facebook-pixel

OAIC Complaints: How to Report a Privacy Breach in Australia

L
Lunyb Security Team
··9 min read

If an Australian organisation has mishandled your personal information, you have the right to complain to the Office of the Australian Information Commissioner (OAIC). This guide explains exactly how to report a privacy breach, what evidence you need, how long the process takes, and what outcomes you can realistically expect.

What Is the OAIC and When Can You Complain?

The Office of the Australian Information Commissioner (OAIC) is the independent federal regulator responsible for enforcing the Privacy Act 1988 and the 13 Australian Privacy Principles (APPs). It handles complaints from individuals whose personal information has been mishandled by an APP entity — including most Australian Government agencies and private-sector organisations with an annual turnover above $3 million.

You can lodge an OAIC complaint if you believe an organisation has:

  • Collected your personal information unfairly or without consent
  • Used or disclosed your data for a purpose you didn't agree to
  • Failed to secure your information, resulting in a data breach
  • Refused to give you access to your own personal information
  • Refused to correct inaccurate data on request
  • Sent unsolicited direct marketing without a valid opt-out
  • Transferred your data overseas without appropriate safeguards

Who the OAIC Cannot Help With

The OAIC does not handle every privacy issue. It generally cannot investigate:

  • Small businesses with turnover under $3 million (with some exceptions like health providers)
  • State or territory government agencies — these fall under state privacy regulators
  • Individuals acting in a personal capacity
  • Media organisations acting in the course of journalism
  • Registered political parties and political acts

For those matters, you may need to contact a state privacy commissioner (e.g. IPC NSW, OVIC in Victoria) or a different regulator like the ACMA for spam and telemarketing complaints.

Step 1: Complain Directly to the Organisation First

Before the OAIC will accept your complaint, you must give the organisation a chance to fix the problem. This is a mandatory step under section 40(1A) of the Privacy Act.

  1. Identify the right contact. Most APP entities are required to publish a Privacy Policy that names a Privacy Officer or complaints contact.
  2. Put your complaint in writing. Email is ideal because it creates a timestamped record.
  3. Be specific. Describe what happened, when it happened, what personal information was involved, and how you want the issue resolved (deletion, correction, apology, compensation).
  4. Set a reasonable deadline. The OAIC considers 30 days a reasonable response period.
  5. Keep everything. Save copies of your complaint, any acknowledgements, and the final response.

If the organisation refuses to respond, gives an unsatisfactory answer, or ignores you for 30 days, you can escalate to the OAIC.

Step 2: Gather Your Evidence

A well-documented complaint moves faster and is more likely to succeed. The OAIC will assess your matter based on what you can prove, not just what you allege.

Key Documents to Collect

Evidence TypeWhy It Matters
Screenshots of the breach or notificationShows exactly what was exposed and when you learned of it
Copies of correspondence with the organisationProves you attempted internal resolution first
The organisation's privacy policy at the relevant timeEstablishes what they promised to do
Records of any financial or emotional harmSupports claims for compensation
Data breach notification emails or lettersConfirms the entity's own admission
A written timeline of eventsHelps the case officer understand the sequence quickly

Step 3: Lodge Your OAIC Complaint

Once you have waited 30 days or received an unsatisfactory response, you can formally lodge with the OAIC. There is no fee.

How to Submit

  1. Online form: The fastest option, available at oaic.gov.au. You'll be guided through fields for your details, the respondent, and a description of the breach.
  2. Post or email: Download the Privacy Complaint Form (P43) and send it to the OAIC's Sydney office or enquiries@oaic.gov.au.
  3. Phone: Call 1300 363 992 if you need help with the form or have accessibility requirements.

What Your Complaint Should Include

  • Your full name and contact details
  • The name of the organisation you're complaining about
  • A clear description of what happened and when
  • Which Australian Privacy Principles you believe were breached (if known)
  • Copies of your prior complaint and the organisation's response
  • The outcome you're seeking

Step 4: What Happens After You Lodge

The OAIC's complaint handling process follows a predictable series of stages, though timeframes vary considerably depending on complexity and current caseload.

The OAIC Process Timeline

StageTypical TimeframeWhat Happens
Acknowledgement1–2 weeksOAIC confirms receipt and assigns a reference number
Preliminary assessment4–8 weeksCase officer decides if the complaint falls within jurisdiction
Conciliation2–6 monthsOAIC facilitates a negotiated resolution between you and the respondent
Investigation6–12+ monthsFormal inquiry if conciliation fails or the matter is serious
DeterminationVariableBinding decision under section 52 of the Privacy Act

Possible Outcomes

If your complaint is upheld, the Commissioner can order the organisation to:

  • Apologise formally
  • Change its practices or policies
  • Correct, destroy, or return your personal information
  • Pay compensation for financial loss, humiliation, or injury to feelings
  • Undertake staff training or independent audits

Compensation awards typically range from a few hundred dollars to tens of thousands, with larger amounts reserved for serious systemic breaches or significant emotional harm.

Notifiable Data Breaches: A Special Category

Since February 2018, the Notifiable Data Breaches (NDB) scheme requires APP entities to notify affected individuals and the OAIC when a breach is likely to result in serious harm.

What Counts as a Notifiable Breach

A notifiable data breach occurs when:

  1. There is unauthorised access to, disclosure of, or loss of personal information held by an entity
  2. The breach is likely to result in serious harm to affected individuals
  3. The entity has been unable to prevent the risk of serious harm through remedial action

If You Receive a Data Breach Notification

Act quickly to protect yourself:

  • Change passwords on the affected service and anywhere you reused them
  • Enable multi-factor authentication (MFA) on all important accounts
  • Place a temporary ban on your credit file with Equifax, illion and Experian
  • Monitor bank and superannuation statements for unusual activity
  • Consider applying for new identity documents if driver licence or passport numbers were exposed — IDCARE (1800 595 160) offers free support
  • Keep the notification letter — you may need it if you later complain to the OAIC

Reducing Your Exposure Before the Next Breach

The best complaint is the one you never have to file. Data breaches will continue happening at Australian organisations, but you can shrink the amount of personal information any single incident exposes.

Practical Steps to Limit Your Data Footprint

  • Use email aliases when signing up for newsletters, promotions and low-trust services so a leaked address doesn't tie back to your primary inbox.
  • Adopt a password manager so every account has a unique credential — the difference between one compromised login and dozens.
  • Turn on encrypted DNS (DNS-over-HTTPS) in your browser and router so your browsing lookups aren't logged in plaintext by intermediaries.
  • Prefer privacy-respecting browsers like Firefox or Brave with tracker blocking enabled by default.
  • Be careful with link shorteners. Some services log clicks, IP addresses and referrers indefinitely. If you share links publicly or in marketing, choose a shortener with a clear privacy policy — services like Lunyb publish exactly what click data is retained. For a broader look at options, our 2026 buyer's guide to URL shorteners compares privacy practices across major providers.
  • Request deletion under APP 11 from any service you no longer use. Entities must destroy or de-identify personal information they no longer need.

If You're Unhappy with the OAIC's Decision

Not every complainant walks away satisfied. If the OAIC decides not to investigate or makes a determination you disagree with, you have options.

Review Rights

  1. Internal review: Ask the OAIC to reconsider a decision to close your complaint under section 41.
  2. Administrative Appeals Tribunal (AAT): Apply for review of a section 52 determination within 28 days.
  3. Federal Court: Enforce a determination as a court order if the respondent refuses to comply.
  4. Commonwealth Ombudsman: Complain about the OAIC's own conduct if you feel the process was mishandled.

Common Mistakes That Weaken a Complaint

OAIC case officers see the same avoidable errors repeatedly. Steering clear of these gives your complaint a much stronger chance.

  • Skipping the internal complaint step. The OAIC will usually send you back to the organisation first.
  • Complaining too late. The Commissioner may decline matters older than 12 months without a good reason for the delay.
  • Being vague. "They misused my data" without specifics rarely progresses. Name dates, systems, and the exact information involved.
  • Emotional language over facts. Case officers respond to evidence, not anger. Keep the tone professional.
  • Asking for outcomes outside the OAIC's power. The regulator cannot fine you personally or jail executives — focus on realistic remedies.
  • Failing to keep records. If you can't produce the original complaint email, it becomes your word against theirs.

Frequently Asked Questions

How long do I have to lodge an OAIC complaint after a privacy breach?

You should complain within 12 months of becoming aware of the breach. The Commissioner has discretion to accept older complaints where there's a reasonable explanation for the delay, such as ongoing negotiations with the organisation or a recent data breach notification revealing a historical incident.

Does it cost anything to complain to the OAIC?

No. Lodging a privacy complaint with the OAIC is completely free, and you don't need a lawyer. The OAIC provides free interpreter services and can accommodate accessibility needs. If your matter proceeds to the Administrative Appeals Tribunal, there may be application fees at that stage.

Can I get compensation for a privacy breach in Australia?

Yes. Under section 52 of the Privacy Act, the Commissioner can order compensation for financial loss, non-economic loss (such as humiliation, embarrassment or distress), and aggravated damages in serious cases. Awards commonly range from $1,000 to $20,000 for individuals, with larger sums possible in representative complaints involving many affected people.

What's the difference between a data breach notification and an OAIC complaint?

A notifiable data breach is the organisation's obligation — they must tell you and the OAIC when your data is compromised in a way likely to cause serious harm. An OAIC complaint is your action — you lodge it if you believe the organisation broke the Privacy Act, whether or not a formal notification was issued. Receiving a breach notification is often the trigger for a complaint but not a substitute for one.

Can I complain about a small business that mishandled my data?

Generally the Privacy Act only covers businesses with annual turnover over $3 million, but there are important exceptions. Small businesses are still covered if they are health service providers, trade in personal information, are contracted service providers to the Commonwealth, or are related to a larger APP entity. If in doubt, contact the OAIC's enquiries line — they can quickly confirm jurisdiction.

Final Word

Australia's privacy framework gives individuals real recourse when their personal information is mishandled — but the system rewards preparation. Complain to the organisation first, document everything, be specific about the harm, and know which Australian Privacy Principles apply to your situation. Reforms currently before Parliament are expected to expand the OAIC's powers further, including a direct right of action in the Federal Court, so understanding the current process is a useful foundation for what's coming next.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles