facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If your personal information has been mishandled by an Australian business or government agency, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). Understanding how OAIC complaints work — and how to prepare a strong one — can make the difference between a quick resolution and a case that stalls for months. This guide walks you through the entire process, from identifying a privacy breach to lodging your complaint and following it through to determination.

What Is the OAIC and When Can You Complain?

The Office of the Australian Information Commissioner (OAIC) is the independent national regulator responsible for enforcing the Privacy Act 1988 and the Australian Privacy Principles (APPs). It handles complaints about how organisations and Commonwealth agencies collect, store, use and disclose personal information.

You can lodge an OAIC complaint if you believe an entity covered by the Privacy Act has interfered with your privacy. This includes:

  • Australian Government agencies (federal departments, Services Australia, the ATO, etc.)
  • Private sector organisations with an annual turnover of more than $3 million
  • Health service providers of any size
  • Credit reporting bodies and credit providers
  • Tax File Number (TFN) recipients
  • Some small businesses that trade in personal information or contract with the Australian Government

State government agencies, most small businesses, and individuals acting in a personal capacity are generally not covered — those complaints usually go to state privacy regulators or other bodies.

What Counts as a Privacy Breach?

A privacy breach — often called an "interference with privacy" under the Act — occurs when an APP entity fails to comply with the Australian Privacy Principles or a registered APP code. Common examples include:

  • Unauthorised disclosure of your personal information to a third party
  • A data breach where your details were exposed due to poor security
  • Collection of information you didn't consent to
  • Refusal to give you access to your own personal information
  • Refusal to correct inaccurate personal information
  • Using your data for direct marketing without a lawful basis
  • Sending your information overseas without appropriate safeguards

Step 1: Complain Directly to the Organisation First

The OAIC will almost always require you to complain to the organisation first before it accepts your complaint. This is not optional — it's built into section 40 of the Privacy Act.

  1. Find the privacy officer. Every APP entity must have a privacy policy that lists a contact point. Check the organisation's website footer or its privacy policy page.
  2. Put your complaint in writing. Email is ideal because it creates a timestamped record. Clearly state what happened, when, what information was involved, and what outcome you want (an apology, correction, compensation, deletion, etc.).
  3. Give them 30 days to respond. This is the standard window the OAIC expects before it will step in.
  4. Keep every reply. Save emails, letters, reference numbers and screenshots.

If the organisation responds unsatisfactorily — or ignores you for 30 days — you can escalate to the OAIC.

Step 2: Gather Evidence Before You Lodge

A well-documented complaint is dramatically more likely to succeed. Before you open the OAIC's complaint form, collect the following:

  • A timeline. Dates the breach occurred, when you found out, and when you contacted the organisation.
  • Copies of communications. All emails to and from the organisation, including the original complaint and their response.
  • Evidence of the breach itself. Screenshots, letters received in error, notification emails, news reports about the data breach, or messages from third parties who received your information.
  • Evidence of harm. If you suffered financial loss, identity theft, emotional distress or reputational damage, document it with medical certificates, bank statements, or written statements.
  • Your requested outcome. Be specific: deletion of records, a written apology, compensation for out-of-pocket costs, systemic changes.

Protecting Yourself While You Wait

Investigations can take months. While your complaint is being handled, take practical steps to reduce further exposure: change passwords, enable two-factor authentication, place a credit ban with credit reporting bodies (Equifax, Illion, Experian), and be alert to phishing that references leaked details. When sharing links to evidence or news articles about the breach in your submission, using a privacy-respecting link tool like Lunyb can help you avoid exposing tracking parameters or referral data in your correspondence.

Step 3: Lodge Your Complaint With the OAIC

Once you've given the organisation 30 days and gathered your evidence, you can formally complain to the OAIC. There are three lodgement methods:

  1. Online form: The fastest option, available at oaic.gov.au. You'll be asked to upload supporting documents.
  2. Email or post: If your matter is complex or you have voluminous evidence, a written letter can work better.
  3. Phone (1300 363 992): Useful for early guidance, but you'll still need to submit the details in writing.

Complaints are free. You do not need a lawyer, though for high-value or complex matters — particularly involving health records or serious identity theft — legal advice from a privacy lawyer or community legal centre can be valuable.

Information You'll Need to Provide

  • Your full name and contact details
  • The name of the organisation or agency involved
  • A clear description of what happened and when
  • Copies of your complaint to the organisation and their response (or evidence they didn't respond)
  • What outcome you're seeking
  • Any supporting documents

What Happens After You Lodge

The OAIC's process is investigative rather than adversarial. It aims to resolve matters through conciliation before considering formal determinations.

Stage 1: Preliminary Assessment

An OAIC officer reviews your complaint to check jurisdiction — whether the entity is covered, whether the conduct could breach an APP, and whether you complained to the organisation first. If your complaint doesn't meet these thresholds, it can be declined under section 41 of the Privacy Act.

Stage 2: Early Resolution

If accepted, the OAIC often tries to resolve the matter informally by contacting the respondent, clarifying the facts and encouraging a negotiated outcome. Many complaints end here — with an apology, a policy change or a modest compensation payment.

Stage 3: Conciliation

If early resolution fails, the OAIC may formally conciliate. Both parties present their positions, and a Commissioner delegate helps negotiate a settlement. Conciliation is confidential and non-binding until an agreement is signed.

Stage 4: Investigation and Determination

For serious or unresolved matters, the Information Commissioner can conduct a formal investigation and issue a legally binding determination under section 52 of the Act. Determinations can order the respondent to:

  • Stop the conduct
  • Take specific steps to remedy the breach
  • Pay compensation for financial loss and/or non-economic loss (such as humiliation)
  • Publish a statement about the breach

Determinations are published on the OAIC website and can be enforced in the Federal Court or Federal Circuit and Family Court.

How Long Does an OAIC Complaint Take?

Timeframes vary widely. The OAIC publishes performance data, but a realistic expectation looks like this:

StageTypical Timeframe
Acknowledgement of your complaint1–2 weeks
Preliminary assessment1–3 months
Early resolution3–6 months
Formal conciliation6–12 months
Determination (contested)12–24+ months

Straightforward matters — a single wrong-address disclosure with a clear remedy — often resolve in a few months. Complex matters involving large data breaches, disputed facts or multiple respondents can take significantly longer.

Compensation: What Can You Actually Receive?

The OAIC has broad power to award compensation, but amounts are typically modest compared to overseas jurisdictions. Based on published determinations:

  • Minor breaches with limited harm: $1,000 – $5,000 for non-economic loss
  • Moderate breaches with clear distress: $5,000 – $20,000
  • Serious breaches (health information, identity theft, aggravating conduct): $20,000 – $50,000+
  • Financial loss: Reimbursed on top, if you can prove causation

The largest awards typically involve sensitive information (health, sexual orientation, criminal history) or where the respondent behaved unreasonably during the complaint.

Notifiable Data Breaches: A Related but Separate Regime

Since 2018, entities covered by the Privacy Act must notify the OAIC and affected individuals of "eligible data breaches" — those likely to cause serious harm. If you receive a data breach notification email, you already have strong evidence for a complaint.

You don't need to wait for the entity's own investigation to conclude. If you believe the response was inadequate — for example, notification was delayed, containment was poor, or you weren't told what data was affected — that itself can be the subject of an OAIC complaint.

When the OAIC Isn't the Right Body

Not every privacy problem belongs with the OAIC. Route your complaint elsewhere if it involves:

  • State government agencies or public hospitals: Contact your state privacy commissioner (e.g. IPC NSW, OVIC in Victoria).
  • Small businesses under $3 million turnover that don't handle health data or trade in information: Generally outside the Privacy Act — try fair trading or consumer affairs.
  • Telecommunications interception or metadata: Commonwealth Ombudsman or Inspector-General of Intelligence and Security.
  • Spam or unsolicited marketing: ACMA under the Spam Act.
  • Defamation or harassment by individuals: Court action or the eSafety Commissioner.

Practical Tips for a Stronger Complaint

  1. Be concise and factual. Emotional language weakens your credibility. Stick to what happened, backed by documents.
  2. Reference the APPs. If you can identify which principle was breached (e.g. APP 6 — use and disclosure, APP 11 — security), your complaint reads more professionally.
  3. Quantify harm. "I spent 14 hours changing passwords and $340 on credit monitoring" is stronger than "I was upset".
  4. Propose a proportionate remedy. Asking for $100,000 for a wrong-address letter undermines your credibility. Match the remedy to the harm.
  5. Respond quickly. When the OAIC asks for more information, prompt responses keep your file moving.

Protecting Your Privacy Going Forward

Prevention is easier than complaint. A few habits significantly reduce your exposure to breaches in the first place: use unique passwords stored in a reputable password manager, enable multi-factor authentication on every account that offers it, use encrypted DNS resolvers, review the privacy settings on your major accounts every six months, and be cautious about which apps you grant contact-list or location access. When you share links — whether in emails, on social media, or in complaint correspondence — consider using a link management tool that strips tracking parameters. Our own honest review of Lunyb and our 2026 URL shortener buyer's guide explain how link tools differ on privacy.

Frequently Asked Questions

Do I need a lawyer to lodge an OAIC complaint?

No. The OAIC process is designed to be accessible to individuals without legal representation. However, for complex matters — particularly involving large-scale data breaches, health information or claims of significant financial loss — a privacy lawyer or community legal centre can help you frame the complaint and negotiate a better outcome.

Is there a time limit for lodging a complaint?

The OAIC generally expects complaints within 12 months of the privacy breach or of you becoming aware of it. Complaints lodged later can still be accepted at the Commissioner's discretion if there's a good reason for the delay, but earlier is always better.

Can I complain about a data breach I heard about in the news but wasn't personally notified about?

You can only complain about interferences with your privacy. If you're a customer of an organisation that suffered a breach but weren't notified, first ask the organisation whether your information was affected. If it was and they failed to notify you, or if their response was inadequate, that becomes a valid complaint.

Will my complaint be public?

Most complaints are handled confidentially. Only formal determinations published under section 52 become public documents, and even then the OAIC often anonymises individual complainants. Conciliated outcomes remain private.

What if the organisation is based overseas?

The Privacy Act has extraterritorial reach: it applies to any entity that carries on business in Australia and collects or holds Australian personal information. So overseas platforms with Australian users are often covered. The OAIC can and does investigate offshore respondents, though enforcement is naturally more difficult when the entity has no local presence.

Final Thoughts

Lodging an OAIC complaint isn't quick, and the compensation is rarely life-changing. But the process is one of the most powerful tools Australian consumers have to hold organisations accountable for how they handle personal information. Even individual complaints contribute to systemic change: OAIC determinations shape industry practice, and patterns of complaints often trigger Commissioner-initiated investigations that can lead to civil penalties in the millions of dollars.

If your privacy has been breached, document everything, complain to the organisation first, and don't be intimidated by the process. The regulator exists precisely so that ordinary Australians have somewhere to turn.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles