facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If your personal information has been mishandled, exposed in a data breach, or used without your consent by an Australian business or government agency, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide walks you through exactly how to report a privacy breach, what the OAIC can and can't do, and how to give your complaint the best chance of a meaningful outcome.

What Is the OAIC and What Does It Do?

The Office of the Australian Information Commissioner (OAIC) is the independent federal regulator responsible for enforcing the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It investigates complaints about how organisations handle personal information, oversees the Notifiable Data Breaches (NDB) scheme, and can pursue enforcement action against entities that breach privacy law.

The OAIC handles complaints against:

  • Australian Government agencies
  • Private-sector businesses with an annual turnover of more than AUD $3 million
  • Smaller businesses that trade in personal information, provide health services, or contract with the federal government
  • Credit providers and credit reporting bodies
  • Tax File Number (TFN) recipients

The OAIC generally cannot investigate state or territory government agencies, most small businesses, employee records held by an employer, or media organisations acting in a journalistic capacity. In those cases, you may need to contact a state privacy commissioner or another regulator instead.

What Counts as a Privacy Breach Under Australian Law?

A privacy breach occurs when personal information is collected, used, disclosed, stored, or destroyed in a way that contravenes the Australian Privacy Principles or another provision of the Privacy Act. This includes both accidental exposure and deliberate misuse.

Common Examples of Reportable Breaches

  • Data breaches: Hackers accessing a customer database, a lost laptop with unencrypted client files, or an email sent to the wrong recipient.
  • Unauthorised disclosure: A staff member sharing your medical records with a third party without consent.
  • Excessive collection: A retailer demanding your driver's licence for a small return.
  • Misuse of information: Using your email address for marketing after you opted out.
  • Refusal of access or correction: An organisation ignoring your request to see or fix your own data.
  • Poor security: Storing customer passwords in plain text or leaving files publicly accessible online.

The Notifiable Data Breaches Scheme

Under the NDB scheme, organisations covered by the Privacy Act must notify both the OAIC and affected individuals when a data breach is likely to result in serious harm. If you received a data breach notification letter or email, that organisation has already reported the incident — but you can still make your own complaint if you believe your rights were violated or the response was inadequate.

Step 1: Complain Directly to the Organisation First

Before the OAIC will accept your complaint, you generally must give the organisation a chance to resolve the issue. This is a mandatory first step in most cases.

  1. Identify the right contact. Look for the organisation's Privacy Officer, Data Protection Officer, or privacy policy page. Most Australian businesses publish contact details for privacy enquiries.
  2. Put your complaint in writing. Email or a written letter creates a paper trail. State clearly what happened, when, what personal information was involved, and what you want the organisation to do.
  3. Set a reasonable deadline. Ask for a response within 30 days. This is the standard timeframe the OAIC expects organisations to meet.
  4. Keep copies of everything. Save the original complaint, any acknowledgements, and every reply.

If the organisation doesn't respond within 30 days, gives an inadequate response, or refuses to fix the problem, you can escalate to the OAIC.

Step 2: How to Lodge an OAIC Complaint

An OAIC complaint is a formal written request for the Information Commissioner to investigate a suspected interference with your privacy. You can lodge one online, by post, or by email — there is no fee.

Ways to Submit Your Complaint

MethodDetailsBest For
Online formVia oaic.gov.au — the fastest optionMost individual complainants
Emailenquiries@oaic.gov.au with attached complaint formPeople who prefer to attach evidence files
PostGPO Box 5288, Sydney NSW 2001Complex matters or those without internet access
Phone (enquiry only)1300 363 992 — for guidance, not lodgementInitial questions before lodging

Information You'll Need to Provide

  • Your full name and contact details
  • The name of the organisation or agency you're complaining about
  • A clear description of what happened and when
  • What personal information was involved
  • How you believe the Privacy Act or APPs were breached
  • What steps you've already taken to resolve the matter
  • The outcome you're seeking (apology, correction, compensation, procedural change)
  • Supporting documents: emails, screenshots, letters, breach notifications

Step 3: What Happens After You Lodge?

Once the OAIC receives your complaint, it moves through a structured assessment and resolution process. Understanding each stage helps set realistic expectations about timing and outcomes.

The OAIC Complaint Process

  1. Acknowledgement (1–2 weeks): You'll receive confirmation that your complaint has been received and a reference number.
  2. Preliminary assessment: The OAIC decides whether it has jurisdiction and whether the complaint is suitable for investigation. Some matters may be declined if you didn't first approach the organisation, if the complaint is more than 12 months old without a good reason, or if it's frivolous or vexatious.
  3. Conciliation: The OAIC often tries to broker a resolution between you and the organisation. This is confidential and non-adversarial, and it resolves the majority of complaints.
  4. Formal investigation: If conciliation fails or the matter is serious, the Commissioner may conduct a formal investigation, request documents, and interview witnesses.
  5. Determination: The Commissioner can make a legally binding determination, including ordering compensation, requiring an apology, or directing procedural changes.

Straightforward complaints can be resolved in a few months, while formal investigations may take a year or longer.

Possible Outcomes and Remedies

The OAIC has broad remedial powers under section 52 of the Privacy Act. Outcomes can be practical, symbolic, or financial.

RemedyDescription
ApologyWritten acknowledgement and apology from the organisation
Correction of recordsFixing inaccurate personal information
Access to informationProviding you with a copy of data held about you
Deletion or de-identificationRemoving information the organisation shouldn't hold
CompensationPayment for financial loss, non-economic loss, or aggravated damages
Procedural changeStaff training, updated policies, new security controls
Civil penalty proceedingsFor serious or repeated interferences, court action with penalties up to millions of dollars for corporations

Pros and Cons of Lodging an OAIC Complaint

Pros

  • Free to lodge — no legal fees required
  • Independent, government-backed regulator with real enforcement powers
  • Conciliation is confidential and low-conflict
  • Can result in compensation and systemic change
  • Creates public accountability for large data breaches

Cons

  • Can be slow — months to years for complex matters
  • OAIC has jurisdictional limits (excludes many small businesses and state agencies)
  • Compensation amounts are typically modest compared with court awards
  • You must usually complain to the organisation first
  • The OAIC prioritises systemic issues; individual complaints may be conciliated rather than fully investigated

How to Strengthen Your Complaint

A well-prepared complaint gets faster attention and better outcomes. Focus on clarity, evidence, and specifics.

  1. Be concise but complete. Stick to facts. A two to four page written statement is usually enough.
  2. Link facts to APPs. Where possible, identify which Australian Privacy Principle you believe was breached (for example, APP 6 for use and disclosure, APP 11 for security).
  3. Quantify harm. Explain financial loss, time spent responding, emotional distress, or reputational damage.
  4. Provide a timeline. A dated sequence of events is much easier to follow than a narrative.
  5. Include evidence. Attach the organisation's privacy policy, correspondence, breach notifications, and any screenshots.
  6. Be specific about the remedy. "An apology, deletion of my records, and $X compensation for time and distress" is stronger than "I want them punished."

Protecting Yourself After a Privacy Breach

While the OAIC handles the regulatory side, you should also take practical steps to limit ongoing harm from exposed personal information.

  • Change compromised passwords and enable multi-factor authentication on important accounts.
  • Place a credit ban with Equifax, Experian, and illion if financial data was exposed. This is free in Australia.
  • Watch for phishing. Breached data is often used in targeted scam emails and text messages. Never click suspicious links — use tools that let you preview or scan destination URLs before visiting them. Services like Lunyb provide safer link handling and privacy-conscious redirection, which is useful when you're being cautious about unfamiliar URLs after a breach.
  • Consider replacing government IDs if driver's licence, passport, or Medicare numbers were exposed. State transport authorities and Services Australia have documented processes for this.
  • Use encrypted DNS and modern browsers with tracker blocking to reduce ongoing data collection about your online activity.
  • Keep a written record of every action you take — this supports any compensation claim.

When to Consider Other Options

The OAIC isn't your only avenue. Depending on the circumstances, you may also consider:

  • State privacy commissioners (NSW, Victoria, Queensland, and others) for complaints about state agencies.
  • Australian Financial Complaints Authority (AFCA) for privacy issues involving banks, insurers, or superannuation funds.
  • Telecommunications Industry Ombudsman (TIO) for telco privacy problems.
  • Class actions: Large-scale breaches (such as those affecting millions of Australians) often lead to representative proceedings. Law firms may contact affected individuals or you can register interest.
  • Civil action: For serious cases with significant harm, private legal advice about damages may be worthwhile.

Related Reading

If you're evaluating tools and services that handle personal data, these guides may help you make more privacy-aware choices:

Frequently Asked Questions

How long do I have to lodge an OAIC complaint?

You should lodge your complaint within 12 months of becoming aware of the privacy breach. The OAIC can decline complaints made outside this window unless you have a reasonable explanation for the delay, such as ongoing negotiation with the organisation or newly discovered evidence.

Does it cost anything to complain to the OAIC?

No. Lodging a privacy complaint with the OAIC is completely free. You are not required to have a lawyer, though you can engage one if you wish. The OAIC also provides free guidance materials and a phone enquiry line at 1300 363 992.

Can I get compensation for a privacy breach?

Yes, in some cases. The Information Commissioner can order compensation for financial loss, non-economic loss (such as distress and humiliation), and in some cases aggravated damages. Amounts typically range from a few hundred dollars for minor incidents to tens of thousands for serious breaches with significant harm. Class action settlements for very large breaches can result in higher per-person payouts.

What if the organisation is a small business not covered by the Privacy Act?

Most businesses with turnover under AUD $3 million are exempt from the Privacy Act unless they fall into a specific category (health service providers, businesses that trade in personal information, credit providers, or federal contractors). If the small business exemption applies, the OAIC cannot investigate. You may still have options through consumer protection agencies, defamation law, or state fair trading offices.

Will my complaint be made public?

Individual complaints are handled confidentially. The OAIC does not publish complainants' names. However, when the Commissioner makes a formal determination, it may be published on the OAIC website with the organisation identified. Very large investigations — such as major data breaches affecting millions of Australians — often attract media coverage regardless of confidentiality within the complaint process itself.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles