facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··9 min read

If an Australian business, government agency, or organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). The OAIC is the national regulator responsible for enforcing the Privacy Act 1988 and investigating breaches of the Australian Privacy Principles (APPs). This guide explains exactly how to lodge an OAIC complaint about a privacy breach, what evidence you need, how long the process takes, and what outcomes you can realistically expect.

What Is the OAIC and When Can You Complain?

The Office of the Australian Information Commissioner (OAIC) is the independent federal agency that oversees privacy and freedom of information law in Australia. You can lodge a complaint with the OAIC when an entity covered by the Privacy Act has interfered with your personal information in a way that breaches the Australian Privacy Principles, a registered APP code, or the Notifiable Data Breaches (NDB) scheme.

Covered entities generally include:

  • Australian Government agencies
  • Private sector organisations with an annual turnover of more than $3 million
  • All health service providers (regardless of turnover)
  • Credit reporting bodies and credit providers
  • Tax File Number recipients
  • Some small businesses that trade in personal information or provide services under Commonwealth contracts

If the entity is a state or territory government agency, a small business not covered by the Act, or an employer dealing with an employee record, the OAIC usually cannot help and you may need to approach a state privacy regulator or ombudsman instead.

Common Examples of Privacy Breaches

  • An organisation discloses your personal data to a third party without consent
  • A company suffers a data breach and your details are leaked online
  • A business refuses to give you access to the personal information it holds about you
  • Your information is used for direct marketing after you opted out
  • Inaccurate personal data is not corrected despite your request
  • A health provider shares your medical records inappropriately

Step 1: Complain Directly to the Organisation First

Before the OAIC will accept a complaint, you must usually give the organisation a chance to fix the problem. This is a mandatory step under section 40(1A) of the Privacy Act. Skipping it is the single most common reason complaints are rejected or sent back.

  1. Identify the correct contact. Look for the organisation's Privacy Officer, Privacy Policy page, or a dedicated privacy@ email address.
  2. Put your complaint in writing. Email creates a time-stamped record. Clearly state what happened, when, which personal information was involved, and what outcome you want (apology, correction, deletion, compensation).
  3. Request a written response. Ask the organisation to reply within 30 days, which is the standard timeframe the OAIC expects.
  4. Keep every reply. Save emails, letters, and reference numbers. You will need these if you escalate.

If the organisation does not respond within 30 days, refuses to address the issue, or gives a response you consider inadequate, you can escalate the matter to the OAIC.

Step 2: Gather Your Evidence Before Lodging

A well-documented complaint moves faster. The OAIC is a small regulator with a large caseload, so clarity directly affects how quickly your matter is triaged.

Checklist of Evidence to Prepare

  • Your full name, contact details, and preferred communication method
  • The exact legal name of the organisation involved (check ABN Lookup if unsure)
  • A timeline of events with dates
  • Copies of all correspondence with the organisation
  • Screenshots of the breach (for example, a public listing exposing your data)
  • Any data breach notification you received
  • Evidence of harm: financial loss, scam attempts, identity theft reports, medical impact, or emotional distress
  • A clear statement of the remedy you are seeking

If sensitive URLs or links are part of your evidence (for example, a page that exposed your details), copy the full URL exactly as it appeared. Avoid using tracking-heavy shortened links from unknown providers when submitting evidence; stick to the original URL or use a transparent, privacy-respecting shortener such as Lunyb if a link is too long to include cleanly in a form.

Step 3: Lodge Your Complaint with the OAIC

The OAIC accepts privacy complaints through several channels. Online lodgement is the fastest and generates an automatic reference number.

Ways to Lodge

  1. Online form: Visit oaic.gov.au and complete the "Privacy complaint form". This is the recommended method.
  2. Email: Send a completed PDF complaint form to enquiries@oaic.gov.au.
  3. Post: GPO Box 5218, Sydney NSW 2001.
  4. Phone: Call 1300 363 992 if you need assistance or an interpreter, though the complaint itself must eventually be in writing.

Information the Form Will Ask For

  • Your personal and contact details
  • The respondent organisation's details
  • A description of the alleged interference with privacy
  • Evidence you have already complained to the organisation
  • The organisation's response (or lack thereof)
  • Any harm or loss you have suffered
  • The outcome you are seeking

Lodgement is free. You do not need a lawyer, although for complex matters involving financial loss or large-scale breaches, legal advice can be useful.

Step 4: What Happens After You Lodge

Once submitted, your complaint moves through a defined OAIC process. Understanding each stage helps you set realistic expectations about timing and outcomes.

Stage 1: Assessment and Triage

The OAIC first checks whether your complaint falls within its jurisdiction, whether you complained to the organisation first, and whether the matter is suitable for investigation. This typically takes a few weeks. The OAIC may decline to investigate if the complaint is frivolous, more than 12 months old without good reason, or already being handled by another body.

Stage 2: Conciliation

Most privacy complaints are resolved through conciliation rather than formal determination. The OAIC acts as an intermediary, helping you and the organisation reach an agreed outcome. Common conciliated outcomes include:

  • Written apology
  • Correction or deletion of your personal information
  • Changes to the organisation's privacy practices
  • Staff training commitments
  • Monetary compensation (typically modest, ranging from a few hundred to several thousand dollars)

Stage 3: Investigation and Determination

If conciliation fails, the Commissioner may conduct a formal investigation and issue a determination under section 52 of the Privacy Act. Determinations are legally enforceable and can require the respondent to:

  • Stop the offending conduct
  • Take specified steps to redress the harm
  • Pay compensation, including for non-economic loss such as distress and humiliation

OAIC Complaint Process at a Glance

StageTypical TimeframeYour RolePossible Outcome
Complain to organisationUp to 30 daysSubmit written complaintResolution or inadequate response
Lodge with OAICSame dayComplete online formReference number issued
Assessment2–6 weeksRespond to clarifying questionsAccepted, declined, or referred
Conciliation3–12 monthsNegotiate via OAICAgreed resolution
Investigation and determination12–24+ monthsProvide further evidenceBinding orders, compensation

Notifiable Data Breaches: A Special Pathway

Since February 2018, the Notifiable Data Breaches (NDB) scheme requires covered entities to notify both the OAIC and affected individuals when a data breach is likely to result in serious harm. If you receive an NDB notification letter or email, you have specific rights.

What to Do If You Receive a Breach Notification

  1. Read the notice carefully to understand which of your data was exposed
  2. Follow the recommended protective steps (change passwords, enable multi-factor authentication, monitor credit reports)
  3. Place a credit ban through Equifax, Experian, or illion if financial data was involved
  4. Report any resulting scams to Scamwatch and ReportCyber
  5. Keep the notification—it is strong evidence if you later lodge an OAIC complaint for inadequate handling of the breach

You can complain to the OAIC not just about the breach itself but about how the organisation handled it: late notification, incomplete information, or failure to offer reasonable remediation.

Representative Complaints and Class Actions

Where many people are affected by the same breach, such as the large-scale incidents involving major Australian telcos, health insurers, and retailers, individuals can join a representative complaint. The OAIC can handle complaints lodged on behalf of a group, and private class actions in the Federal Court have become more common for large breaches. If a representative action is already underway, check whether you are automatically included or need to opt in.

Reducing Your Risk of Future Privacy Breaches

While regulators provide important recourse, prevention remains the best protection. Simple habits significantly reduce how much of your data is exposed in the first place.

Practical Steps

  • Minimise what you share. Only provide the personal information strictly required for a service.
  • Use unique passwords stored in a reputable password manager.
  • Turn on multi-factor authentication for email, banking, government services (myGov), and social accounts.
  • Use encrypted DNS and privacy-focused browsers to limit tracking at the network level.
  • Audit app permissions on your phone every few months.
  • Be cautious with link shorteners. Opaque links can hide phishing destinations. Use transparent tools like Lunyb that let you preview destinations, and read our 2026 buyer's guide to URL shorteners for safer alternatives.
  • Request your data from major services annually to see what they hold.

When to Seek External Help

Some matters sit outside the OAIC's remit or benefit from additional support:

  • State government agencies: Contact the relevant state privacy commissioner (for example, IPC NSW, OVIC Victoria, OIC Queensland).
  • Telecommunications issues: The Telecommunications Industry Ombudsman (TIO) handles telco-specific complaints.
  • Financial services: The Australian Financial Complaints Authority (AFCA) manages banking, insurance, and super disputes.
  • Identity theft: IDCARE offers free specialist case management for identity and cyber support.
  • Scams and cybercrime: Report through Scamwatch and ReportCyber.

Frequently Asked Questions

How long do I have to lodge an OAIC complaint?

The OAIC may decline to investigate complaints lodged more than 12 months after you became aware of the alleged breach. Lodge as soon as practical after the organisation has had a reasonable opportunity (usually 30 days) to respond.

Does it cost anything to complain to the OAIC?

No. Lodging a privacy complaint with the OAIC is free. You do not need legal representation, though you may choose to seek it for complex matters involving significant financial loss.

Can I get compensation for a privacy breach?

Yes, in some cases. Compensation can be agreed during conciliation or ordered through a formal determination. Amounts vary widely and may cover both financial loss and non-economic loss such as distress. Awards are typically modest unless harm is substantial.

Can I complain anonymously?

You can raise concerns anonymously, but a formal complaint usually requires your identity so the OAIC can investigate and the respondent can respond. The OAIC handles your information confidentially within the limits of procedural fairness.

What if the organisation is based overseas?

The Privacy Act has extraterritorial reach. Overseas organisations that collect or hold the personal information of Australians, and have an Australian link, can still be subject to the Act. The OAIC can investigate, although enforcement against foreign entities is more complex.

Will my complaint be made public?

Individual complaints are generally handled privately. However, formal determinations by the Commissioner are published on the OAIC website, usually with the complainant's name anonymised unless they consent to being identified.

Final Thoughts

Lodging an OAIC complaint is one of the most powerful tools Australians have to hold organisations accountable for mishandling personal information. The process rewards preparation: complain to the organisation first, document everything, state clearly what remedy you want, and lodge within the 12-month window. While conciliation delivers most outcomes, the regulator's ability to issue binding determinations and compensation orders ensures that serious breaches carry real consequences. Combine formal complaint pathways with strong personal privacy habits, and you will meaningfully reduce both the frequency and the impact of future breaches.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles