OAIC Complaints: How to Report a Privacy Breach in Australia
If your personal information has been mishandled, exposed, or misused by an Australian organisation, you have a legal right to complain. The Office of the Australian Information Commissioner (OAIC) is the federal regulator that investigates privacy breaches under the Privacy Act 1988 — and lodging a formal complaint is often the fastest way to force accountability, secure remediation, and sometimes obtain compensation.
This guide walks you through exactly how to report a privacy breach to the OAIC in 2026: when the OAIC has jurisdiction, what evidence you need, how to submit the complaint, what happens next, and how to strengthen your own privacy hygiene while you wait for a resolution.
What Is the OAIC and When Can You Complain?
The Office of the Australian Information Commissioner is Australia's independent national regulator for privacy and freedom of information. It enforces the Australian Privacy Principles (APPs), the Notifiable Data Breaches (NDB) scheme, and related credit reporting and health information rules.
You can lodge an OAIC complaint if an entity covered by the Privacy Act has interfered with your privacy. That generally includes:
- Australian Government agencies
- Private sector organisations with an annual turnover of more than AU$3 million
- All private health service providers (regardless of turnover)
- Some small businesses (e.g. those trading in personal information, credit reporting bodies, or contracted service providers to the Commonwealth)
- TFN recipients and credit providers
What the OAIC does NOT handle
The OAIC does not investigate every privacy grievance. It typically won't handle:
- State or territory government agencies (contact the relevant state privacy regulator — e.g. IPC NSW, OVIC in Victoria)
- Individuals acting in a personal capacity (e.g. a neighbour posting about you on social media)
- Small businesses under AU$3 million turnover that don't fall into an exception
- Employee records held by your current or former private-sector employer (the "employee records exemption")
- Media organisations acting in the course of journalism
What Counts as a Privacy Breach Under the Privacy Act?
A privacy breach — technically called an "interference with privacy" — occurs when an APP entity does something that breaches one of the 13 Australian Privacy Principles or another provision of the Act. Common examples include:
- Unauthorised disclosure: Your details are shared with a third party without consent.
- Data breach: A cyber attack, lost laptop, or misdirected email exposes your information.
- Excessive collection: A business demanded ID or biometric data it did not need.
- Failure to secure data: Poor cybersecurity practices led to leakage.
- Refusal of access or correction: An organisation won't let you see or fix your own records.
- Direct marketing without consent or ignoring opt-out requests.
- Misuse of government identifiers like your TFN, Medicare, or Centrelink CRN.
Notifiable Data Breaches (NDB) scheme
Since 2018, any APP entity that experiences an "eligible data breach" likely to result in serious harm must notify both the OAIC and affected individuals as soon as practicable. If you received a data breach notification from a company like Optus, Medibank, Latitude, or your bank, that notification itself is evidence you may have grounds to complain — particularly if the response was inadequate.
Step 1: Complain to the Organisation First
The OAIC almost always requires you to complain to the organisation directly before escalating. This is not a bureaucratic hurdle — it is a formal requirement under section 40(1A) of the Privacy Act. Skipping this step is the number one reason complaints get bounced back.
- Find the right contact. Every APP entity must have a Privacy Officer or a published privacy policy with contact details. Search "[Company name] privacy policy" and look for the complaints section.
- Put your complaint in writing. Email is ideal because it creates a timestamped record. Clearly state that you are making a formal privacy complaint under the Privacy Act 1988.
- Describe the breach. Include dates, what information was involved, how you found out, and what harm has resulted.
- State what you want. Common remedies: an apology, deletion of data, correction of records, changes to their processes, or monetary compensation.
- Give them 30 days to respond. The OAIC generally expects entities to have 30 days to investigate and reply.
Step 2: Gather Your Evidence
A well-documented complaint moves much faster. Before you lodge with the OAIC, assemble a clean evidence pack:
- Copies of the entity's breach notification email or letter (if applicable)
- Your written complaint to the organisation and their response (or proof they didn't reply within 30 days)
- Screenshots showing exposed data, phishing attempts, or fraudulent activity resulting from the breach
- Bank statements or fraud reports if you have suffered financial loss
- Medical or counselling records if you have suffered psychological harm (optional but helpful for compensation)
- A timeline document listing every relevant event with dates
Step 3: Lodge Your Complaint With the OAIC
Once you have given the organisation 30 days (or they have refused to engage), you can escalate. There are three ways to lodge:
- Online form: The fastest method. Visit oaic.gov.au and use the "Privacy complaint form". You can save progress and upload attachments.
- Post: Download the form, print it, and mail it with copies (never originals) of your evidence to GPO Box 5288, Sydney NSW 2001.
- By phone: Call the OAIC Enquiries Line on 1300 363 992 if you have a disability or need help lodging. Written complaints are still preferred.
What to include in your complaint
- Your full name and contact details
- The name of the organisation and, if known, the Privacy Officer
- A concise description of the breach (aim for 1–2 pages)
- The date the breach occurred and the date you became aware
- Proof you complained to the organisation first
- The remedy you are seeking
- Copies of your evidence pack
Step 4: What Happens After You Lodge
The OAIC follows a structured process. Understanding it helps you set realistic expectations — some complaints resolve in weeks, others take a year or more.
| Stage | What Happens | Typical Timeframe |
|---|---|---|
| 1. Acknowledgement | OAIC confirms receipt and assigns a case number | 1–2 weeks |
| 2. Preliminary assessment | OAIC checks jurisdiction and whether you complained to the entity first | 2–6 weeks |
| 3. Conciliation | OAIC facilitates a resolution between you and the entity | 2–6 months |
| 4. Formal investigation | Used if conciliation fails or the matter is serious/systemic | 6–18 months |
| 5. Determination | Commissioner issues a binding decision under s 52 | Varies |
Possible outcomes
- Apology and process changes — the most common outcome
- Deletion or correction of your personal information
- Compensation — typically AU$1,000 to AU$20,000 for non-economic loss; higher amounts (AU$20,000+) in serious cases involving significant distress or financial harm
- Enforceable undertakings requiring the entity to reform practices
- Civil penalties pursued by the Commissioner against the entity (in the most serious cases, up to AU$50 million or more under the 2022 amendments)
Special Cases: Large-Scale Data Breaches
If you were caught up in a major incident such as the Optus, Medibank, Latitude, HWL Ebsworth, or MediSecure breaches, the OAIC typically opens a Commissioner-initiated investigation. You can still lodge an individual complaint — and you should, if you have suffered specific harm — but there are also options like:
- Representative complaints: Where a group of affected individuals share the same issue, one complaint can cover all of them.
- Class actions: Separate from the OAIC process, law firms often run "no win, no fee" class actions for financial compensation. You can pursue both simultaneously.
- IDCARE: Australia's free identity and cyber support service (1800 595 160) — invaluable if your ID documents were exposed.
Protecting Yourself After a Breach
Regulatory complaints take time. In the meantime, take defensive action to reduce the fallout:
- Change passwords on any account associated with the breached service, and enable multi-factor authentication.
- Place a credit ban with Equifax, illion, and Experian — this stops new credit being opened in your name.
- Replace exposed ID documents. Services Australia offers free Medicare card replacements after a breach; states offer subsidised licence and passport replacements in confirmed cases.
- Watch for phishing. Attackers exploit breach data for months. Never click unexpected links — always type URLs directly.
- Use link-safety tools. When sharing links yourself, use a reputable shortener like Lunyb that offers click analytics and secure redirects, so you can spot suspicious activity on links you control. See our honest Lunyb review and our 2026 buyer's guide for details.
- Harden your browsing. Use encrypted DNS (such as 1.1.1.1 or Quad9), a privacy-focused browser, and a password manager.
Common Mistakes That Weaken Your Complaint
- Skipping the internal complaint. The OAIC will send you back to the organisation.
- Emotional language without facts. Stick to dates, actions, and evidence.
- Not specifying a remedy. If you want compensation, say so — and justify the amount with evidence of harm.
- Missing the 12-month window. Complaints lodged more than 12 months after you became aware of the breach can be declined under s 41(1)(c). Act promptly.
- Publicly attacking the entity. Venting on social media can undermine conciliation. Keep the process private until it concludes.
When to Get Legal Help
You do not need a lawyer to lodge an OAIC complaint — the process is designed to be accessible. However, consider legal advice if:
- You have suffered significant financial loss (fraud, identity theft)
- The breach involves sensitive health, sexual orientation, or criminal record information
- You are also considering a class action
- The entity is aggressive or represented by lawyers
Community legal centres, Legal Aid, and the Australian Privacy Foundation can provide free or low-cost guidance. Some private firms operate on "no win, no fee" for representative privacy claims.
Frequently Asked Questions
How much does it cost to lodge an OAIC complaint?
Nothing. The OAIC complaints process is entirely free. You never pay a fee to lodge, conciliate, or receive a determination. Only if you engage a private lawyer or pursue a separate court action will costs arise.
How long do I have to lodge an OAIC complaint?
You should lodge within 12 months of becoming aware of the breach. The Commissioner has discretion to accept late complaints in exceptional circumstances, but you should never rely on that discretion — act as soon as you have exhausted the internal complaints process.
Can I get compensation for a privacy breach?
Yes. The Commissioner can order compensation for both economic loss (fraud, replacement costs) and non-economic loss (stress, humiliation, anxiety). Awards typically range from AU$1,000 to AU$20,000 per person, with higher amounts in cases involving sensitive information or severe distress. Class actions can deliver larger per-person outcomes but take longer.
What if the breach happened at a state government agency or small business?
The OAIC likely can't help. Contact your state privacy regulator — for example, the IPC in New South Wales, OVIC in Victoria, OIC in Queensland, or the Ombudsman in states without a dedicated privacy commissioner. For small businesses under AU$3 million turnover with no exception, you may need to rely on the ACCC (for misleading conduct), Fair Trading, or the courts.
Will the organisation know I complained?
Yes. The OAIC will share your complaint with the entity so they can respond — that's essential to conciliation. Anonymity is not available for formal complaints, though you can raise systemic concerns anonymously via the OAIC's tip-off line without triggering an individual complaint.
Can I complain about a breach that happened years ago?
Only within roughly 12 months of you becoming aware of it. If you only just discovered a long-ago breach — for example, through a recent data-leak notification — the clock starts from your date of awareness, not the date of the breach itself. Document how and when you found out.
Final Thoughts
Lodging an OAIC complaint is one of the most effective tools Australians have to push back against careless or reckless handling of personal data. The process rewards preparation: complain to the entity first, document everything, quantify the harm, and be specific about the remedy you want. Meanwhile, treat every breach as a signal to tighten your own digital defences — strong passwords, multi-factor authentication, credit bans, and careful link hygiene will reduce the damage attackers can do with whatever data is already out there.
Privacy law in Australia is strengthening rapidly, with further reforms to the Privacy Act underway. The more Australians who exercise their complaint rights, the more accountable organisations become.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR share similar goals but differ significantly in scope, consent rules, penalties, and data subject rights. This guide compares both frameworks side by side and outlines practical compliance steps for businesses operating in Singapore.
Bill C-27 Digital Charter: What Canadian Businesses Need to Know
Canada's Bill C-27 Digital Charter Implementation Act will replace PIPEDA, introduce dedicated AI regulation, and impose penalties of up to 5% of global revenue. Here's what businesses need to know and how to prepare before the law takes effect.
ePrivacy Regulations Ireland: Latest Updates for 2026
Ireland's ePrivacy Regulations govern cookies, direct marketing, and electronic communications alongside GDPR. This 2026 guide covers the latest DPC enforcement trends, cookie consent standards, marketing rules, penalties, and a practical compliance checklist for Irish businesses.
Singapore Online Safety Act 2026: Complete Guide for Businesses and Users
Singapore's Online Safety Act framework has expanded significantly for 2026, with new codes covering AI content, stricter platform duties, and tougher enforcement by IMDA. This complete guide breaks down who must comply, what content is regulated, and how businesses and users can navigate the new rules.