facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). The OAIC is the national regulator responsible for enforcing the Privacy Act 1988 and can investigate breaches, order remediation and, in serious cases, impose significant civil penalties. This guide explains exactly how to report a privacy breach, what happens after you lodge your complaint, and how to strengthen your case.

What Is the OAIC and What Can It Investigate?

The Office of the Australian Information Commissioner is Australia's independent privacy and freedom of information regulator. It handles complaints about how Australian Government agencies and most private-sector organisations with an annual turnover of more than $3 million handle personal information under the Australian Privacy Principles (APPs).

The OAIC can investigate a wide range of privacy issues, including:

  • Unauthorised access, use or disclosure of your personal information
  • Data breaches that expose your identity documents, health records or financial data
  • Failure to give you access to, or correct, your personal information
  • Collection of information without your consent or without a lawful purpose
  • Direct marketing without opt-out mechanisms
  • Cross-border data transfers to jurisdictions without adequate protections
  • Mishandling of credit reporting information or tax file numbers

Who the OAIC Cannot Help With

The OAIC has jurisdictional limits. It generally cannot handle complaints about:

  • Small businesses with turnover under $3 million (with some exceptions such as health providers)
  • State and territory government agencies (these have their own privacy regulators)
  • Employee records held by your current or former employer
  • Registered political parties and political acts
  • Media organisations acting in the course of journalism

If your complaint falls outside OAIC jurisdiction, the office will usually redirect you to the correct regulator, such as your state Privacy Commissioner or the Fair Work Ombudsman.

What Counts as a Privacy Breach Under Australian Law?

A privacy breach occurs when personal information is accessed, disclosed, altered, lost or otherwise mishandled in a way that breaches the Australian Privacy Principles or the entity's own privacy obligations. Under the Notifiable Data Breaches (NDB) scheme, organisations must notify both affected individuals and the OAIC when a breach is likely to result in serious harm.

Common Examples of Reportable Breaches

  1. Cyber incidents: Ransomware attacks, phishing compromises or unauthorised database access exposing customer records.
  2. Human error: Emails sent to the wrong recipient, misconfigured cloud storage, or lost unencrypted laptops and USB drives.
  3. Insider misuse: Employees browsing customer records without a legitimate business reason.
  4. Third-party vendor breaches: A supplier or contractor exposing data the organisation entrusted to them.
  5. Physical breaches: Documents left in public spaces, stolen files, or improper disposal of paper records.

Step 1: Complain to the Organisation First

Before the OAIC will accept your complaint, you must generally give the organisation an opportunity to respond. This is a mandatory step under section 40(1A) of the Privacy Act, unless it would be inappropriate to do so (for example, if you fear retaliation or the organisation has already refused to engage).

How to Lodge an Internal Complaint

  1. Locate the organisation's privacy policy — it must include contact details for their Privacy Officer.
  2. Write to the Privacy Officer in writing (email is fine). Keep the tone factual and clear.
  3. State what happened, when it happened, what personal information was affected, and what outcome you want (an apology, correction, deletion, compensation, or process changes).
  4. Give the organisation 30 days to respond substantively.
  5. Keep copies of every message, timestamp and reference number.

If the organisation does not respond within 30 days, responds inadequately, or refuses to engage, you can escalate to the OAIC.

Step 2: Prepare Your Evidence

The strength of your OAIC complaint depends on the quality of your evidence. Regulators receive thousands of complaints each year and prioritise those with clear documentation and identifiable harm.

Evidence Checklist

  • Copies of the organisation's privacy policy at the time of the breach (use the Wayback Machine if it has changed)
  • All correspondence with the organisation, including your original complaint and their responses
  • Screenshots of exposed data, breach notification emails, or news articles about the incident
  • Records of any financial loss, identity theft attempts, scam calls or emotional distress caused by the breach
  • Bank statements, credit report changes, or IDCARE case numbers if identity misuse occurred
  • A clear timeline of events with dates and times

When collecting evidence online, be careful about link tracking and referrer leakage. Using a reputable link management service such as Lunyb to share evidence securely with legal representatives can help you track who has accessed a document while preserving your own privacy metadata. For a broader look at trusted link tools, see our 2026 buyer's guide to URL shorteners.

Step 3: Lodge Your Complaint With the OAIC

Once you have exhausted the internal complaint process, you can file with the OAIC through several channels.

Lodging Options

MethodHowBest For
Online formoaic.gov.au privacy complaint portalMost complaints — fastest turnaround
Emailenquiries@oaic.gov.auWhen you need to attach large evidence files
PostGPO Box 5288, Sydney NSW 2001When you have physical documents or no digital access
Phone1300 363 992Initial enquiries or accessibility support

Information You Must Provide

  1. Your full name and contact details
  2. The name of the organisation or agency you are complaining about
  3. A description of what happened, in chronological order
  4. Copies of your correspondence with the organisation
  5. The outcome you are seeking
  6. Any supporting evidence

The OAIC does not charge a fee to lodge a complaint. You do not need a lawyer, although complex matters (especially those involving representative complaints or significant damages) may benefit from legal advice.

Step 4: What Happens After You Lodge

Once received, the OAIC assesses your complaint against its jurisdictional and merits criteria. The typical process involves several stages.

The OAIC Complaint Lifecycle

  1. Acknowledgement (within 10 business days): You receive confirmation and a case reference number.
  2. Preliminary assessment: The OAIC decides whether it has jurisdiction and whether the complaint has merit.
  3. Conciliation: Most complaints are resolved informally through negotiated outcomes. The OAIC may facilitate a phone conference or written exchange between you and the organisation.
  4. Formal investigation: If conciliation fails, the Commissioner may open a formal investigation, compel documents and interview witnesses.
  5. Determination: The Commissioner can make binding determinations, order compensation, require an apology, or direct changes to practices.
  6. Enforcement: Serious or repeated breaches can be referred to the Federal Court, with civil penalties of up to $50 million for organisations under recent reforms.

Most complaints are resolved within 12 months, though complex investigations can take longer. You will be kept informed at each stage.

Possible Outcomes and Remedies

The Privacy Act gives the Information Commissioner broad powers to remedy privacy breaches. Common outcomes include:

  • An apology: Written or public acknowledgement of the breach
  • Corrective action: Deletion, correction or restricted use of your data
  • Process changes: The organisation must update policies, training or technical controls
  • Financial compensation: For economic loss (e.g. fraud, replacement documents) and non-economic loss (distress, humiliation). Awards typically range from $3,000 to $20,000 for individuals, with higher amounts in serious cases.
  • Public determinations: Naming and shaming, which drives industry-wide behaviour change
  • Civil penalties: For serious or repeated interferences with privacy

Notifiable Data Breaches: Your Rights When You Are Notified

If you receive a notification that your data has been part of a notifiable data breach, the organisation must tell you what information was involved, how the breach happened, and what steps you can take to protect yourself. You have the right to complain to the OAIC even if the organisation has followed all notification requirements — notification does not absolve them of the underlying breach.

Protective Steps After a Breach Notification

  1. Change passwords immediately, especially if you reused them elsewhere. Turn on multi-factor authentication.
  2. Place a temporary credit ban with Equifax, illion and Experian to prevent fraudulent credit applications.
  3. Contact IDCARE (1800 595 160), Australia's free national identity and cyber support service.
  4. If identity documents were exposed, apply for a Commonwealth Victims' Certificate and replace your Medicare card, driver licence or passport.
  5. Monitor bank statements and be alert to targeted phishing attempts referencing the breached data.
  6. Use encrypted DNS resolvers and a privacy-respecting browser to reduce further tracking exposure.

Representative and Class Complaints

Where a breach affects multiple people — such as a large data breach involving thousands of customers — the Privacy Act allows a representative complaint to be lodged on behalf of the affected group. This is similar to a class action but handled through the OAIC. Recent large-scale Australian data breaches have resulted in representative complaints seeking coordinated compensation for affected consumers.

When to Consider a Representative Complaint

  • Many people were affected by the same act or practice
  • The claims raise substantially similar issues of law or fact
  • Individual complaints would be inefficient or overwhelming

Appealing an OAIC Decision

If you disagree with the Commissioner's determination, you have review options. You can apply to the Administrative Review Tribunal (ART) for merits review, or in limited circumstances seek judicial review in the Federal Court. Applications must generally be made within 28 days of the determination.

How to Reduce Your Privacy Risk Going Forward

Prevention is always easier than remediation. Australian consumers can take several practical steps to minimise exposure:

  • Give minimum viable data — never provide more than what is strictly necessary
  • Use unique, complex passwords stored in a reputable password manager
  • Enable multi-factor authentication on every account that offers it
  • Regularly request a copy of your credit report to spot fraudulent accounts
  • Use privacy-respecting link tools when sharing content publicly to avoid leaking analytics or referrer data
  • Review app permissions on your phone quarterly and revoke unnecessary access
  • Read privacy policies before signing up — look for retention periods and third-party sharing

For businesses looking to share links without exposing customer analytics to third-party trackers, privacy-first shorteners like Lunyb provide an alternative to enterprise platforms — you can compare features against providers like Rebrandly to find the right fit.

Frequently Asked Questions

How long do I have to lodge an OAIC privacy complaint?

There is no strict statutory deadline, but the OAIC may decline to investigate complaints made more than 12 months after you became aware of the breach. Lodge as soon as practicable and always after giving the organisation 30 days to respond internally.

Does it cost anything to complain to the OAIC?

No. Lodging a privacy complaint with the OAIC is completely free. You do not need a lawyer, although you may choose to engage one for complex or high-value matters.

Can I get compensation for stress caused by a data breach?

Yes. The Privacy Act allows compensation for non-economic loss such as humiliation, injury to feelings and distress, in addition to any direct financial loss. Awards commonly fall between $3,000 and $20,000 per individual, though serious breaches can attract higher amounts.

What if the breach involves a small business under $3 million turnover?

Small businesses are generally exempt from the Privacy Act, but exceptions apply to health service providers, businesses trading in personal information, credit providers and government contractors. If the small business falls within an exception, you can still complain to the OAIC. Otherwise, consider consumer protection complaints to the ACCC or your state fair trading office.

Will my identity be kept confidential during the complaint process?

The OAIC generally needs to share your identity and complaint details with the organisation so they can respond. You can request that certain details remain confidential where possible, but a fully anonymous complaint is rarely feasible. Public determinations may name the organisation but typically de-identify complainants.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles