facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide walks you through exactly how to report a privacy breach, what evidence you need, what timelines to expect, and how to give your complaint the best possible chance of a good outcome.

What Is the OAIC?

The Office of the Australian Information Commissioner (OAIC) is Australia's independent national privacy regulator. It administers the Privacy Act 1988 (Cth), enforces the 13 Australian Privacy Principles (APPs), and handles complaints from individuals whose personal information has been mishandled by organisations covered by the Act.

The OAIC can investigate complaints, conciliate disputes, make binding determinations, order compensation, and issue civil penalty proceedings against serious or repeated offenders. It also oversees the Notifiable Data Breaches (NDB) scheme, which requires organisations to notify affected individuals of eligible data breaches.

Who Does the OAIC Regulate?

Not every organisation falls under the OAIC's jurisdiction. Generally, the Privacy Act applies to:

  • Australian Government agencies
  • Private sector organisations with an annual turnover of more than $3 million
  • Health service providers of any size
  • Businesses that trade in personal information
  • Credit providers and credit reporting bodies
  • Tax File Number (TFN) recipients

State and territory government agencies are usually covered by their own state privacy laws, not the federal Privacy Act. Small businesses under $3 million turnover are typically exempt, unless they fall into one of the special categories above.

What Counts as a Privacy Breach?

A privacy breach occurs when personal information is collected, used, disclosed, stored or destroyed in a way that contravenes the Australian Privacy Principles or another provision of the Privacy Act. It doesn't need to involve hackers or leaked databases — many complaints involve everyday misconduct.

Common Examples of Reportable Breaches

  • Unauthorised disclosure — an organisation shares your details with a third party without consent.
  • Data breaches — your data is exposed through hacking, phishing or accidental publication.
  • Collection without consent — a business gathers sensitive information you never agreed to provide.
  • Refusal to provide access — you request your own data under APP 12 and are ignored or denied without a valid reason.
  • Refusal to correct inaccurate information — the organisation won't fix wrong data about you (APP 13).
  • Direct marketing misuse — you keep receiving marketing after opting out (APP 7).
  • Overseas disclosure — your information was sent overseas without appropriate safeguards (APP 8).
  • Poor security — an organisation failed to take reasonable steps to protect your information (APP 11).

Step 1: Complain Directly to the Organisation First

Before the OAIC will accept your complaint, you must give the organisation a chance to respond. This is a mandatory step under section 40(1A) of the Privacy Act. Skipping it is the most common reason complaints get bounced back.

How to Make an Effective Internal Complaint

  1. Find the right contact. Most organisations publish a privacy policy naming a Privacy Officer, Data Protection Officer, or complaints email.
  2. Put it in writing. Email is best — it creates a timestamped record.
  3. Be specific. Describe what happened, when, which information was involved, and which APP you believe was breached.
  4. State the outcome you want. This might be an apology, deletion of your data, correction, a policy change, or compensation.
  5. Give them 30 days. The OAIC generally expects organisations to be given at least 30 days to respond.

If the organisation refuses to respond, responds inadequately, or the 30-day window closes without a satisfactory outcome, you can escalate to the OAIC.

Step 2: Gather Your Evidence

A well-documented complaint moves faster and has a higher chance of success. The OAIC assesses complaints based on the material you provide, so treat evidence-gathering as the foundation of your case.

Evidence Checklist

  • Copies of the organisation's privacy policy at the time of the incident
  • Any consent forms, terms of service, or account settings screenshots
  • The full email chain with the organisation's complaints team
  • Screenshots of the breach itself (leaked information, unauthorised messages, etc.)
  • Notification letters from the organisation, if it was a data breach
  • A timeline of events, written in dot points with specific dates
  • Evidence of harm — financial loss, distress, identity theft attempts, spam volume, medical records if the incident affected your health

Save everything in a single folder. If you shared any suspicious or unauthorised links as part of a phishing incident, keep the raw URLs — tools that inspect link destinations, such as Lunyb's link preview features, can help you safely document where a suspicious short link actually leads without clicking through.

Step 3: Lodge Your Complaint With the OAIC

Once you've exhausted the internal process, you can formally complain to the OAIC. There is no fee to lodge a complaint.

Ways to Lodge

MethodDetailsBest For
Online formAvailable at oaic.gov.au — the preferred methodMost complainants
PostGPO Box 5218, Sydney NSW 2001Complex complaints with physical documents
Emailenquiries@oaic.gov.auFollow-up correspondence
Phone1300 363 992 (National Information Line)Initial guidance and accessibility support

What to Include in Your Complaint

  1. Your full name and contact details
  2. The name of the organisation you're complaining about
  3. A clear description of what happened
  4. The dates involved
  5. Which Australian Privacy Principle(s) you believe were breached
  6. Evidence of your internal complaint and the organisation's response (or lack of it)
  7. The outcome you're seeking
  8. Any supporting documents

Step 4: What Happens After You Lodge

Once the OAIC receives your complaint, it moves through a structured pathway. Understanding the process helps you set realistic expectations — some matters resolve in weeks, others take many months.

The OAIC Complaint Pathway

  1. Preliminary assessment. The OAIC checks that your complaint falls within its jurisdiction, that you complained to the organisation first, and that it isn't frivolous or out of time.
  2. Early resolution. Many complaints are resolved at this stage through informal contact between the OAIC and the organisation.
  3. Conciliation. If early resolution fails, the OAIC may formally conciliate — a neutral officer helps both parties negotiate an outcome.
  4. Investigation. For serious or unresolved matters, the Commissioner can open a formal investigation with compulsory information-gathering powers.
  5. Determination. If a breach is confirmed and no agreement is reached, the Commissioner can issue a legally binding determination, including orders for compensation, apology, or corrective action.

Timeframes

The OAIC aims to finalise most complaints within 12 months, but this varies significantly depending on complexity. Simple matters may close in 3–6 months. Investigations that end in a formal determination can take 18 months or more. You should complain within 12 months of becoming aware of the alleged breach, or the OAIC may decline to investigate under section 41(1)(c) of the Privacy Act.

Possible Outcomes

Understanding what the OAIC can and can't do helps you decide whether a complaint is the right path.

What the OAIC Can Do

  • Require the organisation to apologise
  • Order it to change its practices, systems, or staff training
  • Order deletion or correction of your data
  • Award compensation for financial loss and non-economic loss (distress, humiliation, injury to feelings)
  • Publish determinations, creating public accountability
  • Commence civil penalty proceedings for serious or repeated interferences with privacy

What the OAIC Can't Do

  • Impose criminal penalties (that's a court matter)
  • Award unlimited damages — compensation is generally modest, often in the low thousands
  • Deal with complaints against small businesses outside its jurisdiction
  • Force an organisation to reinstate an employment relationship or contract
  • Rule on issues outside the Privacy Act (defamation, consumer law, etc.)

Notifiable Data Breaches: A Special Category

Under the Notifiable Data Breaches (NDB) scheme, organisations covered by the Privacy Act must notify both the OAIC and affected individuals when an eligible data breach occurs — one that's likely to result in serious harm.

What to Do If You Receive a Data Breach Notification

  1. Read it carefully. Note which categories of your data were involved.
  2. Change affected credentials. Update passwords and enable two-factor authentication.
  3. Monitor your accounts. Watch for unauthorised transactions or new accounts opened in your name.
  4. Consider a credit ban. Free short-term credit bans are available through Equifax, Experian and illion.
  5. Report identity theft. Contact IDCARE (1800 595 160) for free case management.
  6. Keep the notification. You may need it as evidence if you later complain to the OAIC about how the breach was handled.

Receiving a notification does not automatically mean you have grounds for a successful complaint. The complaint would need to focus on the organisation's failure to protect your data adequately (APP 11) or how it handled the response — not simply the fact of the breach.

Tips for a Stronger Complaint

The OAIC handles thousands of complaints each year. Making yours easy to assess and hard to dismiss gives it the best chance.

  • Be concise and factual. Assessment officers read hundreds of pages a week — a clear, chronological summary is more persuasive than an emotional narrative.
  • Cite specific APPs. Referencing the exact principle you believe was breached shows you've done your homework.
  • Quantify harm where possible. "I received 47 spam calls in the two weeks after the breach" is stronger than "I got lots of spam."
  • Propose a reasonable outcome. Requests that are proportionate to the harm are taken more seriously.
  • Respond promptly to OAIC requests. If assessment officers ask for more information, reply quickly — delays on your end slow everything down.
  • Consider seeking legal advice. Community legal centres often provide free advice on privacy matters.

Protecting Your Privacy Going Forward

A complaint addresses what already happened. Preventing the next incident is equally important. A few practical habits significantly reduce your exposure:

  • Use unique, strong passwords in a reputable password manager.
  • Enable two-factor authentication on every account that supports it.
  • Use encrypted DNS resolvers and a privacy-respecting browser.
  • Regularly review app permissions on your phone and browser.
  • Before clicking unfamiliar shortened links, preview them with a trustworthy inspector. Reviews like our 2026 buyer's guide to URL shorteners and our honest review of Lunyb cover which services offer preview and safety features.
  • Request access to your data annually from services you use most — it's a good way to spot silent scope creep.

FAQ

How long do I have to lodge an OAIC complaint?

Generally, you should complain within 12 months of becoming aware of the alleged privacy breach. The OAIC has discretion to accept late complaints in exceptional circumstances, but it's not guaranteed — lodge as soon as you have completed the internal complaint step.

Does it cost anything to complain to the OAIC?

No. Lodging a complaint is free. You may choose to pay for legal advice or representation, but it isn't required — the OAIC process is designed to be accessible to individuals without lawyers.

Can I complain about a small business or state government agency?

Usually not to the OAIC. Small businesses with turnover under $3 million are generally exempt from the federal Privacy Act, and state/territory government agencies are covered by state privacy laws (for example, the NSW Information and Privacy Commission or the Office of the Victorian Information Commissioner). Check the relevant state regulator's website for the correct pathway.

How much compensation can I get?

There is no fixed cap, but historical determinations have generally awarded amounts ranging from a few hundred dollars to several thousand for non-economic loss such as distress. Larger awards can occur where there is significant financial loss or particularly serious mishandling. Compensation is not the OAIC's primary focus — behavioural change and systemic remedies often carry more weight.

What if the OAIC decides not to investigate my complaint?

The OAIC can decline to investigate for several reasons — jurisdictional issues, the complaint being made too late, or the matter being trivial or already adequately dealt with. If you disagree, you can request an internal review of the decision. In rare cases, further review may be available through the Administrative Review Tribunal.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles