facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··9 min read

If your personal information has been mishandled by an Australian business or government agency, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide walks you through exactly how to report a privacy breach, what evidence you need, how long the process takes, and what outcomes you can realistically expect.

What Is the OAIC?

The Office of the Australian Information Commissioner (OAIC) is the independent national regulator that oversees privacy and freedom of information in Australia. It administers the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs), which set out how APP entities must handle personal information.

The OAIC has the power to investigate complaints, conciliate disputes, issue determinations, accept enforceable undertakings, and — in serious or repeated cases — seek civil penalties in the Federal Court. As of late 2023, maximum penalties for serious or repeated interferences with privacy rose to A$50 million (or higher, based on turnover) for corporations.

Who Can You Complain About?

You can complain to the OAIC about:

  • Australian Government agencies
  • Private sector organisations with an annual turnover of more than A$3 million
  • Small businesses that trade in personal information, provide health services, or are contracted service providers to the Commonwealth
  • Credit reporting bodies and credit providers
  • Tax File Number (TFN) recipients

Some entities — such as state and territory government agencies, most small businesses, media organisations acting in journalism, and registered political parties — sit outside the OAIC's jurisdiction. State-based complaints usually go to the equivalent state privacy commissioner (e.g. IPC NSW, OVIC in Victoria).

What Counts as a Privacy Breach?

A privacy breach occurs when an APP entity fails to handle your personal information in line with the Australian Privacy Principles. Common examples include:

  • Unauthorised disclosure of your personal data (e.g. sending your file to the wrong person)
  • Collecting more information than is reasonably necessary
  • Failing to secure data, resulting in a data breach or hack
  • Refusing to give you access to your own personal information
  • Refusing to correct inaccurate information
  • Using your data for direct marketing without consent or an opt-out
  • Sending your data overseas without adequate protections
  • Mishandling your Tax File Number or credit information

Notifiable Data Breaches (NDB) Scheme

Under the NDB scheme, APP entities must notify affected individuals and the OAIC when a data breach is likely to result in serious harm. If you've received a data breach notification from a company (as many Australians did during the Optus and Medibank incidents), that letter itself is often the first evidence you need to lodge a complaint.

Step 1: Complain to the Organisation First

Before the OAIC will accept your complaint, you generally must give the organisation an opportunity to fix the problem. This is a mandatory first step in most cases.

  1. Identify the right contact. Look for the entity's Privacy Officer or Privacy Contact — this is required under APP 1 and is usually in their privacy policy.
  2. Put it in writing. Email is best because it creates a timestamped record. Clearly state what happened, when, and how it breached your privacy.
  3. Explain what you want. An apology? Deletion of your data? Correction? Compensation? Be specific.
  4. Give them 30 days. The OAIC generally expects the organisation to have had at least 30 days to respond before it steps in.
  5. Keep every reply. Save emails, letters, reference numbers and screenshots.

If the organisation ignores you, refuses to engage, or their response is inadequate, you can escalate to the OAIC.

Step 2: Gather Your Evidence

The stronger your evidence, the smoother the investigation. Before you lodge, compile:

  • A clear timeline of events (dates, times, who did what)
  • Copies of correspondence with the organisation
  • Any breach notification letters or emails you received
  • Screenshots of the problematic conduct (e.g. exposed data, marketing emails, error pages)
  • Evidence of harm — financial loss, identity fraud reports, medical/mental health impacts, out-of-pocket costs (for example, receipts for new ID documents)
  • Your own identity documents (the OAIC will need to verify you are the affected person)

Redact unrelated third-party details where possible. If you were caught up in a large-scale data breach, note the incident name and any reference number the company gave you.

Step 3: Lodge the OAIC Complaint

You can lodge a privacy complaint with the OAIC in several ways:

  1. Online form: The fastest option is the Privacy Complaint Form on oaic.gov.au.
  2. Email or post: You can download a PDF form and send it to enquiries@oaic.gov.au or by post to GPO Box 5218, Sydney NSW 2001.
  3. Phone assistance: Call 1300 363 992 if you need help completing the form, an interpreter, or accessibility support.

The form asks for your contact details, the respondent organisation, a description of the breach, what you've already done to resolve it, and the outcome you're seeking. There is no fee for lodging an OAIC complaint.

Time Limits

You should lodge your complaint within 12 months of becoming aware of the breach. The Commissioner can decide not to investigate stale complaints, so don't sit on it.

Step 4: What Happens After You Lodge

The OAIC follows a fairly consistent process, though timelines vary depending on complexity and workload.

StageWhat HappensTypical Timeframe
1. AcknowledgementOAIC confirms receipt of your complaint1–2 weeks
2. AssessmentOAIC checks jurisdiction and whether you complained to the entity first4–8 weeks
3. Preliminary inquiriesContacts the organisation for their side1–3 months
4. ConciliationOAIC helps both parties reach a resolution3–6 months
5. Investigation / DeterminationFormal investigation if conciliation fails6–18 months

The majority of complaints are resolved through conciliation, which is a facilitated negotiation rather than a court process. If conciliation succeeds, you might receive an apology, corrections to your data, a change in the organisation's practices, or a modest compensation payment.

Step 5: Possible Outcomes and Remedies

If your complaint is upheld, common remedies include:

  • Apology — written and, occasionally, public
  • Access or correction to your personal information
  • Deletion of information unlawfully collected or held
  • Policy or system changes at the organisation
  • Staff training commitments
  • Compensation for economic loss (e.g. cost of replacing an ID) and non-economic loss (e.g. distress, humiliation)

Compensation amounts vary widely. Historically, non-economic loss awards in individual determinations have ranged from around A$3,000 to A$20,000, with higher awards in aggravated cases. In representative complaints (class-action style), aggregate outcomes can be significantly larger.

If You're Not Happy With the Outcome

If the Commissioner makes a formal determination you disagree with, you can apply to the Administrative Review Tribunal (ART, which replaced the AAT in late 2024) for review. Determinations are enforceable in the Federal Court or Federal Circuit and Family Court.

Representative (Class) Complaints

If a single incident affects many people — think large-scale data breaches — a representative complaint can be lodged on behalf of a group. This is how many of the post-2022 mega-breach cases have progressed. You don't need to be the lead complainant to benefit; you can typically opt in once a representative complaint is on foot.

Practical Tips to Strengthen Your Complaint

1. Be Concrete About Harm

"I feel unsafe" is understandable but weak on its own. Pair it with specifics: "I've received three scam calls referencing my leaked date of birth," or "I spent A$92 replacing my driver's licence and 6 hours on the phone with my bank."

2. Stick to the Facts

Investigators read hundreds of complaints. A tight, chronological summary — even just one page — is more effective than a long emotional narrative. Attach detail as annexures.

3. Reference the APPs

You don't have to be a lawyer, but citing the principle you believe was breached (e.g. "APP 11 — security of personal information") shows the OAIC exactly where to look.

4. Protect Yourself Going Forward

While your complaint is pending, take steps to limit further exposure: enable multi-factor authentication, request a credit ban with Equifax, Illion and Experian, monitor your accounts, and be cautious about oversharing personal data with new services. Using tools that minimise data leakage — encrypted DNS, privacy-focused browsers, and reputable link management platforms like Lunyb for sharing URLs without exposing tracking-heavy referrers — can reduce your ongoing footprint.

5. Don't Discuss the Case Publicly

Public commentary (especially on social media) can complicate conciliation. Save your account for the investigator.

When to Get Legal Help

Most OAIC complaints don't require a lawyer, and community legal centres such as Justice Connect and state-based CLCs can help for free. Consider paid legal advice if:

  • Your case involves large financial loss or serious identity fraud
  • You're joining or leading a representative complaint
  • The respondent is aggressively defending and threatening counter-action
  • You want to explore parallel remedies (e.g. contract law, negligence, defamation)

Related Reading

If you're thinking more broadly about the tools and services you trust with your data, you might also find these guides useful:

Frequently Asked Questions

How long do I have to lodge an OAIC privacy complaint?

You should complain within 12 months of becoming aware of the breach. The Commissioner has discretion to accept later complaints but is not obliged to. Lodging promptly also makes evidence-gathering easier and demonstrates that you took the matter seriously.

Does it cost anything to complain to the OAIC?

No. Lodging a privacy complaint is free. There are also no filing fees for representative complaints. You may incur costs if you decide to hire a private lawyer, but this isn't required — the OAIC's process is designed to be accessible without legal representation.

Can I get compensation for a privacy breach in Australia?

Yes. If the OAIC finds in your favour, remedies can include compensation for both economic loss (out-of-pocket costs) and non-economic loss (stress, humiliation, damage to reputation). Amounts in individual determinations typically range from a few thousand to around A$20,000, with larger sums possible in serious or aggravated cases and in representative complaints.

What if the organisation isn't covered by the Privacy Act?

Many small businesses (annual turnover under A$3 million) and most state government agencies aren't covered by the federal Privacy Act. In those cases, look to your state or territory privacy regulator — for example, IPC NSW, OVIC (Victoria), OIC Queensland, or the equivalent in WA, SA, Tasmania, the ACT or NT. Health information often has its own state-based regime as well.

Will making a complaint hurt my relationship with the organisation?

The Privacy Act prohibits organisations from victimising complainants. In practice, most complaints are handled discreetly by a privacy team that's separate from customer-facing staff. If you experience retaliation — such as service being cut off or aggressive legal threats — that's itself something the OAIC will take seriously and can factor into remedies.

Final Thoughts

Australia's privacy regime has real teeth in 2026, and the OAIC complaints process is one of the most accessible ways for individuals to hold organisations accountable. It's free, doesn't require a lawyer, and — even when compensation is modest — can drive genuine change in how companies treat your personal information. If your data has been mishandled, document what happened, give the organisation a chance to fix it, and don't hesitate to escalate. The system exists precisely because privacy is a right, not a favour.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles