OAIC Complaints: How to Report a Privacy Breach in Australia
If your personal information has been mishandled by an Australian business or federal government agency, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide walks you through the entire OAIC complaints process for a privacy breach — from your first internal complaint to the formal investigation, determinations, and possible compensation. Whether you're an individual whose data was leaked or a small business trying to understand your obligations, this article explains everything you need to know in plain English.
What Is the OAIC and What Does It Regulate?
The Office of the Australian Information Commissioner (OAIC) is the independent federal regulator responsible for enforcing the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). It handles complaints, investigates breaches, and can issue binding determinations against organisations that mishandle personal information.
The OAIC has jurisdiction over:
- Australian Government agencies (with limited exceptions)
- Private-sector organisations with an annual turnover above A$3 million
- All health service providers, regardless of size
- Businesses that trade in personal information or are contracted service providers to the Commonwealth
- Credit reporting bodies and credit providers
- Tax File Number recipients
State and territory public sector agencies are generally covered by state-based privacy regulators (for example, the IPC in NSW or OVIC in Victoria), not the OAIC.
What Counts as a Privacy Breach Under Australian Law?
A privacy breach occurs when personal information is accessed, disclosed, used, or lost in a way that contravenes the Australian Privacy Principles or another provision of the Privacy Act. This includes both malicious incidents and honest mistakes.
Common Examples of Privacy Breaches
- A company sends your medical records to the wrong email address
- A hacker steals a customer database containing your name, address, and driver's licence
- An employee accesses your file without a legitimate business reason
- A business refuses to give you access to your own personal information
- Your data is used for direct marketing when you never consented
- An organisation keeps your information for longer than it needs to
- Personal data is transferred overseas without adequate protection
Notifiable Data Breaches (NDB) Scheme
Since February 2018, organisations covered by the Privacy Act must notify affected individuals and the OAIC when an "eligible data breach" occurs — that is, when unauthorised access or disclosure is likely to result in serious harm. If you receive one of these notifications, it strengthens any subsequent complaint you lodge.
Step 1: Complain Directly to the Organisation First
Before the OAIC will consider your complaint, you generally must give the organisation a reasonable chance to respond. This is a mandatory step under section 40(1A) of the Privacy Act, and skipping it is the most common reason complaints get bounced back.
- Find the right contact. Locate the organisation's Privacy Officer, privacy contact page, or DPO. This is often in the privacy policy on their website.
- Put your complaint in writing. Email is best — it creates a timestamped record. Clearly state what happened, when, and what outcome you want (an apology, deletion of data, compensation, or a change to practices).
- Include supporting evidence. Screenshots, emails, breach notifications, and reference numbers all help.
- Set a deadline. Ask for a response within 30 days. This aligns with what the OAIC considers a reasonable response window.
- Keep every reply. Save the full email chain, including headers.
If the organisation resolves the matter to your satisfaction, you don't need to escalate. If they refuse, ignore you, or take longer than 30 days without a good reason, you can proceed to lodge a formal OAIC complaint.
Step 2: How to Lodge an OAIC Complaint
Complaints to the OAIC must be in writing. There is no filing fee, and you don't need a lawyer, although complex matters may benefit from one.
Three Ways to Submit
- Online form: The fastest option is the Privacy Complaint Form at oaic.gov.au. It walks you through the required fields.
- Email or post: You can send a written complaint to enquiries@oaic.gov.au or by mail to GPO Box 5288, Sydney NSW 2001.
- Phone assistance: If you have a disability, language barrier, or need help drafting your complaint, call 1300 363 992 and a staff member can assist you.
What to Include in Your Complaint
- Your full name and contact details
- The name of the organisation or agency you're complaining about
- A clear timeline of events, in chronological order
- Which Australian Privacy Principle(s) you believe were breached (if known)
- Copies of your earlier correspondence with the organisation
- Any breach notification you received
- The outcome you're seeking
- Whether you've complained to any other regulator (e.g. an industry ombudsman)
Step 3: What Happens After You Lodge
Once received, the OAIC triages your complaint. Not every complaint proceeds to a full investigation — the Commissioner has discretion to decline matters that are trivial, out of jurisdiction, or better handled elsewhere.
The Typical Timeline
| Stage | What Happens | Approximate Timeframe |
|---|---|---|
| Acknowledgement | OAIC confirms receipt and assigns a reference number | 1–2 weeks |
| Preliminary assessment | Case officer reviews jurisdiction and whether internal steps were followed | 4–8 weeks |
| Conciliation | OAIC facilitates a negotiated outcome between you and the respondent | 3–6 months |
| Formal investigation | If conciliation fails, the Commissioner may open an investigation | 6–18 months |
| Determination | Binding decision under section 52, potentially including compensation | Variable |
Conciliation Is the Most Common Outcome
The OAIC strongly favours resolving complaints through conciliation — a structured, without-prejudice negotiation. Outcomes commonly include a written apology, correction or deletion of personal information, staff training commitments, policy changes, and modest compensation payments (typically A$1,000–A$20,000 for non-economic loss, though awards vary).
Step 4: Formal Determinations and Compensation
If conciliation fails and the Commissioner decides the complaint has merit, a formal determination may be issued. These are legally binding and enforceable in the Federal Court.
Types of Remedies
- Declarations that the respondent engaged in conduct that interfered with privacy
- Orders to stop the conduct or perform a specific act (e.g. destroy data)
- Compensation for economic loss (financial harm) and non-economic loss (distress, humiliation, injury to feelings)
- Aggravated damages in cases involving particularly egregious behaviour
Recent representative complaints — such as those following major breaches at telecommunications and health insurance companies — have shown the OAIC is prepared to seek significant collective outcomes affecting millions of Australians at once.
Preserving Evidence Before You Complain
The strength of your complaint depends heavily on the quality of your evidence. Once you suspect a breach, act quickly to preserve proof.
- Take dated screenshots of any relevant websites, portals, or communications.
- Export email threads to PDF, including full headers.
- Note the names of anyone you spoke to on the phone and the date/time.
- Save breach notification letters and any reference numbers.
- Keep a written diary of the impact — sleepless nights, missed work, out-of-pocket costs — because this supports non-economic loss claims.
- If your identity documents were leaked, get an IDCARE case number (1800 595 160) and monitor your credit file.
When sharing sensitive evidence links with lawyers, advocates, or family members, use a link management tool that supports password protection and expiry dates. Services like Lunyb let you generate short, trackable URLs with access controls so you can share evidence securely without exposing raw file locations publicly.
Common Reasons Complaints Get Rejected
Understanding why complaints fail can help you avoid the same pitfalls.
- No prior complaint to the organisation. Always exhaust the internal route first.
- Out of jurisdiction. State agencies, small businesses under A$3M turnover, and individuals acting in a personal capacity generally aren't covered.
- Too old. Complaints lodged more than 12 months after you became aware of the breach may be declined.
- No identifiable harm. Speculative or theoretical concerns without evidence of actual mishandling are hard to progress.
- Better handled elsewhere. Consumer disputes, defamation, and workplace matters often belong with other bodies.
Other Regulators You Might Need Instead
| Issue | Right Regulator |
|---|---|
| State government agency mishandling data | State privacy commissioner (IPC NSW, OVIC, OIC QLD, etc.) |
| Telco or ISP privacy issue | TIO first, then OAIC |
| Bank or insurer | AFCA, then OAIC |
| Spam SMS or emails | ACMA |
| Scam or identity theft | Scamwatch and IDCARE |
| Cybercrime | ReportCyber (police) |
Reducing Your Exposure Going Forward
Filing a complaint helps, but preventing the next breach matters just as much. A few practical steps:
- Use unique passwords with a reputable password manager, and enable multi-factor authentication everywhere.
- Turn on encrypted DNS (DNS-over-HTTPS) in your browser to reduce leakage of your browsing metadata.
- Minimise what you share. Ask why an organisation needs your driver's licence or Medicare number before handing it over — under APP 3, they must have a legitimate need.
- Request access and correction under APP 12 and APP 13 to see what businesses hold about you and fix inaccuracies.
- Use privacy-focused browsers and tracker blockers to limit third-party profiling.
- Shorten and monitor links you share publicly. Tools like Lunyb give you analytics and the ability to revoke a link if it ends up somewhere it shouldn't — useful for professionals sharing client materials.
For more on choosing safer sharing tools, see our 2026 buyer's guide to URL shorteners and our honest review of Lunyb.
What About Class Actions and Representative Complaints?
Where a breach affects many people — think the large-scale telco and health insurer incidents of recent years — the OAIC can accept a representative complaint on behalf of a class. You may also see private class actions filed in the Federal Court. These two tracks can run in parallel and offer different remedies. If you receive a notice about a class action, read it carefully: joining is usually free and doesn't prevent you from lodging your own OAIC complaint about matters not covered by the class.
Frequently Asked Questions
How long do I have to lodge an OAIC complaint?
You should complain within 12 months of becoming aware of the privacy breach. The OAIC can decline complaints lodged later, though it has discretion to accept older matters if there's a good reason for the delay, such as ongoing negotiations with the organisation.
Do I need a lawyer to make a complaint?
No. The OAIC process is designed to be accessible without legal representation. Most complaints resolve through conciliation without lawyers involved. However, if you're seeking significant compensation, a specialist privacy lawyer or community legal centre can help you frame the loss you've suffered.
Will my complaint be made public?
Individual complaints are confidential during the process. However, formal determinations under section 52 are published on the OAIC website, usually with the complainant's name anonymised (e.g. "'EQ' and Great Barrier Reef Marine Park Authority"). Conciliated outcomes remain private unless both parties agree otherwise.
Can I get compensation for stress or embarrassment?
Yes. Under section 52(1)(b)(iii) of the Privacy Act, the Commissioner can order compensation for non-economic loss including humiliation, distress, and injury to feelings. Amounts are generally modest — often between A$1,000 and A$20,000 — but can be higher in serious cases involving sensitive information like health or financial records.
What if the organisation is based overseas?
The Privacy Act has extraterritorial reach under section 5B. If an overseas organisation has an "Australian link" — for example, it carries on business in Australia and collects information from Australians — the OAIC can accept your complaint. Enforcement across borders is harder but not impossible, and the OAIC cooperates with international counterparts.
Does complaining stop the organisation from retaliating against me?
The Privacy Act doesn't provide specific whistleblower protections for complainants, but retaliating against someone for exercising their legal rights could itself breach consumer law, employment law, or the APPs (particularly APP 1's requirement to manage personal information openly and fairly). Document any retaliation and raise it with the OAIC immediately.
Final Thoughts
The OAIC complaints process gives Australians real, enforceable rights when their personal information is mishandled. It's free, it's accessible, and — while it isn't always fast — it produces meaningful outcomes ranging from apologies and policy changes to binding compensation orders. The keys to a successful complaint are simple: complain to the organisation first, preserve your evidence carefully, articulate the harm clearly, and don't hesitate to escalate when a response is inadequate. Privacy is a right, not a privilege, and the regulator exists to enforce it.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.