facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··10 min read

If your personal information has been mishandled, exposed, or misused by an Australian business or government agency, you have the right to make a formal complaint to the Office of the Australian Information Commissioner (OAIC). Understanding how to lodge an OAIC complaint properly can be the difference between a dismissed case and a meaningful investigation that holds an organisation accountable.

This guide explains what the OAIC does, when you can complain, how to prepare your evidence, and what outcomes to expect under the Privacy Act 1988 (Cth).

What Is the OAIC?

The Office of the Australian Information Commissioner (OAIC) is the independent federal regulator responsible for overseeing privacy, freedom of information, and government data governance in Australia. It enforces the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs), which set out how organisations must collect, store, use, and disclose personal information.

The OAIC has the authority to investigate complaints, conduct own-motion investigations, issue determinations, and — since the 2022 amendments — seek civil penalties of up to $50 million for serious or repeated interferences with privacy.

Who the OAIC Regulates

  • Australian Government agencies
  • Private-sector organisations with an annual turnover above $3 million
  • All health service providers (regardless of turnover)
  • Credit reporting bodies and credit providers
  • Tax File Number (TFN) recipients
  • Businesses that trade in personal information

Small businesses with turnover under $3 million are generally exempt, though exceptions apply. State and territory government agencies are usually covered by their own state-level privacy regulators, not the OAIC.

What Counts as a Privacy Breach?

A privacy breach occurs when an organisation covered by the Privacy Act mishandles your personal information in a way that contravenes one of the Australian Privacy Principles. Not every mistake is a breach in the legal sense, but many everyday incidents qualify.

Common Examples of Reportable Breaches

  • Your data was exposed in a cyber incident or unauthorised access event
  • An organisation shared your information with a third party without consent
  • A company refused to give you access to your own personal data
  • Incorrect information was recorded and the organisation refused to fix it
  • Marketing communications continued after you opted out
  • Sensitive information (health, biometric, financial) was collected without a clear lawful basis
  • An employee accessed your file without a legitimate reason
  • Personal data was sent overseas without adequate protection

The Notifiable Data Breaches (NDB) Scheme

Under the NDB scheme, organisations must notify affected individuals and the OAIC when a data breach is likely to result in serious harm. If you received a breach notification letter, that is often your first signal that you may have grounds to complain — especially if you believe the organisation's response was inadequate.

Step 1: Complain to the Organisation First

The OAIC will almost always ask whether you have first raised the issue directly with the organisation involved. This is a mandatory step in most cases, and skipping it can result in your complaint being deferred or dismissed.

  1. Identify the right contact. Most organisations list a Privacy Officer or Privacy Contact on their website's privacy policy.
  2. Put your complaint in writing. Email is ideal because it creates a timestamped record.
  3. Describe the breach clearly. Include dates, what happened, which information was involved, and how you found out.
  4. State what you want. Access, correction, deletion, an apology, compensation, or process changes.
  5. Set a reasonable deadline. The OAIC generally considers 30 days to be reasonable for a response.

If the organisation does not respond within 30 days, or the response is unsatisfactory, you can escalate to the OAIC.

Step 2: Prepare Your Evidence

A strong complaint is built on documentation. Before lodging with the OAIC, gather everything that supports your version of events.

Evidence Checklist

  • Copies of your original written complaint to the organisation
  • Any response you received (or proof of no response)
  • Screenshots of the data exposure, breach notification emails, or unwanted communications
  • Contracts, terms and conditions, or privacy policies in force at the time
  • A timeline of events with specific dates
  • Evidence of harm — financial loss, identity theft attempts, emotional distress, medical records
  • Names of any staff you dealt with

Keep digital copies backed up. When sharing evidence such as screenshots with the OAIC, avoid public file-sharing links. A privacy-focused link management tool like Lunyb lets you generate controlled, trackable short URLs to shared documents so you know exactly who has accessed them — useful when coordinating with legal advisors or handling correspondence trails.

Step 3: Lodge Your Complaint with the OAIC

Once you have given the organisation a chance to respond, you can formally lodge with the OAIC. There is no fee to make a complaint.

How to Lodge

  1. Online form: The fastest method is via the OAIC's Privacy Complaint form at oaic.gov.au.
  2. Post: Send to GPO Box 5288, Sydney NSW 2001.
  3. Phone: Call the OAIC enquiries line on 1300 363 992 for assistance.
  4. Email: enquiries@oaic.gov.au (attach your written complaint and evidence).

Information You'll Need to Provide

  • Your full name and contact details
  • The name of the organisation you're complaining about
  • A clear description of what happened and when
  • What steps you have already taken
  • The outcome you are seeking
  • Supporting documents

Step 4: What Happens After You Lodge

The OAIC follows a structured process. Understanding it helps you set realistic expectations, since privacy investigations can take months.

The OAIC Complaint Process

StageWhat HappensTypical Timeframe
1. AcknowledgementOAIC confirms receipt of your complaintWithin 2 weeks
2. Initial assessmentOAIC decides whether the matter is within jurisdiction4–8 weeks
3. ConciliationOAIC tries to help both parties reach a resolution2–6 months
4. InvestigationFormal inquiry if conciliation fails or matter is serious6–12+ months
5. DeterminationLegally binding decision under s 52 of the Privacy ActVariable

Possible Outcomes

  • Apology or acknowledgement from the organisation
  • Correction, access, or deletion of your personal information
  • Compensation for economic loss and non-economic loss (distress, humiliation)
  • Systemic changes to the organisation's privacy practices, staff training, or policies
  • Civil penalties in serious cases involving repeated or egregious breaches

Compensation awards in Australia have historically been modest — often between $3,000 and $20,000 for non-economic loss — but this is trending upward, particularly following high-profile breaches at major telcos, health insurers, and financial institutions.

When the OAIC May Decline Your Complaint

Not every complaint proceeds. The Commissioner has discretion to decline or discontinue a matter under section 41 of the Privacy Act.

Common Reasons Complaints Are Declined

  • The organisation is not covered by the Privacy Act (e.g. small business exemption)
  • You did not first complain to the organisation
  • The complaint was lodged more than 12 months after you became aware of the issue
  • The matter is trivial, vexatious, or lacks substance
  • Another body (such as a court or industry ombudsman) is better placed to handle it
  • The organisation has already adequately dealt with the complaint

If your complaint is declined, you may be able to seek review through the Administrative Appeals Tribunal (AAT) in limited circumstances, or pursue other avenues such as an industry-specific ombudsman.

Alternatives and Complementary Actions

The OAIC is not the only avenue for privacy grievances. Depending on the situation, other bodies may offer faster or more targeted outcomes.

Other Regulators and Ombudsmen

  • Telecommunications Industry Ombudsman (TIO) — for telco privacy issues
  • Australian Financial Complaints Authority (AFCA) — for banks, insurers, superannuation
  • State privacy regulators — e.g. IPC NSW, OVIC in Victoria, for state government agencies
  • Australian Cyber Security Centre (ACSC) — to report cybercrime and data theft
  • IDCARE — free national identity and cyber support service
  • ASIC and ACCC — for scams and misleading conduct linked to privacy

Protecting Yourself After a Breach

Lodging a complaint is only one part of your response. While the OAIC process plays out, take practical steps to protect yourself from downstream harm such as identity theft, phishing, or credential stuffing attacks.

Immediate Protective Steps

  1. Change passwords for any affected accounts and enable multi-factor authentication.
  2. Place a credit ban with Equifax, illion, and Experian — free for 21 days and renewable.
  3. Monitor bank and superannuation accounts daily for a few weeks.
  4. Report to Scamwatch if you receive follow-up phishing attempts.
  5. Consider replacing identity documents if driver's licence or passport numbers were exposed — most states now offer free replacements for verified breach victims.
  6. Use encrypted DNS and private browsers to reduce ongoing tracking and metadata exposure.
  7. Audit your digital footprint and remove unnecessary accounts and old data.

For anyone routinely sharing links — whether journalists coordinating with sources, small businesses running campaigns, or individuals distributing sensitive documents — tools that give you visibility into who clicks what matter. Explore our 2026 buyer's guide to URL shorteners for a comparison of privacy-conscious options, or read our honest review of Lunyb for an in-depth look at one Australian-friendly option.

Tips for a Successful OAIC Complaint

OAIC caseworkers handle thousands of complaints a year. Making yours easy to assess dramatically improves your chances of a good outcome.

Best Practices

  • Be concise. A chronological summary of 1–2 pages is more effective than a 20-page narrative.
  • Cite the APP. If you can, say which Australian Privacy Principle you believe was breached (e.g. APP 6 — use or disclosure, APP 11 — security).
  • Quantify harm. Bank statements, invoices, medical bills, or a written account of distress all help.
  • Stay professional. Emotional language weakens otherwise strong complaints.
  • Respond promptly. If the OAIC or the organisation asks for more information, reply quickly — delays can cause your file to stall.
  • Keep records of everything, including phone calls (date, time, who you spoke to, what was said).

Recent Trends in Australian Privacy Enforcement

Australia's privacy landscape has shifted significantly since 2022. The Privacy Legislation Amendment (Enforcement and Other Measures) Act increased maximum penalties, and the ongoing Privacy Act Review is expected to introduce a statutory tort for serious invasions of privacy, a direct right of action for individuals, and tighter rules on small business exemptions and children's data.

Practically, this means the OAIC is becoming more assertive, and organisations are under greater pressure to resolve complaints early. Complainants today are more likely to receive meaningful outcomes than five years ago, particularly for breaches involving sensitive information or large-scale data exposure.

Frequently Asked Questions

How long do I have to lodge an OAIC complaint?

Generally, you should lodge within 12 months of becoming aware of the breach. The OAIC can decline complaints made outside this window unless you have a good reason for the delay, such as ongoing negotiations with the organisation or newly discovered evidence.

Does it cost anything to complain to the OAIC?

No. Lodging a privacy complaint with the OAIC is completely free. You do not need a lawyer, although you can engage one if the matter is complex or involves significant potential compensation.

Can I complain about a small business?

Usually not, because businesses with annual turnover under $3 million are generally exempt from the Privacy Act. However, exceptions exist — including all health service providers, businesses trading in personal information, and contractors delivering services to the Commonwealth. The proposed removal of the small business exemption is a key reform under discussion in 2025–2026.

Will my name be shared with the organisation?

Yes. To investigate a complaint fairly, the OAIC must share your identity and the substance of your allegations with the organisation you are complaining about. Anonymous complaints cannot generally be pursued, though you can raise general concerns anonymously through the OAIC's enquiries line.

Can I get compensation for stress or anxiety from a privacy breach?

Yes. The OAIC can award compensation for non-economic loss, including humiliation, injury to feelings, anxiety, and distress. Awards typically range from a few thousand dollars to over $20,000 depending on severity, though larger amounts have been ordered in cases involving sensitive health or financial data.

What if the OAIC's decision goes against me?

You may be able to apply for review through the Administrative Appeals Tribunal (AAT), or pursue the matter through the courts if applicable. Seek independent legal advice — community legal centres and Legal Aid can help if you cannot afford a private lawyer.

Final Thoughts

Reporting a privacy breach to the OAIC can feel intimidating, but the process is designed to be accessible without legal representation. The key is preparation: complain to the organisation first, document everything, cite the relevant Australian Privacy Principles where you can, and be realistic about timeframes. As Australia's privacy regime continues to strengthen, individual complaints are playing a bigger role in shaping how organisations handle personal information — and every well-made complaint helps raise the standard for everyone.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles