facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··9 min read

If an organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). The OAIC is the national regulator responsible for enforcing the Privacy Act 1988 and the Australian Privacy Principles (APPs). This guide walks you through exactly how to report a privacy breach, what evidence to gather, how long the process takes, and what outcomes you can realistically expect.

What Is the OAIC and When Can You Complain?

The Office of the Australian Information Commissioner is the independent Commonwealth regulator for privacy and freedom of information. You can lodge an OAIC complaint when an Australian Privacy Principles entity — most federal government agencies and private sector organisations with turnover above $3 million — has interfered with your privacy.

A "privacy breach" in OAIC terms usually means one of the following:

  • Your personal information was collected, used or disclosed without authorisation.
  • An organisation failed to secure your data and it was accessed, lost or stolen.
  • You were denied access to, or correction of, your own personal information.
  • Direct marketing was sent without consent or without a working opt-out.
  • A tax file number, credit report, or health record was mishandled.

Who the OAIC Cannot Help With

The OAIC does not regulate every organisation. Small businesses with annual turnover under $3 million are generally exempt (with important exceptions for health service providers, credit reporting bodies, and businesses trading in personal information). State and territory government agencies are covered by state regulators — for example, the IPC in New South Wales or OVIC in Victoria. Media organisations acting in the course of journalism are also largely exempt.

Step 1: Complain to the Organisation First

Before the OAIC will accept your complaint, you must first give the organisation a chance to respond. This is a mandatory step under section 40(1A) of the Privacy Act.

  1. Find the right contact. Look for a "Privacy Officer" or "Privacy Contact" in the organisation's privacy policy, usually linked in the website footer.
  2. Put the complaint in writing. Email is best — it creates a timestamped record. Clearly state what happened, when it happened, and what remedy you want.
  3. Reference the APPs. If you can, name the specific principle you believe was breached (e.g. APP 6 for unauthorised disclosure, APP 11 for inadequate security).
  4. Set a deadline. The organisation has 30 days to respond substantively. Note this date clearly.
  5. Keep every reply. Save emails, letters, screenshots and chat transcripts in a dedicated folder.

If the organisation does not reply within 30 days, dismisses your concern, or offers a remedy you consider inadequate, you can escalate to the OAIC.

Step 2: Gather Your Evidence

A well-documented complaint is far more likely to be investigated. The OAIC's Enquiries line receives tens of thousands of contacts each year, and strong evidence helps your matter move past triage quickly.

Essential Documents to Collect

  • Your original complaint to the organisation and all responses.
  • Dates and a timeline of events in chronological order.
  • Copies of the organisation's privacy policy at the time of the breach (use the Wayback Machine if it has since changed).
  • Any data breach notification you received under the Notifiable Data Breaches (NDB) scheme.
  • Evidence of harm — financial loss, identity theft reports, medical certificates for stress, or screenshots of leaked data.
  • Correspondence showing the organisation refused access or correction.

Writing a Clear Timeline

Investigators appreciate a one-page chronology. Use a simple format: date, event, source document. For example: "12 March 2025 — Received marketing SMS from X Pty Ltd after opting out on 1 Feb (Exhibit A)."

Step 3: Lodge the Complaint With the OAIC

Once the organisation's 30 days have elapsed, you can formally lodge. The OAIC offers three channels.

ChannelBest ForProcessing Notes
Online form at oaic.gov.auMost complainantsFastest acknowledgement, usually within 10 business days
Email (enquiries@oaic.gov.au)Attaching large evidence bundlesAllow 2–3 weeks for initial response
Post (GPO Box 5218, Sydney NSW 2001)No digital accessSlowest; add 1–2 weeks for mail handling

What the Online Form Asks

Expect to provide: your contact details, the respondent organisation, a summary of what happened, when you complained to the organisation, their response, the remedy you want, and uploads for your evidence (PDF, DOCX or JPG, generally up to 10 MB per file).

Remedies You Can Request

  • A formal apology.
  • Correction or deletion of your personal information.
  • Changes to the organisation's practices (staff training, policy updates).
  • Compensation for financial loss, non-economic loss (hurt feelings, humiliation), and aggravated damages in serious cases. Reported determinations have ranged from a few thousand dollars to over $20,000 per complainant.

Step 4: What Happens After You Lodge

The OAIC follows a structured process set out in Part V of the Privacy Act. Understanding each stage helps manage expectations about timeframes.

  1. Acknowledgement (within ~10 business days). You receive a reference number and a case officer may be assigned.
  2. Preliminary assessment. The OAIC checks jurisdiction, whether you complained to the organisation first, and whether the matter is within the 12-month lodgement window (older complaints can be rejected under s41).
  3. Conciliation. Most matters are resolved here. The OAIC facilitates a confidential discussion between you and the organisation to agree on a remedy. Around 70% of accepted complaints settle at conciliation.
  4. Investigation. If conciliation fails, the Commissioner may open a formal investigation under s40(1), compelling documents and witnesses.
  5. Determination. The Commissioner can make a binding determination under s52, including compensation orders. Determinations are published on the OAIC's website.
  6. Review. Either party can seek review by the Administrative Review Tribunal (which replaced the AAT in October 2024).

Realistic timeframes: simple matters close in 3–6 months; investigated matters can take 12–24 months; a published determination may take 2+ years.

Reporting a Notifiable Data Breach (For Organisations)

If you are reading this as a business that caused a breach rather than a victim, the NDB scheme imposes separate obligations. You must notify the OAIC and affected individuals as soon as practicable — and no later than 30 days after becoming aware — of any "eligible data breach" likely to result in serious harm.

What Counts as an Eligible Data Breach

  • Unauthorised access to, or disclosure of, personal information.
  • Loss of personal information where unauthorised access is likely.
  • A reasonable person would conclude it is likely to result in serious harm (financial, physical, psychological, reputational).

Using the Online NDB Form

The OAIC's Notifiable Data Breach form asks for: entity details, date of the breach and discovery, data types affected, number of individuals, cause, containment steps, and the notification you plan to send to affected individuals. Keep an internal register of all suspected breaches, even those you assessed as non-notifiable, with your reasoning.

Protecting Yourself After a Breach

Lodging a complaint is only part of the response. Practical self-protection matters just as much, especially if credentials, identity documents or contact details were exposed.

  1. Change passwords on the affected account and anywhere else you reused them. Use a password manager to generate unique passwords.
  2. Enable multi-factor authentication on email, banking and government services like myGov.
  3. Place a credit ban with Equifax, Experian and illion. A 21-day ban is free and can be extended.
  4. Contact IDCARE (1800 595 160) — Australia's free national identity and cyber support service.
  5. Replace identity documents if licence or passport numbers were leaked. State governments offer no-cost replacements for data breach victims in many cases.
  6. Reduce your digital footprint going forward. Share fewer personal details on forms, use alias email addresses for signups, and consider privacy-respecting link tools like Lunyb when you need to share URLs without exposing tracking parameters that profile you across sites.

Common Mistakes That Weaken a Complaint

Skipping the Internal Complaint

The OAIC will usually decline to investigate if you have not given the organisation 30 days to respond. Keep proof of your original email.

Lodging Too Late

Section 41(1)(c) allows the Commissioner to decline complaints lodged more than 12 months after you became aware of the issue. If you are near that limit, lodge now and supplement evidence later.

Overclaiming Damages

Credible, documented loss is far more persuasive than a round-number demand. If you want compensation for stress, a GP letter or counsellor note helps enormously.

Confusing Privacy With Consumer Law

Misleading advertising, defective products, or contract disputes belong with the ACCC or state fair trading offices — not the OAIC. If you are unsure, the OAIC's enquiries team on 1300 363 992 will redirect you.

Pros and Cons of the OAIC Complaints Process

Pros

  • Free to lodge — no filing fees or legal costs required.
  • Binding determinations with real compensation outcomes.
  • Conciliation is confidential and non-adversarial.
  • Published determinations create precedent that benefits others.
  • Independent of the organisation you are complaining about.

Cons

  • Timeframes can be long — months to years for complex matters.
  • No power to award punitive damages for individuals (civil penalty actions sit with the Commissioner, not you).
  • Small business exemption leaves many complainants without a federal remedy.
  • Backlog has grown significantly since the 2022–2024 wave of major breaches.

Related Reading

If you are reviewing privacy and online safety more broadly, you may find these guides useful: our 2026 buyer's guide to URL shorteners, our honest review of Lunyb, and our Rebrandly review for 2026 — all of which touch on data handling practices that matter under the Privacy Act.

Frequently Asked Questions

How much does it cost to lodge an OAIC complaint?

Nothing. Lodging a privacy complaint with the OAIC is completely free. You do not need a lawyer, though you may choose to engage one for complex matters or if you proceed to the Administrative Review Tribunal.

How long does the OAIC take to resolve a complaint?

Timeframes vary considerably. Simple matters that resolve at conciliation often close within 3–6 months. Matters requiring formal investigation can take 12–24 months, and published determinations may take over two years. The OAIC publishes annual performance data in its Corporate Plan.

Can I get compensation for a privacy breach?

Yes. Under section 52 of the Privacy Act, the Commissioner can order compensation for economic loss, non-economic loss (such as hurt feelings and humiliation), and in some cases aggravated damages. Published determinations have ranged from around $1,000 to over $20,000 per complainant, with class-style representative complaints potentially higher.

What if the organisation is a small business under $3 million turnover?

Most small businesses are exempt from the Privacy Act, though exceptions apply to health providers, credit reporting bodies, and businesses that trade in personal information. If the exemption applies, consider complaining to your state consumer affairs regulator, pursuing a civil claim for breach of confidence, or raising the issue through state-based privacy regimes where available.

Do I need to try to resolve it with the organisation first?

Yes. The OAIC requires you to complain to the organisation and give them 30 days to respond before accepting your complaint, except in limited circumstances (for example, where doing so would be unreasonable or futile). Keep written evidence of your original complaint and any response.

Can the OAIC help with overseas companies?

Sometimes. The Privacy Act has extraterritorial reach under section 5B — it applies to foreign organisations that carry on business in Australia and collect or hold personal information in Australia. Major global platforms generally fall within jurisdiction, though enforcement against purely foreign entities can be practically difficult.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles