facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If your personal information has been mishandled by an Australian business or federal government agency, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide walks you through the entire OAIC complaints process for a privacy breach — from your first internal complaint to the formal investigation, determinations, and possible compensation. Whether you're an individual whose data was leaked or a small business trying to understand your obligations, this article explains everything you need to know in plain English.

What Is the OAIC and What Does It Regulate?

The Office of the Australian Information Commissioner (OAIC) is the independent federal regulator responsible for enforcing the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). It handles complaints, investigates breaches, and can issue binding determinations against organisations that mishandle personal information.

The OAIC has jurisdiction over:

  • Australian Government agencies (with limited exceptions)
  • Private-sector organisations with an annual turnover above A$3 million
  • All health service providers, regardless of size
  • Businesses that trade in personal information or are contracted service providers to the Commonwealth
  • Credit reporting bodies and credit providers
  • Tax File Number recipients

State and territory public sector agencies are generally covered by state-based privacy regulators (for example, the IPC in NSW or OVIC in Victoria), not the OAIC.

What Counts as a Privacy Breach Under Australian Law?

A privacy breach occurs when personal information is accessed, disclosed, used, or lost in a way that contravenes the Australian Privacy Principles or another provision of the Privacy Act. This includes both malicious incidents and honest mistakes.

Common Examples of Privacy Breaches

  • A company sends your medical records to the wrong email address
  • A hacker steals a customer database containing your name, address, and driver's licence
  • An employee accesses your file without a legitimate business reason
  • A business refuses to give you access to your own personal information
  • Your data is used for direct marketing when you never consented
  • An organisation keeps your information for longer than it needs to
  • Personal data is transferred overseas without adequate protection

Notifiable Data Breaches (NDB) Scheme

Since February 2018, organisations covered by the Privacy Act must notify affected individuals and the OAIC when an "eligible data breach" occurs — that is, when unauthorised access or disclosure is likely to result in serious harm. If you receive one of these notifications, it strengthens any subsequent complaint you lodge.

Step 1: Complain Directly to the Organisation First

Before the OAIC will consider your complaint, you generally must give the organisation a reasonable chance to respond. This is a mandatory step under section 40(1A) of the Privacy Act, and skipping it is the most common reason complaints get bounced back.

  1. Find the right contact. Locate the organisation's Privacy Officer, privacy contact page, or DPO. This is often in the privacy policy on their website.
  2. Put your complaint in writing. Email is best — it creates a timestamped record. Clearly state what happened, when, and what outcome you want (an apology, deletion of data, compensation, or a change to practices).
  3. Include supporting evidence. Screenshots, emails, breach notifications, and reference numbers all help.
  4. Set a deadline. Ask for a response within 30 days. This aligns with what the OAIC considers a reasonable response window.
  5. Keep every reply. Save the full email chain, including headers.

If the organisation resolves the matter to your satisfaction, you don't need to escalate. If they refuse, ignore you, or take longer than 30 days without a good reason, you can proceed to lodge a formal OAIC complaint.

Step 2: How to Lodge an OAIC Complaint

Complaints to the OAIC must be in writing. There is no filing fee, and you don't need a lawyer, although complex matters may benefit from one.

Three Ways to Submit

  1. Online form: The fastest option is the Privacy Complaint Form at oaic.gov.au. It walks you through the required fields.
  2. Email or post: You can send a written complaint to enquiries@oaic.gov.au or by mail to GPO Box 5288, Sydney NSW 2001.
  3. Phone assistance: If you have a disability, language barrier, or need help drafting your complaint, call 1300 363 992 and a staff member can assist you.

What to Include in Your Complaint

  • Your full name and contact details
  • The name of the organisation or agency you're complaining about
  • A clear timeline of events, in chronological order
  • Which Australian Privacy Principle(s) you believe were breached (if known)
  • Copies of your earlier correspondence with the organisation
  • Any breach notification you received
  • The outcome you're seeking
  • Whether you've complained to any other regulator (e.g. an industry ombudsman)

Step 3: What Happens After You Lodge

Once received, the OAIC triages your complaint. Not every complaint proceeds to a full investigation — the Commissioner has discretion to decline matters that are trivial, out of jurisdiction, or better handled elsewhere.

The Typical Timeline

StageWhat HappensApproximate Timeframe
AcknowledgementOAIC confirms receipt and assigns a reference number1–2 weeks
Preliminary assessmentCase officer reviews jurisdiction and whether internal steps were followed4–8 weeks
ConciliationOAIC facilitates a negotiated outcome between you and the respondent3–6 months
Formal investigationIf conciliation fails, the Commissioner may open an investigation6–18 months
DeterminationBinding decision under section 52, potentially including compensationVariable

Conciliation Is the Most Common Outcome

The OAIC strongly favours resolving complaints through conciliation — a structured, without-prejudice negotiation. Outcomes commonly include a written apology, correction or deletion of personal information, staff training commitments, policy changes, and modest compensation payments (typically A$1,000–A$20,000 for non-economic loss, though awards vary).

Step 4: Formal Determinations and Compensation

If conciliation fails and the Commissioner decides the complaint has merit, a formal determination may be issued. These are legally binding and enforceable in the Federal Court.

Types of Remedies

  • Declarations that the respondent engaged in conduct that interfered with privacy
  • Orders to stop the conduct or perform a specific act (e.g. destroy data)
  • Compensation for economic loss (financial harm) and non-economic loss (distress, humiliation, injury to feelings)
  • Aggravated damages in cases involving particularly egregious behaviour

Recent representative complaints — such as those following major breaches at telecommunications and health insurance companies — have shown the OAIC is prepared to seek significant collective outcomes affecting millions of Australians at once.

Preserving Evidence Before You Complain

The strength of your complaint depends heavily on the quality of your evidence. Once you suspect a breach, act quickly to preserve proof.

  1. Take dated screenshots of any relevant websites, portals, or communications.
  2. Export email threads to PDF, including full headers.
  3. Note the names of anyone you spoke to on the phone and the date/time.
  4. Save breach notification letters and any reference numbers.
  5. Keep a written diary of the impact — sleepless nights, missed work, out-of-pocket costs — because this supports non-economic loss claims.
  6. If your identity documents were leaked, get an IDCARE case number (1800 595 160) and monitor your credit file.

When sharing sensitive evidence links with lawyers, advocates, or family members, use a link management tool that supports password protection and expiry dates. Services like Lunyb let you generate short, trackable URLs with access controls so you can share evidence securely without exposing raw file locations publicly.

Common Reasons Complaints Get Rejected

Understanding why complaints fail can help you avoid the same pitfalls.

  • No prior complaint to the organisation. Always exhaust the internal route first.
  • Out of jurisdiction. State agencies, small businesses under A$3M turnover, and individuals acting in a personal capacity generally aren't covered.
  • Too old. Complaints lodged more than 12 months after you became aware of the breach may be declined.
  • No identifiable harm. Speculative or theoretical concerns without evidence of actual mishandling are hard to progress.
  • Better handled elsewhere. Consumer disputes, defamation, and workplace matters often belong with other bodies.

Other Regulators You Might Need Instead

IssueRight Regulator
State government agency mishandling dataState privacy commissioner (IPC NSW, OVIC, OIC QLD, etc.)
Telco or ISP privacy issueTIO first, then OAIC
Bank or insurerAFCA, then OAIC
Spam SMS or emailsACMA
Scam or identity theftScamwatch and IDCARE
CybercrimeReportCyber (police)

Reducing Your Exposure Going Forward

Filing a complaint helps, but preventing the next breach matters just as much. A few practical steps:

  1. Use unique passwords with a reputable password manager, and enable multi-factor authentication everywhere.
  2. Turn on encrypted DNS (DNS-over-HTTPS) in your browser to reduce leakage of your browsing metadata.
  3. Minimise what you share. Ask why an organisation needs your driver's licence or Medicare number before handing it over — under APP 3, they must have a legitimate need.
  4. Request access and correction under APP 12 and APP 13 to see what businesses hold about you and fix inaccuracies.
  5. Use privacy-focused browsers and tracker blockers to limit third-party profiling.
  6. Shorten and monitor links you share publicly. Tools like Lunyb give you analytics and the ability to revoke a link if it ends up somewhere it shouldn't — useful for professionals sharing client materials.

For more on choosing safer sharing tools, see our 2026 buyer's guide to URL shorteners and our honest review of Lunyb.

What About Class Actions and Representative Complaints?

Where a breach affects many people — think the large-scale telco and health insurer incidents of recent years — the OAIC can accept a representative complaint on behalf of a class. You may also see private class actions filed in the Federal Court. These two tracks can run in parallel and offer different remedies. If you receive a notice about a class action, read it carefully: joining is usually free and doesn't prevent you from lodging your own OAIC complaint about matters not covered by the class.

Frequently Asked Questions

How long do I have to lodge an OAIC complaint?

You should complain within 12 months of becoming aware of the privacy breach. The OAIC can decline complaints lodged later, though it has discretion to accept older matters if there's a good reason for the delay, such as ongoing negotiations with the organisation.

Do I need a lawyer to make a complaint?

No. The OAIC process is designed to be accessible without legal representation. Most complaints resolve through conciliation without lawyers involved. However, if you're seeking significant compensation, a specialist privacy lawyer or community legal centre can help you frame the loss you've suffered.

Will my complaint be made public?

Individual complaints are confidential during the process. However, formal determinations under section 52 are published on the OAIC website, usually with the complainant's name anonymised (e.g. "'EQ' and Great Barrier Reef Marine Park Authority"). Conciliated outcomes remain private unless both parties agree otherwise.

Can I get compensation for stress or embarrassment?

Yes. Under section 52(1)(b)(iii) of the Privacy Act, the Commissioner can order compensation for non-economic loss including humiliation, distress, and injury to feelings. Amounts are generally modest — often between A$1,000 and A$20,000 — but can be higher in serious cases involving sensitive information like health or financial records.

What if the organisation is based overseas?

The Privacy Act has extraterritorial reach under section 5B. If an overseas organisation has an "Australian link" — for example, it carries on business in Australia and collects information from Australians — the OAIC can accept your complaint. Enforcement across borders is harder but not impossible, and the OAIC cooperates with international counterparts.

Does complaining stop the organisation from retaliating against me?

The Privacy Act doesn't provide specific whistleblower protections for complainants, but retaliating against someone for exercising their legal rights could itself breach consumer law, employment law, or the APPs (particularly APP 1's requirement to manage personal information openly and fairly). Document any retaliation and raise it with the OAIC immediately.

Final Thoughts

The OAIC complaints process gives Australians real, enforceable rights when their personal information is mishandled. It's free, it's accessible, and — while it isn't always fast — it produces meaningful outcomes ranging from apologies and policy changes to binding compensation orders. The keys to a successful complaint are simple: complain to the organisation first, preserve your evidence carefully, articulate the harm clearly, and don't hesitate to escalate when a response is inadequate. Privacy is a right, not a privilege, and the regulator exists to enforce it.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles