facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··11 min read

If an Australian business, government agency, or organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide walks you through exactly how the OAIC complaints process works, what counts as a privacy breach under the Privacy Act 1988, and how to give yourself the best chance of a good outcome.

What Is the OAIC?

The Office of the Australian Information Commissioner (OAIC) is the independent national regulator responsible for privacy and freedom of information in Australia. It enforces the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs), which govern how most Australian government agencies and organisations with an annual turnover above $3 million must handle personal information.

The OAIC has several key functions: it investigates privacy complaints, oversees the Notifiable Data Breaches (NDB) scheme, issues determinations that can order compensation, and can pursue civil penalty proceedings against serious offenders. For everyday Australians, its most practical role is acting as the free, independent umpire when you believe your privacy rights have been breached.

What Counts as a Privacy Breach Under Australian Law?

A privacy breach occurs when an entity covered by the Privacy Act mishandles your personal information in a way that breaches one or more of the Australian Privacy Principles. "Personal information" is broadly defined and includes anything that can identify you — your name, address, phone number, email, health information, financial data, and even opinions about you.

Common examples of breaches the OAIC investigates include:

  • Unauthorised disclosure: A company shares your details with a third party without your consent.
  • Data breaches: Hackers access a database containing your information because security controls were inadequate.
  • Collection without consent: An organisation collects sensitive information (health, biometric, political views) without a lawful basis.
  • Refusal of access: A company refuses to give you a copy of the personal information it holds about you.
  • Refusal to correct: The organisation won't fix inaccurate information after you've asked.
  • Direct marketing without opt-out: You keep receiving marketing after unsubscribing.
  • Misuse of government identifiers: Improper use of Medicare, tax file numbers, or similar identifiers.

Who the OAIC Can and Cannot Investigate

The OAIC can investigate Australian government agencies, private sector organisations with annual turnover over $3 million, all health service providers regardless of size, credit reporting bodies, and TFN recipients. It generally cannot investigate small businesses (unless they fall into one of the exceptions), state or territory government agencies (which have their own privacy regulators), individuals acting in a personal capacity, or media organisations acting in the course of journalism.

Step 1: Try to Resolve the Issue Directly First

Before the OAIC will accept your complaint, it generally requires you to first complain directly to the organisation and give them a reasonable chance to respond — usually 30 days. This is a mandatory step under section 40(1A) of the Privacy Act, and skipping it will almost always result in the OAIC declining to investigate.

  1. Find the right contact: Look for the organisation's Privacy Officer or Privacy Policy on its website. Larger organisations must publish this contact.
  2. Put your complaint in writing: Email is best because it creates a timestamped record. Clearly state what happened, when, what personal information was involved, and what outcome you want (an apology, deletion, correction, compensation, procedural change).
  3. Set a deadline: Politely ask for a substantive response within 30 days.
  4. Keep everything: Save copies of every email, letter, screenshot, and reference number.

If the organisation ignores you, gives an inadequate response, or refuses to fix the problem, you can then escalate to the OAIC.

Step 2: Gather Your Evidence

The strength of your OAIC complaint depends almost entirely on the evidence you can present. Investigators cannot act on suspicion alone — they need to see a clear chain of events.

Documents and Records to Collect

  • The organisation's Privacy Policy (download a PDF copy in case it changes later).
  • Copies of any consent forms, terms of service, or contracts you signed.
  • All correspondence with the organisation about the breach.
  • Data breach notification emails (if the organisation notified you under the NDB scheme).
  • Screenshots showing the breach — e.g., your data appearing where it shouldn't.
  • Records of any harm suffered: unauthorised charges, spam, phishing attempts, identity theft reports, medical evidence of stress.
  • A written timeline of events with dates.

A Practical Tip on Suspicious Links

If your data was exposed and you now receive suspicious emails or SMS containing links, don't click them directly. Australian regulators recommend inspecting URLs before opening them. Tools like Lunyb allow you to preview and manage links safely, which is particularly useful when you're documenting phishing attempts that followed a suspected breach. Save the full URL as evidence rather than just a screenshot of the display text.

Step 3: Lodge Your Complaint with the OAIC

Once you've given the organisation 30 days and gathered evidence, you can lodge your complaint with the OAIC. There are three ways to do it:

  1. Online form: The fastest and preferred method. Go to oaic.gov.au and use the Privacy Complaint Form. You'll be able to upload attachments.
  2. Post: Send a written complaint to GPO Box 5288, Sydney NSW 2001.
  3. Phone: Call the OAIC Enquiries Line on 1300 363 992 if you need help preparing your complaint or require an interpreter.

What to Include in Your Complaint

A well-structured complaint should include:

  • Your full name and contact details.
  • The name and contact details of the organisation you're complaining about.
  • A clear, chronological description of what happened.
  • Which Australian Privacy Principles you believe were breached (you don't have to be a lawyer — just do your best).
  • What steps you took to resolve it with the organisation, and their response.
  • The harm or impact the breach has had on you.
  • The outcome you're seeking.
  • All supporting documents.

Lodging a complaint with the OAIC is free. You do not need a lawyer, though you can have a representative act for you if you prefer.

Step 4: What Happens After You Lodge

The OAIC follows a structured process. Understanding the stages helps you know what to expect and how long it might take.

StageWhat HappensTypical Timeframe
1. AcknowledgementOAIC confirms receipt and assigns a case reference.Within 10 business days
2. Preliminary assessmentOAIC decides whether it has jurisdiction and whether the complaint has substance.4–8 weeks
3. ConciliationOAIC attempts to broker a resolution between you and the organisation.3–6 months
4. InvestigationIf conciliation fails, formal investigation begins with compulsory information gathering.6–12 months
5. DeterminationCommissioner issues a binding determination that may award compensation.Additional 3–6 months

Possible Outcomes

The OAIC has broad powers to resolve complaints. Possible outcomes include:

  • A formal apology from the organisation.
  • Correction or deletion of your personal information.
  • Changes to the organisation's practices, systems, or policies.
  • Staff training requirements.
  • Financial compensation for economic loss, expenses, and non-economic loss (hurt feelings, humiliation).
  • In serious or systemic cases, civil penalty proceedings that can lead to fines of up to $50 million or more for corporations.

Historically, most compensation awards to individuals fall between $1,000 and $20,000, though serious cases involving sensitive health or financial information have exceeded this.

The Notifiable Data Breaches Scheme

Since February 2018, Australia has operated a mandatory Notifiable Data Breaches (NDB) scheme. Organisations covered by the Privacy Act must notify both the OAIC and affected individuals when a data breach is likely to result in serious harm.

If you receive a data breach notification, it typically means:

  • The organisation has already told the OAIC.
  • You should follow the recommended protective steps (change passwords, monitor accounts, place credit report bans).
  • You can still lodge your own complaint if you believe the organisation's security was inadequate or its response was poor.

Being notified under the NDB scheme does not replace your right to complain — it simply gives you strong evidence that a breach occurred.

Common Mistakes to Avoid

  1. Skipping the direct complaint step. The OAIC will almost always send you back to the organisation first.
  2. Waiting too long. The OAIC can decline complaints made more than 12 months after you became aware of the issue.
  3. Being vague. "They misused my data" is not enough. Say exactly what data, when, and how.
  4. Emotional rather than factual writing. Investigators respond to evidence, not outrage. Keep the tone professional.
  5. Not quantifying harm. If you want compensation, describe the tangible and intangible impact clearly.
  6. Missing deadlines. Respond promptly to OAIC requests — the case can be closed if you don't.

Protecting Yourself After a Breach

Whether or not you pursue a formal complaint, there are practical steps every affected Australian should take after a suspected privacy breach:

  • Change passwords on the affected account and any account using the same password. Use a password manager to generate unique credentials.
  • Enable multi-factor authentication everywhere it is offered.
  • Place a temporary ban on your credit report with Equifax, Experian, and illion — this is free and prevents fraudulent credit applications.
  • Report identity theft to IDCARE (1800 595 160), Australia's free national identity and cyber support service.
  • Report scams that arrive after the breach to Scamwatch.
  • Use encrypted DNS and a privacy-respecting browser to reduce the amount of data leaked passively during normal browsing.
  • Preview links before clicking in any email or SMS that arrives after the breach. Attackers often follow up known breaches with targeted phishing.

For readers running websites or newsletters that collect subscriber data, this is also a good time to audit how you handle links you send out. Using a reputable link management platform like Lunyb gives you HTTPS-protected redirects and click analytics without exposing subscriber behaviour to third-party trackers. If you're comparing options, our 2026 buyer's guide to URL shorteners walks through the privacy trade-offs of each major provider.

When to Escalate Beyond the OAIC

If you're unhappy with the OAIC's determination, you have further avenues:

  • Administrative Appeals Tribunal (AAT): You can apply for review of certain OAIC decisions.
  • Federal Court: Determinations can be enforced through the Federal Court if the organisation refuses to comply.
  • Commonwealth Ombudsman: If you have a complaint about how the OAIC itself handled your matter.
  • State privacy regulators: If your complaint concerns a state government agency (e.g., NSW IPC, Victorian OVIC).

For sector-specific issues, you may also be able to complain to the Telecommunications Industry Ombudsman, the Australian Financial Complaints Authority, or a relevant industry body — sometimes in parallel with an OAIC complaint.

Frequently Asked Questions

How long does an OAIC privacy complaint take?

Simple complaints resolved through conciliation typically take 3–6 months. Complex investigations resulting in a formal determination can take 12–18 months or longer. The OAIC publishes performance statistics annually, and timeframes have been under pressure due to a rising complaint volume since major Australian data breaches in 2022–2023.

Can I get compensation from an OAIC complaint?

Yes. The Commissioner can order compensation for economic loss (out-of-pocket costs, fraud losses) and non-economic loss (humiliation, injury to feelings, stress). Awards to individuals typically range from $1,000 to $20,000, with higher awards in cases involving sensitive information or serious harm. Compensation is more likely if you can document the specific impact of the breach on your life.

Do I need a lawyer to lodge an OAIC complaint?

No. The OAIC process is designed to be accessible to ordinary people without legal representation. The online complaint form guides you through the required information, and OAIC staff can help by phone. You may choose to engage a lawyer for complex matters or if you're seeking significant compensation, but it's not required.

What if the organisation is a small business under $3 million turnover?

Most small businesses aren't covered by the Privacy Act, so the OAIC generally cannot investigate them. However, there are important exceptions: all health service providers, businesses that trade in personal information, contractors to Australian government agencies, and businesses that have opted in to the Privacy Act are all covered regardless of size. If a small business isn't covered, you may still have options under Australian Consumer Law or state-based fair trading regulators.

Can I complain anonymously?

The OAIC can accept anonymous privacy concerns, but it generally cannot investigate a formal complaint without knowing who is affected — partly because remedies like compensation or correction of records require identifying the individual. If you want the organisation to be investigated but don't want your identity shared with them, you can request confidentiality, and the OAIC will consider whether this is workable in your specific case.

Final Thoughts

The OAIC complaints process is one of the strongest privacy protection tools available to Australians, and it's free to use. The keys to a successful complaint are patience, thorough documentation, and a professional, factual tone. Start by giving the organisation a genuine chance to fix the problem, gather every piece of evidence you can, and then present a clear timeline to the OAIC.

Privacy law in Australia is undergoing its biggest overhaul in decades, with reforms strengthening individual rights, introducing a statutory tort for serious invasions of privacy, and increasing penalties for organisations. Whether or not those reforms directly benefit your current complaint, exercising your existing rights sends a clear signal that Australians expect their personal information to be handled with care.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles