect:

  • A timeline of events with specific dates
  • Copies of correspondence with the organisation
  • Screenshots of any misdirected emails, exposed data, or online listings
  • The organisation's privacy policy (download a copy in case it changes)
  • Any breach notification letter you received
  • Evidence of harm — financial loss, identity theft reports, medical records for stress-related impact, or lost business opportunities

Tips for Preserving Digital Evidence

Take full-page screenshots including URLs and timestamps. If a suspicious link was involved in the breach (for example, a phishing message that scraped your data), preserve the original URL. Analytics-enabled shortening tools like Lunyb can also help you safely archive and share suspicious links with investigators without exposing others to the raw destination.

Step 3: Lodge Your Complaint With the OAIC

Once you've given the organisation a chance to respond, you can submit your complaint to the OAIC. There is no fee to lodge a privacy complaint.

How to Submit

  1. Online form: The fastest method. Visit oaic.gov.au and complete the Privacy Complaint Form.
  2. Email or post: Download the form and send it to the OAIC's Sydney office.
  3. Phone: Call the OAIC enquiries line on 1300 363 992 if you need help lodging or have accessibility requirements.

Information the OAIC Will Ask For

CategoryDetails Required
Your detailsName, contact information, preferred method of communication
The respondentName of the organisation or agency you're complaining about
The breachWhat happened, when, and what personal information was involved
Prior contactEvidence you complained to the organisation and their response (or lack of one)
ImpactHow the breach affected you — financial, emotional, reputational
Desired outcomeWhat resolution you're seeking

Step 4: What Happens After You Lodge

The OAIC follows a structured process, though timeframes vary depending on complexity and current caseload.

Initial Assessment

An officer reviews whether your complaint falls within the OAIC's jurisdiction and meets the threshold requirements (for example, whether you first raised it with the organisation). This stage can take several weeks.

Conciliation

The OAIC's preferred approach is conciliation — helping both parties reach a mutually acceptable outcome without a formal determination. This might include an apology, policy changes, staff retraining, or a compensation payment.

Investigation and Determination

If conciliation fails or the matter is serious, the Commissioner may formally investigate and issue a determination under section 52 of the Privacy Act. Determinations are legally enforceable and can order:

  • The organisation to stop the offending conduct
  • Corrective actions to prevent recurrence
  • Compensation for financial loss and non-economic harm (such as distress)
  • Publication of an apology

Civil Penalties

For serious or repeated interferences with privacy, the OAIC can seek civil penalties in the Federal Court. Following 2022 reforms, maximum penalties for body corporates are the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover during the breach period.

Realistic Timelines and Outcomes

Simple complaints resolved through conciliation can be finalised within a few months. Complex matters involving formal investigation may take a year or more. The OAIC publishes yearly statistics showing typical resolution times — checking these before you lodge can help set expectations.

What the OAIC Cannot Do

  • Impose criminal penalties (that's a matter for police and the DPP)
  • Award unlimited compensation — awards are typically modest, in the low thousands to low tens of thousands
  • Investigate small businesses under $3 million turnover unless an exception applies
  • Handle complaints about state or territory government agencies (contact your state privacy regulator instead)

State and Territory Alternatives

If your complaint is against a state or territory government body, you'll need to go to the relevant state regulator:

JurisdictionRegulator
NSWInformation and Privacy Commission NSW
VictoriaOffice of the Victorian Information Commissioner
QueenslandOffice of the Information Commissioner Queensland
WANo standalone privacy Act (health only via HaDSCO)
SAPrivacy Committee of South Australia
TasmaniaTasmanian Ombudsman
ACTOAIC (handles ACT public sector under an agreement)
NTOffice of the Information Commissioner NT

Protecting Yourself After a Breach

While the OAIC handles the regulatory side, you should take immediate practical steps to reduce ongoing harm from a breach.

Immediate Actions

  1. Change compromised passwords and enable multi-factor authentication on affected accounts.
  2. Place a credit ban with all three Australian credit reporting bodies (Equifax, Experian, illion) if financial details were exposed. A ban lasts 21 days and can be extended.
  3. Contact IDCARE (1800 595 160) — Australia's free national identity and cyber support service.
  4. Report scams to Scamwatch if you receive phishing attempts following the breach.
  5. Monitor your accounts and credit reports for suspicious activity for at least 12 months.

Longer-Term Privacy Hygiene

Use a password manager, keep separate email addresses for high-risk accounts, and be conservative about what you share online. When sharing links containing tracking parameters or session data, use a privacy-conscious shortener — you can see how a service like Lunyb approaches user privacy in this honest review, or compare options in our 2026 buyer's guide.

Getting Help With Your Complaint

You don't need a lawyer to lodge an OAIC complaint, and most people handle the process themselves. However, free help is available from:

  • Community legal centres — many offer free advice on consumer and privacy matters
  • Legal Aid in your state or territory
  • IDCARE case managers for identity crime and data breach support
  • The OAIC enquiries line (1300 363 992) for procedural questions

Frequently Asked Questions

How much does it cost to lodge an OAIC complaint?

Nothing. Lodging a privacy complaint with the OAIC is completely free. There are no filing fees, and you don't need legal representation. If a matter proceeds to Federal Court for enforcement, costs may apply, but the OAIC — not you — runs those proceedings.

How long do I have to make a complaint?

There is no strict statutory limit, but the OAIC may decline to investigate complaints made more than 12 months after you became aware of the breach unless there are good reasons for the delay. Lodge as soon as reasonably possible after giving the organisation their 30-day response window.

Can I get compensation for a privacy breach?

Yes. The Commissioner can order compensation for financial loss, expenses reasonably incurred, and non-economic loss such as humiliation, distress, or injury to feelings. Awards are typically modest — often between $3,000 and $20,000 for individual complaints — but larger amounts have been awarded in serious cases.

What if the organisation is based overseas?

The Privacy Act has extraterritorial reach. If an overseas organisation has an "Australian link" — for example, it carries on business in Australia and collects information here — the OAIC can investigate. Enforcement against purely offshore entities is harder in practice, but the OAIC cooperates with overseas regulators.

Do I have to notify the OAIC if I'm the victim of a breach?

No. The obligation to notify the OAIC under the Notifiable Data Breaches scheme falls on the organisation that suffered the breach, not the individuals affected. You can, however, lodge a complaint if you believe your privacy has been interfered with — including by the organisation's failure to notify you.

Final Thoughts

The OAIC complaints process is designed to be accessible without legal help. The keys to a successful outcome are complaining to the organisation first, gathering solid evidence, being specific about the harm you've suffered, and being clear about the remedy you want. Australia's privacy framework isn't perfect, but it gives individuals real leverage — and every well-documented complaint helps improve the standards organisations are held to.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles