OAIC Complaints: How to Report a Privacy Breach in Australia
If your personal information has been mishandled, leaked, or exposed by an Australian business or government agency, you have a legal right to complain. The Office of the Australian Information Commissioner (OAIC) is the national regulator that handles privacy complaints under the Privacy Act 1988. This guide explains exactly how to lodge an OAIC complaint, what evidence to gather, how long the process takes, and what remedies you can realistically expect.
What Is the OAIC and When Should You Complain?
The Office of the Australian Information Commissioner is the independent Commonwealth regulator responsible for enforcing the Privacy Act, the Australian Privacy Principles (APPs), and the Notifiable Data Breaches (NDB) scheme. It investigates complaints against Australian Government agencies and most private sector organisations with an annual turnover of more than $3 million, along with health service providers, credit reporting bodies, and TFN recipients of any size.
You should consider lodging a complaint with the OAIC when an entity covered by the Privacy Act has done something that appears to breach one of the 13 Australian Privacy Principles. Common examples include:
- Your personal data was exposed in a data breach and you were not properly notified.
- A company refused a reasonable request to access or correct your data.
- Your information was disclosed to a third party without your consent.
- An organisation collected sensitive information (health, biometric, financial) without a lawful basis.
- Direct marketing continued after you opted out.
- Your tax file number or credit report was misused.
What the OAIC Cannot Handle
The OAIC does not deal with complaints about small businesses (unless they fall into a special category), state or territory government agencies, most employee records, media organisations acting in a journalistic capacity, or political parties. State-based bodies such as the Information and Privacy Commission NSW, OVIC in Victoria, or the OIC in Queensland handle those matters instead.
Step 1: Complain Directly to the Organisation First
Before the OAIC will accept your complaint, you must give the organisation or agency a reasonable opportunity to respond. This is a mandatory first step under section 40(1A) of the Privacy Act. Skipping it is the most common reason complaints get bounced back.
- Find the privacy officer. Every APP entity must publish a privacy policy that includes contact details. Look for a "Privacy Officer", "Data Protection Officer", or "Privacy Enquiries" address.
- Put your complaint in writing. Email is best because it timestamps everything. State clearly that you are making a formal privacy complaint under the Privacy Act.
- Describe the issue factually. Include dates, reference numbers, and copies of relevant correspondence.
- Say what you want. Do you want an apology, deletion of your data, a correction, compensation, or a change in practice? Be specific.
- Give them 30 days to respond. This is the standard timeframe the OAIC expects before escalation.
If they don't respond, respond inadequately, or refuse to fix the problem, you can escalate to the OAIC. Keep every email, letter, and reference number — you will need them.
Step 2: Prepare Your Evidence
The OAIC is an evidence-driven regulator. A strong complaint is one that a case officer can assess without chasing you for additional documents. Before you lodge, assemble a clear evidence pack.
Documents to Gather
- Your original written complaint to the organisation.
- Any response you received (or proof of no response, such as read receipts).
- Screenshots of the breach — for example, an email exposing other recipients in the To field, a data breach notification, or a website leaking your details.
- Copies of the organisation's privacy policy at the time of the incident (use the Wayback Machine if it has since changed).
- A timeline of events with dates and times.
- Evidence of harm: financial loss, medical reports for stress-related conditions, screenshots of phishing or scam messages you received after the breach.
Framing the Alleged Breach
Reference the specific Australian Privacy Principle you believe was breached. Case officers process hundreds of complaints, and a submission that says "this breaches APP 6 because the organisation used my information for a secondary purpose I did not consent to" is significantly stronger than one that simply says "they leaked my data".
Step 3: Lodge the Complaint with the OAIC
Complaints are lodged through the OAIC's online privacy complaint form at oaic.gov.au. You can also submit by post, email, or fax, and translation and interpreter services are available at no cost.
Information You'll Need to Provide
- Your full name and contact details.
- The name and contact details of the respondent (the organisation or agency).
- A summary of what happened, in chronological order.
- What steps you have already taken and the outcome.
- What you want the OAIC to do about it.
- Uploaded copies of your supporting evidence.
There is no fee to lodge a complaint. You do not need a lawyer, although you may authorise someone to act on your behalf.
Step 4: What Happens After You Lodge
The OAIC follows a structured intake and investigation process. Understanding the stages helps you set realistic expectations — resolution can take anywhere from a few weeks to well over a year for complex matters.
The OAIC Complaint Journey
| Stage | What Happens | Typical Timeframe |
|---|---|---|
| Acknowledgement | You receive a case reference number and initial contact from an intake officer. | 1–4 weeks |
| Preliminary assessment | OAIC decides whether it has jurisdiction and whether the complaint should proceed. | 1–3 months |
| Early resolution / conciliation | OAIC facilitates a discussion between you and the respondent to reach an agreed outcome. | 2–6 months |
| Formal investigation | Used for serious or systemic matters. OAIC gathers evidence and may issue determinations. | 6–18 months |
| Determination | A binding decision under section 52, which can include compensation and remedial orders. | At the end of investigation |
Most complaints — around 70% according to OAIC annual reports — are resolved at the conciliation stage without a formal determination.
Remedies: What You Can Actually Get
The OAIC has broad remedial powers under section 52 of the Privacy Act. Realistic outcomes include a written apology, correction or deletion of your records, a commitment to change internal practices, staff training, and monetary compensation for economic loss and non-economic loss such as stress, humiliation, or embarrassment.
Compensation amounts in past determinations have ranged from a few hundred dollars for minor distress to tens of thousands for serious breaches involving sensitive information. In late 2024 and 2025, following amendments introduced by the Privacy and Other Legislation Amendment Act, the Commissioner also gained expanded powers to seek civil penalties in the Federal Court for serious or repeated interferences with privacy — with maximum penalties now running into the tens of millions for corporations.
The Notifiable Data Breaches Scheme
If your complaint relates to a data breach, the Notifiable Data Breaches (NDB) scheme is central. Since February 2018, APP entities have been legally required to notify affected individuals and the OAIC when a data breach is "likely to result in serious harm".
What a Compliant Notification Looks Like
- Identifies the organisation and describes the breach.
- Lists the kinds of information involved (name, address, TFN, health data, etc.).
- Recommends specific steps you can take, such as changing passwords or requesting a credit ban.
- Provides a contact point for questions.
If you were caught in a data breach and never received a notification — or the notification was vague, late, or misleading — that itself is grounds for a complaint. Late notification is treated seriously by the OAIC, particularly after the Optus and Medibank incidents reshaped public expectations.
Protecting Yourself After a Breach
Lodging an OAIC complaint addresses the regulatory side, but you still need to protect yourself operationally. Practical steps after any exposure of your personal information include:
- Place a credit ban. Contact Equifax, illion, and Experian to freeze your credit file for 21 days (extendable). This blocks identity thieves from opening new accounts.
- Enable multi-factor authentication on every important account, especially email, banking, myGov, and the ATO.
- Change reused passwords using a password manager to generate unique credentials.
- Watch for phishing. Breached data fuels highly targeted scams. Be suspicious of any unexpected SMS or email referencing the breached organisation.
- Use privacy-conscious tools for sharing links and information online. Services like Lunyb let you shorten and share URLs without exposing tracking metadata, which reduces the surface area attackers can profile you against.
- Consider replacing compromised identity documents — Services Australia and state road authorities have streamlined replacement processes for breach victims.
For a broader look at safe link-sharing tools that respect Australian privacy expectations, see our Best URL Shorteners Buyer's Guide for 2026.
Common Mistakes That Weaken a Complaint
Case officers see the same avoidable errors repeatedly. Steering around them will make your complaint significantly more likely to succeed.
- Skipping the internal complaint. The OAIC will almost always send you back to the organisation if you haven't complained there first.
- Waiting too long. The OAIC can decline complaints made more than 12 months after you became aware of the issue.
- Being emotional rather than factual. Stick to what happened, when, and why it breaches which APP.
- Asking for unrealistic remedies. Demanding a criminal prosecution or a public apology on national television will get you nowhere. Focus on proportionate outcomes.
- Not keeping copies. Every submission, every response, every reference number — keep them all.
Representative Complaints and Class Actions
If a data breach or systemic privacy failure affects many people — as with the Optus, Medibank, Latitude, or MediSecure incidents — the OAIC can accept a representative complaint on behalf of a group. You can also join private class actions in the Federal Court, which are typically run on a no-win-no-fee basis by plaintiff law firms. The two pathways are not mutually exclusive, and pursuing an OAIC complaint does not prevent you from joining a class action later.
FAQ
How long do I have to lodge an OAIC complaint?
There is no strict statutory limit, but the Commissioner can decline complaints made more than 12 months after you became aware of the act or practice. Lodge as soon as practical after the organisation has had 30 days to respond to your internal complaint.
Does it cost anything to complain to the OAIC?
No. Lodging a privacy complaint is free, and you do not need a lawyer. Interpreter and translation services are also provided at no cost if English is not your first language.
Can I get compensation through an OAIC complaint?
Yes. If the Commissioner makes a determination in your favour under section 52, they can order the respondent to pay compensation for financial loss and for non-economic harm such as distress, humiliation, or damaged reputation. Amounts vary widely based on the seriousness of the breach and the evidence provided.
What if the OAIC dismisses my complaint?
You can request an internal review, and in some cases apply to the Administrative Review Tribunal (which replaced the AAT in October 2024) for external review. You may also still be able to pursue the matter through the courts or a state-based privacy regulator if jurisdiction permits.
Is a small business ever covered by the Privacy Act?
Yes. Even businesses with turnover under $3 million are covered if they are health service providers, trade in personal information, are contracted service providers to the Commonwealth, or are related to a larger APP entity. Ongoing reforms are also expected to remove the small business exemption entirely for many categories, so it is worth checking the OAIC's current guidance for your specific situation.
This article is general information and not legal advice. For advice about your specific circumstances, consult a qualified Australian privacy lawyer or contact the OAIC directly.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act reshapes online privacy for every British internet user. Here's what the law actually requires, how it affects encryption and age checks, and practical steps to protect your data without breaking the rules.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 introduces sweeping new rights for individuals and obligations for businesses, including the right to erasure, direct court action, and the phased removal of the small business exemption. This comprehensive guide explains what has changed and how to exercise your new protections.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a complex privacy landscape shaped by PIPEDA, Quebec's Law 25, and the pending CPPA. This 2026 guide covers the laws, principles, and practical steps every Canadian organization needs to protect personal data and stay compliant.
Singapore Online Safety Act 2026: Complete Guide for Users and Businesses
Singapore's Online Safety Act 2026 introduces sweeping new duties for platforms, tougher scam and deepfake rules, and expanded regulator powers. This complete guide breaks down who must comply, the penalties involved, and what businesses and everyday users in Singapore should do to stay safe and compliant.