OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian business or government agency has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide explains what qualifies as a privacy breach, how to lodge an OAIC complaint, what evidence to gather, and what outcomes you can realistically expect.
What Is the OAIC?
The Office of the Australian Information Commissioner (OAIC) is the independent Commonwealth regulator responsible for enforcing the Privacy Act 1988 and the Australian Privacy Principles (APPs). It handles privacy complaints against APP entities, investigates notifiable data breaches, and issues guidance to organisations that handle personal information.
The OAIC's jurisdiction covers most Australian Government agencies and private sector organisations with an annual turnover above $3 million, along with all health service providers, credit reporting bodies, and businesses that trade in personal information regardless of size.
What the OAIC Can and Cannot Do
The OAIC can investigate, conciliate, make determinations, order compensation, and refer serious matters for civil penalty proceedings. It cannot, however, prosecute criminal offences, act on complaints outside its jurisdiction (such as most small businesses or state government agencies), or override state-based privacy laws.
What Counts as a Privacy Breach?
A privacy breach occurs when personal information is accessed, disclosed, lost, or used in a way that breaches the Australian Privacy Principles. Common examples include:
- An organisation losing a laptop or USB drive containing your identity documents.
- A company disclosing your data to a third party without your consent.
- A staff member accessing your records without a legitimate business reason.
- A data breach caused by hacking, phishing, or ransomware.
- Refusal to give you access to, or correct, your personal information held by an organisation.
- Excessive collection of personal data that is not reasonably necessary.
- Use of your information for direct marketing when you have opted out.
Notifiable Data Breaches (NDB) Scheme
Since February 2018, organisations covered by the Privacy Act must notify affected individuals and the OAIC when a data breach is likely to result in serious harm. If you have received a data breach notification letter or email, that organisation has already reported the incident, but you can still lodge a complaint if you believe your matter was handled poorly or you suffered loss.
Step 1: Complain Directly to the Organisation First
The OAIC generally will not accept a complaint until you have given the organisation a reasonable opportunity to respond, usually 30 days. This first step is mandatory in almost all cases.
- Identify the correct contact. Find the organisation's Privacy Officer or the contact listed in their privacy policy.
- Write a clear complaint. State what happened, when, what personal information was involved, and what you want them to do (apology, correction, compensation, process change).
- Send it in writing. Email or a written letter creates a paper trail. Keep copies of everything.
- Set a deadline. Ask for a substantive response within 30 days.
- Track the response. Note dates, names, and the content of any replies.
If the organisation refuses to respond, gives an inadequate response, or fails to reply within 30 days, you can escalate to the OAIC.
Step 2: Prepare Your OAIC Complaint
Before lodging, gather the following:
- Your full contact details and, if relevant, an authorised representative's details.
- The name and contact details of the organisation you are complaining about.
- A concise timeline of events, with dates.
- Copies of your original complaint and the organisation's response (or evidence they failed to respond).
- Any supporting documents: emails, screenshots, letters, breach notifications, transaction records.
- An explanation of how the breach has affected you (financial loss, emotional distress, identity theft risk, wasted time).
- The outcome you are seeking.
Time Limits
You should lodge your complaint within 12 months of becoming aware of the alleged breach. The Commissioner may decline older complaints unless there is a good reason for the delay.
Step 3: Lodge Your Complaint with the OAIC
The OAIC accepts complaints through several channels:
- Online form: The fastest option, available on the OAIC website (oaic.gov.au). You can save progress and attach documents.
- Email: Send a completed privacy complaint form to enquiries@oaic.gov.au.
- Post: Mail to GPO Box 5288, Sydney NSW 2001.
- Phone assistance: Call 1300 363 992 if you need help preparing your complaint or require an interpreter.
There is no fee to lodge a complaint. You do not need a lawyer, though you may nominate a representative.
Step 4: What Happens After You Lodge
The OAIC process generally moves through several stages, though not every complaint reaches every stage.
Assessment
The OAIC first checks whether your complaint is within its jurisdiction, whether you approached the organisation first, and whether the matter appears to raise a privacy issue. This triage typically takes a few weeks.
Early Resolution
Many complaints are resolved informally. The OAIC may contact the organisation and facilitate a quick fix, such as correcting a record, providing an apology, or updating a process.
Conciliation
If early resolution fails, the OAIC may formally conciliate between you and the organisation. Conciliation is confidential and aims to reach a mutually acceptable outcome, which can include monetary compensation, changes to systems, staff training, or written apologies.
Investigation and Determination
If conciliation is unsuccessful and the matter is significant, the Commissioner may formally investigate and make a legally binding determination. Determinations can require the organisation to stop conduct, take specific action, or pay compensation for financial loss and non-economic harm (such as distress and humiliation).
Civil Penalty Proceedings
For serious or repeated interferences with privacy, the Commissioner can seek civil penalties in the Federal Court. Following 2022 reforms, maximum penalties for serious or repeated breaches by corporations reach the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover in the relevant period.
Typical Timelines and Realistic Expectations
The OAIC receives thousands of complaints each year and resources are stretched. Straightforward matters may resolve within a few months, but complex investigations can take 12 to 24 months or more.
| Stage | Typical Timeframe | Likely Outcome |
|---|---|---|
| Initial assessment | 2–6 weeks | Accepted, declined, or referred elsewhere |
| Early resolution | 1–3 months | Informal fix, apology, correction |
| Conciliation | 3–9 months | Settlement, compensation, systemic change |
| Formal investigation | 9–24+ months | Determination, orders, compensation |
| Federal Court proceedings | 1–3 years | Civil penalties, precedent-setting rulings |
Compensation: What Can You Actually Recover?
OAIC determinations have awarded compensation ranging from a few hundred dollars for minor distress to tens of thousands for serious breaches involving sensitive information. Categories of loss include:
- Economic loss: Money spent on credit monitoring, replacing identity documents, or dealing with fraud.
- Non-economic loss: Distress, humiliation, anxiety, or damage to reputation.
- Aggravated damages: Where the organisation acted particularly poorly or without remorse.
Keep detailed records of every cost and impact. A diary of emotional effects, medical records, or evidence of time taken off work can all support a compensation claim.
When the OAIC Is Not the Right Path
Some situations require different regulators:
- State government agencies: Complain to your state privacy commissioner (for example, the Information and Privacy Commission NSW or Office of the Victorian Information Commissioner).
- Telecommunications: The Telecommunications Industry Ombudsman handles telco-specific complaints.
- Small business (under $3m turnover): Usually outside OAIC jurisdiction unless the business trades in personal information or is a health service provider.
- Scams and identity theft: Report to Scamwatch, IDCARE (1800 595 160), and your local police.
- Cybercrime: Report to ReportCyber via cyber.gov.au.
Protecting Yourself Going Forward
After a privacy breach, take defensive action while your complaint proceeds.
- Change compromised passwords and enable multi-factor authentication on all important accounts.
- Place a credit ban with Equifax, Experian and illion to stop new credit being opened in your name.
- Contact IDCARE for free identity recovery support.
- Monitor bank and superannuation accounts for unusual activity.
- Reduce your data footprint. Delete unused accounts, tighten sharing permissions, and be selective about what you post online.
- Use privacy-respecting tools. When sharing links publicly, a shortener like Lunyb can mask long URLs that might otherwise leak query parameters containing personal identifiers. See our honest review of Lunyb or compare options in our 2026 buyer's guide to URL shorteners.
Common Mistakes to Avoid
- Skipping the internal complaint. The OAIC will send you back to the organisation.
- Vague allegations. Be specific about what personal information was involved and which APP was breached.
- Delaying too long. The 12-month clock starts when you become aware of the breach.
- Failing to quantify harm. Compensation depends on demonstrating actual impact.
- Discarding evidence. Keep every email, letter, and screenshot; do not rely on memory.
Recent Reforms to Watch
The Privacy and Other Legislation Amendment Act 2024 introduced a statutory tort for serious invasions of privacy, meaning you may soon be able to sue directly in court for certain intrusions and misuses of information, in addition to complaining to the OAIC. Further reforms flowing from the Privacy Act Review are progressively strengthening consent requirements, transparency obligations, and children's privacy protections. Anyone considering a complaint in 2025 or later should check the current OAIC guidance for the latest position.
Frequently Asked Questions
How much does it cost to lodge an OAIC complaint?
It is free. The OAIC does not charge a lodgement fee, and you do not need a lawyer. You may choose to engage one for complex matters, but many complainants successfully self-represent through conciliation.
Can I complain anonymously?
You can raise concerns anonymously, but the OAIC generally cannot investigate a formal complaint without knowing who you are, because it needs to verify the alleged breach affected you and communicate outcomes. Your identity is kept confidential during conciliation with the organisation only if practical.
What if the organisation is based overseas?
The Privacy Act has extraterritorial reach. It applies to overseas organisations that carry on business in Australia and collect or hold personal information here. The OAIC can investigate, though enforcement against a purely offshore entity can be practically difficult.
Will my complaint be made public?
Most complaints are handled confidentially. However, if the Commissioner makes a formal determination or brings Federal Court proceedings, the outcome is typically published, sometimes with the complainant's name anonymised on request.
Can I appeal an OAIC decision I disagree with?
Yes. You can apply to the Administrative Review Tribunal (which replaced the AAT in 2024) for a merits review of certain OAIC determinations. Strict time limits apply, usually 28 days from the decision, so seek advice promptly if you wish to appeal.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Bill C-27 Digital Charter: What You Need to Know
Bill C-27, Canada's Digital Charter Implementation Act, introduces the CPPA, a new privacy tribunal, and AIDA to modernize privacy and regulate AI. Learn what it means for Canadian businesses and consumers, how it compares globally, and how to prepare.
ICO Fines 2026: Biggest Data Protection Penalties in the UK
The ICO issued record data protection penalties in 2026, with fines topping £6 million for ransomware failures and multi-million pound sanctions for marketing abuses. This guide examines the biggest UK fines of the year and the compliance lessons every organisation must learn.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
Learn how to file a privacy complaint with Ireland's Data Protection Commission (DPC). This step-by-step guide covers evidence gathering, submission channels, timelines, and what happens after you complain under GDPR.
Data Protection Act 2018 Ireland: Complete Guide
A complete guide to Ireland's Data Protection Act 2018, covering its relationship with the GDPR, individual rights, business obligations, DPC enforcement powers, and penalties. Learn what your organisation needs to do to stay compliant.