OAIC Complaints: How to Report a Privacy Breach in Australia
If your personal information has been mishandled by an Australian business or government agency, you have the right to lodge a formal complaint with the Office of the Australian Information Commissioner (OAIC). The OAIC is the independent regulator responsible for enforcing the Privacy Act 1988 and the Australian Privacy Principles (APPs). This guide walks you through the full process of reporting a privacy breach, from gathering evidence to escalating unresolved disputes.
What Is the OAIC and When Can You Complain?
The Office of the Australian Information Commissioner (OAIC) is the national regulator that oversees privacy, freedom of information, and government information policy in Australia. It accepts complaints from individuals who believe an entity covered by the Privacy Act has interfered with their personal information.
You can lodge an OAIC complaint if an organisation or agency has:
- Collected your personal information unlawfully or without consent
- Used or disclosed your data for a purpose you did not agree to
- Failed to keep your information secure, resulting in a data breach
- Refused to give you access to your own records or correct inaccurate data
- Sent you direct marketing without a lawful basis
- Transferred your data overseas without appropriate safeguards
- Mishandled your tax file number, credit information, or health records
Who Is Covered by the Privacy Act?
The Privacy Act generally applies to Australian Government agencies and private sector organisations with an annual turnover of more than AUD $3 million. It also covers smaller businesses in specific sectors such as health service providers, credit reporting bodies, residential tenancy databases, and businesses that trade in personal information. If the entity is not covered, the OAIC cannot investigate — but state-based privacy commissioners or industry ombudsmen may be able to help.
Step 1: Complain Directly to the Organisation First
Before escalating to the OAIC, you are required to raise the issue directly with the organisation or agency involved. This is a mandatory first step in nearly all cases. Give them a clear opportunity to resolve the matter — the law allows them 30 days to respond.
- Find the right contact: Look for the organisation's privacy policy, which must list a Privacy Officer or complaint contact.
- Write a formal complaint: Email or post a dated letter clearly stating what happened, what information was affected, and what remedy you want (an apology, deletion of data, compensation, policy changes, etc.).
- Keep records: Save copies of all correspondence, delivery receipts, and reference numbers.
- Wait up to 30 days: If the entity does not respond, or the response is inadequate, you can then take the matter to the OAIC.
Sample Wording for Your Initial Complaint
Keep your letter factual and concise. Include the date of the alleged breach, what personal information was involved, any evidence you hold, and a specific resolution request. Reference the Australian Privacy Principles where relevant — for example, APP 11 covers security of personal information, while APP 6 covers use and disclosure.
Step 2: Lodging a Formal Complaint With the OAIC
Once the 30-day window has passed without a satisfactory outcome, you can lodge a formal complaint with the OAIC. The process is free, and you do not need a lawyer.
How to Submit Your Complaint
The OAIC accepts complaints through three channels:
- Online form: The Privacy Complaint Form at oaic.gov.au is the fastest option and allows attachments.
- Post: Mail a completed form to GPO Box 5288, Sydney NSW 2001.
- Phone or in-person: Call 1300 363 992 if you need assistance; the OAIC can take verbal complaints in limited circumstances (e.g. accessibility needs).
Information You Need to Include
| Required Detail | Example |
|---|---|
| Your contact details | Full name, phone, email, postal address |
| Name of the respondent | Legal entity name and ABN if known |
| Date of the incident | DD/MM/YYYY, or the date range |
| Description of the breach | What information was mishandled and how |
| Evidence | Emails, screenshots, letters, breach notifications |
| Prior complaint | Copy of your original complaint and any reply |
| Desired outcome | Apology, data deletion, compensation, systemic fix |
Step 3: What Happens After You Lodge
Once the OAIC receives your complaint, it is assessed to determine whether the regulator has jurisdiction and whether the matter should proceed to conciliation, investigation, or be declined. The OAIC publishes service standards but, in practice, complex matters can take six to twelve months.
- Acknowledgement: You should receive confirmation within a few business days.
- Preliminary enquiries: An officer may contact both parties for more information.
- Conciliation: The OAIC will usually try to resolve the complaint informally between you and the respondent — this is where most matters settle.
- Formal investigation: If conciliation fails and the issue is serious, the Commissioner can open a formal investigation under section 40 of the Privacy Act.
- Determination: The Commissioner can issue a binding determination requiring the respondent to apologise, change practices, or pay compensation.
Possible Outcomes and Compensation
Determinations can order compensation for financial loss and for non-economic harm such as humiliation, injury to feelings, or anxiety. Historical awards for individuals have typically ranged from a few thousand dollars up to around AUD $20,000 for serious cases, with higher amounts possible where significant harm is demonstrated. In class-style representative complaints, aggregate awards can be substantially larger.
Notifiable Data Breaches: A Separate but Related Scheme
Australia's Notifiable Data Breaches (NDB) scheme requires covered entities to notify both affected individuals and the OAIC when an eligible data breach occurs — that is, one likely to result in serious harm. If you have received a data breach notification letter, you already have strong evidence to support an OAIC complaint, especially if the organisation's response was slow or inadequate.
Key NDB Timelines
- Entities have 30 days to assess a suspected eligible breach.
- Notification to the OAIC and affected individuals must occur as soon as practicable after the entity determines the breach is notifiable.
- Failure to notify can itself be a breach of the Privacy Act and attract civil penalties.
Preparing Strong Evidence
The quality of your evidence often determines whether conciliation succeeds. Organise your materials chronologically and label each exhibit clearly.
- Screenshots: Capture any webpages, dashboards, emails, or SMS messages that show the breach. Include URLs and timestamps where visible.
- Correspondence log: A simple spreadsheet of dates, senders, and summaries makes it easy for the OAIC officer to follow the timeline.
- Impact statement: Describe how the breach affected you — identity theft risk, scam calls, stress, time spent on remediation, financial loss.
- Third-party reports: Include police reports, bank fraud notifications, or IDCARE case numbers where relevant.
Protecting Yourself While the Complaint Is Open
While your complaint is being handled, take practical steps to limit further exposure. Change passwords and enable multi-factor authentication on affected accounts, place a free credit ban with Equifax, Experian, and illion if financial data was exposed, and be alert for phishing attempts referencing the breach. When sharing sensitive links or files with investigators, legal advisers, or support services, use tools designed for privacy — for example, a privacy-focused link shortener like Lunyb can create short, trackable URLs without exposing underlying document paths or query strings in email signatures and messages.
When the OAIC Cannot or Will Not Investigate
The Commissioner has discretion under section 41 of the Privacy Act to decline complaints. Common reasons include:
- The entity is not covered by the Privacy Act (e.g. a small business under the turnover threshold).
- The complaint is more than 12 months old without reasonable explanation for the delay.
- The matter has already been adequately dealt with by the respondent.
- Another body (such as a state regulator, industry ombudsman, or court) is better suited to handle it.
- The complaint is frivolous, vexatious, or lacking in substance.
Alternative Avenues
| Issue Type | Where to Go Instead |
|---|---|
| State/territory government agency | State privacy commissioner (e.g. IPC NSW, OVIC Victoria) |
| Telecommunications or internet provider | Telecommunications Industry Ombudsman (TIO) |
| Banking or insurance | Australian Financial Complaints Authority (AFCA) |
| Health records (public hospitals) | State health complaints commissioner |
| Scams and identity theft | Scamwatch and IDCARE (1800 595 160) |
| Spam and unsolicited marketing | Australian Communications and Media Authority (ACMA) |
Appealing an OAIC Decision
If you disagree with a Commissioner's determination, you can seek review in the Administrative Review Tribunal (ART), which replaced the former AAT. Review applications generally must be lodged within 28 days of the decision. Determinations in favour of complainants are enforceable in the Federal Court or Federal Circuit and Family Court if the respondent refuses to comply.
Practical Tips to Strengthen Your Complaint
- Act promptly. Lodge within 12 months of becoming aware of the breach.
- Be specific about the APP breached. Referencing the exact principle shows you understand the law.
- Quantify your harm. Keep receipts for any out-of-pocket costs — new passports, credit monitoring, counselling.
- Stay professional. Avoid emotive language; let the facts speak.
- Consider systemic remedies. Asking for staff training or policy changes often achieves better long-term outcomes than compensation alone.
- Seek free legal advice from community legal centres or Legal Aid if the matter is complex.
Related Reading
Protecting your digital footprint goes beyond regulatory complaints. For broader guidance on online privacy and secure link sharing, see our reviews of trusted tools, including the best URL shorteners for 2026 and our honest review of Lunyb.
Frequently Asked Questions
How long do I have to lodge an OAIC complaint?
You should lodge within 12 months of becoming aware of the privacy breach. Later complaints may still be accepted if you can show a reasonable explanation for the delay, but the Commissioner has discretion to decline stale matters.
Does lodging a complaint cost anything?
No. The OAIC's complaint-handling process is completely free. You do not need to engage a lawyer, although legal advice can help in complex cases involving significant financial loss or where you expect to go to formal determination.
Can I get compensation through the OAIC?
Yes. If conciliation includes a settlement or the Commissioner issues a determination in your favour, you may receive compensation for financial loss and for non-economic harm such as stress, humiliation, or anxiety. Awards typically range from a few thousand dollars to around AUD $20,000 for individual complaints, with larger sums possible in serious cases.
What if the organisation ignores the OAIC's determination?
Determinations are legally binding. If the respondent refuses to comply, the OAIC or you can apply to the Federal Court or Federal Circuit and Family Court for enforcement. Non-compliance can also attract civil penalties.
Can I complain about an overseas company that leaked my data?
Yes, if the overseas entity has an "Australian link" — for example, it carries on business in Australia and collected the personal information here. The Privacy Act was amended to clarify its extraterritorial reach, so many global platforms serving Australian users fall within scope.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
GDPR gives everyone in Ireland powerful rights over their personal data, from access and erasure to portability and objection. This guide explains each right in plain English, how to enforce it through the Data Protection Commission, and practical steps to protect your privacy online.
Singapore Online Safety Act 2026: Complete Guide for Businesses and Users
Singapore's Online Safety Act 2026 reshapes how online platforms, advertisers, and intermediaries handle harmful content. This complete guide covers scope, obligations, penalties, and practical compliance steps for businesses and users in Singapore.
How Canadian Businesses Should Handle Data Privacy in 2026
A practical 2026 guide to data privacy for Canadian businesses — covering PIPEDA, Quebec Law 25, consent, breach response, vendor management, and CPPA preparation. Learn exactly what to implement to stay compliant and build customer trust.
Privacy Rights in Canada 2026: A Complete Guide for Individuals and Businesses
Canadian privacy law has changed dramatically with Bill C-27, Quebec's Law 25, and expanded provincial rules. This 2026 guide explains your rights, business obligations, and practical steps to protect personal information in the digital age.